Back to Blog
    Thought LeadershipSep 3, 20266 min read

    Your Newest Employees Aren't Human: Governing AI Agents as Identities

    Your Newest Employees Aren't Human: Governing AI Agents as Identities

    Okta and Deloitte are expanding their APJ alliance around identity governance for AI agents, while NIST examines standards for authorizing non-human identities. Role-based permissions, audit trails, and isolated environments are becoming procurement requirements — not nice-to-haves.

    On September 3, 2026, CRN Asia reported that Okta and Deloitte are expanding their Asia-Pacific and Japan alliance around identity governance and access management — specifically because organizations are introducing more AI agents and "non-human identities." The alliance targets financial services, government, and healthcare: the industries where access control is not a best practice but a regulatory obligation.

    The same report notes the U.S. National Institute of Standards and Technology is examining standards-based approaches for identifying and authorizing software and AI agents — including authorization, auditing, and non-repudiation — and that Singapore's IMDA already recommends, in its Model AI Governance Framework for Agentic AI (updated May 2026), limiting agents' access to tools and data and defining which actions require human approval.

    Your Newest Employees Aren't Human

    Here's the operational reality underneath the partnership news: an AI agent with system access is a new kind of employee, and most organizations are onboarding these employees with none of the discipline they apply to human ones.

    No enterprise would give a new hire the CEO's credentials, skip the background check, and never review what they did with their access. Yet agents are routinely deployed with broad service-account permissions, no defined approval points, and logging that nobody reads. When identity vendors, consultancies, and standards bodies all converge on the same gap in the same season, that gap is about to become a procurement requirement.

    Bob Generale on operating AI agents as non-human identities
    "Treat every agent like a hire. It gets a role, not root. It gets the access the job requires and nothing else. Its work is reviewed at defined checkpoints, and there's a record of everything it touched. That's not bureaucracy — that's the difference between an agent you can put in front of a regulator and one you quietly turn off before the audit."
    — Bob Generale, COO / Co-Founder, Pyra

    The Non-Human Identity Checklist

    Translated into operations, governing agents as identities comes down to four controls — the same ones we treat as non-negotiable in every deployment:

    • Role-based permissions, scoped to the job. An agent built for one workflow needs access to that workflow's systems — not a master key. Least privilege is easiest when the job is defined first.
    • Human approval at defined actions. Singapore's framework says it plainly: decide in advance which actions require sign-off. That decision belongs in the workflow design, not in an incident postmortem.
    • Audit trails that support non-repudiation. NIST's framing is the right bar — not "we log things," but "we can prove which agent did what, under whose authority."
    • Isolated environments. One client's agent should never share an environment with another's. Isolation bounds the blast radius of any credential or behavior failure.

    This is how we build: client-isolated deployments with role-based access and full audit trails, on a platform where approval gates are part of the workflow rather than an add-on.

    Why This Lands Hardest in Regulated Industries

    The alliance's target list — financial services, government, healthcare — is not an accident. In regulated environments, access governance is already codified; Australia's prudential guidance, for example, extends access-control expectations beyond human users to special-purpose accounts and software. As agents proliferate, those existing obligations absorb them. Nobody is waiting for an "AI agent regulation" — the identity and access rules already on the books apply the moment an agent touches a governed system.

    For buyers in regulated industries, that means the vendor question changes from "what can your agent do?" to "show me its role, its checkpoints, and its audit trail." If a vendor can't answer in those terms, the deployment will stall in security review — as it should. If you'd rather start with the answers built in, talk to us.

    Facts about the Okta–Deloitte alliance, NIST's standards work, and Singapore's IMDA framework are from CRN Asia's report of September 3, 2026, verified the same day. Pyra is not affiliated with Okta or Deloitte. Details of the alliance and standards efforts may evolve.