Agent Identity & Access Management: Securing Non-Human Identities

Agents are **non-human identities (NHI)** that hold credentials, call APIs, and touch production systems — yet most teams grant them a single long-lived token with far more access than the task requires. This guide covers the emerging NHI governance trend (Obsidian, SPIRE, SPIFFE), why agent IAM is now a board-level security topic, and how [Smoke Monkey Harness](/solutions/what-is-an-ai-agent-harness) enforces scoped credentials and least-privilege tokens while **Smoke Monkey Canvas** gives you one place to audit every identity in a fleet.
Agent Identity & Access Management: Securing Non-Human Identities: Agents are **non-human identities (NHI)** that hold credentials, call APIs, and touch production systems — yet most teams grant them a single long-lived token with far more access than the task requires. This guide covers the emerging NHI governance trend (Obsidian, SPIRE, SPIFFE), why agent IAM is now a board-level security topic, and how [Smoke Monkey Harness](/solutions/what-is-an-ai-agent-harness) enforces scoped credentials and least-privilege tokens while **Smoke Monkey Canvas** gives you one place to audit every identity in a fleet. Designed as a zero-dependency, open-source TypeScript architecture under the MIT License with native Model Context Protocol (MCP) support and deterministic phase state machines.
- Every agent is an identity that needs its own scoped credentials, not a shared admin token.
- Least privilege means short-lived, per-task tokens bound to a single workspace and a narrow tool set.
- Smoke Monkey Harness bakes identity into `createAgent()` with deny-by-default permissions and per-tool scoping.
- Smoke Monkey Canvas makes a whole fleet inspectable — see which identity called which tool, when, and why.
import { createAgent } from 'smoke-monkey-harness';// Every agent runs as its own scoped, non-human identityconst agent = createAgent({provider: 'anthropic',model: 'claude-sonnet-5',workspacePath: process.cwd(),identity: { principal: 'agent://repo-auditor' },credentials: { ttlSeconds: 900, scope: ['repo:read', 'tests:run'] },permissions: {read_file: 'allow',run_command: 'ask',write_file: 'deny',network: 'deny',},});await agent.run('Audit dependencies and report every outdated package');
Watch: Related Video Guides
Anthropic Just Built an Agentic OS — Open Source Harness Breakdown
Smoke Monkey
Identity and Access Management for Agentic AI: Securing Non-Human Identities
OpenText NetIQ Unplugged
Why Non-Human Identities Are the New Attack Surface
A human identity logs in, does a bounded amount of work, and logs out. An agent identity runs continuously, holds credentials in memory, calls dozens of APIs, and never gets tired. That is exactly why NHI governance became a 2026 security priority: projects like Obsidian, SPIRE, and the SPIFFE standard exist to give workloads a cryptographic, verifiable identity instead of a shared secret. An agent with a standing admin token is indistinguishable from a permanent backdoor. Smoke Monkey Harness treats the agent as a principal from the first line of code, and Smoke Monkey Canvas extends the same model to a whole fleet of agents at once.
A shared token is a shared blast radius
If every agent uses the same credential, one compromised prompt equals total access. Scoped identities turn a fleet-wide breach into a single contained incident.
Least Privilege: Scoping Agent Credentials by Task
Least privilege for an agent has three dimensions: scope (which resources), verbs (read vs write vs execute), and time (how long the credential lives). A review agent needs repo:read and tests:run for fifteen minutes — nothing more. Grant short-lived tokens per task, bind them to a single workspace, and revoke on completion. The harness exposes this directly: you declare permissions in createAgent() and pass a scoped credential with a TTL, so the runtime cannot accidentally exceed the grant. Drive it from code or from Smoke Monkey Canvas — the identity stays scoped.
import { createAgent } from 'smoke-monkey-harness';// Narrow verbs + short TTL = a small blast radiusconst reviewer = createAgent({provider: 'anthropic',model: 'claude-sonnet-5',workspacePath: process.cwd(),identity: { principal: 'agent://pr-reviewer' },credentials: { ttlSeconds: 900, scope: ['repo:read', 'pr:comment'] },permissions: { read_file: 'allow', write_file: 'deny', run_command: 'ask' },});// Dangerous verbs stay gated behind a human approval by default
How Smoke Monkey Enforces Agent IAM
IAM is only real if it is enforced at the tool boundary, not in a prompt. Smoke Monkey Harness routes every tool call through a single permission gate, so run_command, write_file, and network access each resolve against the agent identity before execution. You can attach an audit log, return a signed event per action, and expose the same agent over MCP without loosening the grant. That is the difference between an agent that *promises* to be careful and one that is *structurally incapable* of exceeding its identity. The same gate backs every agent you place on Smoke Monkey Canvas.
import { createAgent, createMcpServer } from 'smoke-monkey-harness';const agent = createAgent({provider: 'anthropic',model: 'claude-sonnet-5',workspacePath: process.cwd(),identity: { principal: 'agent://ci-bot' },credentials: { ttlSeconds: 600, scope: ['repo:read', 'ci:trigger'] },permissions: { read_file: 'allow', run_command: 'ask', write_file: 'deny' },});// Every tool call is attributed to the identity and written to an audit trailcreateMcpServer({ agent, auditLog: './agent-audit.log' });
Auditing and Governing a Fleet on the Canvas
One agent is easy to reason about; fifty are not. Smoke Monkey Canvas (npx @smoke-monkey/canvas start) is a visual spatial multi-agent OS where each agent is a card stamped with its identity, its scope, and its live status. Connect 300+ MCP tools and you can see exactly which principal called which tool across the whole board, approve a risky git push inline, and revoke a misbehaving identity without touching the others. For NHI governance, that single spatial view — combined with the harness audit log — is the control plane most teams are missing. Pair it with MCP server security best practices and agent security sandboxing for defense in depth. Smoke Monkey Harness enforces the grant while Smoke Monkey Canvas makes it visible.
Frequently Asked Questions
Q:What is a non-human identity (NHI) in AI agents?
A non-human identity is any principal that is not a person — including an AI agent — that authenticates to systems and holds credentials. Agents are a fast-growing NHI class because they run autonomously and call many tools.
Q:How does Smoke Monkey Harness scope agent credentials?
You declare a principal, a TTL, and a scope of verbs in `createAgent()`. The runtime enforces the grant at the tool boundary with deny-by-default permissions, so an agent cannot exceed its identity even if prompted to.
Q:Do I need a third-party identity provider like SPIFFE?
Not necessarily. Smoke Monkey ships per-agent identities and audit logs out of the box, and you can bind its principals to SPIFFE/SPIRE or your existing IdP when you want a single enterprise identity fabric.
Q:Can Smoke Monkey Canvas audit multiple agent identities at once?
Yes. `npx @smoke-monkey/canvas start` places every agent on one infinite canvas with its identity and scope visible, so you can review tool calls per principal and revoke a single identity without stopping the fleet.
Related Alternatives & Comparisons
Claude Code Runtime Alternative: Open Source Stdio MCP Agent Harness
LangChain TypeScript Alternative: Zero Dependencies & Deterministic Loops
Claude Agent Skills vs MCP: What Is the Difference? (Free Open Source Guide 2026)
Related Architecture Guides
View all guidesBest Open Source Coding Agents in 2026: Free, Local & Fully Hackable Harnesses
MCP Server Security Best Practices: Hardening Model Context Protocol Agents in 2026
Open Source Coding Agent Harness: Build a Forkable, Local AI Engineering Runtime
Build with Smoke Monkey Harness
Zero dependencies. 24 built-in tools. Human-in-the-loop safety. 100% open source under the MIT License.