Safely manage your Zendesk from the AI assistant you already use, via the Deltastring MCP. Beacon configuration platform
← Back to news

The Replicant in Your Directory: AI Agents and the Identity Security Gap

AI agents are quietly expanding the identity attack surface within enterprise environments faster than governance frameworks can manage. The core problem isn't novel—identity security has always struggled with orphaned accounts, forgotten permissions, and credentials that outlive their purpose. What's changed is scale and speed. Machine identities now outnumber human users by as much as 50 to one in many environments, yet most organizations cannot answer basic questions about who owns these identities, why they exist, or what systems they can access. The 2025 UNC6395 breach of Salesloft's OAuth token demonstrates the mechanism: a single trusted machine identity became the pivot point for lateral movement across hundreds of Salesforce environments, leading attackers to AWS credentials and Snowflake tokens. This wasn't a vulnerability exploit—it was identity trust weaponised. For CX teams deploying AI agents through platforms like Salesforce Agentforce or custom integrations, the implication is stark: every new agent deployment creates identities that inherit permissions, interact across systems at machine speed, and potentially spawn additional downstream identities. If your identity governance programme wasn't designed to track these at scale, you're operating blind.

The data reveals a counterintuitive finding that should concern mature CX operations: organisations with stronger governance practices and continuous visibility into non-human identities still reported a 43% breach rate when AI significantly expanded their identity footprint, compared with 11% among those where AI hadn't changed identity counts. Visibility alone is insufficient. The accountability chain breaks down when AI agents operate at machine speed across multiple systems—there's often no clear owner, no approval trail, and no decision-maker responsible for retirement. For support teams running Zendesk or Freshdesk with integrated AI agents, this raises a critical question: when an AI-powered agent contributes to a security incident or data exposure, who within your organisation owns that identity and its permissions? Traditional identity lifecycle management assumes human behaviour—joining, role changes, departures. AI agents don't follow that pattern. They can be created automatically, inherit permissions from parent identities, and remain active long after the original use case has been forgotten. The governance gap isn't about deploying AI faster than security can keep up; it's about identity programmes that were architecturally designed for people, not machines.

The path forward requires treating machine identities as a distinct governance category with continuous answers to four questions: What identities exist in your environment? Who owns each one? What can they access? When should they be deprovisioned? Without systematic answers to these questions, every new AI agent deployment silently expands your trusted identity footprint. For CX leaders, this means identity governance can no longer be a security team problem alone—it requires collaboration between customer experience operations, platform administrators, and security to maintain an accurate inventory of all identities (human and machine) that can access customer data, interaction histories, and sensitive systems. The organisations that will avoid the next generation of identity-based breaches aren't those deploying AI fastest; they're those treating machine identity governance as a foundational requirement before, not after, agent deployment.