Live Sessions. Real Configurations. Practical IAM & GRC Know-How. Register for NEXIS Hacks | Live & On Demand | Online

IAM

Your AI Agents Already Have Access. Is Your Governance Keeping Up?

23 Sep 2026
Dr. Heiko Klarl
Dr. Heiko Klarl CEO, Nexis

AI agents are becoming part of everyday business operations. Someone builds an agent in Microsoft Copilot Studio, connects it to SharePoint or a CRM, shares it with colleagues – and it starts working. 

Once an agent in Entra ID is connected to business systems, it also becomes part of the organization’s access landscape. 

AI agents can hold permissions, application roles, and group memberships. They can access corporate resources, interact with employees in Teams or Outlook, and act on behalf of human users. Yet the governance processes surrounding them have often not evolved at the same pace. 

This creates a new challenge for Identity and Access Management (IAM) and Governance, Risk and Compliance (GRC): How do you govern AI agents with the same level of transparency and control that you already apply to human identities? 

AI Agents Are Becoming Part of the Identity Landscape 

AI agent governance starts with a simple question: Which agents are actually operating in your environment? 

For many organizations, that question is surprisingly difficult to answer. Agents may have been created by different business units for different purposes. Some have clearly defined responsibilities, while others have evolved from experiments into tools used in daily business processes. 

Once these agents interact with applications and corporate data, identity governance becomes relevant. Organizations need to understand what an agent can access, whether those permissions are appropriate for its purpose, and who is responsible for it. And finally, companies acting in Europe must fulfill all requirements arising from the EU AI Act [1]. 

The principles are familiar from traditional IAM: ownership, least privilege, access governance, and Segregation of Duties (SoD). AI agents do not require an entirely new governance model. You need to include them in the one you already have. 

This becomes especially important when AI agents are not considered in isolation, but in relation to the human users who can operate them. 

The Risk You Cannot See in Separate Reports 

Consider an employee whose individual access is fully compliant. Their permissions have been reviewed and no SoD conflict exists. 

Now assume that the same employee can operate an AI agent with additional permissions. 

Individually, the employee and the agent may look harmless. Together, however, their combined access could create an SoD violation – for example, by enabling the same person to initiate and approve a sensitive transaction. 

The conflict only becomes visible when you analyze human and non-human identities together. 

This is an important shift for identity governance. Looking at an AI agent only as a technical object does not provide the full picture. Organizations also need to understand its relationships with people, applications, permissions, and business processes. 

And SoD is only one part of the equation. Effective AI agent governance should answer several fundamental questions: 

  • Which AI agents exist in our Microsoft environment and what’s their intend? 
  • What applications, data, and resources can they reach? 
  • Are their permissions appropriate for their intended purpose? 
  • Who owns each agent and is accountable for it? 
  • Which human users can operate them? 
  • Which risks emerge from the combination of human and agent access? 

Without this context, organizations may have an inventory of technical objects without meaningful governance over them. 

Establish a Baseline with the NEXIS AI Agent Health Check 

The NEXIS AI Agent Health Check provides a focused, data-driven assessment of AI agents in your Microsoft tenant. Its purpose is to establish a reliable baseline for AI agent governance based on actual tenant data. 

It focuses on the agents visible in your Microsoft environment. Agents that never touch the directory, for example those built on service accounts or authenticating through stored credentials, sit outside this scope and are a natural next conversation. 

Rather than introducing a separate governance model for agents, the assessment brings them into the context of existing identity governance. 

The Health Check focuses on four areas.

The Health Check focuses on four areas. 

Agent inventory: It creates a dated inventory of the AI agents in your Microsoft tenant, including their origin, what they can reach, and which of them appear alongside human colleagues in the digital workplace. 

Agent access and reach: It analyzes where permissions are concentrated and where an agent’s cloud access may be broader than required for its intended purpose. This provides structural transparency into the potential reach of an agent. 

Ownership and accountability: The assessment identifies agents without a registered owner and provides the basis for assigning clear responsibility through established governance workflows. 

Cross-identity SoD: NEXIS analyzes human users and AI agents together to surface access conflicts that stay hidden when you assess each population on its own. 

Together, these findings provide more than an AI agent inventory. They show where governance attention is needed and help organizations prioritize the next steps. 

How Does the NEXIS AI Agent Health Check Work? 

The assessment follows four structured steps. 

It starts with scoping and kick-off, where you define the relevant environment and the objectives of the assessment. Next comes data import and verification, which builds the data foundation for the analysis. 

NEXIS then performs the inventory and reach analysis, identifying and evaluating the agents in the context of their access, ownership, and relationships. Crucially, this analysis connects the agent population with human identities instead of treating AI agents as an isolated category. 

The Health Check concludes with a presentation of findings and recommendations. NEXIS prepares the results for both technical and management stakeholders, including a benchmark comparison against anonymized data from other organizations, and gives a clear view of the current governance status, relevant risks, and the areas to address first. 

The outcome is therefore not another generic AI maturity assessment. It is a concrete view of the AI agents in your Microsoft environment and their position within your identity landscape. 

Bring AI Agents into Identity Governance 

AI agents are already multiplying across enterprise environments, and each one accumulates access to business systems. Governance needs to keep pace. 

The starting point does not have to be a new set of processes. Organizations can extend principles they already rely on for human identities: establish ownership, understand access, enforce least privilege, identify SoD conflicts, and maintain an auditable view of who – or what – can access critical resources. 

The NEXIS AI Agent Health Check creates the baseline needed to do exactly that. 

It answers the questions that matter first: Which AI agents are already present? What can they access? Who is responsible for them? And which risks only become visible when you analyze their access together with human identities? 

That visibility turns AI agent governance from an abstract future requirement into something organizations can address today. 

Ready to see the AI agents already working in your Microsoft tenant? 

Talk to our experts about the NEXIS AI Agent Health Check and establish a clear baseline for AI agent governance. 

Request a Demo

 

[1] Dr. Heiko Klarl, The AI Register Is Not Enough, 25 June 2026