JumpCloud Blog
Blog
Read, engage, and learn about the shifting trends in IT and security, the future of the domainless enterprise, and how organizations are redefining the directory. Source
Actions
Media Outlet details
| Scope | International |
|---|---|
| Language | English |
| Country | United States of America |
|
Similarweb UVM |
Request pricing |
|
Comscore UVM |
Request pricing |
Recent Articles
Search ArticlesHow to Fix 3 Proven Zero Trust Flaws in AI Security
Ask a CIO whether their AI agents are governed under formal identity and access management (IAM) policy, and most say yes. Ask the IT managers on the same team and you get a different answer. In JumpCloud’s Agentic IAM Pulse Report, 68% of CIOs said their agents are fully integrated into formal IAM policies. Only 35% of IT managers and team leads agreed. Thirty-three points separate those two answers. That’s not a disagreement about facts.
Turning Discovery into Action: What to Do When You Find Your First Shadow Agent
Picture this scenario. You just finished a full audit of your IT systems. First, you pulled the OAuth token report from Salesforce. Next, you checked the browser extensions in your device management tools. Finally, you reviewed the API key list that your engineering team maintains. You think you have a good handle on your network. But then, you see it. You found an AI agent that you never approved. It is running on login credentials that your team did not issue.
How to Spot the AI Agents Already Running in Your Environment
If you think agentic shadow AI isn’t running in your environment right now, look closer. It’s not hiding behind a suspicious login or an unusual network spike. It looks like a Slack workflow that auto-responds to support tickets. Or it looks like an API key a developer pasted into a no-code builder last quarter. It could be a browser extension that one of your sales reps installed to summarize call notes, and that now has full read access to your CRM.
Why AI Agents End Up With Access No One Was Meant to Give Them
Your AI agents probably have more access to your systems than the rest of your employees do. And there’s a good chance no one on your team has planned it that way. This is a structural mistake built into how most organizations deploy AI agents today. The identity model that secures human access was never designed to handle autonomous software. So when teams need to get an agent up and running fast, they reach for the tools that already exist.
Empower Users Without Sacrificing Control: The JumpCloud Self-Service Application Catalog for macOS & Windows
Every IT team has been through this: a new hire starts, or an employee needs a tool to finish a project, and the request turns into a support ticket, leaving the employee idle and IT admins buried in routine deployments instead of strategic work. Traditionally, giving employees access to optional software has required IT involvement, whether through support tickets, manual deployments, or other administrative workflows.
See Connected MCP Servers and AI Token Costs Without API Setup
Developers connect MCP servers to their local environments all the time, often without IT approval. The Model Context Protocol (MCP) is an open standard that lets AI tools plug into outside systems like databases, code repositories, and third-party services. If an engineer needs one of those connections in Cursor, Claude Code, VS Code, or Copilot CLI to ship faster, they set it up. Speed wins. That speed creates two blind spots.
Create Self-Service IT Reports with Custom Query Builder
Answering critical audit questions, like identifying which users have access to specific applications on their laptops, often means navigating multiple disconnected systems. Standard reports typically focus on a single domain, forcing you to manually reconcile data or wait for custom engineering scripts. This manual correlation is a major source of operational friction, turning routine compliance checks into hours of tedious work.
Why Your IT-Security Model Needs an Update for the Agentic Era
A sales operations analyst on your team is buried in manual data entry. The IT queue is three weeks deep. So they open a no-code platform, connect an AI agent to the CRM with a personal API key, and then they let it run. By lunch, the agent is already pulling contact records, drafting email sequences, and writing updates back into the database. On its own. Around the clock. The agent now holds standing access to customer data. It authenticates, reads, writes, and decides.
Why Your IT-Security Model Needs an Update for the Agentic Era
A sales operations analyst on your team is buried in manual data entry. The IT queue is three weeks deep. So they open a no-code platform, connect an AI agent to the CRM with a personal API key, and then they let it run. By lunch, the agent is already pulling contact records, drafting email sequences, and writing updates back into the database. On its own. Around the clock. The agent now holds standing access to customer data. It authenticates, reads, writes, and decides.
Shadow IT Was Hard to Govern. Shadow AI Is Harder.
A decade ago, businesses were signing up for cloud tools without telling you. Dropbox here, Slack there, company data moving into apps no one had vetted. That was shadow IT, and companies found the solutions. They rolled out single sign-on, procurement reviews, and tools that caught unsanctioned apps before they could spread. The work was hard, but it worked. Now the same pattern is back, and this version is harder.