ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

A five-part inventory for your AI agent credentials

infoAI safety & securityimportance 22
AI summary · glm-5.3-flash

Orchid's CEO recommends inventorying five attributes of AI agent credentials to rein in over-privileged OAuth tokens and service accounts.

In a Help Net Security video, Orchid co-founder and CEO Roy Katmor argues that AI agents accumulate OAuth tokens, API keys, service accounts, and borrowed human credentials that sit outside normal identity review, leading to authority well beyond the agent's original purpose. He proposes treating each agent as an application and documenting owner and purpose, reachable tools, credentials, effective authority, and runtime behavior. Teams can then compare approved intent with observed behavior and apply scoped controls, including targeted kill switches.

  • Agents often hold OAuth tokens, API keys, and borrowed human accounts with accumulated permissions
  • Recommended inventory: owner/purpose, tools, credentials, effective authority, runtime behavior
  • Compare approved intent with observed behavior and apply scoped kill switches
VendorsOrchid
OrganizationsRoy Katmor
Full article164 words · extracted from helpnetsecurity.com · click to collapse

In this Help Net Security video, Roy Katmor, co-founder and CEO of Orchid, explains why AI agents hold credentials that nobody reviews. Organizations build agents in AI studios, connect them to enterprise tools, and give them accounts to do useful work. The agent is approved, the studio is approved, but the identities behind them sit outside the usual review process.

Katmor walks through an onboarding agent that touches HR, an identity provider, ticketing, payroll, and internal apps. Behind each connection sits an OAuth token, an API key, a service account, or a borrowed human account. Permissions accumulate, and the account ends up with authority well past the agent’s original job.

He argues for treating each agent as an application and inventorying five things: owner and purpose, tools it can reach, credentials it uses, effective authority, and runtime behavior. Teams can then compare approved intent with observed behavior and apply scoped controls, including a targeted kill switch.

Download: The Agentic Software Development Guide

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/09/04/ai-agent-credentials-video/