Every enterprise leader I talk to can tell me how many employees their company has. Very few know how many AI agents they have.
That’s the defining identity security disparity no one has addressed yet. Developers, platform teams, and business users create AI agents by clicking “enable” in a software as a service (SaaS) tool. Those agents inherit credentials. They call other AI agents. They connect to data through Model Context Protocol (MCP) servers that nobody logged.
Unlike with a human employee, no one runs a background check on an AI agent, assigns it a manager, or schedules a quarterly access review with it.
Veza from ServiceNow was purpose-built to answer a fundamental security question: Who has access to what? Agentic AI introduced a new class of worker, creating new identity and access challenges that traditional approaches weren’t designed to address.
The question that matters isn’t how many AI agents an organization has. It’s the one security leaders have been asking about humans for years: Who can take, has taken, and should take what action on what resource?
That's difficult to answer in regard to an AI agent for three reasons:
- An AI agent’s permissions are usually borrowed. It runs as a service account, an API key, or a delegated human identity. As such, its true reach is the union of everything a particular credential can touch, not what the agent was designed to do.
- An AI agent has no manager. When the engineer who built an AI agent changes teams, the agent keeps running with the same access and the accountability trail goes cold.
- An AI agent’s blast radius is a graph, not a list: agent to model to MCP server to database to customer record. Understanding exposure means traversing relationships, not reading an entitlements table.
At ServiceNow, we’ve taken measures to govern and control AI agents. Veza AI Agent Security is now generally available with ServiceNow AI Control Tower, putting AI agent access risk in the same place enterprises are already governing their AI portfolios. The team building an AI agent and the team accountable for it work from the same view.
Veza AI Agent Security now supports ServiceNow, Anthropic Claude, OpenAI Assistants, LangSmith, Microsoft 365 agents, and Workday agent platform integrations—extending coverage that already spanned Amazon Bedrock, Salesforce Agentforce and Einstein, Microsoft Copilot Studio, Azure AI Foundry, and Google Vertex AI.
Across all of them, one view shows the AI agents, the models behind them, their human owners, and the resources they can reach. Human ownership is assignable and tied to the owner’s lifecycle, so when a person leaves or moves, their AI agents surface immediately instead of quietly persisting.
MCP became the default way for AI agents to reach enterprise data faster than most governance teams could write policies for it. A new MCP dashboard gives centralized visibility into MCP servers across the environment—the inventory step that has to exist before any least-privilege conversation is possible.
The Veza from ServiceNow Access Graph can answer almost any access question, which turns out to be a problem. Set the source, destination, or direction wrong, and it doesn’t give you an error message; it answers a different question. An empty result looks like no access, but it actually means the question was asked backward. The capability was never the bottleneck. Knowing what to ask was.
That’s why we prebuilt graph queries for AI agents. Select an agent, and five investigations are one click away:
- AI agent to resources
- AI agent to users
- AI agent to owner
- AI agent to model
- AI agent to MCP server
Each opens as a preview—counts first, graph snapshot second—before you commit to the full view. There’s a broader lesson in this graph preview: A governance capability nobody knows how to invoke isn’t a governance capability. We’ll extend the lessons learned from prebuilt graph queries beyond AI agents to nonhuman and human identities.
At Veza from ServiceNow, we’ve spent years helping organizations gain visibility into dormant human accounts. Our research found that 38% of identity provider users are dormant.
That debt took years to accumulate, one unreviewed account at a time. AI agents will build the same debt in months. They get created faster, by more people, and nobody is counting them.
The AI agent population in your environment is still small enough to govern. That’s the argument for moving now. Every agent running without an owner or a permission boundary is a finding on an audit you haven't scheduled yet, as well as a credential nobody is watching.
Don't wait for the cleanup project. Inventory the AI agents, attach human owners, and make their access answerable in one click while the number is still small. Who can take, has taken, and should take what action on what resource? Ask that now for every identity, human or not.
Find out how ServiceNow can help you take control of risk across every identity type.