From Service Accounts to Agentic Identities: A Zero Trust Governance Framework for Delegated Authority, Runtime Tool Control, and Accountable Non-Human Actors in Enterprise Cybersecurity
Abstract
Agentic AI is changing enterprise cybersecurity as AI systems move beyond passive content generation toward autonomous planning, tool use, delegated execution, and operational action. As agents connect to email, code repositories, security operations center (SOC) platforms, finance workflows, cloud services, and enterprise application programming interfaces (APIs), they increasingly function as dynamic non-human identities rather than conventional software tools or service accounts. Existing identity and access management (IAM), Zero Trust, machine identity, and AI-governance approaches remain fragmented in their treatment of delegated authority, task intent, autonomy, runtime tool use, and auditable organizational consequences. This paper addresses these gaps by proposing the AIGATE (Agentic Identity Governance, Authority, Tool-Control and Evidence) Framework. AIGATE integrates eight governance layers: agent identity registration, lifecycle governance, delegated authority mapping, intent-bound access, least agency and least privilege, runtime tool-call control, audit evidence and accountability, and revocation and resilience. The framework treats agents as governed non-human enterprise identities whose actions remain attributable to designated human and organizational roles. AIGATE is developed through a structured critical synthesis of the recent literature on agentic AI security, machine identity, Zero Trust, runtime enforcement, and AI governance, with literature-derived governance requirements mapped explicitly to the eight framework layers. Three SOC, DevOps, and finance scenarios are used as illustrative applications rather than empirical validation. The contribution is an integrated governance architecture connecting identity, delegated authority, autonomy, runtime enforcement, evidence, and revocation across the agent lifecycle.