AI agent identity lifecycle: joiner, mover and leaver for non-human accounts
ILM Reference editors · Published 2026-09-23 · 4 minute read
AI agents and service accounts need the same lifecycle as people: an owner at creation, a review when their scope changes, and removal when the work ends. What differs is the trigger, because no HR record starts or stops them. Most governance vendors shipped features for this in 2026; discovery of accounts created inside applications remains the weakest point.
Why does the JML model break for non-human identities?
Joiner-mover-leaver depends on an HR event. A person joins, a record appears in the HR system, and provisioning follows. An AI agent or a service account has no HR record. An engineer, a platform or another agent creates it, and it keeps working after the project that needed it ends.
Orchid Security's Identity Gap: 2026 Snapshot, based on anonymized telemetry from enterprise applications between April 2025 and March 2026, states that 67% of non-human accounts are created directly within applications. The share will differ in every estate, but the point holds: an account created inside an application never passes through the provisioning flow that JML relies on.
What replaces the HR trigger?
The common answer in 2026 is sponsorship: every non-human identity has a named person accountable for it. Microsoft's Entra what's new page lists "Manage Agent ID sponsorship lifecycle with Lifecycle Workflows" as generally available in May 2026, with tasks for sponsor transfers and notifications. Sponsorship maps onto the familiar stages:
- Joiner: the agent or service account is registered with a sponsor, a purpose and a scope.
- Mover: the sponsor changes role, or the agent's scope grows; the sponsorship transfers or the access is reviewed.
- Leaver: the project ends, or the sponsor leaves with no successor; credentials are revoked and the account removed.
- Review: the agent's permissions are certified on a schedule, like any other access.
When a sponsor leaves, the identities they sponsor face the same failure as an orphan account: they keep working with no owner. Treat a sponsor's leaver event as a trigger to review every identity that person sponsors.
What did vendors announce in 2026?
| Date | Vendor | What was announced |
|---|---|---|
| 2026-09-22 | Okta | Resource Access Certifications for reviewing agent permissions over time, listed as available; Shadow AI Agent Discovery for Endpoints planned for Q3 2026. |
| 2026-09-21 | Lumos | MCP Governance, which records agents' MCP tool calls with the human identity and enforces policy before an action runs. |
| 2026-08-04 | SailPoint | Agentic Fabric generally available for AI and machine identities, alongside Human Fabric, which SailPoint says evolved from Identity Security Cloud. |
| 2026-07-28 | Saviynt | Zuma, an AI identity security platform with Zuma Insights, Zuma Access and Zuma Governance. |
| 2026-06-29 | SailPoint | Completed the acquisition of Entro Security, which secures non-human identities, secrets and tokens. |
| 2026-06-15 | C1 | C1 Autonomous Worker, an agent that runs tasks such as revoking unused admin access, using the operator's own permissions. |
| 2026-03-02 | Veza | ServiceNow completed its acquisition of Veza; the Access Graph is to be integrated across the ServiceNow platform. |
Each item links to its source on the news page.
Where are the gaps?
Three gaps are visible in the public material.
Discovery. Several vendors describe finding agents on endpoints, in cloud platforms or through tool-call monitoring. Accounts created inside an application's own user store are harder to see from outside the application. That is the same problem this site tracks for local accounts in disconnected applications, and it is where Orchid Security positions its discovery, feeding what it finds to the IGA already in place; Orchid joined SailPoint's Technology Alliance Partner program in August 2026.
Credentials. An agent that authenticates with a hardcoded key or a shared service account is not stopped by disabling an identity record. The leaver step has to include rotating or revoking the credential.
Standards. The OpenID Foundation approved the AuthZEN Authorization API 1.0 as a Final Specification on 12 January 2026, and the NIST NCCoE project on software and AI agent identity and authorization was still reviewing public comments when we checked in September 2026. Interoperable agent governance is early.
What should a lifecycle program do now?
- Inventory non-human accounts per application, including accounts created locally inside the application.
- Assign a sponsor to every one, and add sponsor departure to the leaver checklist.
- Put agent and service account permissions into the regular certification cycle, reviewed by the sponsor.
- Record the credential type for each account, so a leaver action includes rotation where needed.
- Ask each vendor which non-human accounts it discovers on its own, and which it governs only after someone registers them.
Sources
- Orchid Security, Identity Gap: 2026 Snapshot
- Microsoft Learn, What's new in Microsoft Entra
- Okta newsroom
- Lumos blog, MCP Governance
- SailPoint press release, SailPoint Identity Security
- SailPoint press release, Entro Security acquisition
- Saviynt press release, Zuma
- C1 blog, C1 Autonomous Worker
- Veza blog, ServiceNow acquisition
- OpenID Foundation, AuthZEN Authorization API 1.0
- NIST NCCoE, software and AI agent identity and authorization
- Orchid Security, SailPoint partnership
Reviewed Sep 2026