An AI agent is an identity.
Treat it like one.
The industry is building a separate product category for AI security. That is an architectural mistake. An AI agent authenticates, holds role assignments, and reaches data — which makes it a non-human identity with extra metadata, not a new species requiring a new graph.
A subtype, not a peer.
We considered making AI identity a peer of human and non-human. It was wrong, and we reversed it. Making AI a peer category forces you to duplicate every engine — reach, lifecycle, governance, attack paths — and then reconcile two answers for the same estate.
Modelled as a subtype, an AI agent inherits every capability that already exists for non-human identities on day one, and gains AI-specific signals on top. One trust engine. One lifecycle engine. One attack-path engine that recognizes AI, CI/CD, non-human, and human source types alike.
Zero feature duplication. Three first-class views.
Risky until proven safe.
Human identities get the benefit of the doubt because they have managers, joiners-movers-leavers processes, and someone who notices when they leave. Non-human identities have none of that. Nobody offboards a service principal.
So AuditGraph inverts the default for every NHI, AI agents included: the absence of a risk signal is itself a signal, never a neutral gap. An AI agent with no owner, no expiry, and no recorded purpose does not score well because it is quiet. It scores badly because nobody can say what it is for.
AI risk, expressed as identity risk.
Because agents live on the same graph, the questions you can already ask about a service principal work unchanged on an agent.
Agent discovery
AI agent service principals identified from a maintained pattern library — first-party Copilot identities, Cognitive Services principals, and the app registrations teams create for their own agents.
Agent → model → data reachability
The distinctive chain. Not “this agent exists” but “this agent can reach a model that can reach a dataset classified as PHI” — computed through the scope hierarchy, not assumed.
Federation and consent exposure
OAuth consent grants, federated credential subject claims, and the delegated permissions an agent accumulated that nobody re-reviewed.
Agents with no telemetry
An agent producing no runtime signal is not evidence of safety. It is a control gap, mapped as one, rather than an empty row.
The same nine verdicts
ORPHANED, GHOST_MSI, AT_RISK, FEDERATED_MISCONFIGURED and the rest apply to agents exactly as they apply to any other non-human identity.
Ownership and purpose
Who owns this agent, what was it provisioned for, and when was that last confirmed. Where the answer is unknown, it displays as unknown.
This is our newest surface.
AI identity coverage is real and shipping, but it is not as hardened as the identity estate underneath it. Here is exactly where each piece stands.
AI-identity risk surfaced as identity risk on the canonical graph. Functional, in hardening.
The AI-identity runtime surface. Usable, incomplete — not yet something to base a purchase on.
Inventory of models and AI workloads discovered in the tenant.
Federation and provenance trust for AI and non-human identities.
Agents as first-class identities with full reach maths. This is the part that is solid.
Alpha means usable but not yet trustworthy for a buying decision. We publish it because you will find out anyway, and finding out later is worse.
AI is the wedge.
Identity is the product.
Calling ourselves an AI security platform would be the easier pitch in 2026. We decline it, because the AI agents in your tenant are a small and fast-growing slice of a much larger problem — and a product built only for that slice cannot answer the question that actually matters, which spans humans and machines too.
AuditGraph is an Identity Security Graph with AI-native identity intelligence. The agents get you in the door. The graph is why you stay.
Find out what your agents can reach.
Most teams can name their AI agents. Very few can say which of them can reach regulated data. The assessment answers that against your own tenant.
Free forever on a bounded estate · 30-day trial unlocks everything · No credit card
Read-only access · No agents · No log ingestion · Azure generally available