Home · AI Security & Identity · AI Agent Governance

Your AI agents are staff now.
Give each one a passport.

Every AI agent and automation in your business has access to something: your inbox, your diary, your customer data, maybe your bank. We give each one an identity, a job description, limits, an owner and an off switch, so you always know what your AI can do and can stop it in seconds.

AGENT PASSPORTInvoice chaserACTIVEIdentitysvc-invoice-chaser@…OwnerFinance leadPurposeChase overdue invoicesCan readXero · one mailboxCan doSend remindersCannotPay · refund · deleteSpend limit£0Next reviewQuarterlyKill switchtested

Who gave the robot the keys?

Nobody can list your AI agents

Ask who has one running and you get a shrug. Zapier, Make, ChatGPT, Copilot, a voice agent…

Agents use someone's login

An automation runs as the owner, or as a leaver whose account is still open.

An agent can spend money

Ordering, refunding or paying, with no limit set and nobody checking.

No record of what it did

When something goes wrong you can't tell whether a person or the AI did it.

No owner

The person who set it up has left. It's still running.

No off switch

If an agent misbehaves at 2am, who stops it, and how?

Every agent on the register

  • ✓An AI agent register: every agent, automation and AI connector, with what it can see and do
  • ✓A passport for each one: its own identity, a named owner, a purpose, and data and spending limits
  • ✓Least-privilege access: each agent cut down to only what its job needs
  • ✓Human-in-the-loop rules: which actions need a person to approve first
  • ✓A kill switch, and a tested procedure for stopping any agent in minutes
  • ✓Quarterly access reviews, prepared by us and approved by you in twenty minutes

This is the joiner, mover and leaver process every well-run company has for people, applied to AI. It comes from 13 years of identity and access management.

The agent register

One line per agent. Yours to keep, kept current.

AgentOwnerCan doLimitReviewed
Voice agentOffice mgrBook · transferNo disclosureSep
Invoice chaserFinanceSend reminders£0 spendSep
Lead routerSales leadCreate CRM recordRead-only emailAug
Copilot (all staff)OwnerRead · draftNo sendSep
Old Zap · ex-staffnoneRefundsnoneRetired

Illustrative example. The last line is the one most firms find.

From unknown to under control

A register for a small firm usually takes a few days. The fixes depend on what we find. You get a timeline up front.

1

Discover

We find every agent, bot and AI connector across your accounts, including the ones nobody remembers.

2

Assess

Each one scored on what it can access, what it can do, who owns it and what would happen if it went wrong.

3

Fix

Own identities, tight permissions, limits, approvals and off switches put in place. Nothing breaks: we test as we go.

4

Keep

Quarterly reviews, a register that stays current, and new agents onboarded properly before they go live.

What this looks like in practice

A 30-person distributor had eleven automations and three AI assistants. Four ran under the former operations manager's login, still active six months after she left. One could issue refunds with no cap. Within two weeks every agent had its own identity, the refund agent had a limit and an approval step, and the leaver's account was finally closed.

Illustrative example, drawn from typical findings. Not a named client.

“Access control is the part most AI suppliers wave at. It's the part we came from.”

Michael LewisFounder, Eutaxis · 13 years in identity & access management

The things everyone asks first

What counts as an AI agent?

Anything that acts on your behalf without a person pressing the button each time: AI assistants with connectors (Copilot, Gemini, ChatGPT), voice agents, chatbots, Zapier, Make and n8n automations, API integrations and scheduled scripts. If it has a login, a key or a connector, it goes on the register.

We only have a few automations. Is this overkill?

If you can name them all, say what each can access and switch any one off in a minute, you're ahead of most. Most firms can't. The first step is the register, and it's usually quick. What you do next depends on what we find.

Will this slow our automations down or break them?

No. We change who the agent logs in as and what it's allowed to touch, not what it does. Every change is tested before the old access is removed.

Do we need new software?

Usually not. Most of this uses controls you already have in Microsoft 365, Google Workspace and your automation platforms. Where a tool would help, we'll say so, and it's your choice.

Who does the quarterly review?

We prepare it: what each agent did, what it could access, and what changed. You approve it or ask questions. Twenty minutes, four times a year.

How much does it cost?

It depends on how many agents and systems you have. After a free discovery call we give you a fixed price for the register and the fixes, and a monthly figure if you want us to keep it reviewed.

The other AI Security & Identity services

See how the five fit together →

How many AI agents are running in your business right now?

If you're not sure, that's the first thing we'll find out. Book a free 30-minute call.