AI エージェントもチームの一員、全エージェントのセキュリティ確保フレームワークを公開
本文の状態
日本語全文を表示中
詳細モードで約10分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
VentureBeat AI
JumpCloud の調査によると非人間アイデンティティが人間ユーザーを上回る現状に対し、AI エージェントを正式な組織メンバーとして登録・管理するガバナンスフレームワークの重要性が示される。
AI深層分析を開く2026年8月7日 02:06
AI深層分析
キーポイント
非人間アイデンティティの急増と管理不足
JumpCloud の調査では、組織の 83% で非人間アイデンティティ(AI エージェントなど)が人間ユーザーを超えているが、ガバナンス対策を講じているのはわずか 21% に過ぎない。
シャドウ AI のリスクと発見の重要性
製品チームや個人が主導して導入されたエージェントは公式記録を持たず、IT が事後に管理責任を負う「シャドウ AI」が発生しており、全環境での継続的な発掘が必要である。
正式なアイデンティティとしての登録
各エージェントをディレクトリ上の正式なアイデンティティとして登録し、明確な目的、権限スコープ、そして行動の責任者となる人間の名前を割り当てるべきである。
ガバナンスフレームワークの構築
エージェントにエンタイトルメントを付与し、条件付きアクセスポリシーを適用し、定期的なアクセスレビューの対象とすることで、組織全体のセキュリティを強化する必要がある。
エージェントの正式な登録と所有権の明確化
エージェントは適切なアイデンティティとして登録され、条件付きアクセスポリシーやアクセスレビューの対象となる必要がある。名義所有者が定義されたエージェントは、所有権が失効した際に自動的に権限を喪失し、ゾンビエージェントの問題を防ぐ。
重要な引用
AI agents are now operating inside those same systems.
Shadow AI is the practical consequence: agents operating across production environments with no formal record, no defined owner, and no systematic way to stop them if something goes wrong.
Agents registered as proper identities can be assigned entitlements, subjected to conditional access policies, and included in access reviews.
The governing principle for that access is least privilege: each agent should have entitlements scoped precisely to what its defined purpose requires.
編集コメントを表示
編集コメント
AI エージェントが組織のインフラに深く組み込まれる中、従来の「人間中心」のセキュリティモデルでは対応しきれない新たな課題が浮き彫りになっている。本記事は、エージェントを単なるツールではなく管理対象の「メンバー」として捉え直す視点を提供しており、実務的なガバナンス指針として極めて価値が高い。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
JumpCloud 提供
現代の労働力において、人間か非人間かを問わず、すべてのアイデンティティを保護するための実践的なフレームワークです。
組織にはすでに人間のアイデンティティを管理する厳格なプロセスが確立されています。新入社員はオンボーディングを経て、役割と権限セットを与えられ、アクセスの責任者となるマネージャーが指名されます。退社時には資格情報が無効化され、アクセス権限も停止されます。これは IT 業界でよく知られたプロセスです。システムにアクセスできる労働力内のすべてのアイデンティティは、組織の世界に参加した瞬間から離脱するまで、常に把握され、範囲が明確に定義され、責任の所在が明確である必要があります。
AI エージェントは今や、同じようなシステム内で活動しています。Salesforce にアクセスし、Jira でチケットを作成し、インフラをプロビジョニングし、財務取引を処理し、チームに代わってコミュニケーションを行います。実質的な意味において、これらは組織の一員です。しかし、多くの組織では、これらのエージェントはオンボーディングされたことがなく、責任者を指名されておらず、目的が達成された後のオフボーディングプロセスも存在しません。
JumpCloud の 2026 年第 3 四半期の調査によると、非人間のアイデンティティの数は、83% の組織で人間ユーザーを上回っており、それらに特化したガバナンス制御を導入しているのはわずか 21% に過ぎません。以下のフレームワークは、このギャップを埋めるために設計されています。
ステージ 1: 環境内で稼働するすべてのエージェントを発見する
ガバナンスの第一歩は正確なインベントリ(資産目録)の作成ですが、多くの組織が不完全な状態のまま対応しています。AI エージェントは、製品チームや運用リーダー、そして迅速に行動するためのツールと動機を持つ個人によって展開されています。その結果、IT 部門は事後になってガバナンス責任を背負わされることが多く、何がどこで展開されているのか全体像を把握できていないケースがほとんどです。
