Full Report
Persistent AI coworkers may operate continuously with standing access, creating identity risks that existing security models were not designed to handle. Token Security explains why these agents need their own identities, owners, scoped permissions, and lifecycle controls. [...]
Analysis Summary
# Best Practices: Securing Persistent AI Coworkers
## Overview
This summary addresses the security risks associated with the "Third Wave" of AI—persistent AI coworkers. Unlike temporary session-scoped chats, these agents operate continuously with standing access. Current identity models (like human-centric OAuth) fail to account for the speed of access accumulation and the lack of distinct machine identities for these agents, leading to "access creep" and tainted audit logs.
## Key Recommendations
### Immediate Actions
1. **Inventory AI Agents:** Perform a discovery exercise to identify all AI agents, connectors, and plugins currently active in the environment.
2. **Audit Credential Sharing:** Identify instances where human credentials (OAuth tokens or session hand-offs) are being used to power persistent AI workflows.
3. **Establish Human Owners:** For every identified AI agent, assign a human "owner" responsible for its actions and access lifecycle.
### Short-term Improvements (1-3 months)
1. **Transition to Service Accounts:** Where possible, migrate AI agents from personal user accounts to dedicated service accounts to separate human and machine identities.
2. **Implement Scoped Permissions:** Refine permissions to the minimum set required for the agent’s specific task, rather than granting broad, human-level access.
3. **Cleanse Audit Logs:** Update logging procedures to distinguish between actions taken by a human and those taken by an AI agent acting on behalf of that human.
### Long-term Strategy (3+ months)
1. **Automated Lifecycle Management:** Implement automated provisioning and deprovisioning workflows specifically for AI coworkers to prevent "standing privilege" risks.
2. **Dynamic Access Provisioning:** Move toward a model where agents can request just-in-time (JIT) access for specific tasks rather than holding permanent high-level permissions.
3. **Identity Governance for AI:** Integrate AI agent identities into the broader corporate Identity Governance and Administration (IGA) framework.
## Implementation Guidance
### For Small Organizations
- Focus on manual inventory and "low-tech" tracking of which employees have connected AI plugins to corporate data.
- Utilize built-in platform controls (e.g., OpenAI/Anthropic workspace settings) to restrict third-party plugin usage.
### For Medium Organizations
- Implement formal naming conventions for service accounts used by AI.
- Conduct monthly access reviews specifically for AI-linked service accounts to mitigate access creep.
### For Large Enterprises
- Deploy specialized Identity Threat Detection and Response (ITDR) or AI-specific security tools to automate the discovery of "shadow" AI agents.
- Enforce the use of JWT (JSON Web Tokens) assertions or dedicated machine identities over static bearer tokens.
## Configuration Examples
- **Identity Separation:** Instead of `[email protected]` authorizing a plugin, create a specific identity: `[email protected]`.
- **Token Scoping:** Limit OAuth scopes to `read-only` for specific directories rather than `full-access` to the entire drive, preventing the agent from autonomously escalating its reach.
## Compliance Alignment
- **NIST:** Aligns with the *NIST Concept Paper on Identity and Authority for Software Agents*.
- **SOC 2:** Addresses the "hidden" gaps in identity controls that traditional SOC 2 audits might overlook.
- **ISO/IEC 27001:** Supports access control (A.9) and operations security (A.12) by ensuring machine identities are managed.
## Common Pitfalls to Avoid
- **The "Human-in-the-Loop" Fallacy:** Relying on humans to approve every action. This fails at scale and leads to "approval fatigue," where humans click "Allow" without reviewing.
- **Tainted Logs:** Failing to distinguish between a human and an agent, which makes forensic investigation impossible after a breach.
- **Standing Privilege:** Leaving an agent’s access active long after the specific project or task it was built for has ended.
## Resources
- **NIST Identity Concept Paper:** [h]xxps://www.nist.gov/news-events/news/2026/02/new-concept-paper-identity-and-authority-software-agents
- **Token Security AI Identity Management:** [h]xxps://www.token.security/blog/token-security-extends-identity-governance-to-autonomous-ai-with-ai-agent-identity-lifecycle-management
- **OpenAI Developer Documentation (Auth):** [h]xxps://developers.openai.com/plugins/build/auth