As AI agents move from answering questions to taking action, businesses need clearer identity, permissions and approval boundaries. Learn why RBAC is becoming essential.

The biggest question about an AI agent is no longer simply, “What can it do?”
A more important question is: What should it be allowed to do?
An AI assistant that summarises a document creates one level of risk. An agent that can open customer records, update CRM fields, send messages, create tasks, access employee information or trigger workflows creates a very different one.
That is why identity and access management are becoming central to the agent era.
In February 2026, the US National Institute of Standards and Technology (NIST) began examining how established identity and authorisation practices should apply to software and AI agents. The concern is straightforward: once agents can access multiple datasets, applications and tools, businesses need reliable ways to identify them, authorise their actions and audit what they have done.
The future of AI governance therefore is not only about making agents intelligent.
It is about giving them boundaries.
Traditional access control is usually designed around people.
A salesperson may see customer records but not payroll. An HR manager may access employee information but not change CRM deals. An administrator may have broader permissions because their responsibilities require them.
AI agents introduce another type of identity into that structure.
An agent may work across several applications in seconds. It may read information from one system, use it to make a decision and then take an action somewhere else.
Microsoft's 2026 security guidance recommends treating agents as distinct identities rather than allowing them to operate through broad shared accounts. It also recommends tightly scoped permissions, approved tool access and clear auditability.
That distinction matters because an agent's capability and its authority are not the same thing.
An agent may be technically capable of accessing 50,000 customer records.
That does not mean its job requires access to all 50,000.
Role-Based Access Control, or RBAC, assigns permissions according to a defined role rather than simply giving everyone broad access.
The concept is not new. What changes in an agentic environment is the speed and scale at which permissions can be used.
Imagine a future sales agent whose job is to prepare follow-ups.
It might reasonably need permission to read selected CRM records, view previous activity and create a draft.
But should it also be able to:
Export the entire customer database?
Delete customer records?
Change another employee's permissions?
Send thousands of messages without approval?
Access HR, payroll or unrelated operational information?
Probably not simply because those systems are technically connected.
Good access design starts by matching permissions to the smallest practical job the agent needs to perform.
This is the principle of least privilege: give a person, application or agent the access required for its purpose, and no more.
Businesses should avoid treating access as a simple yes-or-no decision.
Reading a customer record is different from changing it.
Changing a record is different from deleting it.
Preparing a transaction is different from approving it.
Viewing a report is different from exporting the underlying data.
And operating inside one workflow is very different from receiving administrator-level access across the organisation.
The World Economic Forum's 2026 work on AI-agent governance similarly emphasises defining what agents are authorised to do and making that authority enforceable and auditable as deployments scale.
This suggests that businesses should think about permissions at the action level, not merely the application level.
Instead of:
“Agent A has CRM access.”
A clearer policy might be:
“Agent A can read assigned lead records and prepare follow-up drafts, but cannot delete records, export databases or send communications without approval.”
The second description is far easier to govern.
The goal of agentic AI should not automatically be maximum autonomy.
Some actions are low risk and repetitive. Others affect customers, money, employee records, legal obligations or sensitive information.
A useful design can therefore combine automation with deliberate approval points.
An agent might prepare an action and a person approves it.
Or an agent may operate independently for routine work but require additional authorisation when an action crosses a predefined risk threshold.
This is not necessarily a limitation of automation. It is a way of keeping accountability visible.
NIST's current work specifically highlights identification, authorisation, auditing and non-repudiation as important areas for agent identity.
When something changes, a business should ideally be able to answer:
Who — or what — performed the action?
Under which permissions?
On whose behalf?
What information was accessed?
And who was responsible for the workflow?
Permissions become harder to manage when customer information, tasks, employee records, appointments and communications sit across disconnected applications.
Each system may have separate users, separate roles and separate access rules.
As organisations add agents on top of that environment, permission management can become even more fragmented.
This is one reason businesses should consider the access model behind their software architecture, not only its visible features.
TrueValue Platform is designed around a shared platform foundation, with identity, permissions and access controls forming part of how connected Products operate. Particular permissions and security controls depend on the Product and workflow involved
That does not mean every workflow should automatically be opened to AI.
It means identity and permissions are foundational considerations before increasingly autonomous software is introduced.
For businesses already considering multiple AI agents, our guide to controlling AI agent sprawl explores the related questions of ownership, data, permissions and human oversight.
RBAC defines what an AI agent can access or do according to its assigned role. For example, an agent may receive permission to read particular records and create drafts while being prevented from deleting data or changing administrative settings.
Security guidance increasingly recommends giving agents distinguishable identities and narrowly scoped authority rather than relying on broad shared credentials. This makes access management, revocation and auditing clearer.
No. Access should be aligned with the specific workflow. More access does not automatically make an agent more useful and can increase the impact of errors or misuse.
No. RBAC is one layer. Organisations may also need identity management, tool restrictions, logging, human approvals, monitoring, lifecycle management and periodic access reviews depending on the workflow and level of autonomy.
AI agents will increasingly be able to interact with the same business systems people use every day.
That makes permissions a business-design question, not just an IT setting.
Before giving an agent access, define its purpose. Decide what it can read, change, send, approve and export. Separate routine actions from high-impact ones. Keep a human owner visible. Make important actions auditable.
The agent may decide how to complete a task.
Your business should still decide what it is allowed to do.
If you are reviewing how identities, permissions and connected workflows fit across your operations, request a personalised demo of TrueValue Platform.
Continue exploring connected workflows, product playbooks, and strategic guides.

AI agents are multiplying across business workflows. Learn how to recognise agent sprawl and create clearer ownership, permissions, data and human oversight.

AI agents may not replace business software, but they could radically change how people interact with it. Explore what happens when work shifts from navigating screens to requesting outcomes.

AI agents depend on the customer information behind them. Learn how data quality, CRM structure and connected customer context can prepare businesses for AI.