Without effective governance, an AI agent can easily become a hidden non-human identity with access across systems and a critical role in business processes. Discover how to expose these governance gaps and control the permissions and dependencies behind them.
For years, shadow IT wasn’t contained by policy alone. It was limited by skill sets.
To build the monster spreadsheet that ran an entire department, someone had to understand references, functions and perhaps a bit of Visual Basic for Applications. Power Automate demanded its own technical knowledge.
That cognitive cost acted as a natural brake.
AI has removed that brake.
Now, anyone can describe a process in plain English, get back something that works, test it and move on. Each time this happens, they’re creating a new non-human identity, or connecting an agent to existing identities, permissions and stored connections.
That ease of creation means something new running inside the organisation, possibly unknown and potentially accessing systems and supporting a real business process.
AI agents make shadow IT harder to see
An agent may access several systems, use stored connections and run without direct supervision. If its identity, owner and dependencies are unclear, the organisation may not know what it can reach or which process now relies on it.
The organisation may only discover that dependency when the agent stops working, reaches the wrong resource or behaves in a way nobody expected.
This extends the shadow IT problem organisations already know.
A spreadsheet may contain obscure logic and depend heavily on its creator, but it usually acts when someone opens or uses it.
By contrast, an agent can operate in the background, inherit access through stored connections and take actions across several services without direct supervision.
Its operational reach is wider, while its role in the process can be harder to see.
The controls are improving, but visibility comes first
Microsoft’s controls provide identity, ownership, access reviews, lifecycle management and operational oversight for agents brought into its control plane.
The gap is everything outside that view. A self-built or embedded agent may appear only as an existing workload identity, stored connection or software grant. The organisation may therefore have no clear record of the agent itself, its owner or its role in a business process.
Discovery must come first.
Agent 365 and Entra can help inventory registered agents, while Defender for Cloud Apps, Global Secure Access and Defender for Endpoint can surface unmanaged AI activity across networks and devices. Combined with application ownership and service dependency records, these signals show where further investigation is needed.
AI agents expose a wider governance problem. Similar gaps in visibility, ownership and lifecycle management may already exist across service principals, scripts, flows and other non-human identities. Agent governance should strengthen that wider control model.
Govern the identity and capability around the agent
Every agent supporting a business process needs an accountable owner, limited access, periodic review and a clear route to shutdown. The organisation should understand what the agent can reach, which processes depend on it and whether its outputs are safe to act on.
That governance should extend to the non-human identities, connections and automations that enable the agent to operate. Ownership must cover the complete chain of access and dependency, rather than the visible agent alone.
If the owner leaves, the business process changes or the agent gains new capabilities, its access, dependencies and continued operation should be reviewed.
Apply more control as capability increases
Control should increase with capability and consequence. Low-risk experimentation can remain open, with stronger requirements introduced when an agent runs autonomously, sends data outside the organisation or gains permissions beyond its creator.
A simple assistant searching approved internal content does not need the same oversight as an agent that changes customer records, sends external communications or initiates a financial process.
Each increase in autonomy, access or potential impact should move the agent into a higher level of governance.
For instance:
Level 1: Build freely
Agents use information the maker can already access, run when asked and remain within a small audience. Platform policy blocks risky connectors and wider sharing.
Level 2: Managed self-service
Scheduled, event-driven or shared agents move into a managed environment with controlled data, sharing, expiry and ownership reviews.
Level 3: Human review
An agent that can act without supervision, reach external systems, use permissions beyond its creator or touch regulated data requires approval from the owner of the data or business risk.
Keep the control plane broad
The same governance model should cover Power Automate flows, scripts and legacy service principals.
These technologies may maintain access, move data and support critical processes, but they don’t receive the agent-specific identity protections available through Entra Agent ID.
The objective should be a consistent view of automated activity, regardless of whether it was created in Copilot Studio, Power Automate, a developer tool or a departmental platform. Otherwise, stronger agent governance may leave older and less visible routes untouched.
Resilience depends on what you can discover and contain
The immediate task is to bring AI agents into view and apply controls that reflect their access, autonomy and potential impact. The wider resilience challenge is to extend the same visibility, ownership and lifecycle discipline across the non-human identities and automations that support them.
As AI makes automation easier to create, organisations need a consistent view of what is operating, what it can access and which processes depend on it. Without that, stronger controls around agents may still leave critical activity outside effective governance.
If you need a clearer view of the AI agents and non-human identities operating across your organisation, contact the Kocho team to discuss how to strengthen discovery, ownership and access governance.
Microsoft Entra e-Guide
Move beyond legacy identity with Microsoft Entra
Discover how to:
- Migrate identity services without disrupting business operations
- Simplify provisioning with HR‑driven, API‑based workflows
- Replace fragile on‑premises components with resilient cloud controls
- Strengthen access decisions using Conditional Access
- Reduce long‑term technical debt and identity risk
Don't Miss
Great enterprise identity resources
Got a question? Need more information?
Our expert team is here to help.