ARKION
Field Notes/Field Note No. 10
Field Note · Governance

Every Agent
Answers
to a Human.

AI agents get hired by the thousand and never show up in your HR system. Arkion wires every agent identity, and every sub-agent it spawns, to a named human owner drawn from the identity provider you already run. When that human changes roles, is compromised, or walks out the door, the company holds real options instead of none.

Published
September 15, 2026
Category
Governance
Read Time
8 min
Reference
FN-10-2026

The most dangerous question in enterprise AI right now is also the simplest one: who owns this agent? Most organizations can name the model, the vendor, and the cloud bill behind an agent. Ask which human being is accountable for its identity, who vouched for it, who renews it, who is answerable when it acts, and the room goes quiet. That silence is the gap this field note is about.

Your People Are Governed. Your Agents Are Not.

Enterprises spent two decades building serious identity systems for people. Okta, Microsoft Entra ID, Ping: directories that know who joined, who moved, who left, and what each person may touch. That machinery works, and Arkion does not ask you to replace an inch of it. We connect to it, and we treat it as what it already is: the single source of truth for human beings.

Every identity Arkion issues for an agent is anchored to an owner, and an owner is not a text field or a spreadsheet column. It is a live binding to a human identity in the directory you already operate. Before an agent’s identity goes live, that named person attests it: what the agent is for, what it may reach, and how long it should live. The attestation is recorded, the certificate is issued, and from that moment the agent acts under an identity a specific human has put their name behind. Accountability is established at issuance, not reconstructed after an incident.

Agents That Spawn Agents

Here is where most identity thinking breaks down. Modern agent architectures are not one model with one credential. An orchestrator plans, then fans the work out to sub-agents, which may spawn workers of their own, at whatever depth the task demands. In most stacks today, those children either borrow the parent’s credentials or mint anonymous ones, and the chain of accountability snaps at the first fork.

In Arkion’s identity system, a sub-agent never inherits its parent’s identity. It receives an identity of its own, and that identity carries its lineage: issued under this parent agent, which is owned by this human. The chain holds at any depth. Pick any sub-agent in the estate, at any level of the tree, and you can walk it back through every parent to a person whose name is on an attestation.

The plainest way to picture it: an org chart that machines cannot opt out of. Every agent reports to something, and every chain of reports ends at a human being. Spawning does not dilute ownership. It extends it.

The ownership chain, from an IdP entry to a working sub-agent.ABC Corp holds every human identity in Okta or Microsoft Entra ID. One of those humans, Mark Smith, Chief Operating Officer, owns two agent groups on the Arkion estate: Marketing AI Agents and the Inventory Management Agent. The Inventory Management Agent spawns Purchasing and Order Processing sub-agents, which handle purchase orders, order placement, billing, and AP/AR. A repeating gold trace walks one sub-agent back up the chain to Mark and his IdP entry: every path in the estate resolves to one named human.§ · ABC CORPOKTA / ENTRA ID · HUMAN IDENTITIESMark SmithChief Operating OfficerNHI-USR-3241 · ATTESTEDOWNSOWNSMARKETING AI AGENTSINVENTORY MANAGEMENT AGENTSPAWNSSPAWNSPURCHASING SUB-AGENTSProcessing purchase ordersORDER PROCESSING SUB-AGENTSPlacing orders, billing, AP/AREVERY PATH IN THE ESTATE RESOLVES TO ONE NAMED HUMAN.
One chain, from an IdP entry to a working sub-agent. At every node, Arkion issues a distinct cryptographic identity.
Every agent, every sub-agent, at any depth: the chain ends at a name.

The Day the Owner Leaves

The most reliable identity event in any enterprise is that people leave. Your IdP already handles that moment well for humans: Okta can automatically deactivate downstream app accounts when a user is deactivated, and Microsoft Entra ID Governance offers leaver workflows built for exactly this transition. Badges stop working by the afternoon. But the agents that person created, attested, and quietly wired into production? Few organizations can even list them, let alone decide their fate. They keep running, keep authenticating, and answer to no one.

