Safely manage your Zendesk from the AI assistant you already use, via the Deltastring MCP. Beacon configuration platform
← Back to news

AI Agents Broke the Security Playbook. Here's What Replaces It.

AI agents have fundamentally broken the security model that enterprise teams relied on for two decades: the assumption that environments are knowable and controllable through fixed vendor workflows. Unlike traditional applications, agents operate autonomously, acquire access across systems, change behaviour based on context, and can disappear before the next inventory scan. Token Security's research reveals the scale of the problem: enterprises are deploying everything from human-triggered chatbots to fully autonomous production services, with over a fifth of local agents already holding direct access to production data. The old build-versus-buy security question has become obsolete. The real question now is which layer security teams should own—and the answer has direct implications for how CX platforms like Zendesk and Salesforce will need to evolve their governance models, particularly as agentic customer service becomes mainstream.

The operationalization gap has widened dramatically because vendor dashboards cannot anticipate environment-specific risks. A platform can flag overprivileged accounts or stale credentials, but it cannot answer the questions that matter: which agents created in the past fortnight can reach production through inherited human credentials? Which local coding agents still hold active tokens after projects ended? These questions depend entirely on an organisation's cloud footprint, SaaS stack, development practices, and AI adoption patterns—variables no vendor roadmap can predict. For CX teams already running agent-assisted workflows in Agentforce, Freshdesk, or similar platforms, this creates an uncomfortable reality: the governance controls built into these systems are necessary but insufficient. The hidden cost of "just building it" yourself is equally prohibitive—security teams cannot realistically rebuild integrations across AWS, Azure, GitHub, Salesforce, Okta, and agent frameworks whilst maintaining normalised, live data across all systems.

The winning model is "buy the foundation, build the operating layer." Security teams should invest in continuous discovery, integrations, normalisation, and identity correlation—the structurally complex capabilities that require depth and constant maintenance—whilst owning the workflows, automations, and reviews that reflect their specific environment. For CX professionals, this means identity becomes the control plane that actually governs agentic AI. Every agent eventually requires access; many borrow credentials from employees and become indistinguishable from them in audit logs. A live identity foundation allows teams to answer the critical questions: who owns this agent, what is it supposed to do, which systems can it reach, and does its access match its intent? Without this foundation, custom CX workflows sit on unstable ground, relying on stale exports and partial inventories. The teams that will move fast without losing control are not those with the longest tool lists but those who understand which layer to own—and for agentic AI in customer service environments, that layer is identity.