• 10 min read

Enterprise Agent Permission Management: What to Buy First

tl;dr

Authorized agents with valid credentials are the bigger enterprise agent risk, not shadow agents. Most organizations prioritize inventory and shadow detection, but runtime per-action permission checks are the control that actually stops costly breaches. Short-lived delegated tokens and policy checks on every tool call should be your first procurement priority.

Featured image for "Enterprise Agent Permission Management: What to Buy First"

91% of organizations cannot stop a risky AI agent action before it executes, according to Netskope’s research — and 54% of them already reported a confirmed or suspected agent security incident in the past year. That’s the uncomfortable starting point for anyone shopping for enterprise agent permission management in 2026. The tools exist. The budgets are being approved. The controls are arriving months after the agents did.

Here’s the part most buyers get wrong: the industry’s spending is tilted toward inventory and shadow agent detection, while the incidents that actually make headlines come from known agents holding valid credentials. The two most instructive cases on record — a chat integration whose OAuth tokens bulk-exported Salesforce customer data for ten days, and a public GitHub issue that steered an agent into private repositories — were standing grants doing exactly what they were allowed to do. Not rogue agents. Authorized ones.

That distinction should drive your entire procurement order.

Why can’t organizations stop a risky agent action before it runs?

Because most permission models were never designed to make a decision at the moment of action. They grant access up front and review activity afterward — a workflow that worked when the actor was a human moving at human speed. Agents broke that assumption. Lumos measured over 450,000 agent actions in a single week at its own company, which has fewer than 200 employees. By the time a security team reviews that volume, the damage is historical record, not risk.

The adoption numbers make the gap concrete. Proofpoint’s 2026 AI and Human Risk Landscape report found that 87% of organizations have moved AI assistants beyond pilot, yet 52% aren’t confident their controls could detect a compromise. So the exposure isn’t hypothetical pilot-stage risk anymore. It’s production risk with no runtime brake.

The root cause sits one layer below tooling, in a design decision most teams made without thinking about it: the agent runs as the user. As WorkOS explains, this collapses what the user is allowed to do and what the agent is allowed to do into one permission set, so the agent inherits everything — including the ability to delete records, export data, or touch production infrastructure. The OWASP Top 10 for LLM applications (2025) names this failure mode excessive agency, and lists it among the most commonly exploited vulnerability classes in production agent systems. When an agent deletes a production database, it usually had permission to.

The pattern I keep seeing across vendor announcements — Netskope, Lumos, Akeyless, Proofpoint, Okta — is convergence on per-action runtime authorization as the control layer that matters. Post-hoc audit can’t mitigate damage from a standing privilege when the actor moves at machine speed. The industry has largely figured this out. The buying order hasn’t caught up.

Is the bigger threat shadow agents or authorized agents?

This is where the market’s attention and the evidence point in different directions.

The visibility argument is real and well-funded. Gartner predicts the average global Fortune 500 enterprise will run more than 150,000 agents by 2028, while only 13% of organizations think they have adequate agent governance. That’s the framing behind Microsoft Agent 365’s registry and shadow agent detection, and behind WSO2’s newly GA’d control plane. The hygiene problem is also genuinely bad: Opal Labs found that more than 96% of non-human identities have no recorded purpose, and only 10% of their access was reviewed in the past year.

But look at what actually goes wrong. The Netskope data and the two high-profile incidents both involve known agents with valid credentials. As the Instacart CISO put it, long-standing credentials for AI agents are “basically full compromise with a delay timer”. Inventory tells you an agent exists. It doesn’t tell you what it can reach or what it just did — a point Lumos makes explicitly, and one that matches the incident record.

My read: inventory is table stakes, not the control plane. You need a registry eventually, but a registry without runtime enforcement is a well-indexed list of your blast radii. If you can only fund one initiative this quarter, fund the one that would have stopped the Salesforce bulk export — a broker that issues short-lived delegated tokens, plus a policy check on every tool call. We’ve covered this structural mismatch before in Agent Permission Models: The Unbudgeted Identity Crisis, and the procurement data suggests most enterprises still haven’t closed it.

What does the enterprise agent permission management market look like?

Small, growing fast, and fragmented along architectural lines. Mordor Intelligence projects the AI agent permission management market growing from USD 0.21 billion in 2026 to USD 1.02 billion in 2031 — a 37.18% CAGR. Meanwhile Auth0 cites projections that the ratio of non-human to human identities will hit 50:1 by 2030. Permission complexity is multiplying faster than headcount, which is why this category went from niche to board agenda in about eighteen months.

The tools cluster into four rough camps:

Here’s the comparison on the dimensions that actually drive cost and risk:

ToolPricingControl modelBest fit
Microsoft Agent 365$15/user/monthRegistry, shadow detection, lifecycleMicrosoft-centric enterprises
Amazon Bedrock AgentCore (Identity + Policy)~$60/month at reference workloadToken broker + Cedar checks per tool callAWS-hosted agent fleets
WSO2 Agent Manager— (open-source)Open control plane, framework-agnosticTeams avoiding ecosystem lock-in
Agent Planners$500/month Scale, $1,000/month AgencyMandatory human approval on every writeHigh-stakes, low-volume workflows
Salesforce Agentforce$0.10 per standard action, $550/user/month top tierConsumption-metered agent actionsSalesforce-native deployments

The dash for WSO2 isn’t an oversight — no pricing appears in the research, and it’s open-source, so license cost isn’t the meaningful comparison anyway. Integration cost is.

How does agent permission pricing actually work?

Badly, if you want predictable line items. The pricing models split three ways, and each one hides a different surprise.

