HR events should trigger agent review, not silently transfer authority
Enterprise agents are starting to look like workers in product language while behaving like a web of non-human identities in technical systems. Ema's September launch illustrates the span: one onboarding request can touch HR, payroll, identity, devices, and email. Microsoft now documents agent sponsors, technical owners, access expiry, sponsorship transfer, and mover/leaver lifecycle workflows. The operational implication is immediate: when a worker changes role or leaves, every agent tied to that person needs a decision.
That does not mean HR should administer service principals or inspect token caches. HR owns authoritative worker events and effective dates. The business sponsor decides whether the agent's purpose continues. IAM and IT resolve identities, credentials, runtimes, and access. Security tests containment. Privacy and records teams decide what state must be retained, deleted, or held. Finance and procurement close licenses and commitments. A safe workflow preserves those boundaries while making one lifecycle result visible.
The rule is simple: an agent's authority must not outlive its sponsor, documented purpose, or current risk decision. Implementing the rule is harder because the "agent" is rarely one object. It may include a directory identity, an app registration, a service principal, a user-like account, several OAuth grants, connector workers, browser sessions, a container, scheduled jobs, subagents, a memory database, logs, backups, vendor accounts, and cloud spend.
Current practitioner discussion reflects the older non-human-identity problem: organizations discover more machine identities than people, many without a live owner, and owner fields that outlast the person who set them. Agent autonomy makes the defect more consequential because a stale identity can select tools and produce external effects rather than merely support a predictable daemon.