Securafy AI Lab

Ghost Agents: The AI Identities Your Offboarding Process Never Catches

Written by Rodney Hall | Sep 28, 2026, 3:00:00 PM

An employee builds a scheduling agent that pulls calendar data, drafts emails, and posts updates to a shared channel. She connects it to your CRM, gives it an API key with broad read and write access, and moves on to other projects within a few months. Eight months later she leaves the company for a competitor. IT disables her email, her VPN token, and her laptop, but nobody disables the agent, because nobody on the offboarding checklist knows it exists.

Ghost agents are AI agents that keep valid credentials after the employee who built or supervised them leaves. They exist because offboarding checklists cover laptops, email, and VPN access, but not the API keys and service accounts an employee set up for AI tools. Closing the gap means giving every AI agent a named owner and a decommissioning step.

This is not a rare misconfiguration limited to large enterprises with sprawling IT environments. Employees across sales, marketing, finance, and operations now spin up AI agents through tools like Zapier, Make, Copilot Studio, and internal chatbots without ever touching your identity provider or looping in IT. Each agent gets its own credential, API key, or service account permission the moment it is created. That credential outlives the person who requested it far more often than most security teams assume, and it keeps that access long after anyone remembers why it was granted.

What Exactly Counts as a Ghost Agent?

A ghost agent is any AI agent, bot, or automation whose access and permissions persist after its human sponsor is gone, whether that sponsor left the company entirely or simply moved to a different role. The agent keeps authenticating, pulling data, and triggering downstream actions with nobody reviewing what it does or why. OWASP's Non-Human Identities Top 10 puts a name to this exact failure mode, listing improper offboarding as one of its top risk categories and describing three recurring patterns behind it: stale identities left behind when an application is retired, orphaned identities whose original owner departs with no replacement assigned, and partially offboarded employees whose service credentials survive their own exit from the company.

The distinction that matters for your business is between an agent someone still owns and one nobody does. A supervised agent has a name attached to it in your systems, a defined purpose, and someone accountable for reviewing its behavior on a schedule. A ghost agent has none of that, and that absence is exactly what makes it invisible during a normal security review or audit.

Offboarding gap What happens Business consequence
Stale identity An application or workflow is retired but its agent credential is never revoked Unused access sits active indefinitely, waiting to be found by an attacker or an auditor
Orphaned identity The employee who owned the agent leaves or changes roles and no one is assigned to replace them No one is accountable for reviewing what the agent does or deciding whether to shut it down
Partial offboarding IT disables the employee's login but the service account or API key they created stays active A departed employee, or anyone who later obtains that credential, can still reach production systems

The numbers behind this pattern are not reassuring. In the same research, 31 percent of security leaders named insufficient non-human identity offboarding as one of their top three threats, and 32 percent of the non-human identity security incidents they tracked already involved an orphaned identity like the ones described above. Just as telling, 51 percent of organizations still have no formal process for revoking long-lived API keys once they are no longer needed. That means the ghost agent problem is not a future risk your business can plan around later. It is already showing up in incident data today.

How Much Risk Does an Orphaned AI Agent Actually Carry?

An orphaned agent carries risk in direct proportion to what it can touch and how long it goes unnoticed. Every day it keeps running unmonitored is another day of exposure with no one accountable for its behavior, and in most environments nobody is even watching for it. The risk does not announce itself. It accumulates quietly in the background of systems your team assumes are under control.

That assumption does not hold up well. Gartner's 2025 research on machine identity found that IAM teams are responsible for only 44 percent of an organization's machine identities, which means the majority of service accounts, API keys, and agent credentials in a typical company sit outside the team whose job is to secure them. CyberArk's 2025 identity security research puts a number on the scale of that gap: machine identities now outnumber human identities by roughly 82 to 1 inside the average organization, and half of the security leaders surveyed had already experienced a security incident tied to a compromised machine identity.

Most businesses would never let a departed employee keep their badge, their laptop, and their building access indefinitely. An unrevoked agent credential is functionally the same arrangement, except it is far harder to see, and it will not show up on anyone's badge return report.

Why Hasn't Standard IT Offboarding Caught This Already?

Standard offboarding was built for a single human identity tied to one record in your identity provider, not for the sprawl of service accounts, API tokens, and delegated permissions an employee accumulates by connecting AI tools to other systems over time. IT disables the login it knows about and calls the process complete. The agent's own credential often lives inside a separate automation platform, a SaaS admin console, or a script nobody ever documented, and that platform was never wired into your offboarding checklist in the first place.