これが「シャドウ AI」の実態です。正式な記録がなく、明確な所有者も定められておらず、何か問題が起きた際に停止させる体系的な手段もないまま、本番環境で動作するエージェントが存在している状態です。自社のエージェント群を発見・把握することは、一度きりの監査ではなく、継続的な取り組みとして捉える必要があります。エージェントが稼働しうるあらゆる環境——クラウドプラットフォーム、管理されたデバイス、SaaS 連携、オンプレミスシステムなど——全体にわたってインベントリを構築しましょう。各エージェントについて、アクセス権限を持つ範囲や影響を与えるワークフロー、そして動作トリガーとなる条件を文書化することが重要です。このインベントリこそが、本フレームワークの他のすべての要素を支える基盤となります。
第 2 ステージ:すべてのエージェントを正式なアイデンティティとして登録し、名義所有者を明確にする
環境内で稼働するすべてのエージェントは、ディレクトリ上に正式なアイデンティティとして存在させるべきです。これは従業員に割り当てる基本的な属性と同じものです。具体的には、定義された目的、許可された行動の範囲、そしてその振る舞いに対して責任を持つ名義上の人間所有者を明確に設定します。
エージェントを適切にガバナンスできる組織とできない組織を分けるのは、このアーキテクチャ上の決断です。正式なアイデンティティとして登録されたエージェントには、権限の付与や条件付きアクセスポリシーの適用、アクセスレビューへの組み込みが可能になります。一方、環境変数内の API キーやサービスアカウントの代わりとして存在するだけのエージェントは、体系的な手段による管理が不可能です。
登録機能はまた、「ゾンビエージェント」の問題に対処するための仕組みでもあります。ゾンビエージェントとは、本来の目的を終えたにもかかわらず稼働を続け、システムへのアクセスを維持し、権限を蓄積し続けるエージェントのことです。すべてのエージェントに更新責任を持つ名義所有者が割り当てられていれば、所有権が失われたエージェントは自動的にアクセス権を失います。このオフボーディング(権限剥奪)は、何かが壊れた後の反応的な清掃ではなく、プロセスの結果として自然に発生します。
ステージ 3: 最小権限とゼロステータン認証を用いてエージェントのアクセスを管理する
登録されたエージェントには、業務遂行に必要なアクセス権が必要です。そのアクセス権を管理する基本原則は「最小権限」です。各エージェントは、定義された目的に必要不可欠な範囲に限定された権限を持つべきであり、可能であれば時間制限を設け、エージェントの挙動に変化が生じた場合は即座に権限を取り消せるようにする必要があります。
環境変数に保存された認証情報は、恒久的なリスク要因です。一度設定されれば回転(ローテーション)されない静的な API キーも同様に、持続的な脅威となります。
実際には、エージェントのアクセスを安全に管理するには、特権操作に対してのみ即時発行される認証情報を提供し、エージェントが機密システムに到達する前に人間の承認が必要となる承認ワークフローを構築し、状況に応じて即座に対応できる緊急停止メカニズムを維持することが重要です。
特権的な Web アプリケーション、SSH サーバー、データベースへのアクセスが必要なエージェントの場合、認証情報の遮蔽は追加の要件となります。これは、実行中のモデルに基盤となる認証情報が露出することなく、エージェントがタスクを完了できることを意味します。すべての特権セッションは記録され、監査可能である必要があります。
ステージ 4:デプロイ時だけでなく、継続的にエージェントの行動をガバナンスする
最初の 3 つのステージで制御枠組みを整えます。ガバナンスとは、それらを最新の状態に保つための取り組みです。具体的には、エージェントが実際に実行していることが、許可されている範囲と一致しているかを常に検証し、乖離が生じた場合には軌道修正を行う継続的な実践を指します。
すべてのエージェントのアクションはログに残すべきです。アクセス権限の見直しも定期的に行い、各エージェントが現在の目的に照らして適切な権限を保持しているかを評価する必要があります。エージェントの行動が定義された範囲から逸脱した場合は、インシデント化する前に異常を検知できる仕組みが必要です。また、エージェントの役割が終わった際には、何かが悪化したことを待って対応するのではなく、アクセス権限の剥奪を手順として確立しておくべきです。
ガバナンスとはまた、説明責任に答えるために必要な監査証跡を維持することでもあります。「このエージェントは何にアクセスしたのか」「どのような行動を取ったのか」「誰が承認したのか」「結果はどうだったのか」。これらの問いに答えられるかどうかが問われます。特定のエージェントについてその連鎖を再構築できない組織は、実質的なガバナンスを行えているとは言えません。単に導入しただけで、あとは運任せにしている状態です。
このフレームワークの4つの段階すべてを支える基盤
IT環境が分断されている場合、このフレームワークの各ステージを実行するのは格段に難しくなります。アイデンティティ管理、アクセス制御、デバイス管理、セキュリティ対策などがバラバラのシステムに散在していると、ガバナンスの隙間が生じ、組織は場所によって異なるポリシーを適用する羽目に陥り、どこでも一貫したガバナンスを実現できなくなります。
