When an employee joins, there is a process: account creation, access assignment, training, an owner. When they leave, there is another: revocation, return of assets, transfer of responsibility. When an agent joins, there is an install command. When it stops being used, it usually does not leave — it just stops being called.
Non-human identity lifecycle
The problem has a name in IAM vocabulary and a known solution. What changes is scale: non-human identities already outnumber human ones in most cloud environments, and agents accelerate that.
Minimum onboarding has six fields:
- Named human owner — a person, not a team. Teams do not answer at three in the morning.
- Purpose in one sentence, which later serves to judge whether the permissions make sense.
- Its own identity, derived from execution context.
- Permission scope at rest, with per-task elevation where needed.
- Log destination and the associated alert.
- Review date — without one, everything becomes permanent.
The offboarding nobody performs
A discontinued agent usually leaves three residues: the service account with live permissions, the secret in the vault, and a configuration entry in somebody's client. All three keep working.
A retired agent's credential is the perfect definition of orphaned access: nobody uses it, nobody watches it, and it still opens the door.
Offboarding is short: revoke the identity, delete the secret, remove it from client configurations, and archive the logs for the retention period. Four steps, and their value appears precisely when somebody finds the forgotten credential.
How to find what is already orphaned
Join two lists: identities holding write permissions and identities with a recorded call in the last ninety days. The difference is your offboarding backlog — and it is usually larger than the team expects, because nobody was ever assigned to look.