
Six identity classes from human to autonomous agent
Difference between an agent and a service account
Four breaks in service account governance
Delegation chain and the actor in the token
Risk profile for each identity class
One primary control per class
Identity class map for your company
Four places agents come from
Agent registries in six vendor consoles
Three identity sources: apps, grants, sign-ins
Two cloud sources: IAM and AI service logs
Four network and code sources
Two endpoint sources for shadow agents
Agent inventory register with 16 fields
Agent identity card: 9 fields
Sponsor, owner and backup
Agent purpose in one sentence
Purpose-to-permissions map
Expiry date and review cadence
Agent onboarding policy: 7 intake steps
Orphaned agent handover
Static key vs short-lived token
Workload identity federation in AWS, Google Cloud and Azure
Token exchange and on-behalf-of access
MCP authorization: one token, one audience
Per-task scope and just-in-time access
Human approval for high-risk actions
Token lifetime table by agent class
Four credential types an agent holds
Rotation without downtime: the overlap window
Seven-step rotation runbook
What survives a revocation
Eight-check revocation test
Proof of cut-off in the agent card
Seven signals of an agent baseline
Z-score and robust z-score for deviation
Percent over baseline and new-resource rate
Three action zones with thresholds
Agent risk score formula
Catalog of eight detections for agents outside their role
Five questions every agent log answers
20-field telemetry schema for agents
Four log sources: runtime, cloud, identity, SaaS
Field mapping into your SIEM
Enrichment from the agent register
Six correlation rules in Sigma
SOC triage playbook with owner routing
Five response stages mapped to NIST SP 800-61 Rev. 3
Four severity levels for agent incidents
Kill switch in five levels
Evidence checklist for the first hour
Messages to the owner and the business
Four agent compromise scenarios
A 60-minute tabletop exercise
This course contains the use of artificial intelligence
AI agents are getting access to email, code, cloud accounts and customer data faster than any IAM team can see them. Can you name every agent in your company, its owner and exactly what it is allowed to do?
You already run identity for people: SSO, MFA, roles, joiners and leavers. Agents do not follow that path. A vendor switches on a copilot, a developer ships an agent with a static API key, an employee connects a tool through an OAuth grant, and none of them goes through your onboarding. Nobody owns the agent, nobody wrote down its purpose, and the key it uses never expires. When an alert fires, the SOC cannot tell whether the agent is doing its job or has gone beyond it. When you revoke a key, you cannot be sure the agent has really lost access.
After this course you run AI agents as their own identity class. You know where agents live in your environment and keep them in a registry. Every agent gets an owner, a purpose, data boundaries and a lifetime before it gets access. Static keys give way to short-lived tokens issued for one task. You rotate credentials without downtime and prove with a test that revoked access is gone. Agent logs reach the SIEM and link back to the registry, the SOC has a triage playbook, and when an agent is compromised, you contain it in minutes with a kill switch your team has already rehearsed.
The course is taught by Mike, founder and head of strategy of PapaHR Academy. He is not presented here as a security engineer: he brings the discipline of building processes, owners and rules for new systems, and the technical content is built on public identity standards, such as OAuth 2.0 token exchange, and on cloud provider documentation.
#1 HR instructor on Udemy, with 2,000,000+ students on Udemy
Founder and head of strategy of PapaHR Academy, where 170,000+ students have trained
20 years of experience at Wargaming, Preply, iDeals, Starlightmedia and Sense Bank, including the growth of the unicorn Preply
First you learn to see: how an agent differs from a service account and where agents hide in your identity provider, cloud, SaaS consoles, network and code. Then you take control of the agent lifecycle: owner and purpose, short-lived access for one task, and rotation and revocation you can prove. Finally you move into operations: behavioral baselines, agent telemetry in the SIEM and SOC, and incident response with a kill switch. The format is hands-on, built on real-world scenarios, and each lesson stands on its own. A SOC analyst who has to handle an agent alert tomorrow can watch lesson seven tonight and open the triage playbook in the morning.
The course does not cover model security, such as jailbreaks and red teaming of language models, agent development or vendor selection. It stays on identity and access, where your team can act right away.
What's included:
Lifetime access to all materials
Active instructor support in Q&A
Udemy Certificate of Completion
A practical assignment tied to your own company in every lesson
Ready-to-use tools: an identity class map, an agent registry, an agent card with an onboarding policy, a token and access design with a scope review checklist, a rotation runbook with a revocation test, a detection catalog with a risk score calculator, an agent telemetry schema with a SOC triage playbook and an incident response playbook with a tabletop scenario
Non-human identity is a new field, and the engineers who build agent inventories and response playbooks now will set the rules their companies follow for years. Every month an agent runs without an owner and with a key that never expires is a month of open access nobody watches.
Enroll now and start your first lesson today.