JumpCloud の調査によると、IT 環境が完全に統一された組織は、断片化したスタックを運用する組織に比べて、ビジネスの重要ワークフローでエージェントを導入する可能性が 5 倍高いことがわかりました。人間、デバイス、そしてエージェントに対して一貫したポリシーを同時に適用できるかどうかが、AI の導入に合わせてガバナンスが追いつくのか、それとも遅れをとるのかを決定づけます。
これが「アジェンティック IAM」の核心となる前提です。人間、デバイス、エージェントを単一の統一的な制御層を通じて管理することが、このフレームワークを実践的なものとして大規模に実行可能にするのです。
すべてのアイデンティティ(人間に限らない)を保護することは、AI を安全にスケールさせるための運用基盤です。今これを構築する組織はリスクを低減できるだけでなく、AI をより多くのワークフローへ展開し、スピードを上げることができます。そして何よりも、環境内のすべてのアイデンティティが把握され、管理され、責任の所在が明確であるという確信を持って行動できるようになります。
JumpCloud の「2026 年第 3 四半期 IT トレンド調査レポート」(対象:米英の IT リーダー 800 名)は こちらで入手可能です。本記事で言及されているアジェンティック IAM ライフサイクルフレームワークは JumpCloud が開発したもので、詳細は こちらをご覧ください。
Greg Keller 氏は JumpCloud の CTO 兼共同創業者です。
スポンサー記事は、投稿料を支払う企業または VentureBeat とビジネス関係にある企業が制作したコンテンツであり、必ず明確に表示されています。詳しくは sales@venturebeat.com までお問い合わせください。
原文を表示
Presented by JumpCloud
A practical framework for securing every identity in the modern workforce, human or not.
Your organization already has a rigorous process for governing human identities. New employees go through onboarding. They get a role, a set of entitlements, and a named manager accountable for their access. When they leave, their credentials are revoked and access is terminated. It’s a well known IT process: every workforce identity that can access your systems needs to be known, scoped, and accountable from the moment they enter your world, to the moment they are off-boarded.
AI agents are now operating inside those same systems. They access Salesforce, create tickets in Jira, provision infrastructure, process financial transactions, and communicate on behalf of your teams. In every meaningful sense they are members of your workforce, except that in most organizations they were never onboarded, have no named owner, and have no offboarding process when their purpose expires.
JumpCloud’s Q3 2026 research found that non-human identities now outnumber human users in 83% of organizations, and only 21% have implemented governance controls specifically for them. The framework below is designed to close that gap.
Stage 1: Discover every agent operating in your environment
Governance starts with an accurate inventory, and most organizations are working with an incomplete one. AI agents are being deployed by product teams, operations leaders, and individual contributors who have both the tools and the motivation to move fast. IT inherits the governance responsibility after the fact, often without knowing the full scope of what has been deployed.
