Key findings
It's a secrets problem before it's an identity problem. Many AI agents don't have their own distinct identity, so they operate using API keys, tokens, and other credentials issued to humans or workloads.
Those credentials can sit outside agent-specific identity controls. When no enterprise IdP mediates the exchange, agent activity can create a governance blind spot that standard identity reviews may not expose.
Discovery and attribution come first. Find where agent credentials actually live and identify the human or workload that owns them.
Prevention has to run alongside cleanup. Block new secret exposure while you migrate credentials already in use.






