How to Secure AI Agents: JumpCloud’s Four-Stage Identity Governance Framework
JumpCloud outlines a four-stage plan to discover, register and govern AI agents as non-human identities proliferate across critical corporate systems.
Summary
In a sponsored VentureBeat article published on August 6, 2026, JumpCloud argues that AI agents should be governed as workforce identities rather than treated merely as software integrations. These agents can interact with Salesforce, open Jira tickets, provision infrastructure, process financial transactions and communicate for employees. Yet many organizations allegedly deploy them without the onboarding, ownership and offboarding controls routinely applied to human workers. The article was written by JumpCloud CTO and co-founder Greg Keller and presents the company’s “Agentic IAM” approach, so its recommendations should be read as vendor-backed guidance rather than independent reporting.
The scale of the issue is supported by figures from JumpCloud’s Q3 2026 IT Trends Research report, which surveyed 800 IT leaders in the United States and United Kingdom. According to the company, non-human identities outnumber human users at 83% of organizations, while only 21% have governance controls designed specifically for those identities. The article does not provide enough methodological detail to independently assess those findings, but the figures illustrate the gap JumpCloud says has emerged between rapid agent deployment and identity governance.
JumpCloud’s proposed framework begins with continuous discovery. Organizations are advised to inventory agents across cloud services, managed devices, SaaS integrations and on-premises systems, recording each agent’s access, workflow influence and action triggers. The second stage is formal registration: every agent should receive a directory identity, a defined purpose, an authorized scope and a named human owner. JumpCloud contends that agents hidden behind shared service accounts, static API keys or environment variables cannot be governed systematically. Formal ownership is also intended to eliminate “Zombie Agents” that continue operating after their original task or project has ended.
The third stage applies least-privilege access and seeks to eliminate permanent credentials. Recommended controls include time-bounded entitlements, just-in-time credentials for privileged work, human approval before sensitive access, emergency shutdown mechanisms and credential shielding so the underlying model never sees secrets used for web applications, SSH servers or databases. JumpCloud also calls for privileged sessions to be recorded. The fourth stage adds continuous behavioral governance through action logging, recurring access reviews, anomaly detection, prompt revocation when an agent’s purpose ends and an audit trail linking actions to authorization, ownership and outcomes.
The article’s broader interpretation is that fragmented identity, device and security tools make these controls difficult to apply consistently. JumpCloud reports that organizations with fully unified IT environments are five times more likely to place agents in business-critical workflows than organizations with fragmented technology stacks. That association does not establish that unified systems cause safer or greater adoption, but it supports the company’s case for one control layer spanning people, devices and agents. Affected groups include IT administrators, security teams, compliance officers, business leaders and employees whose systems or data agents can reach. What happens next depends on whether organizations can identify shadow deployments, assign accountable owners and replace static credentials; the article does not quantify implementation costs, deployment timelines or the real-world effectiveness of the framework.
Positives
- JumpCloud provides a concrete four-stage process covering agent discovery, formal identity registration, least-privilege access and continuous behavioral governance.
- The framework requires every AI agent to have a named human owner, a documented purpose and a defined scope of authorized action.
- The recommended access controls include just-in-time credentials, human approval for sensitive operations and immediate emergency shutdown mechanisms.
- JumpCloud calls for every agent action and privileged session to be recorded, creating evidence for audits and incident investigations.
- The Q3 2026 survey of 800 US and UK IT leaders gives organizations a benchmark for comparing their non-human identity governance practices.
Risks & concerns
- JumpCloud reports that non-human identities already outnumber human users in 83% of organizations, increasing the number of identities security teams must track.
- Only 21% of surveyed organizations reportedly have governance controls specifically designed for non-human identities.
- Agents deployed through shadow AI may operate in production without a formal record, defined owner or systematic shutdown process.
- Static API keys, credentials stored in environment variables and service-account workarounds can leave agents with persistent, poorly governed access.
- The framework comes from a sponsored article written by JumpCloud’s CTO, and the supplied article does not include independent validation of the survey findings or recommended architecture.
- The article does not specify the cost, staffing requirements, implementation timeline or measured security outcomes associated with adopting Agentic IAM.