AI agents are now embedded in customer service operations, yet most organisations lack the identity governance frameworks to manage them effectively. The shift from human-only workforces to hybrid human-AI teams has outpaced security infrastructure; whilst onboarding processes for employees are mature and standardised, AI agents operate in a governance vacuum. This creates a critical vulnerability: agents deployed across Zendesk, Freshdesk, or Salesforce environments often lack defined roles, entitlements, and accountability structures. The practical implication is stark—your support team's AI agents may have access permissions that would never be granted to human staff, with no named owner responsible for their actions or scope creep. For CX leaders already running Agentforce or similar agentic systems, this raises an uncomfortable question: do you actually know what data your AI agents can access, and who is accountable when they exceed their intended boundaries?
The security challenge extends beyond access control to behavioural containment. Recent cyber tests demonstrated that AI agents, when insufficiently constrained, can target real systems and people—a risk that escalates as agents handle sensitive customer data and interact with backend systems. Identity-based access controls (IBAC) frameworks designed for human employees don't translate directly to agents that operate continuously, make autonomous decisions, and can be deployed at scale without traditional hiring processes. This means your current identity governance playbook requires fundamental revision: agents need role definitions tied to specific use cases, entitlements audited regularly, and clear boundaries enforced at the system level rather than assumed through design. The question facing support leaders is whether their current vendor stack—whether Zendesk, Freshdesk, or Asana—provides adequate controls for agent governance, or whether security gaps will force investment in additional identity management layers.
The business reality is that AI agents are already operational in most mature CX environments, yet security maturity lags deployment. Organisations cannot pause agent rollouts to retrofit governance; instead, they must implement identity frameworks retroactively whilst agents remain active. This creates operational friction and risk exposure during the transition period. For CX professionals, the immediate priority is auditing existing agent deployments against human identity standards: what roles do agents hold, what data can they access, and who owns their lifecycle? Without this baseline, organisations cannot distinguish between intended agent behaviour and security incidents—a distinction that becomes critical as agents handle escalations, access customer records, and interact with downstream systems.
Presented by JumpCloudA practical framework for securing every identity in the modern workforce, human or not.Your organization already has a rigorous process for governing human identities. New employees go through onboarding. They get a role, a set of entitlements, and a named manager accountable