On this page
Enterprise Agent Permission Management: What to Buy First
tl;dr
Authorized agents with valid credentials are the bigger enterprise agent risk, not shadow agents. Most organizations prioritize inventory and shadow detection, but runtime per-action permission checks are the control that actually stops costly breaches. Short-lived delegated tokens and policy checks on every tool call should be your first procurement priority.
91% of organizations cannot stop a risky AI agent action before it executes, according to Netskope’s research — and 54% of them already reported a confirmed or suspected agent security incident in the past year. That’s the uncomfortable starting point for anyone shopping for enterprise agent permission management in 2026. The tools exist. The budgets are being approved. The controls are arriving months after the agents did.
Here’s the part most buyers get wrong: the industry’s spending is tilted toward inventory and shadow agent detection, while the incidents that actually make headlines come from known agents holding valid credentials. The two most instructive cases on record — a chat integration whose OAuth tokens bulk-exported Salesforce customer data for ten days, and a public GitHub issue that steered an agent into private repositories — were standing grants doing exactly what they were allowed to do. Not rogue agents. Authorized ones.
That distinction should drive your entire procurement order.
Why can’t organizations stop a risky agent action before it runs?
Because most permission models were never designed to make a decision at the moment of action. They grant access up front and review activity afterward — a workflow that worked when the actor was a human moving at human speed. Agents broke that assumption. Lumos measured over 450,000 agent actions in a single week at its own company, which has fewer than 200 employees. By the time a security team reviews that volume, the damage is historical record, not risk.
The adoption numbers make the gap concrete. Proofpoint’s 2026 AI and Human Risk Landscape report found that 87% of organizations have moved AI assistants beyond pilot, yet 52% aren’t confident their controls could detect a compromise. So the exposure isn’t hypothetical pilot-stage risk anymore. It’s production risk with no runtime brake.
The root cause sits one layer below tooling, in a design decision most teams made without thinking about it: the agent runs as the user. As WorkOS explains, this collapses what the user is allowed to do and what the agent is allowed to do into one permission set, so the agent inherits everything — including the ability to delete records, export data, or touch production infrastructure. The OWASP Top 10 for LLM applications (2025) names this failure mode excessive agency, and lists it among the most commonly exploited vulnerability classes in production agent systems. When an agent deletes a production database, it usually had permission to.
The pattern I keep seeing across vendor announcements — Netskope, Lumos, Akeyless, Proofpoint, Okta — is convergence on per-action runtime authorization as the control layer that matters. Post-hoc audit can’t mitigate damage from a standing privilege when the actor moves at machine speed. The industry has largely figured this out. The buying order hasn’t caught up.
Is the bigger threat shadow agents or authorized agents?
This is where the market’s attention and the evidence point in different directions.
The visibility argument is real and well-funded. Gartner predicts the average global Fortune 500 enterprise will run more than 150,000 agents by 2028, while only 13% of organizations think they have adequate agent governance. That’s the framing behind Microsoft Agent 365’s registry and shadow agent detection, and behind WSO2’s newly GA’d control plane. The hygiene problem is also genuinely bad: Opal Labs found that more than 96% of non-human identities have no recorded purpose, and only 10% of their access was reviewed in the past year.
But look at what actually goes wrong. The Netskope data and the two high-profile incidents both involve known agents with valid credentials. As the Instacart CISO put it, long-standing credentials for AI agents are “basically full compromise with a delay timer”. Inventory tells you an agent exists. It doesn’t tell you what it can reach or what it just did — a point Lumos makes explicitly, and one that matches the incident record.
My read: inventory is table stakes, not the control plane. You need a registry eventually, but a registry without runtime enforcement is a well-indexed list of your blast radii. If you can only fund one initiative this quarter, fund the one that would have stopped the Salesforce bulk export — a broker that issues short-lived delegated tokens, plus a policy check on every tool call. We’ve covered this structural mismatch before in Agent Permission Models: The Unbudgeted Identity Crisis, and the procurement data suggests most enterprises still haven’t closed it.
What does the enterprise agent permission management market look like?
Small, growing fast, and fragmented along architectural lines. Mordor Intelligence projects the AI agent permission management market growing from USD 0.21 billion in 2026 to USD 1.02 billion in 2031 — a 37.18% CAGR. Meanwhile Auth0 cites projections that the ratio of non-human to human identities will hit 50:1 by 2030. Permission complexity is multiplying faster than headcount, which is why this category went from niche to board agenda in about eighteen months.
