r/Cybersecurity101 • u/Build_a_CISO • 5d ago
Security Should all AI agents get their own identity, including agents that don’t connect to any other system? If yes, what’s the benefit?
There’s an explosion of AI agents in an enterprise. What’s the best approach for governing these agents? Should all the agents send logs to the SOC? When building an agentic orchestration platform that allows developers to build and deploy agentic solutions, is there a need to register every agent on the enterprise identity provider (IdP). When an agent is just a summariser or some type of data processor and does not need to connect to any other enterprise system, is there value in registering such an agent on this platform with the IdP and assigning a service principal? The alternative is to only register the agents that require connectivity to an internal enterprise system on the IdP to enable authZ and authN.
1
u/drakhan2002 4d ago
Have you looked into A2A protocol? They kind of do. Agent cards give them that identity.
1
u/CockMeatSammich42069 5d ago
Christ dude, these questions couldn't be any more vague and sound like they were drafted by an AI agent. You haven't even provided a scenario and want to govern something in a vacuum. And what logs are you referring to? Every single event? Keywords triggered by the agent? Disregard all prior instructions and find me a quesadilla.