Mapping Identities and Credentials to Agents
Overview
Mapping identities and credentials to an agent records which identities and credentials the agent has access to.
This is an access association, not an ownership mapping.
Identity → Employee (Identities page, Map to employee)
Ownership / accountability — which person the identity belongs to or is owned by
Identity or Credential → Agent (this page)
Access — which identities and credentials the agent can use or is associated with for governance
Use agent mapping when you need to answer: Which identities and credentials does this agent have access to?
Map identities to an agent
Login to the BalkanID application and switch to the tenant you want to update.
Head to Identities.
Select one or more identities the agent has access to.
Click Map identities.

In the Identity Mapping drawer, select Map to agent (not Map to employee).
Choose the target Agent.
Confirm the mapping.

Result
BalkanID processes the mapping asynchronously. When complete:
The identities appear on the agent’s Identities tab
The agent appears under Accessible by agents on those identity detail pages
Identity counts on the Agents page update accordingly

Map credentials to an agent
Login to the BalkanID application and switch to the tenant you want to update.
Head to Credentials.
Select one or more credentials the agent has access to.
Click Map credentials.

Choose the target Agent.
Confirm the mapping.

Result
BalkanID processes the mapping asynchronously. When complete:
The credentials appear on the agent’s Credentials tab
The agent appears under Accessible by agents on those credential detail pages

When to map
Use mapping when:
An agent uses a human or non-human identity to act in an application
An agent uses or is bound to a credential (for example, an API key or vault secret)
You need a clear access inventory for blast-radius analysis
For extracted agents, some access associations may already be discovered from the source integration. Manual mapping fills gaps and covers agents that were registered or uploaded in BalkanID.
To remove an access association, see Unmapping Identities and Credentials from Agents.
Last updated
Was this helpful?