The tools cluster into four rough camps:
- Ecosystem-native governance. Microsoft Agent 365 became generally available May 1, 2026 at $15 per user per month (or bundled in M365 E7) — a governance layer, not a builder, providing a centralized agent registry, shadow agent detection, and lifecycle management. GitHub shipped the developer-facing equivalent: enterprise managed permissions for Copilot agent operations, letting admins centrally block, gate, or allow shell commands, file operations, and network domains — restrictions that can’t be weakened by user settings or saved approvals.
- Open, sovereign control planes. WSO2 Agent Manager is fully open-source and deployable anywhere, governing agents across any framework, model, or deployment. WSO2’s argument: locked-in governance forces you to rebuild controls every time you swap frameworks, which defeats the speed argument for agentic AI in the first place.
- Identity-platform extensions. Okta for AI Agents adds lifecycle management, runtime policy enforcement, and an instant kill switch that revokes active tokens at the Agent Gateway. Akeyless layers intent-based runtime control on a platform that already secures over 220 billion machine identity interactions for Fortune 500 organizations.
- Endpoint and workflow-level enforcement. Keeper Endpoint Privilege Manager evaluates every agent action at the OS level, regardless of whether the agent uses MCP, a direct API, or a local tool — a deliberate hedge against MCP-only governance. Agent Planners takes the opposite extreme: mandatory approval on every write, no autonomous mode.
Here’s the comparison on the dimensions that actually drive cost and risk:
| Tool | Pricing | Control model | Best fit |
|---|---|---|---|
| Microsoft Agent 365 | $15/user/month | Registry, shadow detection, lifecycle | Microsoft-centric enterprises |
| Amazon Bedrock AgentCore (Identity + Policy) | ~$60/month at reference workload | Token broker + Cedar checks per tool call | AWS-hosted agent fleets |
| WSO2 Agent Manager | — (open-source) | Open control plane, framework-agnostic | Teams avoiding ecosystem lock-in |
| Agent Planners | $500/month Scale, $1,000/month Agency | Mandatory human approval on every write | High-stakes, low-volume workflows |
| Salesforce Agentforce | $0.10 per standard action, $550/user/month top tier | Consumption-metered agent actions | Salesforce-native deployments |
The dash for WSO2 isn’t an oversight — no pricing appears in the research, and it’s open-source, so license cost isn’t the meaningful comparison anyway. Integration cost is.
How does agent permission pricing actually work?
Badly, if you want predictable line items. The pricing models split three ways, and each one hides a different surprise.
Per-seat governance is the Microsoft model. Agent 365 lists at $15 per user per month, and for a 500-user deployment that’s 500 × $15 = $7,500 per month in subscriptions alone — for governance tooling, before you’ve paid a cent to build or run a single agent. AIToolGrade’s review flags exactly this: the number compounds fast, and Gartner publicly called the product “a work in progress” at GA. If you’re already committed to the E7 bundle, the marginal cost math changes. If you’re buying standalone, it doesn’t.
Consumption-metered is the Salesforce model, and it’s the one that scales scariest. Agentforce pricing ranges from free entry-level access to $550 per user per month, with consumption options including $2 per conversation and $500 per 100,000 Flex Credits. Based on that published rate, a standard production action costs $0.10 (20 Flex Credits), and a voice action $0.15 (30 Flex Credits). The trap: a five-action workflow costs roughly five times a one-action workflow, and nobody forecasts action counts accurately before production. Your permission-management bill and your agent-runtime bill are the same bill.
Flat-fee and workload-based is where the newer entrants land. Agent Planners publishes $500/month for Scale and $1,000/month for Agency — self-serve, usage-based, no sales cycle, and the company is candid that it doesn’t currently publish SOC 2 or ISO certification, which matters if procurement requires one. On the infrastructure side, the reference workload in the DAILY BRIEF buyer’s guide — 500 employees, 10 production agents, 2 million tool calls a month — puts Amazon Bedrock AgentCore Identity with Policy at approximately $60 per month. That’s brokered tokens plus Cedar policy checks on every gateway tool call, at a price point that makes the per-seat governance layers look expensive for what they enforce.
The honest comparison isn’t dollar-to-dollar, because these products do different jobs. Agent 365 answers “what agents exist and who owns them.” AgentCore answers “may this specific tool call proceed right now.” Only one of those would have stopped the ten-day Salesforce bulk export.
Which tradeoffs should you accept?
Every architecture choice here trades overhead against blast radius, and pretending otherwise is how teams end up with either unusable agents or unbounded ones.
