Machine identities now outnumber human identities by 109:1, and the gap is widening.
DevOps pipelines, cloud workloads, and the rapid adoption of AI agents, now utilized by 99% of organizations, are driving non-human identities to become the fastest-growing attack surface in cybersecurity.
In our previous discussion, we established that every identity in the enterprise is privileged. Modern privileged access management, or PAM, must extend privilege controls across workforce, endpoints, cloud infrastructure, and AI agents. While securing human access remains vital, the operational gravity of the enterprise has shifted.
Identity weaknesses played a material role in nearly 90% of recent Unit 42 incident response investigations. Attackers are no longer breaking in; they are logging in using stolen machine credentials, abusing standing privileges, and moving laterally through hidden access paths.
A recent Unit 42 investigation showed how quickly that risk can spread: An attacker used frontier AI agents to move through an enterprise network in less than 10 hours. We must move just as fast.
To stop these attacks at machine speed, identity security must evolve beyond human-centric workflows to discover, control, and govern machine and agentic identities on a single platform.
Non-Human Identities Need a New Operating Model
Unfortunately, organizations have not paid enough attention to the world of machines and agents (also referred to as non-human identities). They operate invisibly under the hood at a vastly different scale and speed than the human workforce.
In the early days, the primary risks were exposed hard-coded secrets and misconfigurations caused by manual processes. As cloud and SaaS adoption accelerated, ephemeral containers and workloads were spinning up and down in seconds, with each platform approaching authentication differently. That led to the vault sprawl and siloed tools challenge, with passwords, API keys, tokens, and secrets of every kind scattered across cloud vaults, CI/CD pipelines, configuration files, and application code. Risk compounded over the years as organizations tried to force-fit manual approaches and siloed tools instead of building a strong machine identity foundation.
Now, as enterprises introduce AI agents into this chaotic mix, their elevated privileges and non-deterministic behaviors amplify existing risks introduces new ones.
This expanding privilege control gap, compounded by the explosion of machine and agentic identities, demands a new operating model built on strong machine and agentic foundation.

The underlying challenges boil down to the three V's: Volume, variety, and velocity.
- Volume: Machine identities outnumber humans exponentially. The low incremental cost of spinning up dynamic workloads and autonomous AI agents skews this ratio daily.
- Variety: Non-human entities utilize an endless array of access credentials—API keys, OAuth tokens, JSON tokens, SSH keys, database credentials, and SSL certificates—across hybrid, multi-cloud, and multi-generational environments.
- Velocity: Workloads and AI agents operate at machine speed and scale up or down in seconds. Security controls must adapt dynamically without slowing down developer and business velocity.
The Fallacy of Extending SSO from Humans to Agents
As organizations rush to adopt AI agents, there is an immediate ask of identity security teams to quickly “enable access” for these agents—even if the organization hasn’t quite figured out their broader machine identity strategy.
AI agents may behave like humans, but they must be secured as machine workloads.
Since AI agents tend to behave like humans, there is an urge to simply lump agents in with the human workforce and extend capabilities like single sign-on, or SSO, to the world of agents.
This approach is flawed. SSO was meant to solve the human identity security challenge, so the human workforce can seamlessly access all apps without having to remember multiple passwords. Extending that philosophy to agents, which operate at machine speed and are known to hallucinate, is an inherently risky move born from identity and access management, or IAM, designed around human-centric thinking.
AI agents may behave like humans, but they must be secured as machine workloads.
The approach should be rooted in the fact that AI agents are the next evolution of machine identities. They are closer to cloud-native workloads, spinning up and down on demand and operating at a scale and speed that human-centric IAM systems were not built to handle.
Gartner Guidance Alignment: Treat AI Agents as Workloads
In their June 2026 research, IAM for AI Agents: A One-Size-Fits-All Strategy Is Guaranteed to Fail, Gartner emphasizes that treating AI agents as an entirely new, human-like user constituency leads to analysis paralysis. Instead, Gartner recommends adopting the workload premise: treating AI agents as workloads to unlock established IAM tooling, standards, and security controls. As a first step, Gartner recommends assigning each AI agent a unique workload identity using the Secure Production Identity Framework for Everyone, or SPIFFE.
By assigning AI agents a workload identity, it’s possible to leverage existing investments in secrets management, endpoint protection, and just-in-time privileged access management, or JIT PAM, to govern agents’ temporary use of human identities.
Further, instead of reinventing the wheel, Gartner recommends that organizations leverage the proven OAuth 2.0 framework to allow humans to delegate access rights to agents and workloads.
How Idira Solves for Machines and AI Agents
Aligning with Gartner’s guidance, the Idira Identity Security Platform manages AI agents as autonomous workloads. This unified approach extends the trusted machine identity and secrets management capabilities organizations already use for AI agent security.
This approach is fundamentally different from what human-centric IAM vendors offer. It’s built for a future where millions of agents will co-exist with other machine workloads federating across multiple trust domains. Idira supports standard protocols, including SPIFFE for authentication and OAuth 2.0 for authorization, within a single, unified platform. This enables agents and workloads to seamlessly leverage secrets, API keys, and other machine credentials across the enterprise estate.
Start With a Machine Identity Foundation
Idira’s approach provides organizations the robust machine identity foundation required to securely scale their agents and machine workloads instead of just extending their workforce SSO solution to accommodate agents.
This foundation extends well beyond enabling standards-based, cryptographically verifiable identities for every workload and agent. It essentially provides the plumbing to enable any workload to access any target, across any environment.
Hybrid? Multi-Cloud? Multi-generational enterprise estate? Doesn’t matter. Enterprises should be able to develop and evolve without needing to worry about what access method matches with a given target. Or whether an unexpected agent will gain privileges to a key business asset.

