Introduction to Agents
What is an agent?
In BalkanID, an agent is a governed automation actor — for example an AI agent, bot, workflow, or other non-human automation — that can use tools, credentials, and application access on behalf of your organization.
Unlike a human employee, an agent typically:
Operates continuously or on a schedule
Authenticates with credentials rather than interactive login
May call tools, APIs, or MCP servers to take action
Can hold broad access across applications if misconfigured
Agents extend IGA for Non-Human Identities (NHI) so you can govern automation with the same rigor you apply to people and traditional service accounts.
Why Agents matter
Automation increasingly holds powerful access: API keys, vault secrets, MCP tool servers, and application permissions. Without a dedicated agent inventory, that access is hard to find, own, and investigate.
Common governance questions Agents help you answer:
Which automation actors exist in our environment?
Who is accountable for each agent?
Which identities and credentials does the agent have access to?
What resources can the agent reach, and what is its blast radius?
Which agents were discovered from an application versus registered manually?
Core concepts
Owner
The owner is the employee in BalkanID who is accountable for the agent — its purpose, access, and lifecycle follow-up.
Ownership is about accountability. It is not the same as saying the agent “is” that person as an identity.
Access associations
Agents can be associated with identities and credentials that they have access to.
Owner
Employee accountable for the agent
Identity / credential → Agent mapping
Which identities and credentials the agent has access to
Extracted vs registered agents
Extracted
Discovered automatically from a supported application integration. Most fields stay read-only and refresh on sync.
Manually registered / CSV
Created in BalkanID. You control the inventory fields and can edit or delete them according to your role.
How agents enter BalkanID
Agents can enter your tenant in three ways:
Add agents one by one in the BalkanID UI
Import or update many agents in bulk
Extract agents automatically from a supported application
See Adding Agents for an overview of all three methods.
What you can do with Agents
Once Agents (Early Access) is enabled, BalkanID lets you:
Inventory agents under Configure → Agents
Assign an employee owner for accountability
Associate the identities and credentials an agent has access to
Inspect an agent’s access footprint and blast radius
Discover agents from supported application integrations
To learn how the Agents UI works day to day, continue to Viewing Agents.
Related Documentation
Last updated
Was this helpful?