Per-seat governance is the Microsoft model. Agent 365 lists at $15 per user per month, and for a 500-user deployment that’s 500 × $15 = $7,500 per month in subscriptions alone — for governance tooling, before you’ve paid a cent to build or run a single agent. AIToolGrade’s review flags exactly this: the number compounds fast, and Gartner publicly called the product “a work in progress” at GA. If you’re already committed to the E7 bundle, the marginal cost math changes. If you’re buying standalone, it doesn’t.

Consumption-metered is the Salesforce model, and it’s the one that scales scariest. Agentforce pricing ranges from free entry-level access to $550 per user per month, with consumption options including $2 per conversation and $500 per 100,000 Flex Credits. Based on that published rate, a standard production action costs $0.10 (20 Flex Credits), and a voice action $0.15 (30 Flex Credits). The trap: a five-action workflow costs roughly five times a one-action workflow, and nobody forecasts action counts accurately before production. Your permission-management bill and your agent-runtime bill are the same bill.

Flat-fee and workload-based is where the newer entrants land. Agent Planners publishes $500/month for Scale and $1,000/month for Agency — self-serve, usage-based, no sales cycle, and the company is candid that it doesn’t currently publish SOC 2 or ISO certification, which matters if procurement requires one. On the infrastructure side, the reference workload in the DAILY BRIEF buyer’s guide — 500 employees, 10 production agents, 2 million tool calls a month — puts Amazon Bedrock AgentCore Identity with Policy at approximately $60 per month. That’s brokered tokens plus Cedar policy checks on every gateway tool call, at a price point that makes the per-seat governance layers look expensive for what they enforce.

The honest comparison isn’t dollar-to-dollar, because these products do different jobs. Agent 365 answers “what agents exist and who owns them.” AgentCore answers “may this specific tool call proceed right now.” Only one of those would have stopped the ten-day Salesforce bulk export.

Which tradeoffs should you accept?

Every architecture choice here trades overhead against blast radius, and pretending otherwise is how teams end up with either unusable agents or unbounded ones.

Runtime checks vs. standing grants. Per-call authorization eliminates excessive agency risk but adds latency and compute cost to every action. Static standing privileges are nearly free to implement and give an agent unlimited blast radius at machine speed. Given that agents make hundreds of thousands of actions weekly at companies the size of Lumos, the latency tax is real — but so is the alternative. Gravitee’s approach of evaluating policy inside the gateway plugin rather than calling out to a microservice is one answer to the latency side; Keeper’s OS-level evaluation is an answer to the coverage side, catching actions that bypass MCP entirely.

Fine-grained policy vs. broad roles. Intent-based, per-action policies — what Proofpoint’s Semantic Business Policies and Akeyless’s Runtime Authority are selling — block behavior that role-based grants can’t see. The cost is continuous policy maintenance as agent workflows and tooling evolve. Netskope’s nine intent-based action categories (data destruction, credential manipulation, remote code execution, and so on) are a reasonable taxonomy to start from, but someone has to own keeping those policies current. Budget for that person before you sign.

Human approval vs. autonomy. Mandatory approval on every high-risk action eliminates unauthorized-action risk and negates most of the efficiency you adopted agents for. Agent Planners embraces this fully — no autonomous mode exists, so no configuration drift can quietly remove the gate. That’s the right call for irreversible, high-value operations like ad spend or payouts. It’s the wrong call for a coding agent touching a git branch. GitHub’s tiered model — block, require approval, or allow, set centrally and immune to user-side weakening — is a sensible middle path for developer fleets.

One customer anecdote worth weighing, with the caveat that it’s a vendor-quoted testimonial: MJS Packaging’s IT director says Okta for AI Agents lets them deploy across the enterprise “while eliminating security blind spots”. Treat that as directional, not evidentiary. The kill switch capability behind it, though — instant revocation of active tokens at the gateway — is a concrete feature you should demand from whatever you buy.

What should you buy first?

The buyer’s guide that anchors most of this analysis is blunt about sequencing, and the incident record backs it up. The recommended order: first a broker that issues short-lived delegated tokens, second a policy check on every tool call, third human approval only for irreversible actions. The reasoning is architectural, not preference: a policy engine is useless if the agent is still holding a long-lived credential, because the decision service doesn’t touch the key. Aembit’s gateway makes the same bet from the other direction — the agent never holds the downstream credential at all.

So here’s the decision framework I’d use:

  1. If your agents run on AWS: start with Amazon Bedrock AgentCore Identity with Policy. It brokers delegated tokens and checks every gateway tool call’s arguments in Cedar, at a cost the reference workload puts around $60 a month.
  2. If your agents span clouds and self-hosted MCP servers: start with Aembit or an equivalent credential broker, then layer per-call policy.
  3. If you’re Microsoft-centric and already buying E7: take Agent 365’s registry as a free rider on the bundle — but don’t mistake it for runtime enforcement, and don’t pay $7,500 a month standalone for inventory alone.
  4. If you’re framework-agnostic or sovereignty-constrained: evaluate WSO2 Agent Manager before committing to any ecosystem-native layer, since rebuilding governance on every framework swap erases the speed you bought agents for.

What I’d push back on is the current spending pattern: inventory first, shadow detection second, runtime control whenever the budget cycle allows. That ordering optimizes for the risk that hasn’t materialized while underfunding the one that already has a body count. The open question worth taking to your next architecture review: if an authorized agent with valid credentials executed a destructive action at 3 a.m. tonight, which layer you’ve actually purchased would stop it — and how many seconds would it take? If the answer is “the audit log, tomorrow morning,” you’ve bought a post-mortem, not a control.