A five-part inventory for your AI agent credentials

A five-part inventory for your AI agent credentials
Roy Katmor explains that AI agents are often trusted in approved studios and apps while the credentials behind them go unreviewed, creating hidden access risks. He recommends inventorying each agent’s owner, tools, credentials, effective authority, and behavior, then enforcing scoped controls and a targeted kill switch. #Orchid #RoyKatmor #HelpNetSecurity #AIagents

Keypoints

  • AI agents are being granted access without proper identity review.
  • Agents connect to HR, identity, ticketing, payroll, and internal applications.
  • OAuth tokens, API keys, service accounts, and borrowed human accounts can accumulate excessive permissions.
  • Each agent should be tracked like an application with defined owner, purpose, tools, credentials, authority, and runtime behavior.
  • Organizations should compare approved intent with observed behavior and use scoped controls, including a kill switch.

Read More: https://www.helpnetsecurity.com/2026/09/04/ai-agent-credentials-video/