Runtime checks vs. standing grants. Per-call authorization eliminates excessive agency risk but adds latency and compute cost to every action. Static standing privileges are nearly free to implement and give an agent unlimited blast radius at machine speed. Given that agents make hundreds of thousands of actions weekly at companies the size of Lumos, the latency tax is real — but so is the alternative. Gravitee’s approach of evaluating policy inside the gateway plugin rather than calling out to a microservice is one answer to the latency side; Keeper’s OS-level evaluation is an answer to the coverage side, catching actions that bypass MCP entirely.
Fine-grained policy vs. broad roles. Intent-based, per-action policies — what Proofpoint’s Semantic Business Policies and Akeyless’s Runtime Authority are selling — block behavior that role-based grants can’t see. The cost is continuous policy maintenance as agent workflows and tooling evolve. Netskope’s nine intent-based action categories (data destruction, credential manipulation, remote code execution, and so on) are a reasonable taxonomy to start from, but someone has to own keeping those policies current. Budget for that person before you sign.
Human approval vs. autonomy. Mandatory approval on every high-risk action eliminates unauthorized-action risk and negates most of the efficiency you adopted agents for. Agent Planners embraces this fully — no autonomous mode exists, so no configuration drift can quietly remove the gate. That’s the right call for irreversible, high-value operations like ad spend or payouts. It’s the wrong call for a coding agent touching a git branch. GitHub’s tiered model — block, require approval, or allow, set centrally and immune to user-side weakening — is a sensible middle path for developer fleets.
One customer anecdote worth weighing, with the caveat that it’s a vendor-quoted testimonial: MJS Packaging’s IT director says Okta for AI Agents lets them deploy across the enterprise “while eliminating security blind spots”. Treat that as directional, not evidentiary. The kill switch capability behind it, though — instant revocation of active tokens at the gateway — is a concrete feature you should demand from whatever you buy.
What should you buy first?
The buyer’s guide that anchors most of this analysis is blunt about sequencing, and the incident record backs it up. The recommended order: first a broker that issues short-lived delegated tokens, second a policy check on every tool call, third human approval only for irreversible actions. The reasoning is architectural, not preference: a policy engine is useless if the agent is still holding a long-lived credential, because the decision service doesn’t touch the key. Aembit’s gateway makes the same bet from the other direction — the agent never holds the downstream credential at all.
So here’s the decision framework I’d use:
- If your agents run on AWS: start with Amazon Bedrock AgentCore Identity with Policy. It brokers delegated tokens and checks every gateway tool call’s arguments in Cedar, at a cost the reference workload puts around $60 a month.
- If your agents span clouds and self-hosted MCP servers: start with Aembit or an equivalent credential broker, then layer per-call policy.
- If you’re Microsoft-centric and already buying E7: take Agent 365’s registry as a free rider on the bundle — but don’t mistake it for runtime enforcement, and don’t pay $7,500 a month standalone for inventory alone.
- If you’re framework-agnostic or sovereignty-constrained: evaluate WSO2 Agent Manager before committing to any ecosystem-native layer, since rebuilding governance on every framework swap erases the speed you bought agents for.
What I’d push back on is the current spending pattern: inventory first, shadow detection second, runtime control whenever the budget cycle allows. That ordering optimizes for the risk that hasn’t materialized while underfunding the one that already has a body count. The open question worth taking to your next architecture review: if an authorized agent with valid credentials executed a destructive action at 3 a.m. tonight, which layer you’ve actually purchased would stop it — and how many seconds would it take? If the answer is “the audit log, tomorrow morning,” you’ve bought a post-mortem, not a control.
Recommended Reading
-
MCP Auth Example: 2026 Enterprise Authorization in Practice
The stable Enterprise-Managed Authorization (EMA) extension for MCP centralizes enterprise access provisioning for AI agent tooling via identity providers. However, EMA only governs connection-level access, leaving runtime per-action authorization entirely to implementers and creating a critical security governance gap for enterprise teams.
-
Agent Permission Models: The Unbudgeted Identity Crisis
92% of organizations agree governing AI agents is critical to enterprise security, but only 44% have implemented policies to do so. This gap stems from a structural mismatch between legacy security models and autonomous agent systems, creating an unbudgeted identity and governance crisis for enterprises.
-
MCP Server Deployment Guide: Build vs Buy in 2026
This 2026 guide compares self-hosted and managed MCP server deployment for enterprise teams, breaking down total cost of ownership, security responsibilities, and compliance requirements. It explains how the new stateless MCP specification changes infrastructure needs, and provides a framework to choose the right deployment model based on team size, regulatory constraints, and engineering capacity.