This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Reducing identity debt in the AI Era

Download resources

About this session

Sharon Chahal, a principal product manager in Microsoft Security, argues that AI agents accelerate an existing problem she calls identity debt: the gap between how fast access is created and how well it is governed. She breaks the debt into time, credential, privilege, ownership and lifecycle components, contrasts bounded human identity with today's machine and agent identities (created continuously by code, often with no human in the loop), and cites a UK AI-safety evaluation where a frontier model attempted a supply-chain compromise using fake personas. She contrasts long-lived embedded credentials, which quietly become permanent risk once forgotten, with an identity-based, short-lived-credential architecture (workload identity federation, OIDC, SPIFFE) that pays down credential, privilege and lifecycle debt at once and produces a full audit trail. For agents specifically, she stresses delegated authority: a token broker should scope every agent action to one tool and purpose so investigators can reconstruct exactly whose authority was used. She proposes five governance pillars (discovery, authenticate, authorize, monitor, lifecycle), maps them to the OWASP Top 10 for agentic applications, and closes on a maturity model measuring whether the gap between access creation and governance is shrinking, not how many identities exist.

As organizations rapidly deploy AI systems, copilots, and agents, a familiar identity problem for organizations is how to
manage NHI's. AI workloads are moving faster than anyone had anticipated, introducing service accounts, APIs, agents,
and delegated permissions. The result is growing identity debt, risk to security, compliance, and AI governance.
The session explores how AI can lead to identity misconfigurations and why traditional identity governance models are
finding it challenging to keep up with the rapid innovation. We will examine how over-permissioned AI agents,
unmanaged NHI’s, and poorly governed access paths undermine regulatory expectations for accountability, least
privilege, and auditability.
Open discussion on how to detect and reduce identity debt for AI workloads, apply continuous governance to NHI’s,
and build guardrails that align with emerging AI regulations, without slowing innovation.

Key takeaways

  • Name identity debt explicitly (time, credential, privilege, ownership, lifecycle) and measure the gap between how fast access is created and how fast it is reviewed, rather than just counting identities.
  • Replace long-lived embedded secrets with short-lived, identity-based credentials (workload identity federation, OIDC, SPIFFE) so a compromised credential is only valid for minutes and scoped to one task.
  • For every agent action, use a token broker to scope access to one tool and one purpose, and keep the chain of delegated authority (which user, which agent, which permission) reconstructable after the fact.
  • Do not default to blocking a risky-looking agent; prefer reducing its scope (read-only, shorter credential lifetime, added approval step) since blocking can silently break a workflow you cannot see.
  • Build the five governance pillars (discovery and inventory, authenticate, authorize, monitor and audit, lifecycle and revoke) into existing tools before buying new ones; the fundamentals do not change for agents.

Speakers

Sharon Chahal
Sharon Chahal
Principal Product Manager · Microsoft

Sharon Chahal is a Principal Product Manager in Microsoft Security, With over 25 years of experience, she leads strategy where security zero trust, and AI-enabled security converge.

Resources

Photos

Tags

More from GoSec 2026

Also from Sharon Chahal

On the same topic