Shadow AI is the practical consequence: agents operating across production environments with no formal record, no defined owner, and no systematic way to stop them if something goes wrong. Discovering your agent population is an ongoing practice, not a one-time audit. Build an inventory across every environment where agents could be running: cloud platforms, managed devices, SaaS integrations, and on-premise systems. For each agent, document what it can access, what workflows it influences, and what triggers its actions. That inventory is the foundation everything else in this framework depends on.
Stage 2: Register every agent as a formal identity with a named owner
Every agent that operates in your environment should exist as a formal identity in your directory, with the same basic attributes you assign to any employee: a defined purpose, a scope of authorized action, and a named human owner who is accountable for its behavior.
This is the architectural decision that separates organizations that can govern their agents from those that cannot. Agents registered as proper identities can be assigned entitlements, subjected to conditional access policies, and included in access reviews. Agents that exist only as service account workarounds or API keys in environment variables are ungovernable by any systematic means.
Registration is also the mechanism for addressing Zombie Agents: agents that outlived their original purpose but kept running, kept accessing systems, and kept accumulating permissions. When every agent has a named owner responsible for its renewal, agents without active ownership naturally lose their access when that ownership lapses. The offboarding happens as a consequence of process rather than as a reactive cleanup after something breaks.
Stage 3: Manage agent access with least privilege and zero standing credentials
Registered agents need access to do their jobs. The governing principle for that access is least privilege: each agent should have entitlements scoped precisely to what its defined purpose requires, with access that is time-bounded wherever possible and revocable immediately if the agent’s behavior changes.
Standing credentials in environment variables are a persistent liability. Static API keys that never rotate are a persistent liability. In practice, managing agent access securely means issuing just-in-time credentials for privileged operations, building approval workflows that require human sign-off before agents reach sensitive systems, and maintaining emergency shutdown mechanisms that work at the speed the situation requires.
For agents that need access to privileged web applications, SSH servers, or databases, credential shielding is an additional requirement: the agent should be able to complete its task without the underlying credentials ever being exposed to the model running it. Every privileged session should be recorded and available for audit.
Stage 4: Govern agent behavior continuously, not just at deployment
The first three stages establish the controls. Governance is what keeps them current. It is the ongoing practice of verifying that what agents are actually doing matches what they are authorized to do, and course-correcting when those diverge.
Every agent action should be logged. Access reviews should happen on a regular cadence, evaluating whether each agent’s entitlements remain appropriate for its current purpose. When an agent’s behavior deviates from its defined scope, the anomaly should be detectable before it becomes an incident. When an agent’s purpose ends, access revocation should be a procedural step, not a reactive measure triggered by something going wrong.
Governance also means maintaining the audit trail needed to answer accountability questions: what did this agent access, what actions did it take, who authorized it, and what was the outcome? Organizations that cannot reconstruct that chain for any given agent are not governing their agents in any meaningful sense. They have deployed them and hoped for the best.
The foundation underneath all four stages
Each stage of this framework becomes significantly harder to execute when the underlying IT environment is fragmented. Identity, access, device management, and security controls spread across disconnected systems create the gaps where agent governance falls through, and organizations end up applying different policies in different places rather than consistent governance everywhere.
JumpCloud’s research found that organizations operating in fully unified IT environments are five times more likely to deploy agents in business-critical workflows than those running fragmented stacks. Whether the control layer is coherent enough to apply consistent policies across humans, devices, and agents simultaneously is what determines whether governance scales with AI adoption or lags behind it.
This is the core premise of Agentic IAM: that governing humans, devices, and agents through a single coherent control layer is what makes the framework above executable at scale rather than aspirational.
Securing every identity, human or not, is the operational foundation that makes AI safe to scale. Organizations that build it now will not just reduce risk. They will expand AI into more workflows, move faster, and do it with the confidence that comes from knowing every identity in their environment is known, governed, and accountable.
JumpCloud’s Q3 2026 IT Trends Research report (n=800 IT leaders, US + UK) is available here. The Agentic IAM lifecycle framework referenced in this article was developed by JumpCloud and is available here.
Greg Keller is CTO and Co-founder at JumpCloud.
Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact sales@venturebeat.com.
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み