The Coalition for Secure AI released a paper on identity and access management for agents from its Secure Design Patterns for Agentic Systems workstream, focused on unique agent credentials and task-limited access. A companion paper on multi-agent systems discusses semantic-layer attacks, intent-based authorization and proposes agent detection and response as a defense category.
Why it matters
Agent identity and scoped credentials are a core open problem named in NIST, CISA and OWASP work, and this is an industry design pattern for it.
Key facts
As stated in the sources, with where to find them.
- Two papers: 'Agentic Identity and Access Management' and 'The Future of Agentic Security: From Chatbots to Autonomous Swarms'.Release announcement
Findings that cite this record
No tracked finding cites this record yet.
Key questions this bears on
- Where are deployed AI agents actually being exploited?Mostly around the model: connectors, credentials, tools, and packages, rather than the model alone.
Sources
Related records
Aug 14, 2025
Jul 16, 2025
Dec 9, 2025
Feb 17, 2025
Feb 6, 2025
Feb 17, 2026