The security industry has already named this failure. OWASP’s Non-Human Identities Top 10 ranks improper offboarding as the number one risk, ahead of every leak and misconfiguration on the list. The Cloud Security Alliance found that only 20% of organizations have formal processes for offboarding and revoking API keys, and in a January 2026 survey, 78% reported no documented, formally adopted policy for creating or removing AI identities. The cost of getting it wrong for even one account is already on record: CISA’s February 2024 advisory traced a breach of a state government organization to a former employee’s admin account that, in the advisory’s words, “was not disabled immediately following the employee’s departure.” That was one human login. Now multiply it by every agent and sub-agent that employee ever spawned.

Because Arkion listens for the same offboarding signals your IdP already sends, a departure is not a blind spot. It is a decision point, and the company gets to choose from a position of full visibility:

Option 01
Decommission the estate.
  • Retire the identity of every agent and sub-agent anchored to the departing owner. Certificates revoked, identities archived, a clean sweep with a cryptographic record of exactly which identities were revoked and when.
Option 02
Transfer ownership.
  • Reassign the estate to a new owner, who re-attests each agent they take on. The work continues without interruption, and accountability moves with the handover instead of evaporating.
Option 03
Wind down in stages.
  • Keep business-critical agents running under a temporary custodian with a fixed expiry, while a permanent owner ramps up. Nothing runs ownerless, and nothing critical goes dark on day one.

When Something Goes Wrong

Ownership chains earn their keep on bad days, and we will be honest about those days: none of what follows prevents an attack from starting. What it does is decide how far an attack travels, and how fast it ends.

If the human turns.Insider abuse is the oldest problem in security, now with machine reach attached. When an employee’s intent or credentials go bad, the ownership chain gives the response a boundary drawn in advance: every certificate anchored to that human identity can be revoked estate-wide in a single action once the abuse is seen, and new issuance under that owner is blocked in the same motion. The insider can still act alone. They no longer command machines.

If the agent is compromised. We wrote in FN-04 that you cannot reliably stop an agent from being tricked; you can only decide what the trick is worth. A hijacked agent is not a villain, it is a governed identity being steered by someone else’s instructions, and the response is surgical: revoke that agent’s identity and those of its descendants, without touching the owner’s other agents or the human’s own access. Then the lineage becomes the investigation’s map: which parent spawned it, which human attested it, what it was scoped to reach, and where its identity was actually presented, every step signed and logged.

Who Pays for This Agent?

The ownership chain answers a second question, and it is the one the CFO asks. Agents rack up real costs: model tokens, compute, API calls, the transactions they execute. In most companies that spend lands in undifferentiated cloud and vendor bills, and the person staring at them cannot say which agent spent what, for whom, or why. The identity layer already knows the missing half: which identity took each action, and on whose authority.

Because every agent and sub-agent acts under its own identity, every cost-bearing action arrives with a name attached. Costs roll up the same lineage as accountability: sub-agent to parent agent to human owner to department. Showing each team what its agents spend, or charging that spend back to the budget that authorized it, no longer takes a quarterly spreadsheet reconstruction: the identity chain supplies the attribution, and your existing cost tooling supplies the amounts. The chain that carries responsibility carries the bill.

The timing matters. In the FinOps Foundation’s 2026 survey of nearly 1,200 cloud-spend practitioners, 98% said they now manage AI spend, up from 31% two years earlier. They named allocating AI costs to business units among their top challenges, calling it harder than it ever was for traditional infrastructure, and their single most requested tooling capability was granular monitoring of AI spend, down to tokens and individual model requests. Grain that fine needs an identity on every action. The lineage already provides one.

Professional services firms will feel this first, because their billing is already governed. Bar guidance has long required that costs billed to a client be the actual amounts paid on the client’s behalf, with no undisclosed markup. In July 2024, the ABA’s first formal ethics opinion on generative AI extended that discipline to machines: a lawyer billing hourly must bill actual time, not the time the tool saved, and a per-use AI service engaged for a particular client is ordinarily billable to that client as an expense, at cost. Meanwhile, 68% of corporate legal professionals say they do not know whether their outside firms use AI. Put those together and every managing partner meets the same question: how do you prove what an agent actually did, and what it actually cost, on a particular matter?

