TechVision Research · White Paper · August 2026
Rethinking Identity for the Agentic Enterprise
Role-based access control was built for an organization that no longer exists. AI agents do not break that model gently — they break it at machine speed.
- Why entitlement reviews and role mining stop working when an agent acts ten thousand times in an afternoon
- Two constructs that replace the guesswork: function-based access control and Artificial Identity
- A vendor-neutral read of 30+ platforms, scored on dated public evidence rather than positioning
- A four-quarter adoption path and eight questions to put to any vendor before you sign
20 pages28 dated sourcesNo paywallVendor-neutral

Read the full paper
Tell us where to send it. One email, no sequence, unsubscribe in a click.
No sales call is triggered by this download. See our privacy notice.
The problem
Identity inherited a nineteenth-century org chart
Access control learned its shape from industrial-era management: someone is in charge at the top, levels distinguish responsibility, and most of the work happens at the bottom. RBAC formalized that hierarchy into a standard, and the enterprise has been maintaining it ever since — roles nobody can define, attribute data invented on the fly, and ninety-day reviews that certify entitlements nobody understands.
Agentic AI does not introduce a new problem so much as remove the last of the slack from the old one. Four properties of agents make the pre-provisioned role untenable.
- 01
Volume and speedA human accumulates entitlements over a career. An agent can be instantiated, act ten thousand times, and disappear inside an afternoon.
- 02
EphemeralityAgents are created for a task. Provisioning them as durable identities with standing privilege produces exactly the orphaned, over-permissioned accounts governance was built to eliminate.
- 03
Delegation and chainsAn agent acts for a person and calls other agents. Impersonating the human is the easy implementation — and the one that destroys attribution and defeats separation of duties.
- 04
Autonomy without a roleThere is no org-chart position for an agent. Giving it one — a service account with better branding — reproduces every pathology above, faster.
The organizations that handle agentic AI well will not be the ones with the largest entitlement catalogues. They will be the ones that can say what a function is, who authorised it, and when its authority ended.
What is inside
Ten sections, written for people who have to decide something
- 01The problem: identity was designed for an organization that no longer exists
- 02What agentic AI changes
- 03A different premise: function-based access control (FuBAC)
- 04The second construct: Artificial Identity and its nine attributes
- 05Why now: the supporting standards arrived in 2026
- 06The vendor landscape, and how to read it — two evidence tables
- 07A phased adoption path across four quarters
- 08Procurement in a consolidating market
- 09Eight questions to put to any vendor
- 10Where TechVision Research fits
Who it is for
Three people usually read this together
The CISO
You need a defensible position on agent authorization before the board asks, and a caveat you can quote about how early this market actually is.
The security architect
You want the standards detail — Authorization API 1.0, MCP enterprise-managed authorization, A2A, the WIMSE delegation gap — and where each one stops.
The identity program leader
You have to decide how much governance to keep, what moves to run time, and how to restate segregation of duties without stalling the program.
Free download
Read it before your next vendor conversation
Every claim in the paper is tied to a dated public source, and every vendor entry to a shipped product or a published specification. Nothing in it is an endorsement.
Five fields. No sales sequence.