← InsightsResearchCyberJAN 2026 · 10 MIN

Identity is the new perimeter — for agents, too

Architecting non-human identity for the next decade of automation.

Ravi Subramanian
Cyber

Workload identity has been a serviceable solution for service-to-service authentication. It is not a serviceable solution for an enterprise running thousands of autonomous agents — each with its own role, scope, and trust relationship.

What changes

Identity becomes a first-class asset of the AI platform. Lifecycle, scoping, and revocation must work at agent granularity. Audit trails must record actions at the identity level — not the workload level.

Architecture pattern

We see the most credible architectures combine workload identity, ephemeral credentials, and policy-as-code into a single agent-identity plane — operated by the platform team, audited by the security team, consumed by the engineering teams.

Keep reading

More from the lab.

All insights
AI
ReportAPR 2026

The Reinvention Index 2026: agentic at scale

The benchmark on what works when AI moves from pilot to operating model — across enterprise scale and sector.

Banking
PulseAPR 2026

Banking after the agent — fee, margin, trust

What conversational AI does to fee income, margin, and trust — by region.

Industrial
BriefingMAR 2026

What sovereign AI means for European industrials

Compute, capital, and the new geography of advantage.