Credential exposure compounds the problem well beyond this one gap. In the 2025 Verizon Data Breach Investigations Report, compromised credentials served as the initial access vector in 22 percent of breaches reviewed, and separate DBIR research found the median daily share of credential stuffing attempts against authentication systems reached 19 percent, climbing to 25 percent at larger organizations. An agent's credential is just as usable to an attacker as an employee's password, and it usually carries broader system access with far less scrutiny attached to it than a human login gets.

Decommissioning an agent is also not the same operation as deleting an account. The NIST AI Risk Management Framework's agentic profile, developed with the Cloud Security Alliance, treats decommissioning as its own formal step rather than an afterthought, calling for the revocation of every credential, API key, and tool authority an agent holds, along with notification to any external system that maintained a trust relationship with that agent's identity. Skip that step and dependent workflows can keep firing even after someone on your team believes the agent has been shut down.

Does My Business Need a Formal AI Agent Governance Program If We're Not a Large Enterprise?

Yes, and the smaller your IT team, the more exposed you likely already are. Large enterprises at least have dedicated identity teams chasing this problem, even if they are only catching a minority of it, as the research above shows. Small and mid-sized businesses usually have AI agents that individual employees adopted on their own initiative, with no central rollout, no approval process, and no one assigned to track what got connected to what.

The fastest way to know where you actually stand is to look, not guess. Running a structured cybersecurity assessment against your current environment will surface the service accounts, API integrations, and automation tools that never made it onto anyone's formal inventory. For most leadership teams, that assessment is the first time they see how many of these ghost agents already exist inside their own environment.

What Does a Defensible Governance Approach Look Like?

A defensible approach treats every AI agent as an identity with a full lifecycle, from the day it is provisioned through active use to formal decommissioning, with a named human accountable at each stage. That is a shift in mindset more than a shift in tooling. Most of the controls below can be built on top of processes you already run for human employee accounts, rather than requiring an entirely new system.

The cost of skipping this is measurable, not theoretical. IBM's 2025 Cost of a Data Breach report found that 97 percent of organizations that suffered an AI-related security incident admitted they lacked proper AI access controls at the time, and 63 percent had no AI governance policy in place at all. Where shadow AI use was high, it added an average of 670,000 dollars to the total cost of a breach. That is the price tag attached to exactly the gap ghost agents represent: access nobody was governing.

In practice, closing that gap means a handful of concrete changes to how your IT and security functions operate day to day:

  • Maintain an inventory of every AI agent, its credentials, and its human owner, updated whenever an agent is created or modified.
  • Make agent access review a mandatory step in offboarding, not an optional one someone remembers only if they have time.
  • Set default expiration dates on agent credentials so access lapses automatically unless someone actively renews it.
  • Review agent activity logs on a fixed schedule, not only after something already looks wrong.

Securafy's AI governance and security services build exactly this kind of lifecycle discipline into a client's existing IT operations, so agent identities get the same ownership, review cadence, and audit trail as employee accounts instead of living outside that structure entirely.

Who Should Own This Inside Your Business?

Ownership belongs with whoever already owns identity and access management for your company, typically your IT team or your managed security provider, but it only works if HR offboarding procedures get updated to include an agent access checklist alongside the badge and laptop return. Treat AI agents as a distinct identity category with its own review cadence, not as something your existing offboarding steps will catch by accident.

If you are evaluating new identity, automation, or AI platform tools as part of closing this gap, vet vendors on how they handle credential expiration and deprovisioning by default, not only on price or feature lists. Securafy's cybersecurity buyer's guide walks through the questions worth asking a vendor before you commit, including how their platform handles exactly this kind of identity lifecycle across its full lifespan.

Where To Go From Here

Ghost agents build up quietly, one unsupervised automation at a time, and the fix starts with knowing which ones your business already has running. Getting your team trained on how AI agents get created, connected, and retired closes this gap at the source, before it becomes an audit finding or worse.

If your team is moving faster with AI than your guardrails are, start with structured training rather than another tool. Securafy AI University gives your people role-based AI training with security built into the material, not bolted on afterward.

If you would rather talk through your specific environment first, book a strategy call with Securafy and we will walk your current AI usage, exposure, and the fastest path to safe adoption.