๐ New blog post published โ โThe Unseen Variable: Identity, Agentic AI and the Path of Least Resistanceโ
๐
Published 20 Nov 2025
๐ Read here: https://cirriustech.co.uk/blog/the-unseen-variable/
In brief:
In an age of human-centric identity defence and vendor promises of agentic AI doing โeverything for youโ, weโre overlooking something critical: workload identities and the brittle tokens they carry. While we focus on secure control planes for people and agents, attackers will take the path of least resistance - and that path often runs straight through identities we barely govern.
Key themes I explore:
โข Why agentic workloads are being added as โfirst-class citizensโ in identity - and why thatโs not the full story.
โข How workloads multiply identity surfaces, each with its own defaults, audit gaps and licence SKUs.
โข How a semi-autonomous agent can sidestep the โagent control planeโ entirely by using a service principal, hidden secret or long-lived token - essentially an escape hatch.
โข Why token protection (proof of possession, crypto-binding, avoiding tokens in URL query params) remains profoundly weak industry-wide.
โข Why the next wave of identity risk will not come from the human plane, but from machine identity exploitation at scale.
If youโre working in cloud security, identity architecture, devsecops or adversarial-AI defense, I hope this resonates and gives you a sharper mental model. Iโd love to hear your thoughts on how your organisation is handling workload identities and how youโre bridging the human/agent/workload identity gap.
๐ Feel free to share, comment or reach out for a deeper conversation on these themes.
#cloudsecurity #identity #agenticAI #workloadidentities #cybersecurity #defenseevasion #automation #AIsecurity

The Unseen Variable: Identity, Agentic AI and the Path of Least Resistance
Hero image generated by ChatGPT This is a personal blog and all content herein is my own opinion and not that of my employer. Enjoying the content? If you value the time, effort, and resources invested in creating it, please consider supporting me on Ko-fi. The Unseen Variable: Identity, Agentic AI and the Path of Least Resistance Every few years the industry rediscovers a truth that has always been hiding in plain sight. We rename it, formalise it, and publish new frameworks around it, but the core idea remains the same. In distributed systems, adversarial systems, and economic systems, the path of least resistance always wins โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ .




