Dan Cahana — Notable Capital - Agent Identity Security Framework - May 2025
FreePreparing for a non-human future: agent identity security framework
FreeFree tier
About Dan Cahana — Notable Capital - Agent Identity Security Framework - May 2025
Dan Cahana's blog post 'The Identity Shift: Preparing for a Non-Human Future' on Notable Capital's website presents a framework for Agent Identity Security, addressing the challenges of managing non-human identities (NHIs) in enterprise environments. It outlines the risks of ungoverned agentic identities—such as shadow agents, excessive permissions, and lack of control—and proposes a secure posture based on visibility, authentication/authorization, and guardrails. The post is aimed at CISOs and agent developers, urging proactive adoption of security standards to enable safe agentic AI adoption at scale.
Key Features
Visibility into all agents operating within the enterprise
Authentication and Authorization via OAuth and per-agent tokens
Guardrails for agentic identity control
Framework for assessing agent security posture (based on Sunil Agrawal's model)
Pros & Cons
Pros
- Addresses a critical emerging security challenge before it becomes a crisis
- Provides a structured framework (visibility, authentication, authorization) for agent security
- Encourages proactive security posture over reactive mitigation
- Relevant for both security practitioners and agent developers
Cons
- Conceptual framework rather than a ready-to-use tool or software
- Limited detail on specific implementation steps or technologies
- Focuses primarily on enterprise risks, less on small-scale or individual use
Best For
Enterprise security teams managing non-human identitiesCISOs preparing for agentic AI adoptionAgent developers implementing security standards in their productsGovernance of shadow agents in enterprise environments
FAQ
What are non-human identities (NHIs)?
Non-human identities are digital identities for agents, bots, and automated systems that act independently in enterprise environments, often outnumbering human users.
What risks do ungoverned agents pose?
Shadow agents, excessive permissions, and lack of control can lead to privilege escalation, data breaches, and compliance issues.
What is the first step towards securing agents?
Defining a secure posture starting with visibility into all agents operating within the enterprise.