Scope an agent’s identity to the matter, and the question answers itself. The agent’s work becomes an attributable line: which matter, what work, every action signed, ready for the cost figures to join. It is the same non-repudiation substrate we described in FN-03, pointed at billing. When the client asks what they are paying for, the answer is not an estimate. It is a signed record.

Why We Built Arkion

Two truths sit in tension. Machine estates are decentralized and fast: identities issued, rotated, and retired at machine pace, on the signing engine we benchmarked in FN-09 at tens of thousands of signatures a second. Accountability is centralized and human: a name, a decision, a person answerable for what acts under their authority, and for what it spends. Most platforms pick one. Speed without a chain of command gives you an ungoverned swarm. A chain of command without speed gives you a bottleneck the business will route around.

Arkion exists at the intersection: certificates issued and revoked at machine speed, in a decentralized estate, with the chain of ownership intact from the deepest sub-agent to the human being your IdP already knows. That is the level of command and governance we believe the agentic enterprise requires, and it is the reason this company was built.

The Test Worth Running
Pick one AI agent running in your environment today and try to answer four questions: which human owns it, what did that human attest it may do, whose budget is paying for what it does, and what happens to it the day that human resigns? If any answer takes longer than a minute, the chain is already broken. You just have not needed it yet.
Arkion Research Desk
Field Note FN-10-2026 · Distributed under arkion.ai/field-notes
For questions or to discuss findings: research@arkion.ai
Sources & Notes
  • OWASP Non-Human Identities Top 10, 2025 edition: NHI1:2025, Improper Offboarding, ranked first among non-human identity risks (owasp.org/www-project-non-human-identities-top-10).
  • Cloud Security Alliance, The State of Non-Human Identity Security survey report (September 2024): 20% of organizations report formal processes for offboarding and revoking API keys. Self-reported survey data.
  • Cloud Security Alliance, The State of Non-Human Identity and AI Security (January 2026), a survey of 383 IT and security professionals commissioned by Oasis Security: 78% of organizations report no documented, formally adopted policies for creating or removing AI identities. Self-reported survey data; we cite it with the commissioning noted.
  • CISA Cybersecurity Advisory AA24-046A (February 2024): threat actor used a former employee’s administrator credentials to access a state government organization; the quoted line on the account not being disabled is from the advisory.
  • Okta documentation, “Automatically deactivate app users” (help.okta.com), and Microsoft Entra ID Governance lifecycle workflows (learn.microsoft.com): the IdP lifecycle signals referenced in this note. Both capabilities are configuration-dependent; Entra lifecycle workflows require Governance licensing.
  • FinOps Foundation, State of FinOps 2026 (sixth annual survey, 1,192 respondents): 98% of respondents now manage AI spend, up from 63% in 2025 and 31% in 2024; “allocating AI costs to business units” listed among top challenges cited, described as harder than traditional infrastructure; granular monitoring of AI spend (tokens, LLM requests, GPU utilization) ranked first among requested tooling features. Self-reported practitioner survey. The connection to identity-based attribution is Arkion’s inference, not the survey’s.
  • ABA Standing Committee on Ethics and Professional Responsibility, Formal Opinion 93-379 (December 1993): disbursements billed to clients must reflect actual amounts paid on the client’s behalf; undisclosed surcharges are improper. ABA formal opinions are advisory; binding rules are adopted state by state.
  • ABA Formal Opinion 512 (July 29, 2024), the ABA’s first formal ethics guidance on generative AI: lawyers billing hourly must bill actual time when using AI tools, and per-use, client-specific AI service charges are ordinarily billable to the client as an expense at cost, while general-purpose tool subscriptions are treated as overhead.
  • Thomson Reuters Institute, “The great AI disconnect” (March 2026), reporting on its 2026 AI in Professional Services Report: 68% of corporate legal professionals say they do not know whether their outside law firms are using AI. Self-reported survey data from a legal-technology vendor’s research arm.
  • Product behavior described in this note reflects the ownership, lineage, and cost-attribution architecture of the Arkion platform. Integration with human identity providers uses the standard lifecycle and provisioning interfaces those platforms expose; capability specifics are available to design partners under NDA.
Next Step

Put a name on
every agent.

A read-only Discovery Scan will show you the non-human identities operating in one environment, including the ones no human currently owns. Or start with the brief your board can read in one sitting.