Agentic AI,
Identity & Access Management,
Privileged Access Management
Royal Bank of Canada, Ping Identity on Privilege, Runtime Control and AI Governance
With the increasing autonomy of AI agents granted access to enterprise applications, data, and privileged systems, the landscape of identity governance is changing dramatically. Identity teams within organizations are now grappling with a crucial question: How can they effectively govern identities that operate autonomously and at machine speed?
This pressing issue was at the forefront during a recent “Proof of Concept” discussion, where two industry leaders, Melissa Carvalho and Gaurav Sharma, shared their insights. Carvalho, who serves as the Vice President of Global Security Identity and Access Management at the Royal Bank of Canada, along with Sharma, the Vice President of Workforce Product Strategy at Ping Identity, explored how AI agents are transforming identity governance, privileged access management, and accountability in organizations.
The evolving nature of AI and its integration into business processes has prompted the National Institute of Standards and Technology (NIST) to begin focusing on AI agent identity and authorization frameworks. This shift highlights the necessity for organizations to identify which AI agents exist within their systems, understand who owns these agents, determine what resources they can access, and assess whether they have the authorization to perform specific actions at any given time.
Carvalho emphasized the need for a paradigm shift, stating, “We really have to redefine what we think of privilege and how we manage privilege access for these agents, or for these accounts.” This statement underscores the growing complexity around privilege management as AI agents continue to be integrated into business operations.
During their discussion, Carvalho and Sharma elaborated on several key themes that organizations must address to navigate this new landscape effectively. One significant point raised was the requirement for entirely new strategies concerning privileged access and least-privilege controls tailored specifically for AI agents. This includes reevaluating existing frameworks and implementing more dynamic governance measures.
Further, they delved into the importance of discovering shadow agents—those entities operating without proper oversight—and establishing prioritization in controls based on potential risks. This risk-based approach enables organizations to focus their resources where they can make the most significant impact, especially considering the potential “blast radius” of a compromise involving an AI agent.
Continuous monitoring was another critical point of discussion. In a world where AI agents gain more autonomy, the need for real-time monitoring and runtime authorization becomes paramount. Sharma highlighted that organizations must be equipped to respond swiftly to any identified anomalies in agent behavior to minimize potential damage and ensure rapid containment of any threats.
The evolving dialogue surrounding AI governance also paves the way for further discussions on identity and access management. Organizations need to not only adapt but also anticipate future needs as AI technologies become increasingly sophisticated and integral to operational efficiency. As such, the landscape of privileged access management is expected to continue evolving swiftly, necessitating continuous education and adaptation among identity professionals.
Organizations interested in staying informed on these pressing issues can reference prior installments of the “Proof of Concept,” which have previously addressed various critical topics, including crisis response and managing the aftermath of security breaches. Engaging with these resources can provide invaluable insights as businesses navigate the complexities of AI integration into their identity governance frameworks.

