DEV Community

Auth By Example
Auth By Example

Posted on

SOC 2 CC6 and ISO 27001 still assume humans — agents break the evidence model

SOC 2 CC6 / CC7 and ISO 27001 Annex A access controls were designed around human users: provisioned accounts, predictable sessions, and admin actions you can attribute to a person.

AI agents break those operating assumptions. A token can be valid at consent time, then an agent chains tools and produces side effects the quarterly user-access review never sees. OAuth still answers "can this client use this token?" — it does not fully answer "should this agent, for this user, call this tool on this resource right now?"

Useful evidence for agentic systems usually needs:

  • Actor — user + agent/workload identity, not a shared automation mailbox
  • Decision — policy allow/deny at the tool call or sensitive action
  • Resource and action — what was touched, not only that SSO worked
  • Review coverage — non-human identities and agent entitlements in the access review cycle

We published a practical CC6 / ISO 27001 checklist for AI agents (I'm with Permit.io):

https://www.permit.io/blog/ai-agents-soc2-iso27001-access-control-checklist?utm_source=devto&utm_medium=social&utm_campaign=ai-agents-soc2-iso27001-access-control-checklist&utm_content=authbyexample-article

Top comments (0)