---
title: Supplementary information for AI agent identities
description: Key capabilities and benefits of securing AI-driven solutions using AI agent identities, summary of managed object types for AI agents
component: pingoneaic
page_id: pingoneaic:identity-for-ai:ai-agent-identities-supplementary-information
canonical_url: https://docs.pingidentity.com/pingoneaic/identity-for-ai/ai-agent-identities-supplementary-information.html
llms_txt: https://docs.pingidentity.com/pingoneaic/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
section_ids:
  key-capabilities-and-benefits: Key capabilities and benefits
  ai-agent-identity-managed-object-types: AI agent identity managed object types
---

# Supplementary information for AI agent identities

## Key capabilities and benefits

The following table summarizes the key capabilities and benefits of securing your AI-driven solutions using AI agent identities:

| Capabilities                                                                                                                                                                               | Benefits                                                                                                                                                          |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Specialized agent identity**: Treats AI agents as distinct entities with unique identities and privileges, rather than using simple impersonation.                                       | **Granular security and least privilege**: Eliminates "over-privileged" accounts by applying tailored security policies specific to autonomous entities.          |
| **Streamlined onboarding & lifecycle**: Manual onboarding using OAuth 2.0 grant flow or automated onboarding via Dynamic Client Registration (DCR), with centralized lifecycle management. | **Operational efficiency**: Reduces administrative overhead and "agent sprawl" while ensuring agents can be instantly revoked or rotated.                         |
| **Advanced access and token delegation**: Sophisticated token exchange mechanisms to manage "on-behalf-of" permissions and resource scoping.                                               | **Reduced complexity**: Simplifies the "who, what, and how" of agent access using low-code tools, ensuring secure delegation without custom-coded security logic. |
| **Dedicated agent observability**: Isolated logging and monitoring that separates agent telemetry from end users and static applications.                                                  | **Clear auditability**: Provides an auditable trail of AI activity, making it easy to prove compliance and understand exactly when an agent acted autonomously.   |

## AI agent identity managed object types

The following table summarizes the managed object types related to AI agent identities:

| Managed object type | Description                                                                                                                                                                                                                                                  |
| ------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| AI agent            | This is distinct from the user managed object type. It provides unique AI agent identities and allows for clear accountability and distinct audit trails for their activities, with Advanced Identity Cloud acting as the dedicated Identity Provider (IdP). |
| AI agent privilege  | This lets AI agent identities have delegated privileges, ensuring that they can only access specific applications, act for specific end users or groups of end users, and use specific OAuth 2.0 scopes.                                                     |
