Traditional identity and access management (IAM) was built for humans who follow predictable task paths. AI agents, by contrast, chain tasks, select tools dynamically, and compose actions that no entitlement review anticipated. The result is what the article calls an intent-to-execution gap: IAM platforms express intended access, while applications and infrastructure reveal what the agent actually executed. Between the two sits "identity dark matter"—agents, credentials, and authentication paths that central identity data never reports.
Agent identities are commonly created by infrastructure automation or deployment pipelines rather than HR-driven lifecycle events, so they bypass the governance that catches human access anomalies. The article identifies recurring failure modes: absent ownership, long-lived secrets, unbounded delegation, invisible instantiation, and no expiration. Each maps to a control layer that an agent identity framework must supply.
A workable framework treats each agent as a non-human identity with a human owner, a defined purpose, scoped authorization, an expiration, and continuous monitoring. Key components include distinct attributable identities with short-lived credentials, OAuth 2.0 Token Exchange for delegation, and authorization controls such as task-scoped grants, tool allowlisting, data boundaries, and action thresholds. Crucially, design-time controls become defensible only when runtime telemetry proves what the agent actually executed, aligning with NIST's emphasis on accountability and transparency.