Scoped credentials alone won't secure AI agents: NTT DATA AIVista and Snowflake frame action-level governance as the missing layer

A VentureBeat survey found that 69% of enterprises running AI agents still share credentials across agents and users. NTT DATA AIVista and Snowflake argue that scoped credentials are necessary but not sufficient, and that enterprises deploying autonomous systems at scale need action-level authorization and tamper-resistant audit trails woven into every agent interaction.

The framing at VB Transform 2026 treats identity as a solved starting point rather than a destination. Mukesh Karki, CTO of NTT DATA AIVista, called provability the license to operate in regulated industries, while Mayank Upadhyay, chief security and trust officer at Snowflake, traced the security problem to assumptions carried over from deterministic software.

In traditional software, a human clicks and the system calls a predictable API. Agents are different: they explore, reroute, and try unexpected paths when given more permission than a specific task requires. Embedding a single static API key in an agent compounds this by giving it the union of every user's needs. The forensic consequence follows immediately: when something goes wrong, attribution to the right agent becomes difficult or impossible.

Karki, whose client base is mostly in insurance, healthcare, and finance, treats scoped credentials as a baseline that regulated environments enforce anyway. The real constraint, he argues, operates at two additional levels: the jurisdiction in which an agent acts and the internal rules of the specific organization. A claims adjustment agent running in Washington State faces different regulations than one in California, and every individual claim carries different conditions. Action-level authorization must account for all three simultaneously.

Upadhyay's organizational analogy places agents one rung below employees rather than alongside them. Treat them like interns, he suggested: capable of contributing, but unpredictable enough that oversight remains necessary. Snowflake's platform implements this through layered controls where administrators set platform-wide guardrails such as read-only operations, and developers narrow permissions further when launching each agent session.

The governance framework Upadhyay described covers three layers. The agent layer handles identity, tool permissions, and MCP governance. The model layer addresses indirect prompt injection and keeps prompts inside the customer's VPC so the model provider cannot read them. The data layer enforces least-privilege access, zero-copy architecture, and role-based access control. All three layers are presented as required for agents to operate safely in regulated environments.

For enterprises auditing existing deployments, Upadhyay recommends starting with static secret permissions, which he identifies as the largest fixable attack vector. The second priority is an MCP gateway that gives administrators visibility into which developers are connecting to which servers, addressing shadow AI that grows when teams run unauthorized open-source MCP servers without IT knowledge.

Confidence scoring can gate autonomous execution on high-risk actions, and sandboxing offers a middle path for lower-stakes operations. But Karki identified the harder constraint: governance built after deployment is governance that cannot prove what an agent did and why. Retrofitting provability into a running agentic system is not merely difficult, it undermines the audit trail that regulators in Karki's industries require.

The sponsor's framing deserves scrutiny on its own terms. Expanding AI agent security beyond scoped credentials to action-level authorization and three-layer governance fits the commercial interests of companies that sell platforms where that governance can be implemented. That does not make the technical argument wrong. It means the governance requirements NTT DATA AIVista and Snowflake describe reflect the compliance posture of regulated industries and the commercial positioning of the sponsors, not a universal baseline for every team deploying agents. For enterprises building agentic systems today, the concrete question is whether provability is a first-class design constraint from the start, or a retrofit that arrives when auditors start asking questions.

Subscribe to AI Enthusiast Log

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe