Securafy AI Lab

Your AI Agents Outnumber Your Employees 82 to 1. Who's Managing Their Access?

Written by Rodney Hall | Oct 6, 2026, 1:00:00 PM

Nobody is. That's the uncomfortable answer for most mid-sized businesses running AI agents today. Agents get provisioned fast, granted broad access to get them working, and then left alone. The access review process built for employees, with onboarding checks, periodic audits, and offboarding triggers, was never extended to the automated identities now outnumbering your staff by a wide margin.

We see this pattern in nearly every mid-sized environment we assess. A marketing team connects an agent to the CRM to draft outreach and gives it export rights it will use once. A finance team wires an agent into the accounting platform with read-write access because read-only broke a workflow on day one. Each decision made sense in isolation. None of them got revisited once the agent was working, and none of them was made by anyone thinking about what happens if that agent's credential leaks.

What's Actually Behind The 82-To-1 Identity Ratio?

CyberArk's 2025 Identity Security Landscape report, built on responses from 2,600 security decision-makers, found that machine identities now outnumber human identities by 82 to 1 inside the average organization. That number covers every service account, API key, and bot, not AI agents alone, but agents are the fastest-growing and least governed slice of that population. Every one of those 82 machine identities is a login, and a login is an access decision somebody made once and then stopped thinking about.

The same report found that 68 percent of security leaders say their organization lacks the identity controls needed for AI, and 47 percent cannot secure the AI tools employees have already adopted on their own. Those numbers describe a pattern most IT teams recognize on sight: an agent gets connected to billing, the CRM, or a shared inbox because a task needs automating this week, not because anyone mapped out what access that task actually requires.

This is also why the 82:1 figure understates the real exposure rather than exaggerating it. A human employee's access maps roughly to one job description. A single AI agent frequently touches several systems at once, email, a database, a payment processor, a scheduling tool, each connection carrying its own credential and its own permission set. Count those individually, the way most identity tooling does, and the true number of access points an agent controls is often higher than the headline ratio suggests.

Is Over-Permissioned Access A Measurable Problem, Or Just A Theoretical One?

It's measurable, and the numbers aren't close. A 2026 survey of IT and security professionals from the Cloud Security Alliance and Oasis Security found that 51 percent flagged over-permissioned access as a top non-human identity pain point, and 79 percent rated their own confidence in preventing an attack through one of these identities as low or moderate. Nearly a quarter said it takes more than 24 hours to rotate or revoke a credential once they know it has been exposed.

That delay window is where an incident becomes a breach. An agent with standing write access to your customer database doesn't need a sophisticated attacker to cause damage. A leaked key, a compromised connected app, or a bug in the agent's own logic is enough, and the blast radius is bounded only by what that agent was allowed to touch in the first place.

If you don't already know how many agents in your environment carry standing access nobody has reviewed since setup, that's worth finding out before it finds you. Securafy's cybersecurity assessment is a reasonable place to start that inventory.

How Do You Know If An Agent Already Has Too Much Access?

You know by checking what it can do against what it actually does, and most businesses have never run that comparison. A handful of signs show up consistently when we run this check for clients, and any one of them is worth acting on without waiting for the rest.

  1. The agent's credential has admin or owner-level rights instead of the specific read, write, or send permissions its task needs.
  2. Nobody can name the person accountable for that agent's access without checking with someone else first.
  3. The credential has been active for more than a year with no rotation and no expiration date.
  4. The agent can reach systems unrelated to its stated job, because it was built on a platform connection that was already broad.
  5. There is no log anyone reviews showing what the agent actually did with its access last month.

Any single item on that list is a gap. Two or three together describe an agent that is, functionally, an unmanaged privileged account with a friendly interface.

What Does Least Privilege Actually Require For An AI Agent?

It requires treating each agent as its own identity, not a shared credential borrowed from a human account or another agent. A joint guidance on agentic AI security from CISA, the NSA, and international cybersecurity partners lays out what that looks like in practice, and it goes further than most companies have gone on their own.

  • A distinct identity per agent: each agent gets its own cryptographically anchored identity, not a shared service account inherited from whichever developer set it up first.
  • Scope tied to task, not convenience: permissions get restricted to the narrowest level the agent's specific job requires, not the broadest level that avoids future support tickets.
  • Ephemeral credentials: static, long-lived secrets get replaced with credentials that expire automatically once the job finishes, instead of sitting active for months.
  • A reconciled registry: every agent and key gets checked against a trusted inventory on a set schedule, and anything not on that list gets denied by default.

Few mid-sized organizations do all four today, and trying to retrofit all of them at once usually stalls the whole effort. The practical order is to fix scope first, since narrowing what an agent can touch cuts your exposure immediately, even before you've solved identity architecture, then layer in credential expiration and registry checks as your environment matures.

This is the gap Securafy closes for clients through our AI security services, scoping and monitoring agent access as a standing part of how we manage an environment rather than a one-time cleanup project.

Who Should Own AI Agent Access Decisions Inside A Mid-Sized Business?

The same person or team that owns identity and access management for your human employees should own it for your agents too, typically IT leadership or your managed security provider. What's different is the review cadence: agent access needs checking far more often than an annual human audit, because agents get reconfigured and connected to new tools much more frequently than an employee's job changes.

In practice, that means putting agent access on the same calendar as your other security reviews rather than treating it as a separate, lower-priority task. A quarterly check of what each agent can reach, cross-referenced against what it has actually used, catches the permissions that crept in during a rushed integration long before an audit or an incident forces the question. Ownership without a recurring check is just a title on an org chart.

Access control Typical for a human employee Typical for an AI agent today
Access granted at setup Scoped to role, approved by a manager Broad, granted to get the integration working fast
Credential lifespan Rotated on a forced schedule Static and long-lived by default
Periodic access review Quarterly or annual audit Rarely reviewed again after initial setup
Named owner A manager and HR Often nobody, once the original builder moves on

That last row is where most of the risk sits. An agent without a named human owner does not lose its access when priorities shift or a project ends. It keeps running with whatever permissions it started with, and those permissions only ever get added to, never trimmed back.

If you're evaluating identity or access management tooling to close this gap, telling genuine least-privilege enforcement apart from a vendor's marketing claim matters more than the feature list. Securafy's cybersecurity buyer's guide walks through the questions worth asking before you sign a contract, including which of them apply specifically to non-human identities.

Why This Can't Wait For A Slower Rollout

The urgency here isn't hypothetical. Gartner predicts that AI agents will cut the time it takes attackers to exploit an exposed account in half by 2027, largely by automating the credential-testing and social-engineering steps that used to slow a human attacker down. An over-permissioned agent is a bigger target sitting still while that window keeps shrinking.

None of this requires new theory to solve. NIST's zero trust architecture framework has treated non-person entities, its term for service accounts and automated processes, as identities requiring the same least-privilege enforcement as any user since 2020. The gap in most companies isn't a missing standard. It's that the standard never got applied past the human accounts it was originally written to cover.

Scaling AI agents without scaling access governance alongside them is how a company ends up with 82 unmanaged identities for every employee it can actually name. Fixing that doesn't require ripping out your AI tools or slowing down adoption. It requires treating every agent the way you'd treat a new hire with system access: define the job, scope the permissions to that job, name an owner, and review it on a schedule instead of assuming it will get reviewed eventually.

Businesses that get this right tend to do one thing differently from the ones that don't: they build the access review into how an agent gets deployed in the first place, not into a cleanup project six months later. Retrofitting least privilege onto dozens of agents already running in production is slower and more disruptive than scoping it correctly before the first one goes live. If you're still early in agent adoption, that's the advantage to use while you still have it.

Where To Go From Here

The 82-to-1 ratio is not going to shrink on its own, and neither will the access those identities carry unless someone actively scopes it down. Start by finding out exactly how many agents in your environment currently have more access than their job requires.

If your team is moving faster with AI than your guardrails are, start with structured training rather than another tool. Securafy AI University gives your people role-based AI training with security built into the material, not bolted on afterward.

If you would rather talk through your specific environment first, book a strategy call with Securafy and we will walk your current AI usage, exposure, and the fastest path to safe adoption.