SOC 2 CC6 / CC7 and ISO 27001 Annex A access controls were designed around human users: provisioned accounts, predictable sessions, and admin actions you can attribute to a person.
AI agents break those operating assumptions. A token can be valid at consent time, then an agent chains tools and produces side effects the quarterly user-access review never sees. OAuth still answers "can this client use this token?" — it does not fully answer "should this agent, for this user, call this tool on this resource right now?"
Useful evidence for agentic systems usually needs:
- Actor — user + agent/workload identity, not a shared automation mailbox
- Decision — policy allow/deny at the tool call or sensitive action
- Resource and action — what was touched, not only that SSO worked
- Review coverage — non-human identities and agent entitlements in the access review cycle
We published a practical CC6 / ISO 27001 checklist for AI agents (I'm with Permit.io):
Top comments (0)