# AI Agent Identity & Access Management Tools: evaluation worksheet

Source: https://dutygraph.com/directory/ai-governance/categories/identity-access/
Editorial date: 2026-09-07

## Scope

- Organization / team:
- Task and expected output:
- Human owner:
- Product and version:
- Evaluation date / environment:
- Reviewer:

## Questions

### 1. Is the agent linked to a responsible human and a specific delegation record?

- Observation (demonstrated / described / unknown):
- Evidence reference:
- Limitation or follow-up:

### 2. Can access be limited by action, resource, tenant and duration rather than a broad application role?

- Observation (demonstrated / described / unknown):
- Evidence reference:
- Limitation or follow-up:

### 3. How are credentials issued, rotated and revoked, including already-issued tokens?

- Observation (demonstrated / described / unknown):
- Evidence reference:
- Limitation or follow-up:

### 4. What happens to agent access when its owner leaves, changes role or loses an entitlement?

- Observation (demonstrated / described / unknown):
- Evidence reference:
- Limitation or follow-up:

## Evidence checklist

- [ ] An entitlement and resource-scope record
- [ ] Allowed and denied access attempts
- [ ] A lifecycle change with measured revocation behavior

## Boundary to check

Authentication answers which identity is calling. It does not, by itself, explain why a business task was delegated or whether every requested action is appropriate. Runtime authorization and separation-of-duties decisions may live in other systems.

## Decision

- Fit for the scoped task:
- Unresolved gaps:
- Next action, owner and date:

This is a planning worksheet, not an endorsement, access approval or compliance certification. Keep confidential evaluation notes in your organization's approved storage.
