TPI Thoughts

The Fundamentals Don't Care About Your AI Strategy

There is a lot of energy right now around AI agentic security. Non-human identity. Machine credentials. Agentic attack surfaces. The attention is deserved. AI agents are real, they are in production environments right now, and the credential risk they introduce is genuinely underappreciated. It is a topic worth its own dedicated piece — and one we will get to on this site.

What I want to add to that conversation — not counter it, add to it — is a reminder that the fundamentals have to come first. Not instead of agentic security. Before it. Because the organizations that have not gotten the basics right are not ready to layer new identity types on top of a foundation that is already shaky.


I talk to security practitioners every week. The conversations I am having in 2026 are not primarily about AI agents. They are about the same things they have always been about.

Who has domain admin rights in your environment right now? Not who should have them. Who actually has them. Can you answer that question in under ten minutes?

When did your service account passwords last rotate? Do you know which service accounts exist? Do you know who owns them?

Are your privileged sessions being monitored? Not recorded — monitored. Is anyone or anything looking at that activity in real time, or does the recording only get reviewed after something goes wrong?

Do your administrators have local admin rights on their everyday workstations? Is EPM in place? Are they actually using the vault launcher, or are they copying credentials manually because it is faster?

These are not new questions. They are not exciting questions. They do not generate conference sessions or analyst reports. And in most organizations I encounter, they do not have clean answers.


PAM has always been about three things in this order: people, process, and controls.

People who understand what privileged access means, why it matters, and what their responsibilities are in protecting it. Process that defines how privileged access is granted, reviewed, revoked, and monitored — consistently, not just when an audit is coming. Controls that enforce the process and provide the visibility to know when something is going wrong.

The organizations that have those three things in order are genuinely better positioned to handle AI agents, agentic credentials, and whatever the next threat vector turns out to be. Because the same discipline that builds a solid PAM foundation — least privilege, credential management, behavioral monitoring, access reviews — applies directly to non-human identities. The framework does not change. The identity type sitting on top of it is new.

That is actually the encouraging part of the agentic conversation for practitioners who have done the foundational work. You are not starting over. You are extending a discipline you already have into a new class of identity. The vault, the access controls, the behavioral monitoring, the review cadence — those things all apply. The agent is just the newest account type that needs to be managed the same way you manage everything else.

For organizations that have not built that foundation yet, that is where to start. Not because agentic security is not important — it is — but because you cannot secure your AI agents if you cannot account for your service accounts. You cannot monitor agentic behavior if you have no baseline for human privileged behavior. You cannot apply least privilege to a machine identity if you have never enforced it on your administrators.


The fundamentals are not a phase you graduate from. They are the thing you maintain continuously while everything else around them changes. The threat landscape evolves. The identity types multiply. The attack surfaces expand. The fundamentals are what you come back to every time, because they are what holds everything else up.

Build the foundation. Train your people. Document your process. Enforce your controls. Then extend all of it to your agents.

The agents will still be there.