System and method for real time governance of AI agents in a cloud computing environment
A system and method for discovering artificial intelligence (AI) agent identities operating in a cloud computing environment and applying controls on the same, is presented. The method detecting a plurality of identities across multiple identity provider (IdP) systems of a cloud computing environment; detecting in the plurality of identities a first identity corresponding to an AI agent; generating a representation of the detected plurality of identities including the first identity based on a unified identity model; and applying a control on the first identity in the generated representation.
1 . A method for discovering artificial intelligence (AI) agent identities operating in a cloud computing environment and applying controls, comprising: detecting a plurality of identities across multiple identity provider (IdP) systems of a cloud computing environment; detecting in the plurality of identities a first identity corresponding to an AI agent; generating a representation of the detected plurality of identities, including the first identity based on a unified identity model; and applying a control on the first identity in the generated representation.
2 . The method of claim 1 , further comprising:
determining that the first identity corresponds to an AI agent based on a detection associating the first identity with an AI software as a service application.
3 . The method of claim 1 , further comprising:
applying a first control on the first identity; and
applying a second control on a second identity, the second identity associated with a human user, wherein the first control is more restricted than the second control.
4 . The method of claim 1 , further comprising:
generating an inventory of a group of identities of the plurality of identities, each identity in the group of identities associated with an AI agent.
5 . The method of claim 4 , further comprising:
associating the group of identities with a registered AI agent, a discovered AI agent, and an inferred AI agent.
6 . The method of claim 1 , further comprising:
applying the control to periodically initiate a user access review for the first identity.
7 . The method of claim 1 , further comprising:
applying the control on the generated representation to include any one of: disabling the first identity, blocking the first identity from performing additional operations, halting request-execution capabilities associated with the first identity, preventing the first identity from accessing enterprise computing resources, or any combination thereof.
8 . The method of claim 1 , further comprising:
generating a behavior baseline of the first identity based on a plurality of actions initiated by the first identity; and
determining that the first identity is associated with the AI agent based on the behavior baseline matching a predetermined agentic behavior.
9 . The method of claim 8 , further comprising:
determining that the first identity is associated with the AI agent based on the behavior baseline, mismatching a predetermined human user behavior baseline.
10 . A non-transitory computer-readable medium storing a set of instructions for discovering artificial intelligence (AI) agent identities operating in a cloud computing environment and applying controls, the set of instructions comprising: one or more instructions that, when executed by one or more processing circuitries of a device, cause the device to: detect a plurality of identities across multiple identity provider (IdP) systems of a cloud computing environment; detect in the plurality of identities a first identity corresponding to an AI agent; generate a representation of the detected plurality of identities including the first identity based on a unified identity model; and apply a control on the first identity in the generated representation.
11 . A system for discovering artificial intelligence (AI) agent identities operating in a cloud computing environment and applying controls comprising: a processing circuitry; a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to: detect a plurality of identities across multiple identity provider (IdP) systems of a cloud computing environment; detect in the plurality of identities a first identity corresponding to an AI agent; generate a representation of the detected plurality of identities including the first identity based on a unified identity model; and apply a control on the first identity in the generated representation.
12 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
determine that the first identity corresponds to an AI agent based on a detection associating the first identity with an AI software as a service application.
13 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
apply a first control on the first identity; and
apply a second control on a second identity, the second identity associated with a human user, wherein the first control is more restricted than the second control.
14 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
generate an inventory of a group of identities of the plurality of identities, each identity in the group of identities associated with an AI agent.
15 . The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
associate the group of identities with a registered AI agent, a discovered AI agent, and an inferred AI agent.
16 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
apply the control to periodically initiate a user access review for the first identity.
17 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
apply the control on the generated representation to include any one of:
disable the first identity, blocking the first identity from performing additional operations, halting request-execution capabilities associated with the first identity, preventing the first identity from accessing enterprise computing resources, or any combination thereof.
18 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
generate a behavior baseline of the first identity based on a plurality of actions initiated by the first identity; and
determine that the first identity is associated with the AI agent based on the behavior baseline matching a predetermined agentic behavior.
19 . The system of claim 18 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
determine that the first identity is associated with the AI agent based on the behavior baseline mismatching a predetermined human user behavior baseline.