Identity, delegation and runtime policy
Get ready for agentic access
AI agents do not act alone. A single task can involve a human requester, agent, service account, workflow, API token, tool and sensitive system. This guide helps you see where access decisions happen today and where runtime policy needs to sit next.

How to use this guide
Use these questions as a working inventory, not a scorecard.
For each section, capture what exists today, what is planned and what is unknown. Pay special attention to places where access crosses boundaries: human to agent, agent to tool, tool to system, system to data or service account to production resource.
The goal is to identify where policy needs to be enforced at runtime, where access should be scoped to the task and where evidence needs to connect the full action chain.
Your readiness snapshot
This is not a grade. It is a way to see where the next conversation should start.
What to look for next
For others, that foundation is already in place. The next step is extending it into the agentic action chain: understanding which agents exist, what they can touch, whose authority they use, where policy checks should happen and how to enforce runtime controls at each trigger point.