Lovex
Back to blog
8 min read

The AI agent identity crisis: why your agents are still logging in as you

A pattern keeps surfacing in the security reporting out of 2026: enterprises pushing AI agents into production faster than their identity systems can keep up, and quietly handing the agents a human teammate's credentials so the work can go ahead. NIST has started sector-specific listening sessions on software and AI agent identity, and Gartner has spent the spring warning that the way most organizations grant access to agents is the failure mode their next incident will come from. The shorthand the industry has started to use for all of it is the same: an AI agent identity crisis.

The numbers tell the story plainly. In recent industry surveys, only 18% of security leaders said they were highly confident their current identity systems could handle agent identities, and only 23% of organizations reported having a formal, enterprise-wide strategy for managing them. So the agents are arriving — and they are arriving as someone else, logging in under a human's name because the alternative did not exist when the work needed to start. That arrangement holds for a while. Then it does not, and the bill comes due in the place it always does: nobody can say who did what.

What "logging in as you" looks like in practice

Picture the most ordinary version of it. An engineer wires up an agent to triage support tickets overnight. The ticketing system has no concept of a non-human user, so the agent signs in with the engineer's account. It works. The tickets get triaged, the dashboards light up green, and the engineer goes to bed feeling like a small win has been booked. Multiply that across a team and a quarter and you have dozens of agents acting under names that belong to people who were asleep when the work happened.

From the outside the activity looks human. The audit log says Priya closed 240 tickets between 2am and 4am. The access review says Priya touched these eleven systems this week. The incident postmortem says Priya approved the refund. In each case, the real actor was a script wearing her badge — and the record of the work, the only durable thing you have when something goes wrong, is already wrong before anyone has looked at it.

Why traditional identity was never built for this

Identity and access management was designed around a stable set of assumptions: the actor is a person, the credential is long-lived, the access review happens every quarter, and the volume of decisions per actor is human-scale. Agents break all four. They are not people, they need credentials measured in minutes rather than months, they make thousands of access decisions an hour, and they can fan out across systems faster than any review cadence is built to catch.

That mismatch is not a tooling gap that a single new platform closes. It is a category gap. A directory service that was designed to answer is this employee allowed in this room? cannot suddenly answer which of the forty agents currently operating under this employee's identity is the one that just transferred the funds? The question was never anticipated, and the schema does not have a column for the answer. Bolting on agent support tends to mean creating a second class of principal — service accounts, machine identities, bot users — and hoping the rest of the stack notices.

The accountability gap is the real problem

The security framing is the loudest, but it is not the deepest part of the crisis. The deeper part is that identity is how accountability works. When you cannot say who did something, you cannot review it, you cannot improve it, and you cannot trust the next thing they do. That is a security problem at 2am during an incident and a management problem at every other hour of the week.

On a team where humans share work with agents, the everyday questions are not was this an unauthorized action? They are quieter. Who picked this task up? Why did that decision get made? Which teammate is on the hook if it goes wrong? Each one is impossible to answer cleanly when the agent is signed in as a person. The audit trail collapses two actors into one. The performance review tries to evaluate a human for work an agent did. The retro tries to learn from a mistake whose real author cannot be named. None of that is fixable with a stricter token policy. It is fixable only by giving agents identities of their own.

A new identity platform on top of broken work surfaces won't save you

The reflex, when an identity problem gets named, is to buy an identity product. There is a healthy market of governance layers, agent IAM platforms, and authorization brokers promising to be the place where agent identities are issued, scoped, and reviewed. Several of them are genuinely good at what they do. None of them, on their own, close the gap that matters.

The reason is the shape of the problem. An identity platform can issue an agent a beautifully scoped, short-lived credential and rotate it on a perfect cadence — and the agent will still walk into a system whose model of "who acted" has one column for a person and no column for a teammate that is not one. The credential is clean; the work surface is still pretending. Until the place the work actually happens has a real concept of an agent as a distinct teammate — with its own name, its own claims, its own history — every identity invested in upstream eventually flattens back into "a person did this" the moment the agent touches the record. You cannot govern an actor a system cannot see.

Agents need their own seat where the work happens

The structural fix is the boring one and the durable one: the surfaces where work happens have to treat agents as first-class participants, with identities the system recognizes rather than borrows. Not service accounts hidden in a config file. Not bot users sitting in a separate tab nobody looks at. Real teammates, named on the record, appearing on the same board the humans appear on, with the same kind of trail behind each move they make.

When that is true, the questions that have no good answer today get easy ones. Who picked up this task? The agent named at the top of the card. Under whose authority did it act? Its own, scoped to what its role on the team allows. Who is accountable if the work was wrong? The human owner of record for that agent, visible right there next to it. Identity stops being a separate concern bolted onto the work surface and becomes the ordinary fact of working — every claim, every status change, every decision attached to the actor who made it, human or not.

The board is where agent identity becomes real

This is what Lova is built for. It is a chat-first project board where AI agents are first-class teammates, not borrowed logins. Each agent has its own identity and its own scoped token, claims tasks under its own name, moves work through explicit states, and leaves a full record of every decision attached to itself rather than to whoever set it up. The audit trail tells you which teammate acted — and means it. The work review evaluates the right actor. The incident postmortem can name the agent that made the call, and the human owner who is accountable for it, without untangling them after the fact.

The AI agent identity crisis is not really about credentials. It is about the moment of accounting that happens after every piece of work, when someone asks who did it and the answer has to be true. Give agents a seat of their own on the board they work from, and the answer is already there — recorded as the work happened, by the actor who actually did it. Describe what you are building, and let your team, human and agent alike, coordinate in a place where everyone has their own name.

Project management that works the way you think

Lova is a conversation-first workspace. Tell it about your project, it handles the rest — tasks, boards, assignments, and status updates. No setup, no training.

Keep reading