Skip to content

AI Agents Need an Identity Lifecycle Just Like Human Employees

Bottom line: AI agents with far-reaching access rights to SAP, Salesforce and ServiceNow need the same identity lifecycle of provisioning, recertification and deprovisioning as human employees to avoid losing control over core systems.

AI agents are already accessing SAP, Salesforce and ServiceNow systems autonomously, often with far-reaching permissions and without clear governance. Companies that fail to manage these agents like employees risk losing control over their core systems.

AI agents have long been in productive use at many companies, interacting autonomously with central business applications such as SAP, Salesforce and ServiceNow. In doing so, they are sometimes granted far-reaching access rights that they need to carry out their tasks. Unlike human employees, however, these agents often lack a defined governance framework that regulates, monitors and, when necessary, revokes their permissions over their entire lifecycle.

For CISOs, this represents a new category of identities that classic identity and access management processes do not cover. An AI agent that was once equipped with extensive rights often remains permanently active, even if its scope of tasks changes or it is no longer needed. Missing offboarding processes for agents increase the attack surface in core systems that contain business-critical data and processes.

The demand, therefore, is to apply the same lifecycle approach to AI agents that is established for human employees: provisioning with minimally necessary rights, regular recertification of permissions, monitoring of actual usage, and orderly deprovisioning as soon as an agent is retired or repurposed. Without these controls, a growing number of unmonitored, highly privileged identities emerges in SAP, Salesforce and ServiceNow environments.

For security leaders at DACH companies, this creates the need to expand existing identity governance programs with a dedicated category for non-human identities, or AI agents. This includes inventorying agent accounts with the same level of detail as privileged user accounts, tying access rights to specific business processes, and clearly assigning responsibilities for the ongoing maintenance of these identities.


Source: www.security-insider.de · Published August 17, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: