Smartflow for IT governs AI agents that work in service management, infrastructure and engineering. Agents read, diagnose and prepare changes. Privileged actions pause for a person with authority to approve them, who can be required to step up and re-verify their identity first. Every step lands in a tamper-evident record your change and access reviews can use.
Where do agents already work in IT?
Service desk agents reset passwords, unlock accounts and grant application access. Operations agents restart services, scale clusters and edit configuration. Coding agents open pull requests, run migrations and deploy. Each acts through a credential: a service account, an API token, or a developer's own session. In most environments that credential can do far more than the task in front of it.
What goes wrong?
Two incidents mark the pattern. In July 2025 a coding agent deleted a production database during a declared code freeze. In April 2026 an agent working on an unrelated task found an API token with broad permissions and deleted a company's production database and its backups in nine seconds. There was no confirmation step.
The service desk carries its own exposure. In its October 2024 industry letter, the New York Department of Financial Services named AI-enabled social engineering, including deepfakes, as a leading risk and recommended authentication that resists it. An agent that resets credentials on request moves that attack to machine speed.
What do the rules already require?
These requirements apply to people today. They apply to agents the moment an agent holds the credential.
- 23 NYCRR 500.7, the NYDFS Cybersecurity Regulation. Enforceable for covered entities. Limit access to what the job requires, minimize privileged accounts, review access at least annually, and for larger Class A companies monitor privileged activity. The regulation's definition of a privileged account includes service accounts, which is where most agent credentials sit.
- NIST SP 800-53, control CM-3. A standard, binding where a contract or federal mandate adopts it. Review each proposed change, approve or reject it, record the decision, implement only approved changes, and keep the records.
- NYDFS industry letter, May 21, 2026. Guidance. Recommends human oversight of AI-generated code before it reaches production.
- NIST NCCoE concept paper on software and AI agent identity and authorization, February 2026. A draft covering authorization, auditing and non-repudiation for agents.
The common thread is a named person, a decision before the change, and a record.
How does Smartflow apply it?
Smartflow sits in the path between your agents and the models and tools they use, on your infrastructure.
- A key per agent. Each agent gets its own virtual key, with allowlists for the models and routes it may use. Shield rules limit which tools it may call.
- Inline policy. Every model call and MCP tool call is checked against those allowlists and your policy. Personal identifiers are redacted before prompts leave.
- The accountable human. When an action is outside policy, it pauses as an approval ticket. A person with approval rights decides, and you can require that person to step up and re-verify their identity first.
- Evidence. Each decision is recorded with the agent's key, the action and its arguments, the policy, the approver and the time. Records are hash-chained, every sealed record carries an RFC 3161 timestamp, and Smartflow exports to Splunk, Datadog, OTLP, and JSON logs your SIEM can ingest. If your team works in ServiceNow, Smartflow can open GRC findings and incidents there. Turn on the WORM archive to write records to Azure immutable blob storage in your account, and set retention to cover your review and examination cycle; the audit default is 365 days.
| Action the agent prepares | The record captures |
|---|---|
| Grant privileged or administrative access | Account, system, privilege, expiry, approver |
| Reset MFA or credentials for an executive or administrator | Account, channel of request, approver |
| Create a service account or long-lived API token | Name, scope, expiry, approver |
| Change a firewall or network rule | Rule, before and after, approver |
| Deploy to production or change production configuration | Service, version or key, approver |
| Mute an alert or change a monitor | Monitor, change, duration |
| Delete data or run a schema migration | Object, scope, approver |
Routine work passes through and is recorded: diagnosis, log queries, ticket updates, test runs and pull requests.
What changes for your reviews?
Access reviews gain a list of every privileged action an agent took and who approved it. Change records gain the approver and the exact arguments of each agent change, captured at the moment of action. Incident reviews start from a sealed, time-stamped timeline instead of a reconstruction.
Rollout
- Inventory. List every agent, the credential it uses and what that credential can reach.
- Observe. Route agent traffic through Smartflow with approvals off for two weeks.
- Scope. Issue each agent its own key, with allowlists narrower than its owner's access.
- Approve. Turn on approvals for the seven actions above, and grant approval rights to the owners of those systems.
- Review. Feed Smartflow's record into your quarterly access review and change audit.
Related: Smartflow for Claude Code covers configuration for the most widely deployed coding agent.
Quick answers
Do access rules written for people apply to AI agents?
When the agent acts through a credential, the credential's rules apply. Under 23 NYCRR 500, a privileged account includes a service account, and access must be limited to what the job requires. An agent holding that account is in scope.
What should an agent never do without a person?
Grant privileged access, reset MFA for an administrator, create long-lived tokens, change network rules, deploy to production, and delete data. Each of these should pause for a person with approval rights, with the decision recorded before the change runs.
How does this fit our change process?
Each approval produces the record NIST CM-3 describes: the proposed change, the decision, the approver and the time. Agent changes enter the change audit with the same evidence as changes made by people.
Download the full guide
The PDF adds a control map from 23 NYCRR 500.7 and NIST CM-3 to Smartflow's record, the full decision map for IT actions, a rollout checklist, and the questions to ask any vendor that proposes to govern IT agents.
Sources
Verified as of September 25, 2026.
- New York Department of Financial Services: 23 NYCRR Part 500, Second Amendment; implementation timeline; industry letters of October 16, 2024 and May 21, 2026.
- NIST, SP 800-53 Rev. 5, Release 5.2.0, August 27, 2025.
- NIST NCCoE, software and AI agent identity and authorization concept paper, February 5, 2026.
- The Register, Replit production database deletion, July 22, 2025.
- Euronews, AI agent deletes company database in nine seconds, April 28, 2026.
Put this in the path of your own agents.
Policy enforced inline between your agents and every model and tool they reach, with a record bound to the human who owns it.
Request a Demo Read the docs