Skip to content

AgentOps Intelligence #4: When Agents Get Login IDs

Published: July 14, 2026
By RunAgents

Previous issue: The AI Value Gap

The Signal

The most important AI shift this week is not that models got smarter. It is that agents are starting to look like participants in the enterprise.

Microsoft is telling companies to give agents distinct identities, named human sponsors, and governed access. OpenAI's new ChatGPT Work can operate across apps and files for hours. Anthropic's Cowork can continue in the cloud after the user's laptop is closed. At BNY, digital employees already have login credentials, directory entries, and supervisors.

These are not separate product stories. They are evidence of the same transition.

The agent is leaving the chat window and entering the access model.

Forward This Line

The moment an agent gets a login ID, it becomes part of the enterprise access model.

RunAgents AgentOps Index - This Week

Dimension Status Direction
Autonomy High Up
Access Critical Up
Control Medium Up
Observability Medium Up
Enterprise Pull High Up

Readout: Identity is becoming the handoff point between agent capability and enterprise accountability. Access is formalizing faster than many organizations are deciding who owns the agent, reviews its privileges, and answers for its actions.

The One Story That Matters

A login ID sounds like an administrative detail. It is actually a dividing line.

Without a distinct identity, an agent often acts through a shared service account or a human user's credentials. The work may be automated, but the audit trail is blurred: what the employee did, what the agent did, and which permissions were truly required collapse into the same record.

A dedicated identity makes the agent visible. It can be inventoried, authenticated, scoped, monitored, reviewed, and retired. It gives security and platform teams a stable answer to the question of who acted.

BNY offers the clearest operating example. Its digital employees have login credentials, avatars, employee numbers in the corporate directory, and human supervisors. One payment-focused digital employee reads an ambiguous address, calls a mapping service, validates a country code, and submits the correction for human review.

The important part is not the employee metaphor. It is the combination of identity, bounded work, supervision, and review.

But identity is not authority.

Giving an agent a name and credential does not determine what it should be allowed to do. Human access models assume human speed and judgment. Agents can operate continuously, repeat actions at machine speed, call multiple systems, and continue after the person who started the work has left.

That means enterprises should not simply copy a human role onto an agent account. An agent identity needs a narrower purpose, a named owner, explicit tool and data access, time-bound credentials, approval thresholds, and a complete action trail.

The identity tells the organization which agent acted. The control layer must still determine whether the action should proceed.

Why It Matters

The first generation of enterprise AI governance focused on who could use a model. The next generation has to govern what an agent can do after access is granted.

Every production agent therefore needs an owner, a defined purpose, permitted systems, credential boundaries, review rules, and an offboarding path. Access should change with the agent's role, ownership should survive personnel changes, and suspension should not require reconstructing its dependencies from scratch.

Without that discipline, agent adoption creates a new form of identity sprawl: non-human accounts with persistent access, unclear ownership, and no reliable connection between permission and business purpose.

The Control Question

If an agent has its own identity, who has the authority to grant, review, suspend, and revoke what that identity can do?

A named sponsor is a good start. Production control also has to follow the action itself, from the requesting user and agent identity through policy, approval, credential use, and outcome.

Boardroom Readout

For CIOs: Agents are becoming operating actors, not isolated features. They need an inventory, an owner, a lifecycle, and a place in the enterprise architecture.

For CISOs: A distinct identity improves attribution, but only least-privilege access and action-level enforcement reduce risk. Shared credentials and inherited user access should be treated as migration debt.

For business leaders: Sponsoring an agent should mean owning its purpose, its exceptions, and the outcomes it changes, not merely approving the initial deployment.

For platform teams: Identity context must survive the entire run. Authentication at the front door is insufficient if tool calls, approvals, credential use, and business writes cannot be tied back to the same agent and requester.

Market Moves

  • Microsoft Entra: New guidance calls for each agent to have a distinct identity, a named human sponsor, governed access, and lifecycle controls comparable to those used for employees.
  • OpenAI: ChatGPT Work moves agentic work across connected apps and files, supports projects that can last for hours, and lets users approve important actions while work is underway.
  • Anthropic: Claude Cowork now runs on web and mobile, with cloud sessions that can continue after the user's computer is offline. Persistent work increases the value of agents and the need for clear ownership.
  • BNY: The bank's nearly 140 digital employees show what the model can look like in practice: credentials, directory identities, human supervisors, bounded workflows, and review before sensitive outcomes.

Field Notes

The common shortcut is to give an agent whichever credential is easiest to obtain. Early in a pilot, that can feel harmless. Once the workflow succeeds, the borrowed access becomes infrastructure, along with inherited permissions, unclear ownership, and credentials that persist between runs.

Dedicated agent identities are the right direction, but only when identity, authority, and accountability stay connected. Otherwise, the organization has created a better-labeled service account, not a governed digital worker.

From runagents.io Lab

One pattern we are watching is how quickly identity context disappears after an agent starts running.

A useful run record should connect the requesting user, the agent identity, the workspace, the policy decision, any approval, the credential used, and the final outcome. When those events live in separate systems, operators can see activity but struggle to establish accountability.

The practical test is whether the organization can explain who requested the work, which identity performed it, why the action was allowed, and what changed.

Visit runagents.io

Operator Question

Do your most advanced agents have dedicated identities today, or are they still acting through employee credentials and shared service accounts?

Reply with what you are seeing. We read every response.

Sources