The Agent Is a New Joiner, Not a New Tool
Vishal Sachar
Co-Founder & CEO of CLRT
When a person joins your company, an old and unglamorous machine switches on. They sign a contract that bounds what they may do. They get an account scoped to their role, not to the whole building. They serve a probation period in which their work is watched, a named manager reviews what they produce and answers for it, and their access grows as trust does. When they leave, a checklist takes it all back. When an agent joins your company, none of this happens. It arrives through an install flow, inherits whatever the person installing it could reach, and starts work immediately, with no manager, no probation, and no leaving date. The industry calls this adoption. Any HR department would call it negligence.
The category error is in the word tool. A tool acts when a person uses it and stops when they put it down, so whatever it does is straightforwardly the user's act. An agent is not that. It reads, decides, and acts across systems on delegated authority, often when nobody is watching, which is the entire point of buying it. That is not a description of software in use. It is a description of a junior colleague, and organisations already know exactly how to admit a capable, fallible colleague: gradually, under supervision, with authority that is earned rather than assumed. The install flow ignores all of it. One consent screen, clicked once, typically grants in thirty seconds a standing authority no human employee would be given in their first year.
The population this is happening to is larger than most boards imagine. CyberArk's 2025 identity survey of 2,600 security leaders, vendor research, so read it directionally, counts 82 machine identities for every human one, up from 45 to one in 2022. Two findings sit beside that ratio and sharpen it. 42 percent of those machine identities hold privileged or sensitive access. And 88 percent of the security leaders surveyed define a privileged user as a human. Hold those together and the picture is uncomfortable: nearly half the machine population carries sensitive access, while the governance concept meant to control sensitive access is still reserved, in most minds, for people. Agents make this worse, not better, because a service account does one narrow thing forever, and an agent is a general actor whose behaviour shifts with every model update and every instruction it happens to read.
The correction does not require inventing anything. Onboarding is the control system companies have run for a century, and it maps onto agents with almost no translation. Least privilege is the role-scoped account: the agent gets the access its job description requires, not the access its installer happens to hold. Probation is the supervised period: the agent drafts, a person commits, and its output is judged against defined pass criteria before any scope grows. The manager is a named human who reads the agent's work and answers for it, because accountability that belongs to everyone belongs to no one at exactly the moment something goes wrong. And offboarding is the leaving date: an inventory of what was granted, and a revocation path that actually runs when the agent is retired, replaced, or fails its review.
The platforms have started to notice. Microsoft announced Entra Agent ID in preview in May 2025, a directory entry for agents so they can be identified and governed like other identities. That is necessary, and it is the easy half. A directory tells you the agent exists. It cannot tell you what the agent's job is. Writing the role description is the work: what this agent may read, what it may write, what it must escalate, what wrong looks like for this process in this business, and what evidence a probation review would actually examine. Those are judgment calls about your operation, not settings in a console, and they are where in-house efforts stall, because the demo works without any of them and the incident that proves they were missing arrives months later, politely, in an audit nobody can answer.
The sharpest asymmetry is at the exit. A person who leaves hands back a laptop and a badge, and a process exists because people have been leaving companies for as long as there have been companies. An agent that is abandoned rarely leaves at all. The pilot ends, the champion moves on, and the tokens stay live, which is how an experiment becomes a standing credential nobody remembers granting. An organisation that cannot list its agents, what each may touch, and who manages each one has not adopted AI. It has hired a workforce it cannot name, on terms it never wrote down, with nobody assigned to notice when one of them goes wrong.
One consent screen grants in thirty seconds a standing authority no human employee would be given in their first year.
A deeper dive
The second-order traps are where the joiner frame earns its keep, because each one is invisible until it is expensive. The first is attribution. Most agents today act on the installer's credentials, so the audit trail records a person doing things that person never did, which means the one record you would reach for after an incident is quietly wrong from the start. The second is probation without pass criteria, which is not probation but theatre: a review that examines whether the output looked fine is a review the agent will always pass, and the only reviews that mean anything are the ones defined before the agent ran, with evidence a machine cannot charm. The third is scope creep by connection. Every new tool an agent is wired into is a promotion nobody approved, and because each grant is individually reasonable, the cumulative authority is never examined by anyone. The CyberArk finding that 88 percent of security leaders still picture a human when they hear privileged user is the cultural version of the same trap: the entire vocabulary of control was built for a population that is now a rounding error inside the identity count.
What makes this genuinely hard is that none of it can be bought as a feature. The registry can be, and the platform vendors will sell you one. But the role description, the pass criteria, the escalation thresholds, and the revocation inventory are all statements about your specific business: which data is radioactive, which actions are reversible, which mistakes are survivable and which end up in front of a regulator. Writing them requires reading the operation the way a careful chief of staff reads a new hire's first month, and then encoding those judgments as scoped credentials, review gates, and logs that attribute actions to the agent rather than to whoever installed it. That combination of operational judgment and unglamorous engineering is precisely what in-house efforts skip, because the agent works impressively without it, right up until the day it turns out to have been working unsupervised the whole time.
Work with CLRT
This is the work CLRT does. We onboard agents the way you onboard people: the role description that decides what an agent may touch, the probation gate its work must pass before its authority grows, the audit trail that makes its actions attributable, and the offboarding path that actually ends. If you want to know where an agent belongs in your operation, and on what terms it should be admitted, that judgment is what our diagnostic at ascent.clrtstudio.com is built to reach. Bring us the agent you have already installed, and we will write the terms it should have joined on.

Vishal Sachar
Vishal Sachar is the Co-Founder and CEO of CLRT, where he helps UAE businesses make sense of applied agentic AI and put it to work. He writes on agentic systems, AI governance, and the economics of automation. Reach him at vishal@clrtstudio.com or on LinkedIn.


