
Insider risk is often discussed in terms of intent, whether someone with legitimate access deliberately misuses it or an account is compromised and used by an unauthorized party. But another way to look at the challenge is through access itself.
Every badge, credential, service account and AI agent creates a pathway into an organization’s trusted environments. As those pathways multiply, security teams need to understand not just who has access, but where that access exists and what it allows.
The physical side of insider risk
A person does not need to be acting maliciously to create a security issue. An outdated badge permission, unclear operating procedure or lack of visibility during an incident can all make it harder for an organization to identify and respond to unusual activity.
Chris Robertson, Director, Technical Consultant Team, Luminys:
“After more than 25 years working in physical security, one thing I’ve learned is that managing insider risk often comes back to the fundamentals. Who has access to a physical space? Are those access permissions still appropriate for that person’s role? And can the security team quickly verify what happened when an incident occurs? Effective access control, video security and strong operating procedures give organizations the visibility they need to identify potential insider threats, investigate incidents and act on what they can verify.
Technology has improved considerably, especially when video security, access control and search tools work together, but good security still depends on how teams design and manage the system every day. Teams must review permissions. Video needs to be usable when an investigation happens. Operators need tools they understand and trust. Insider Threat Awareness Month is an essential moment to take a closer look at those basics and make sure the physical security program is doing what the organization expects it to do.”
The software environment is adding new trusted actors
The same concept applies to the software supply chain, where AI agents can now operate with access that was once reserved for human developers.
These systems can do more than generate recommendations. Depending on how they are configured, they can access repositories, select packages, modify code and interact with development infrastructure. That creates a need to understand the agent’s permissions and the components and systems it can influence.
Hari Srinivasan, Vice President of Products & Strategy, Lineaje:
“Insider Threat Awareness Month can no longer focus solely on human actors. Today, enterprise insider risk extends to autonomous software agents operating inside development pipelines. Organizations are granting AI agents privileged access to private repositories, CI/CD systems, package managers, skills repositories, and systems of records. Functionally, these agents act as credentialed insiders: they select third-party packages, write and refactor code, and push commits directly into trusted environments. Further, they can access, process, transmit, and transform data from systems of record, as well as from external models and other agents.
When an autonomous agent is untracked or misgoverned, it not only introduces bugs, but also injects supply chain risk directly into production builds at machine speed, and could leak sensitive and business critical data. To contain this emerging vector, security teams must treat every AI agent as an insider and a potential actor involved in the software supply chain. That demands complete visibility into package, model, skills, MCPs and third-party agent provenance, along with continuous assessment of agent-generated code. Enforce automated policy control and governance that neutralize vulnerable or malicious components and actions before impact.”
Visibility has to follow the access
These two environments may require different security technologies, but the underlying challenge is similar. Security teams cannot effectively manage trusted access they cannot see.
In a physical environment, that visibility may come from connecting access control with video so teams can establish who entered a space and what happened afterward. In software development, it may require tracking AI agents and the packages, models and other components they interact with.
The more access points an organization creates, the more important it becomes to understand them collectively rather than treating each one as an isolated security issue.
Rethinking insider risk beyond the awareness month
Insider Threat Awareness Month is an opportunity to revisit the controls around trusted access before another layer of complexity is added. For some organizations, that may mean reviewing physical permissions and investigation workflows. For others, it may mean putting new governance around AI agents operating in development environments.
The common requirement is visibility. Organizations need to know what has been granted access, what that access enables and whether the safeguards around it remain appropriate as their environments change.
Join our LinkedIn group Information Security Community!











