Identity and Access Management
Identity and Access Management (IAM) is the security discipline of verifying who users and programs are and controlling what resources each may access.
Identity and Access Management (IAM) is the field and set of systems for authenticating principals such as people, services and programs, and for granting and managing what actions each may take on which resources. Major cloud providers offer permission services under this name, typically bundling permissions into roles that are assigned to principals.
The principle of least privilege, granting only the permissions a task needs, is central to it. The same approach applies to programs that call tools on their own, such as AI agents, which can be given their own identity and only the roles they need instead of a shared key.
This entry is based on AIPOST articles and widely known facts. If something is wrong, please send us a correction request.
Articles covering this entry
Runtime sandboxing, network isolation and operating-system separation help, but they cannot replace identity and access management or cloud boundaries.
IAM, short for Identity and Access Management, gives the agent its own cryptographically verified identity.