
A registrar at a mid-sized university asked a helper tool to speed up admissions triage last Tuesday. By Friday, that helper was reading student records in the student system, writing notes into the learning platform, and pulling contact data from the customer database. Nobody filed a ticket. Nobody signed an access request. And when the annual access review campaign runs in October, that helper will not appear on any certification sheet, because nothing on this campus knows to ask about it.
That is not a hypothetical. That is Tuesday.
I have spent fourteen years on the buyer's side of the identity table in higher education, and I can tell you the pattern I am watching right now is the fastest-moving governance gap I have seen since the arrival of cloud SIS. Every major identity governance vendor now sells an "agent identity" product. Saviynt shipped an Identity Control Plane for AI Agents. SailPoint shipped Agent Identity Security. One Identity, Saviynt, and SafePaaS have all published guidance. The capability is on the truck. The implementation instructions are not.
And this is landing in institutions that have not yet solved the human version of the same problem.
Ninety-two percent of organizations cannot rotate a machine credential on a ninety-day cycle. Non-human identities grew seventy-six percent last year, driven by agent proliferation, per Infosecurity Magazine's reporting on the governance gap.
Read that twice, because it is the single most important sentence in any identity budget conversation you will have this fiscal year.
If your team is still chasing the same stale service accounts you chased in 2023, if your Banner-to-directory reconciliation still needs a human at 2 a.m., if your quarterly access review still ships as a spreadsheet to a department chair who signs it without reading it, then you have not solved the ghost account problem for the humans on your payroll. You are about to inherit the ghost agent problem on top of it.
The math is not subtle. A human employee acquires access slowly, through tickets, forms, and conversations. An agent acquires access at the speed of an API call. One staffer inviting a helper into a workflow can generate more permission grants in an afternoon than a whole department generated last semester. When the auditor asks who approved that, the answer is going to be "nobody, because nobody was asked."
That is a governance failure, not a technology failure. And it will be discovered by your auditor, not by your security operations center.
I read four vendor briefings on agent identity last week. Every one of them used the word lifecycle. Every one of them meant provisioning and retirement. Create the agent. Retire the agent. Ship the SKU.
That is not what a higher-ed identity governance leader means by lifecycle. You mean the messy middle. You mean the semester when a student worker turns into a graduate assistant turns into an adjunct turns into a staffer, and each of those transitions requires a role change, an access review, and a certification campaign the department chair can actually read and sign.
There is no public higher-ed case study of an identity governance platform running a certification campaign on agent-generated role requests across application boundaries. I looked. My team looked. Perplexity looked. The gap between "we can provision an agent" and "the registrar can attest to what an agent should still have access to" is where the actual governance work lives, and no vendor has shipped a reference customer for it in higher education.
This is prediction three from my worldview landing exactly on schedule. Capability without guidance is the load-bearing-human pattern moved up one layer of the stack. The institution inherits the implementation problem, and the vendor moves on to the next SKU.
One. Who is the identity authority for agents on your campus? Is it your identity governance platform, your identity provider, the application that spawned the agent, or a spreadsheet on somebody's desktop? If the answer is "it depends," you have already surrendered governance to whichever product owner shouts loudest.
Two. What is your certification cadence for non-human identities? If human access reviews are annual, non-human reviews probably need to be quarterly at minimum, because agents change permissions faster than humans do. What does your registrar or department chair actually see when an agent is on the campaign sheet?
Three. What is your revocation path? When an agent is decommissioned or misbehaves, who has the authority to pull its credentials in every system it touched? If the answer routes through a vendor's support ticket, you have not solved this.
Four. Where does the agent's authority come from? Did a human delegate it? Is there an audit trail of that delegation? Can you reconstruct, six months later, who authorized the agent to read financial aid data? This is the digital locksmith question, and it is the one your auditor will ask first.
Five. When your identity provider is the breach, what breaks? Ask OneLogin's customers this week. Infosecurity Magazine reported unauthorized access to customer credentials, and the disclosure itself flagged the growing risk from AI-driven agents used for authentication. If your entire agent-authorization chain roots to a single external identity provider and that provider is compromised, your certification campaigns are running on stolen credentials and you will not know for two hundred and forty-one days.
Answering those five questions does not require a new product. It requires a governance conversation between your identity lead, your security officer, your registrar or business owner, and your internal audit function. That conversation belongs on your calendar this month, not next fiscal year.
Here is where I have to be honest about where QuickLaunch fits. We are a certified Ellucian partner for identity lifecycle management and integration on Banner and Colleague. We do not sell an agent-identity governance product today. What we sell is the layer underneath it. The layer that knows, in real time, that a student became a graduate assistant on Tuesday and their access should have changed by Wednesday.
That layer is the foundation you have to have before agent governance can work. If your human lifecycle is still manual, delayed, forgotten, or orphaned, then bolting an agent governance platform on top of it will produce beautiful reports about ghosts in a house you never cleaned. Grambling State, Central Carolina Technical College, Kilgore, Stephen F. Austin, and National Louis University are running fully automated SIS-to-directory synchronization with sixty to seventy percent workforce reduction in the identity function. That is the boring, load-bearing work that has to be done first.
Then, and only then, does an agent identity certification campaign have a fighting chance of meaning something.
Fourteen years on the buyer's side and I have never seen a week where the identity provider itself is a headline breach in the same news cycle as the enterprise resource system getting scalped for the fourth time. University of Phoenix disclosed three and a half million records exposed through the same Oracle enterprise database vector that already hit Princeton, Penn, and Harvard last fall, per Infosecurity Magazine. OneLogin disclosed unauthorized access the same week. If you sent your team a note asking whether you are exposed, that is the right instinct and it is not enough.
Here is what keeps me up. The auditors are getting smarter about agents faster than the identity teams are. The first agent-driven incident that hits the news in higher education is going to be discovered in a compliance review, not a security alert. The institution will not have a story. The vendor will have a statement. The board will have questions the CIO cannot answer. And the answer to every one of those questions will start with "we did not know the agent had that access, because nobody certified it."
You can prevent that. Not with a product. With a decision. Own the identity layer. Extend your certification campaign to include the non-human identities on your campus this fiscal year, even if you have to do it in a spreadsheet the first time. Get the practice reps in before the vendors show up with a plan that assumes you already know what good looks like.
The locksmith works on your locks. Not somebody else's brand of lock. Own the keys, own the ledger of who holds which key, and own the moment when a key needs to be pulled. That is the whole job. Agents just make the ledger longer and the moment shorter.
Primary: Start with the QuickLaunch AI Agent Audit Workbook. It walks your team through the five questions above and gives you a template for extending your next access certification campaign to include non-human identities. No product purchase required, just a working session with your identity lead.
Secondary: Subscribe to the QuickLaunch column. Weekly, practitioner-first, from a fourteen-year buyer with receipts. #ItsExistential
Raymond Todd Blackwood is the President of QuickLaunch and writes about identity, agentic AI, and the messy reality of higher-ed IT. #ItsExistential