Permanent access was always a bad idea. AI agents just made it catastrophic.
By Alex Lei - Senior VP APJ at Saviynt Source: Saviynt. Lei. For decades, enterprise security operated on a simple assumption: grant access once and trust it indefinitely. Once granted, those permissions - for people, applications and systems - were rarely reviewed and almost never removed, because that was the path of least resistance. Security teams call this standing privilege. That model was already showing its age before AI entered the picture. Now, AI agents have made it untenable. Unlike human employees who log in, complete tasks, and sign out, AI agents operate continuously, autonomously, and at scale. They do not simply access data, they traverse it, reason over it, and act on it across multiple systems simultaneously. An agent with permanent permission to read and change data across an organisation’s core business systems and its cloud storage is no longer just another user. It is a permanent attack surface, a way in that never clocks out. “Ghost” administrators AI agent...