
The enterprise workforce is about to double. I call it the 100,000 Agent Problem: as AI moves from passive Advisor Mode into autonomous Action Mode, organizations will soon run more agents than employees. Most security teams are making the same mistake on the way in, treating agents like synthetic employees and handing them human logins.
Legacy vendors encourage it, selling “comprehensive” identity management across humans, machines, and agents as if identity meant the same thing in all three cases. Both humans and cars need fuel; that doesn’t mean people should drink gasoline, or that you should expect 30 miles to a burrito in your Hyundai. If someone tells you agents just need another flavor of the identity system you already own, ask whether they’re the ones who sold you that system.
Agents are different.
Human governance is established long before anyone logs in – employment contracts, background checks, job titles, reputation. Humans have careers; agents have lifecycles. Humans build trust through accountability; agents require monitoring and verification.
We call these models enthusiastic interns for a reason. They lack a conscience, they don’t possess human judgment, and they simply want to do the job well. A human employee might pause and push back when a command feels off. An agent executes, at machine speed, with no fear of being reprimanded for it.
Role separation exists on purpose, the person who starts a purchase order isn’t the one who approves it, because separation of duties reduces fraud and error. An agent needs no protection from a conflict of interest, and it doesn’t specialize in job tasks the way people do. A capable agent is a polyglot, able to navigate sales, finance, and fulfillment in a single path. No human holds all three roles, and no agent should need all three roles’ full access to do the work. Model that with legacy IAM and you’d hand it a “sales” group and an “accounts payable” group and call it done, granting everything else those roles can do.
Identity stops at the door. Agents don’t.
The deeper problem is structural. An identity provider is a database of user records. When a user signs in, it passes a group to the application, and the application grants the permissions attached to it. That handshake happens once, at login. The IdP does not sit in the path of the transactions that follow and has no interactions with ongoing API calls. For a human clicking through a UI, the blast radius of a mistake is bounded by how fast a person can work. An agent removes that boundary. It runs at the speed of computation, around the clock. Borrowed privilege stops being a latent risk and becomes a live exposure that may execute thousands of times a day while nobody watches.
Least privilege has to mean something different here: not privilege inherited from a human role, but privilege scoped to the transaction, the specific tools the job requires and nothing adjacent.
What a purpose-built record looks like
This is why we built AgentProfile: a discrete profile for every agent, with a unique record, a human manager, and credentials scoped to what that agent’s job requires, independent of any person’s.
Three things change when governance binds to the agent rather than borrows from a person:
First, security shifts from a one-time login event to continuous runtime enforcement, with policy applied to every transaction rather than granted once and abandoned.
Second, context consolidates, so every model invocation and tool call maps back to one record, and a misbehaving agent can be deprovisioned cleanly, everywhere at once.
Finally, agent cost becomes truly visible: when every call logs back to a specific agent, you can finally see spend per agent instead of losing it in a pooled account. That’s the difference between knowing an agent works and knowing whether it’s worth running.
Autonomy doesn’t cancel ownership
None of this removes the human. Every agent should have a manager who carries ultimate responsibility for what it does, the way a director owns the actions of their team, and who holds the approval lever. A refund above a threshold, a contract term outside the standard book, a change to production: each route to a person before it executes, exactly as it would for an employee with the same authority. The agent runs on its own most of the time and pulls a human in at the moments that matter.
Every shift in software has needed its own security model. Stop retrofitting human identity tools for digital workers, and governance stops being a brake. It becomes a launchpad.
_____
About Oren Michels
Oren Michels is Co-Founder and Chief Executive Officer of barndoor.ai, where he leads company strategy, vision, and execution for its enterprise AI governance and agent control plane platform. He previously co-founded Mashery, which was acquired by Intel, and has built and scaled multiple enterprise software companies. He is also an investor, advisor, and Tony-nominated Broadway producer.
Join our LinkedIn group Information Security Community!