This foundational approach for agents ensures you don’t end up creating yet another new silo for your AI agents, independent from non-agentic, machine workloads.
New Agentic Capabilities for Non-Deterministic Workloads
AI agents differ from other machine workloads with their ability to reason, make decisions, and follow non-deterministic paths to achieve their goals.
Machine identity is the foundation. Agentic controls are the next layer. Together, they extend security and privilege controls to these non-deterministic actors without introducing silos.
Some of the key innovations in this area include:
- Unified agent and MCP registry
- Agent identity broker
- Strong access policies
- Short-lived tokens
- Clear audit separation of agent and human
- Agent activity map

We're working on more exciting innovations in this rapidly evolving space. Watch out for more in the coming months.
Discover, Control, and Govern Every Identity
Idira packages non-human identity security into a single operating framework across three pillars:
- Discover: Automatically discover secrets, cloud vaults, machine workloads, and AI agents across hybrid multi-cloud environments. Onboard entities into a centralized registry enriched with ownership context, access permissions, and risk posture.
- Control: Enforce strong authentication, zero standing privileges, or ZSP, and JIT task-based access via the Idira Agent Identity Broker. Manage on-behalf-of delegation flows to isolate agent actions from human user sessions.
- Govern: Maintain continuous compliance through detailed audit logs, separation of human vs. agent actions, automated access reviews, and complete lifecycle governance from onboarding to offboarding.
Idira Activity Insights shows how AI agents interact with tools on behalf of humans.
To provide full protection across the AI lifecycle, Idira’s agentic identity capabilities natively integrate as the AI Identity Security module within Prisma AIRS 3.0. Coupled with runtime enforcement in the AI Gateway, organizations can securely scale AI innovation without compromising enterprise security. More to come on this soon.
Secure Your Non-Human Identities at Machine Speed
Securing the AI-driven enterprise requires an identity-first control plane capable of moving at machine speed. By unifying human, machine, and agentic identity defense, Idira enables organizations to eliminate standing risk, protect critical secrets, and confidently deploy autonomous agentic workflows.
Ready to see this in action? Request a customized demo of Idira Machine and Agentic Identity Security.
FAQs
How does SPIFFE support AI agent identity security?
SPIFFE (Secure Production Identity Framework for Everyone) issues cryptographically verifiable, short-lived workload identities. Treating AI agents as workloads under SPIFFE enables automated secrets management and fine-grained access governance across multi-cloud environments.
What is the difference between machine identities and agentic identities?
Machine identities refer to non-human credentials (API keys, certificates, service accounts) used by static applications and containers. Agentic identities represent autonomous AI agents that make decisions, execute multi-step tool calls, and require real-time task-based access controls.
How does Idira integrate with Prisma AIRS 3.0?
Idira serves as its AI Identity Security control plane, managing identity governance, on-behalf-of delegation flows, and secrets. Prisma AIRS provides end-to-end security across the AI lifecycle, securing AI agents, applications, models, and data from development to deployment.