Skip to main content

Aug 7, 2026

The Governance Model That Wasn't Built for This

Patricia Titus

When identity governance was first formalized, the model made sense. One human requests access, another human approves it, and the access is logged. From there, humans periodically reviewed whether that access still made sense. The whole architecture assumes a person exists at the end of every access decision: someone you can call or question if something goes wrong.

That architectural assumption is now woefully incomplete in most enterprises.

"Governance model assumes a person at the end of every access decision," says Patricia Titus, Abnormal AI’s Field CISO, who has worked as a security leader in financial services, government, and technology sectors. "And that's simply not true anymore."

Service accounts don't have performance reviews. They don't get offboarded. They don't call you back when something looks suspicious. An API key provisioned for a project three years ago is still active, still carrying the permissions it was granted at creation, and no one in your organization could tell you with confidence what it should be able to do.

"We built identity governance for a world where humans were the only actors. And that's gone."

— Patricia Titus, Field CISO, Abnormal AI

This problem has been growing for years. But agentic AI has accelerated it in ways most organizations haven't fully registered. 

Mike Britton, Abnormal AI’s CIO and a former CISO in multiple major enterprise organizations, frames the multiplier plainly: in the old world, a hundred service accounts was a governance challenge. Now, the same environment might have a thousand agentic identities, each with permissions, each taking actions, and almost none of them with a behavioral baseline that would flag when something is wrong.

What makes this more than an access hygiene problem is the attacker logic. Piotr Wojtyla, Head of Threat Intel at Abnormal, has tracked how attackers approach the expanded identity surface: "In this day and age, a lot of it comes down to APIs, tokens—some form of a token—because a token is a programmatic way in which you authenticate." When an attacker targets a machine identity, they're not trying to trick a human into clicking something. They're going after credentials that operate autonomously, carry standing access, and will continue operating after compromise without triggering the kinds of alerts a human ATO scenario might.


Ungoverned enterprise permissions rose from 5% to 28% of total permissions in a single year, driven almost entirely by service accounts and agentic workflows. (HelpNet Security)


Houston Hopkins, Abnormal AI’s CISO, with experience at some of the largest organizations in the world, has walked through exactly what that looks like in an active investigation. An attacker scans the internet, finds a way to grab credentials off a piece of exposed infrastructure, then enumerates the access those credentials carry. "Once that credential is lifted off that particular machine, you can then see that credential being used for malicious purposes—it's coming from a new location, accessing things it's never accessed before, looking at things at a volume it's just never done before." 

The signal is all behavioral. The only way to catch it is to already know what normal looks like for that identity. For most non-human identities, no one has ever defined what normal is.

"If you can't see it, how can you protect it? You're either consciously admitting there's a bunch of noise over there you just want to be blind to—or you're saying discovery is difficult and you need help knowing what's out there."

— Stephen Harrison, VP Product, Abnormal AI

Stephen Harrison, Abnormal AI’s VP of Product, spent years as a CISO before moving to the product side. His governance philosophy comes from watching what happens when organizations skip the inventory step: "If you're a bus driver and there's an accident, you count the people on the bus before they get off and make sure they all get back on. Inventory is part of integrity." 

The same logic applies to non-human identities. If you don't know what agents and service accounts are running in your environment, what permissions they carry, and what they normally do, you have no foundation for any of what comes next.

Protect Against Evolving Email Threats

See how behavioral AI detects attacks that legacy defenses miss.