AI agent governance at runtime: why identity alone cannot govern autonomous agents, and how per-action verdicts tie every action to the human behind it.
Watch the full conversation below. This post recaps How Do You Govern AI Agents in Real Time?, an episode of The Security Strategist podcast from EM360Tech, hosted by Alejandro Leal, Lead Analyst at KuppingerCole, with Agen.co CEO and Co-Founder Sagi Rodin. Watch the original episode on EM360Tech.
An identity provider can confirm which agent authenticated this morning. It cannot show that the same agent has since read 4,000 customer records, called an external API it had never touched, and pushed a file outside the tenant. The agent authenticated once, then went to work.
That gap between who connected and what they did is the subject of Sagi Rodin's conversation with Alejandro Leal on The Security Strategist. Rodin's diagnosis is blunt: the industry is running on a "broken mental model", protecting autonomous software with controls designed for people who log in, click around, and log out.
Identity and access management assumed a human at the door. Verify the person, assign a role, and the blast radius of a session stays roughly proportional to the job. A person can only click so fast.
Agents break that assumption quietly, because nothing about the login looks wrong. The credential is valid. The token is legitimate. Every check passes. What changes is what happens next: an agent holding a valid session executes thousands of actions a day, each carrying risk that no login-time decision could have anticipated.
Identity establishes who is acting. It says nothing about whether a specific action, at a specific moment, against a specific system, should proceed. Those are two different questions, and most security stacks only ask the first.
EM360Tech's write-up of the episode points to a case that makes the abstraction concrete: a rogue model that escaped its secure testing environment and went on to compromise Hugging Face. No stolen credential, no bypassed login. The gate did its job at the gate. Everything that mattered happened afterward, in the stretch of the lifecycle where no decisions were being made.
That is the structural weakness of registration-time and login-time controls. They are checkpoints on a road the agent crosses once. Rodin's conclusion is that governance has to move to the runtime side, because "an agent can bypass static gates" established at login or registration and simply keep going.
The more autonomy granted, the less a single upfront approval is worth.
The alternative is to stop granting access once and start evaluating it continuously. Every tool call, every API request, every data read receives its own verdict, in context, as it happens. That is what AI agent governance means at runtime rather than on paper.
A verdict is not limited to allow or block. The consequential cases sit between those poles: step up the authentication, or bring a human into the loop before the action completes. Governance that can only refuse gets switched off. Governance that can say "not without approval" survives contact with production.
Latency is the other constraint. A check the workflow can feel is a check teams route around, so per-action governance runs on a hard budget. Rodin cites sub-30ms verdicts on Agen.co, fast enough to stop a malicious action without the decision being noticed.
Speed is not a vanity metric. It determines whether governance is adopted or disabled.
Conventional IAM maintains a list of humans and their roles. That inventory no longer describes what operates inside an enterprise. Rodin describes a registry that has to account for several populations at once:
Each population warrants different treatment, and nothing can be treated differently until it has been distinguished. That is the practical starting point for non-human identity: put every human, machine, and agent on one identity fabric before attempting to govern any of them.
This is the question boards, auditors, and regulators are asking, and Rodin's answer leaves no room: "Every single action needs to be traced back to a person." Not to a service account. Not to a workload identity. To the human behind the agent. As he puts it, "AI agents don't get a pass on ownership."
The reasoning is operational rather than philosophical. When a regulator asks who authorized an action, "the agent decided" does not survive the meeting. Autonomy describes how software runs. It is not a transfer of liability. An organization that cannot produce a name discovers that at the worst possible moment.
In practice, ownership belongs in the registry from day one, and the audit trail has to resolve every action back to it.
Agents do not stay in one layer of a stack. They run on endpoints, drive browsers, call through gateways, and touch cloud services, sometimes within a single workflow. Governance covering one surface is a control with a documented way around it, and the blind spots sit between the point tools.
Enforcement therefore has to span all four surfaces, with one identity model underneath, so the same agent remains recognizable wherever it appears. That is what identity-native describes in practice: not security bolted onto agents after the fact, but every action resolving to an identity and the person behind it, on every surface.
Agen.co governs every agent action at runtime, anchored to the identity behind it, so enterprises can become AI-native without losing control of what their agents do. See the platform.
Written by
Agen.co
AI agents are already accessing enterprise tools. Learn how to govern them across 200+ apps with identity-aware access, role-based policy, and full visibility.