Set up agent identity governance: inventory, sponsors, and bulk decommission
Every AI agent you create is a non-human identity (NHI): it has a lifecycle, it has a human sponsor, and it has per-channel limits on what it can reach. This guide walks the four-step sequence an access review actually runs — inventory → sponsor → reach → decommission — with the exact request and response at each step, no code required.What an AI-agent NHI is
The Cloud Security Alliance’s NHI framework asks a security team to answer, on demand: which agent identities exist, who sponsors each one, what can each one touch, and can you stop them all right now. Each Orbit agent carries the inputs for those answers:- Lifecycle. A created agent starts in
draft. Promoting it toactiveputs it in service — routed traffic reaches it. Suspending it takes it out of service:suspendedagents stop receiving traffic, but nothing is deleted and recordings, history, and spend attribution are preserved. Suspension is reversible; deletion is not the decommission path. - Sponsor. Every agent row stamps the human who created it. That sponsor id is attributed in the inventory and resolved to the member roster. When the sponsor leaves, the id stays on the row — a null-resolving sponsor is a review finding, not missing data.
- Reach. Per-channel concurrency caps bound what the agent can
touch right now, per channel. A missing cap fails open (no limit);
a cap of
0blocks the agent on that channel outright.
The inventory surface
In the dashboard, open Settings → Agent identities: one row per agent in your organization, with a lifecycle-status filter, a sponsor filter, and a search box. The same surface is callable asGET /api/v1/settings/agent-identities for audit tooling.
Two access rules apply to every request on this surface:
- Scope + role. Reads require the
agents:readscope; writes requireagents:write. Both also require the owner/admin role — decommissioning an identity estate is never a self-service action. - Organization scope. You only ever see your own organization’s agents and your own member roster.
Enumerate the inventory
Page through the inventory and filter it to the estate you are auditing. The query acceptsstatus, sponsorId, a case-insensitive
search over name and description, plus page / pageSize
(pageSize caps at 100).
data carries:
A typical row:
sponsor resolves to null when the agent predates sponsor
stamping (rare) — treat it as a review finding. A sponsor id whose
member left the roster still returns the id with an empty name and
email, so attribution survives off-boarding.
Assign and review human sponsors
Sponsorship is recorded at creation time — the person who creates the agent is its sponsor. Reviewing sponsors is the second step of the sequence:- Pull the inventory and group rows by
sponsor.id. - Confirm each sponsor is still an active member of your
organization. A sponsor id that resolves with an empty
nameandemailmeans the member has left the roster — the attribution stays, but someone currently in the org should own the agent. - Where an agent’s sponsor no longer makes sense — the member left, the project moved teams — reassign ownership by recreating or re-pointing the agent under the new owner. There is no sponsor-edit endpoint; sponsorship follows creation.
Per-channel reach settings
channelCaps on each row is what the agent can reach right now. Use
it as a review checklist:
- No cap listed → no limit. A missing channel fails open; the agent has no concurrency bound on that channel.
maxConcurrent: 0→ blocked. The agent cannot run on that channel at all.- Anything in between → bounded concurrency.
voice channel and a collections-script description
is exactly the finding a CSA-style review looks for.
Bulk suspend and reactivate
When the review decides an agent (or the estate) comes out of service, suspend it — never delete it. Bulk suspension is one call:- Bounded per call. Up to 500 explicit ids, or
{ "all": true }to suspend the entire inventory at once. - Idempotent. Re-suspending an already-suspended agent is a no-op; re-running the same body returns a stable response.
- Mis-targets are reported, not dropped. Any id your organization
does not own — or that simply does not exist — comes back in
notFound, so a typo never silently skips an agent. ChecknotFoundon every run. - Audited. Every bulk suspend writes to your organization’s audit log with the requested ids, the ids actually suspended, and the not-found set.
- Suspend the selection and confirm
notFoundis empty. - Verify the agents are out of service — re-run the inventory with
status=suspendedand confirm the ids are there. - If the suspension turns out to be wrong, reactivate each agent
through the agent management surface (set its lifecycle back to
active). Recordings, conversation history, and spend attribution are untouched by the suspend, so a reactivated agent returns to service whole.
Alert on drifted identities
The inventory is also the signal source for ongoing monitoring. Two conditions are worth a scheduled check against your alerting stack:- Un-sponsored identities. Pull the full inventory and alert on
any row whose
sponsorisnull, or whosesponsor.idno longer resolves to a current member (emptyname/email). Each drifted agent is an identity with no accountable human — the exact row a CSA review asks you to explain. - Reach wider than intent. Alert on rows where
channelCapsis empty (no cap on any channel) for agents that should be bounded, or where a cap you expect is missing.
Related
- Agent identity governance (compliance reference) — the control surface this walk-through exercises.
- SCIM provisioning — the IdP-driven half of the same NHI lifecycle.
- Authorization mandates — scoped, expiring mandate detail on top of the identity.