Give every agent an identity
An agent should be identifiable in the same way as a service account or contractor. Its activity must not disappear inside a shared human login.

As AI moves from answering questions to taking action, every organisation needs a clearer way to define access, ownership and accountability.
The goal is not to slow useful innovation. It is to make sure each agent has a purpose, a bounded identity, the right amount of access and a person who remains responsible for the outcome.
See the practical frameworkEarly AI use often begins with a person asking questions or preparing a draft. The next step is more consequential: an agent may search internal sources, classify an enquiry, update a record, prepare a workflow or take a defined action in another system.
That change is useful, but it means an organisation needs to answer familiar technology-governance questions in a new form: who is this agent, what is it allowed to access, who owns its behaviour and how would we know if something went wrong?
“Treat an agent as a new kind of digital colleague: useful, bounded, identifiable and always connected to human accountability.”
The shift
A person asks an AI tool for a draft or answer.
The agent can use selected internal information and systems.
The agent can prepare or complete an approved task.
Identity, permissions, logs, ownership and review become essential.
The right level of governance depends on the task. These principles help teams avoid both extremes: treating every experiment as high risk, or connecting a powerful agent without enough control.
An agent should be identifiable in the same way as a service account or contractor. Its activity must not disappear inside a shared human login.
Define the task, intended users, source information, expected outcome and person accountable before deciding which tools or permissions to connect.
Give access to the smallest useful set of systems, information and actions. A broad connection is not a shortcut to a safe pilot.
Set clear approval points for commitments, changes, external communication and anything that can materially affect a customer, colleague or system.
Record who initiated the work, which agent acted, the sources used, the outcome and any exception. Visibility makes review possible.
Agents need an owner, periodic access review, a way to stop them safely and a decision about whether the work still creates value.
Choose an example to see the questions a team should answer before it broadens an agent's access or autonomy.
Selected pattern
A named service identity with read-only access to a defined knowledge set.
It can explain and cite a source. It cannot change the source or make a decision for the user.
The process or content owner keeps the source material current.
A named owner is not just an escalation address. They decide whether the agent's purpose, access and outcomes remain appropriate as the work changes.
Good governance begins before an agent is released and continues while it is in use. It should be practical enough that teams actually follow it.
01
Describe the outcome, owner, users, information, risk and what the agent must never do.
02
Choose the smallest useful capability, identity, sources, permissions and human approval points.
03
Test realistic examples, including weak inputs and exceptions, before widening access or autonomy.
04
Monitor use, outcomes, changes, costs and incidents. Keep a simple route for users to challenge an answer.
05
Confirm that access remains appropriate, evidence of value exists and the owner still accepts accountability.
The goal is not perfect prediction. It is a clear, reviewable path from useful experiment to accountable operation.
Microsoft's Entra Agent ID direction reflects a growing need to identify and manage non-human AI actors. It is an important conversation for organisations using Microsoft AI services, especially where agents use enterprise information or connected systems.
However, technology control is only one part of the answer. The organisation still needs a defined use case, selected information sources, practical approval points, an accountable business owner and a way to review the result. Those questions apply regardless of the platform an agent uses.
Five questions before connecting an agent
What business task is the agent improving, and how will we know?
Which approved sources and systems does it genuinely need?
Which identity, permissions and environments are appropriate?
Where must a person approve, challenge or take over?
Who reviews access, activity, changes, incidents and value over time?
Use an AI readiness assessment to align opportunity, data, governance and investment decisions.
Read the AI readiness assessmentGive staff a practical boundary for using AI safely and consistently.
Read the AI risk policy guideUnderstand how data loss prevention and classification support safer AI adoption.
Read the AI readiness guideHelp ordinary business users get more from AI, with verification and safe reuse built in.
Start the practical AI courseConsider the operating, governance and measurable-value questions around everyday AI assistants.
Read the executive overviewSee how Wavex helps organisations identify, build and improve useful AI work.
Explore AI adoption servicesWavex can help you select a practical use case, assess the information and permissions around it, and build a controlled path from pilot to real value.
Tell us what work you would like an AI agent to improve. a sector specialist will be in touch. We aim to reply within 1 hour. We aim to reply within 1 hour.