Any identity with meaningful access needs three things. A named human who’s accountable for it. Visibility into what it’s doing. A fast way to shut it off.
Employees have all three. Most AI agents have none of them.
Three Controls Most Agents Are Missing
The numbers come from JumpCloud’s Agentic IAM Pulse Report, based on responses from IT, security, and identity decision-makers across the U.S. and U.K.
No owner. 83% of organizations have no designated security leader or clear accountability for what AI agents do. When an agent behaves strangely, there’s no name on the record to call.
No visibility. 59% lack centralized visibility into agent activity. The behavior may be logged somewhere, but nobody is watching it in one place.
No kill switch. 55% have no centralized way to cut an agent’s access across all systems. Stopping one means disabling it system by system, by hand, while it’s still running.
These compound. Without an owner, nobody investigates. Without visibility, there’s nothing to investigate. Without a kill switch, knowing doesn’t help you act quickly.
What Missing Controls Look Like in Practice
Picture an agent that processes vendor invoices and has access to financial systems. It reads a document with an instruction embedded in it and treats that instruction as part of the task. It moves a payment.
The audit log records a normal access event from a legitimate identity. No credential was stolen. No password was cracked. The agent did exactly what it was authorized to do, on a task it was told to do by data it was told to read.
Now walk the three controls. With no centralized visibility, nobody sees it. With no kill switch, nobody can stop it quickly once they do. With no named owner, there’s no one to call while the clock runs.
The technical vulnerability matters less here than the response time. Every one of those gaps adds minutes or days to how long the situation runs unchecked.
Quick check: Could you shut an agent down today?
Zombie Agents Are the End State
A zombie agent is an abandoned agent that keeps running after the work that justified it ended. It still holds valid credentials. It still has access. Nobody owns it.
They form quietly. A customer service agent gets deployed to handle tier-one tickets. The project that funded it wraps up. The team moves to a different tool. Nobody revokes the agent’s access, because revoking it was never anybody’s specific job. It has an owner on paper, but that person left the company six months ago.
Nothing about this requires an attacker. It’s the default outcome when agents are deployed without a defined end to their lifecycle. Every one of them is standing access that no one is watching, and they surface during an audit or after an incident.
One Lifecycle for Every Identity
The fix is the process you already run for people, applied to agents.
Discover. Find the agents already running in your environment, including the ones business units provisioned directly.
Register. Give each one a formal identity record with a named human owner attached. Every agent gets a record. Every record gets an owner.
Manage. Scope credentials, replace standing authority with just-in-time elevation, and put human approval in front of high-risk actions. Keep a centralized way to cut access.
Govern. Keep logs and audit trails, and run access reviews on a schedule, the same way you review employee access.
This is what JumpCloud’s platform does across human, non-human, and agentic identities. When an employee offboards, deprovisioning triggers across connected systems. The same lifecycle applies to agents, including agents tied to a departing employee’s account and agents that have outlived their operational window.
Zombie agents don’t accumulate when every agent follows the same lifecycle as your workforce. The goal isn’t fewer agents. It’s knowing, at any moment, which ones you have, who owns them, and how to stop them.
For the full governance model, read The Silent Rollback.