Two security executives said this week that companies need to account for every badge, credential, service account and A.I. agent as a potential insider threat, warning that trusted access points are multiplying faster than security teams can see them.
The comments, published on Tuesday by Cybersecurity Insiders to mark Insider Threat Awareness Month, framed insider risk as a matter of access as much as intent. A person does not need to act maliciously to create a problem, they argued: an outdated badge permission or an unclear procedure can be enough to leave a company unable to identify and answer unusual activity.
On the physical side, Chris Robertson, director of the technical consultant team at Luminys, a video security company, said the basics still decide outcomes. “After more than 25 years working in physical security, one thing I’ve learned is that managing insider risk often comes back to the fundamentals,” he said. “Who has access to a physical space? Are those access permissions still appropriate for that person’s role? And can the security team quickly verify what happened when an incident occurs?”
The same logic now reaches the software supply chain, said Hari Srinivasan, vice president of products and strategy at Lineaje. “Today, enterprise insider risk extends to autonomous software agents operating inside development pipelines,” he said. Organizations are granting such agents privileged access to private repositories, CI/CD systems and package managers, where they select third-party packages, write code and push commits directly into trusted environments. “Functionally, these agents act as credentialed insiders,” he said.
An untracked or badly governed agent can inject supply-chain risk into production builds at machine speed and leak sensitive data, Mr. Srinivasan said. He called for treating every A.I. agent as an insider, with visibility into the provenance of packages, models and third-party agents, and continuous checks of agent-written code.
The two settings need different tools, but the underlying test is the same, the executives said. “Security teams cannot effectively manage trusted access they cannot see,” the publication wrote. In a building, that can mean linking access control to video so investigators can establish who entered a space and what happened afterward. In software, it means tracking agents and every component they touch.

