Skip to content

Security1 publisher2 min readPublished

Two of Ping's four AI agent classes act on a human's own login

Ping Identity executives split enterprise AI agents into four classes at their Austin conference. The two that live on endpoints have no identity of their own, so their actions authenticate as the employee who lent them the credential.

The Watch · Security desk

Illustration accompanying Two of Ping's four AI agent classes act on a human's own login

What happened

  • Ping Identity executives told the company's Ping YOUniverse conference in Austin on Sept. 1-2 that enterprises are running four distinct types of AI agent, each needing separate management.
  • Partner agents act inside a user's own online accounts on credentials the user lends them, sending and replying to email, booking travel, checking bank accounts and scheduling meetings.
  • Sharma said many enterprises run agents in what he called YOLO mode, enabling the --dangerously-skip-permissions option and stripping guardrails to move faster.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Anything an attacker drives through a partner agent reaches the mail, banking and calendar the employee can reach. The account's record shows the employee doing it.
  • contradiction Sharma's ranking and the governance gap point at different classes: the agents with no identity of their own sit second from the bottom of his risk list, while the top two are the ones an identity platform can already see.
  • constraint The owner, guardrail and audit-trail requirement cannot be met with scoped just-in-time credentials for half the taxonomy, because there is no agent identity to issue them to.
  • decision An IAM owner has to decide which class each agent in use belongs to before any control applies, since the same policy cannot cover a Salesforce-embedded agent and a browser session on a lent login.

Borrowing a human's credential breaks the log. A partner agent sends and replies to mail, makes travel arrangements, checks bank accounts and schedules meetings inside the user's own accounts, with credentials the user lends it [4]. Ping says that class does not have and does not require an identity of its own; the human logs into an OpenAI or Anthropic account, or hands the agent their identity to act on their behalf [5]. The action then authenticates as the employee and appears in the account's record as the employee [21].

Ping's risk order does not follow that gap. Sharma said employee agents are not that risky, that the partner agents are riskier because they talk to more than one user, that workload agents are riskier still because they operate across a domain, and that the multi-domain autonomous agents such as the SaaS-embedded ones are the riskiest and the most useful to the enterprise [11]. That places the credential-borrowing class second from the bottom of four [20]. The two classes ranked above it are the two that get identities of their own, because they are not tied to a specific human user and act largely on their own [6].

"LLMs suggest, but AI agents act," Sharma said [14]. "Every agent needs an owner, needs guardrails, and needs an audit trail," he said [15]. He proposed one recurring test: "Is this agent, at this moment, authorized to perform this action?" [16] On a lent login, the answer is whatever the human is authorized to do [22].

Sharma also said many enterprises put agents in what he called "YOLO mode" for the sake of accelerated productivity, enabling the "--dangerously-skip-permissions" option and removing guardrails [13]. He said AI agents are a new class of identity and not NHIs, so they need to be governed in new ways [17]. Darryl Jones, Ping's VP of consumer segment strategy, put the change this way: "It's not creating a new security problem, but it's making the identity problem bigger" [9].

No incident was reported; these were conference remarks. Ping sells identity management, and its executives said platforms must implement zero-trust policies including just-in-time access and least privilege [18], with a move away from shared persistent credentials toward "ephemeral just-in-time credentials tightly scoped to specific tasks" [19]. Scoped credentials need an identity to bind to. Two of the four classes in this taxonomy have one [23]. For the other two, the only usable record is which employee lent which account to which agent. Sharma's own question from the stage was "Can we have this massive explosion of digital workers and still manage the risks?" [24]

What to watch

  • Whether Ping ships agent discovery that covers endpoint agents operating under a human's own account login, and on what date.
  • Whether any identity provider publishes a way to distinguish an agent action from a human action inside the same authenticated session.
  • The first reported case of an attacker abusing a partner agent's borrowed credential, and whether the logs name the employee rather than the agent.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories