AI agents are entering the enterprise through SaaS apps, custom workflows, OAuth grants, and API connections. The problem is not just that they exist. It is that many teams cannot see who owns them, what they can access, or how their permissions change over time. That turns shadow AI into an identity governance gap. In Alchemy’s recent webinar with Okta, we broke down the controls IT and security leaders need if they want to support AI use without giving up visibility or access discipline.
AI agents now show up across Microsoft Copilot, AWS Bedrock, Salesforce Agentforce, Google Vertex, and custom builds. Each platform creates different credential patterns and spreads non-human identities across clouds, SaaS, and code. That fragmentation matters because many of these agents have no clear owner, no central inventory, and no lifecycle control.
The highest-risk cases are often the agents teams build for themselves. Those agents can rely on long-lived API keys, static secrets in code, shared service accounts, or old credentials that stay active long after the project changes. Once access expands, very few teams can see the full footprint in one place. That is why shadow AI is not just an AI issue. It is an identity governance issue.
A strong AI agent security program starts by treating agents as first-class non-human identities. In the webinar, Pascal outlined a four-part ownership model: a technical owner, a business owner, an IAM custodian, and a risk approver. Without those roles, agent accounts are easy to miss in access reviews, and stale credentials stay active far too long.
The control model also needs least privilege by default. That means vaulting or rotating standing credentials, using short-lived tokens where possible, adding just-in-time access for sensitive actions, and alerting on long periods of inactivity. John’s live demo made this concrete. One user could read inventory. Another could write it. The agent could only act within both the user’s permissions and the policy set for the agent itself.
The roadmap from the session was practical. Phase one is discovery across cloud and on-prem so you can enumerate service accounts, managed identities, and API keys. Phase two maps ownership and begins classification and risk scoring. Phase three rotates high-risk credentials, adds just-in-time access, and sends non-human identity events into SIEM and SOAR. Phase four folds agents into steady-state identity governance with automated provisioning, reporting, and recurring reviews.
Most teams do not need a large reset. They need a way to centralize inventory, assign accountability, and add control in stages. That is where Alchemy focuses its work. We help organizations apply architecture-first planning, advisory depth, and a practical roadmap that fits the way AI is already entering the business.
AI agent security is not a side topic anymore. If agents can act across SaaS, APIs, and internal data, they belong inside the same ownership, policy, and review model you expect for any other identity. That is where Alchemy is most useful, helping teams move from scattered agent activity to a program they can govern with confidence. Start with the recording, then book an AI Agent Security strategy session if you want to map the issue to your own environment.
AI agents may already be operating across SaaS platforms, endpoints, and custom environments. Alchemy’s AI Agent Security Mastermind helps you identify your agent footprint, assign owners, review permissions, apply runtime guardrails, and build a prioritized action plan. Book a strategy session to see where agents live, what they can access, and which controls your team should address first.