Watchlight AI
Back to Blog
Agent Runtime GovernanceIAMAI SecurityEnterprise AIAgentic AI

Why Agent Runtime Governance Is the Missing Layer in IAM

Aldo PietropaoloFebruary 19, 20266 min read
Share

We just published a new position paper: Why Agent Runtime Governance Is the Missing Layer in IAM.

It makes a simple argument: as enterprises move from human-driven access to autonomous AI execution, they require a new control layer that existing identity infrastructure was never designed to provide.

This post summarizes the core argument. The full paper goes deeper on each point.


The Problem

Identity and Access Management has evolved steadily for 30 years. SSO, federation, MFA, zero trust, privileged access management, identity governance — each capability emerged when the threat model demanded it.

Every one of these capabilities was designed for a world where humans are the primary actors. A human authenticates. A human requests access. A human exercises judgment about what actions to take. The entire model assumes a person at the keyboard.

AI agents break that assumption. They don't log in and log out. They don't follow predictable workflows. They reason about goals, choose their own action sequences, delegate to sub-agents, invoke tools dynamically, and execute autonomously — often faster than any human can review.

When organizations deploy agents today, they reach for what they know: service accounts, API keys, OAuth tokens, RBAC policies. These tools work for human-driven access. They are insufficient for autonomous execution.

The Gap

The paper identifies five structural gaps between existing security infrastructure and what AI agents require:

No Intent Layer. IAM answers "can this entity access this resource?" It cannot answer "why is this entity accessing this resource right now, and does that reason align with an approved business objective?" For humans, we assume intent. For agents, intent must be declared, validated, and enforced.

No Delegation Model. When a human asks an agent to perform a task, and that agent delegates to sub-agents, who authorized the final action? IAM tracks individual identities. It does not track delegation chains — the trust path from the authorizing human through every agent that touched it.

No Runtime Context. RBAC assigns permissions at provisioning time. ABAC evaluates attributes at request time. Neither evaluates the evolving runtime context of an autonomous agent: its current goal, how far along it is, whether it has deviated from its plan, and whether its time-boxed authority has expired.

No Secrets Governance for Autonomous Actors. PAM vaults control access through human approval workflows. Agents need credentials injected into their execution context, scoped to a specific action, with TTLs measured in minutes — not stored credentials with broad access.

No Behavioral Observability. A log entry that says agent-47 READ customers is useless for governance. You need to know which agent, doing what, for what reason, authorized by whom, evaluated against which policy, and whether the action was consistent with the agent's declared purpose.

These are not feature requests for existing products. They represent a missing architectural layer.

The Category

The paper defines Agent Runtime Governance (ARG) as the discipline of enforcing governance continuously during agent execution — governing every action, every delegation, every tool invocation, in real time.

ARG is not a replacement for IAM. It is a new layer that sits between identity infrastructure and agent execution:

  • IAM / IGA handles identity lifecycle, access provisioning, periodic review — on a timescale of days to quarters
  • Agent Runtime Governance handles intent validation, delegation tracking, runtime policy enforcement, behavioral observability — on a timescale of milliseconds to hours
  • Agent Frameworks handle execution, tool orchestration, LLM interaction — on a timescale of milliseconds to minutes

Each layer has a distinct function. None can substitute for the others.

The Minimum Requirements

The paper specifies seven non-negotiable capabilities that any ARG system must provide:

  1. Agent Identity and Registry — Every agent has unique, verifiable identity. Unregistered agents are denied execution.
  2. Intent Declaration and Validation — Agents declare purpose, goal, and intent. Inconsistent declarations result in denied execution.
  3. Runtime Policy Enforcement — Policy evaluated on every action, at the moment of execution, using formal policy languages.
  4. Delegation Chain Tracking — Cryptographically verifiable trust chains from human decisions through every agent in the path.
  5. Secrets Governance — Short-lived, purpose-bound tokens. No long-lived credentials in agent hands.
  6. Behavioral Observability — Every action logged with full governance context: identity, intent, goal, delegation chain, policy evaluation, outcome.
  7. Safe Failure and Kill Switches — Fail-closed semantics. Emergency stops at individual, group, and system-wide levels.

Each requirement includes a concrete test — a question you can ask about your current environment to determine whether you meet it. If you're deploying agents and can't answer these questions, the paper explains why that matters and what to do about it.

Why This Matters Now

The window between "agents are experimental" and "agents are in production" is closing fast. Many organizations have already crossed it. The governance infrastructure needs to be in place before the first material incident forces the conversation — not after.

If you've read our 12 Non-Negotiable Principles for Agent Runtime Governance, this new paper complements it. The principles framework defines what to build. This position paper defines why the category exists and where it fits in the enterprise security stack.

Download the full position paper here.


If you're evaluating how Agent Runtime Governance fits into your security architecture, we'd like to talk.

Subscribe to Watchlight Insights

Get new writing on Agent Runtime Governance, AI agent security, agent identity, and delegated authorization, delivered when we publish. No noise, just the new posts.

Unsubscribe anytime. We never share your email.

Found this useful? Share it with your network.
Watchlight AI Beacon

Put runtime governance in front of every agent action

Watchlight AI Beacon is available now, fully on-premises and air-gapped. Request a demo to see it in your environment.

Request a Demo
Recommended Workshop

Agent Governance Readiness Assessment

Evaluate your governance posture against the 12 principles. Get a maturity score and roadmap.

2-3 days · Download one-pager (PDF)

We value your privacy

We use cookies to enhance your browsing experience, analyze site traffic, and personalize content. You can choose to accept all cookies or customize your preferences. Learn more