Blog

Who Gave the Agent Permission?

Authors: neupac | 17th Jul 2026

Role-Based Access Control in an Enterprise Run by Software

Role-based access control has for years been the unspoken piece of the security stack. The organization’s hierarchy would be drawn up, permission assignments would follow from job titles, and all was well. The finance analyst did not see the source code but the ledgers; the developer did not have permission to reach the wire transfer queue but the staging environment. This approach has worked because the population was well defined – a small number of known people, whose roles would change occasionally once per year.

Not anymore. The enterprise is filling with a different kind of worker, one that reasons, delegates, and acts on its own. According to Microsoft, 80% of Fortune 500 enterprises have already embraced the agent-based model. Gartner sees just 17% of enterprises using agents, with over 60% planning to do so within the next two years, which is the fastest adoption rate it has ever seen. We are about to assign permission models, which have traditionally been used for a few thousand people, to govern a few million of pieces of software, and that will be no easy task.

The model that worked for people is straining under machines

This is something security practitioners feel acutely. As Gartner puts it bluntly, traditional role-based access controls and onboarding are not scalable in an environment where there are thousands or millions of machine identities acting around the clock. Identity has shifted from background control to core infrastructure, and one-to-one mapping of one actor, role, and permission set no longer works. Delegation, autonomy, and context drive the agents, all of which are concepts foreign to a static access grant.

There is no abstract risk in getting this wrong. By 2028, Gartner expects one in four data breaches to occur across agent-based attack surfaces due to poor machine identities and the lack of context-aware policies. The other side of the coin comes from Forrester, which finds that 49% of security decision-makers identify agent-based AI as one of their concerns. Agents impersonate each other and increase their privileges. Non-human identity, according to Forrester, is still in its infancy. With a growing number of actors beyond counting, a minor mistake turns into an outage.

“Role” still matters, but the definition has to widen

None of this retires RBAC. This asks the term “role” to carry more weight than just a job description ever had. In its playbook about adopting an agent, the World Economic Forum treats the concept of authority as a set of permissions, the right to read, write, execute, communicate, or transact. Even the concept of representational authority is divided into acting on behalf of the company and decision-making authority. Adopting an agent is similar to adopting a new employee, access should be given deliberately and start from least privilege, not with the keys to the castle.

However, teams fail to anticipate what comes next once agents start working with each other. The World Economic Forum has a great insight for the whiteboard, when using agents in a pipeline, authorization is not additive. The downstream agent acts based on the intersection of its permissions and the permissions of the agent that initiated it, and the orchestrator of the flow cannot delegate any authority that it does not have itself. Permissions accumulate through delegation down the chain, and one sloppy permission given at the top of the chain expands the impact below. That is still RBAC, it just has to start thinking graphically now.

The way Microsoft describes the discipline needed for that is Zero Trust for AI, verify everything, work with least privilege, assume compromise. For agents operating too fast to be reviewed, these principles define the limit of governance.

From static lists to enforcement that runs while the agent does

The fundamental shift lies in where the control exists: permissions granted to specific people are important, but who enforces the rule is even more critical. Access management used to be about writing the policy, in a documentation format and annual compliance process. That worked when behaviors moved slowly, but breaks immediately once the object governed starts adapting on its own. According to platform architects like Varun Raj, traditional external and post-facto governance is inadequate in dealing with systems that evolve in-production. Hence governance needs to be a part of the execution path that judges and intervenes based on events as they unfold.

The findings by McKinsey on scaling of agents have reached similar conclusions as well: Access control policies are automatically evaluated based on the identity of the agent and the actions performed and agents are treated exactly the same way as any other system as the autonomy increases. Thus, the policies stop being mere PDFs and start enforcing themselves. The Identity space is also gearing up for this new reality of self-evolving systems by reinventing the OAuth protocol, Model Context Protocol, and Workload identity to verify delegations among non-human entities. Otherwise, RBAC for agents is just a wishlist.

Putting governed access at the core

Most enterprises are nowhere near ready, and the maturity metrics back this up. According to McKinsey’s 2026 trust survey, just about 30% of organizations can claim mature state when it comes to governance and agentic AI controls. One interesting detail calls for a closer look – enterprises that explicitly assign accountability for responsible AI outperform the rest by quite a margin, scoring 2.6 as opposed to 1.8. Regional tailwinds included – Asia-Pacific holds the leading position in the world on this metric, meaning an opportunity for local leaders rather than a catching up exercise.

Closing this gap is precisely the goal of NEUPAC’s development. Our patented platform brings role-based access control to first class of governance within the secure-by-design, zero-trust architecture. This way, the agents perform within your enterprise perimeters, rather than outside. The governance layer provides real-time insights into all actions, decision logs, and policy enforcement with the level of auditability demanded by the boards, while the agentic fabric coordinates multi-agent cooperation and delegation within the defined enterprise perimeters, which is where non-additive authorization needs to take place. And because the same control plane governs users and budgets between tenants, the question becomes no longer about who the agent is, but about what it can interact with, on whose behalf, and at what cost.

The Forrester recommendations on how to start working in this field sound like NEUPAC platform specifications: every single agent should have unique credentials, least privilege, full logging, and a designated owner controlling its life cycle. No autonomous agents. Once the RBAC is stripped down to the bare essence, it appears to be a rather straightforward solution. The very point of role-based access control was, as it is, providing the clarity on who performs certain actions within the organization and what each actor was allowed to do. This promise gains weight, not loses it, once some of these actors become software.

This is when your agents multiply faster than your access model can describe them. See how NEUPAC governs, optimizes, and scales enterprise AI agents

  • AI Agent Security
  • AI Agents
  • Role-Based Access Control

Know our Author

Lokesh Sapre

Principal Product Manager - NEUPAC™

Connect with him on

Related Posts.

FinOps for AI: When the Meter Never Stops
AI FinOps , FinOps , Generative AI
chat
logo-icon

NIA

NEUPAC™ AI Assistant · Online