What is an AI agent?
By Identra · Updated
An AI agent is software that uses an AI model to choose and carry out actions toward a goal with some autonomy. It looks at the result of each step and picks the next one without a person directing every operation.
How does an AI agent work?
Give an agent a goal, like finding out why last night's CI build failed. The model reads the task and proposes a step. The software around it runs that step if it's allowed, hands back the result, and the model decides whether to keep going, ask for help or stop.
Tools are how it touches anything. Search, file reads, API calls, a browser, a shell. Claude Code running the test suite in a repo is a tool call. The model wanting to run a command and the software letting it run are two separate decisions, and your controls belong on the second one.
Memory is optional. Some agents keep context for one task and drop it. Others write notes they read again next week. Stored memory needs access rules and a way to correct it, because a stale or planted note will shape later decisions.
How is an AI agent different from a chatbot or a script?
There's no boundary everyone agrees on. A chat window can sit in front of something that edits files and posts in Slack. For a security review, ignore the product label. Look at what it gets to decide, which tools it has and what its credentials allow.
Basic chatbot
- What it does
- Returns an answer a person then uses
- What to review
- What it can see and what it generates
Conventional script
- What it does
- Follows fixed logic, branches included
- What to review
- Code, inputs, credentials and permissions
AI agent
- What it does
- Uses a model to pick some actions as it goes
- What to review
- Allowed actions, delegated authority, execution limits
What does an AI agent do at a company?
Say a support agent picks up a billing dispute. It reads the ticket, pulls the invoice, checks the refund policy and drafts a reply. A support specialist approves any refund and anything that goes to the customer.
It can read that one customer's record and propose a refund. The payment system needs its own authorization before money moves. Exporting the customer table or editing admin roles is simply outside what its credentials allow.
Then an attachment tells it to email billing records to an outside address to complete verification. That's attacker text sitting inside a real ticket. The workflow should block the destination and log the attempt. Whoever approves anything should see the recipient, the data and the amount.
Why do AI agents need identities and owners?
An AI agent identity separates the software doing the work from the person who asked for it. Audit logs should tie together the agent, the task, its credentials and the user whose authority it carries. If five agents share one API key, you can't tell who did what or revoke just one of them.
Someone has to own each agent. An agent registry records the owner along with approved tools, reachable systems and how to stop it. When that person leaves, the agent shouldn't become an orphan.
When an agent acts for a user or hands work to another agent, delegation should carry the purpose and scope along with it. Permission to close a ticket isn't permission to do everything the requester can do.
What are the main security risks of AI agents?
Prompt injection makes an agent treat attacker text as instructions. It arrives through web pages, PDFs, emails and tool results. Once the agent can act, a planted sentence turns into data leaving the building or a record changing.
Agents also just get things wrong. Wrong customer. Wrong file. A retry after a timeout. Retrying a search is harmless. Retrying a payment isn't.
Excessive agency is the name for giving an agent more tools, permissions or autonomy than the job needs. Stolen credentials and compromised tools add more ways in. Good answers in testing tell you very little about whether it's safe to let it act.
How can security teams control AI agents?
Write down what the task is allowed to change. Apply least privilege to tools, records and destinations, and enforce it in the systems that execute actions, where nothing the model outputs can rewrite the rules.
- Record the owner, purpose, data, tools and credentials before switching it on.
- Separate read from write. Use short-lived, narrowly scoped credentials where the system supports them.
- Require approval for external sends, payments, deletions and permission changes, tied to the exact action and target.
- Restrict shell commands, file paths and network destinations. Keep secrets out of the model's context.
- Cap run time, retries and spend. Make writes safe to repeat.
- Log attempted actions, decisions, outcomes and approvers.
- Test with poisoned documents and misleading tool output. Confirm an operator can stop a run midway and revoke its access.
How Identra thinks about it
Identra shows security teams the AI agents in the browser, on endpoints and across connected identity, SaaS and cloud services, including owners for agents found through supported provider integrations. Teams can detect AI agents driving the browser and block them by policy, deny destructive endpoint commands when blocking policy is on, and review each recorded endpoint agent run with its user, device and outcome.
Go deeper: AI security, built on identity
Frequently asked questions
Does an AI agent need to be fully autonomous?
No. Plenty of agents pick steps inside a narrow task and ask a person before anything consequential. Match the autonomy to the risk.
Does every AI agent need long-term memory?
No. Many keep context only for the current task. Persistent memory helps with ongoing work but needs rules for access, retention and correction.
Is every application that uses a language model an agent?
No. An app that summarizes text in a fixed workflow uses a model without being an agent. An agent has the model choosing at least some actions as the task unfolds.
Can an AI agent use a person's account?
Some do, through a signed-in browser session or delegated OAuth access. Record whose authority is in use, tell agent activity apart from human activity where you can, and limit it to the approved task.
Does human approval make an AI agent safe?
Only if the reviewer can see the exact action, target and consequence. A vague confirmation prompt gets clicked through. Approval also doesn't replace access controls.
