AI Agents Are Multiplying Faster Than Security Teams Can Track Them: What CrowdStrike's Numbers Reveal About Nonhuman Identity Drift
The Specific Event
CrowdStrike and Okta both reported strong gains this week, driven in part by what analysts are calling the "nonhuman identity" problem. The underlying figure is striking: AI agents may generate approximately 90 new nonhuman identities per human worker inside corporate networks. CIOs are now being told, in direct terms, that they are no longer managing systems where humans are the primary actors. The identities multiplying inside enterprise infrastructure belong to agents, bots, and automated processes that operate continuously, across permissions and data boundaries, with no single human accountable for their behavior at the moment of action.
This is not a cybersecurity story in the narrow sense. It is an organizational structure story. And the organizational theory implications are more disruptive than the security headlines suggest.
When Coordination Assumptions Break Down
Classical coordination theory assumes that organizational actors bring pre-existing competence to their roles. Markets coordinate through price signals that competent actors interpret. Hierarchies coordinate through authority structures that competent humans obey. Networks coordinate through relational trust between competent parties. The assumption of ex-ante competence is so deeply embedded in these frameworks that it rarely gets stated explicitly.
The nonhuman identity explosion breaks that assumption at the structural level. When 90 agents operate per worker, the question of "who is coordinating what" becomes genuinely ambiguous. The agents are not incompetent - they execute their defined functions reliably. But they are not competent in the organizational sense either. They do not interpret context, negotiate competing priorities, or recognize when a permission boundary was drawn correctly in January but is now wrong in August. Rahman (2021) described algorithmic systems as "invisible cages" that constrain worker behavior without workers understanding the cage's geometry. The nonhuman identity problem inverts this: now the agents themselves are inside the cage, and the humans managing them often cannot see the agents clearly enough to know what constraints to impose.
The Topology Problem for CIOs
My dissertation research distinguishes between topology and topography in algorithmically-mediated environments. Topography is knowing where specific features are located - which button grants which permission, which API endpoint connects to which dataset. Topology is understanding the shape of the constraint structure itself - how permissions propagate, where access boundaries are likely to drift under load, and which identity relationships create systemic exposure when any single agent is compromised.
The 90-identities-per-worker figure is a topography number. It tells you how many entities exist. It does not tell you anything about the topology of how those entities relate to each other, to human workers, or to organizational data structures. CIOs who respond by building better topographic maps - better inventories of which agents exist - are doing necessary work, but they are not solving the structural problem. The agents will keep multiplying faster than any inventory can track them. What CIOs need is a structural schema for how nonhuman identity drift happens: the underlying pattern by which agent permissions expand incrementally, each expansion individually reasonable, until the aggregate state is indefensible.
This is precisely what Hatano and Inagaki (1986) distinguished as the difference between routine expertise and adaptive expertise. Routine expertise - knowing how to revoke a specific agent's credentials - fails in novel configurations. Adaptive expertise - understanding why permissions drift and under what organizational conditions drift accelerates - transfers across the novel configurations that will keep appearing as agent populations grow.
The Variance Puzzle at the Organizational Level
Kellogg, Valentine, and Christin (2020) documented dramatic variance in outcomes among workers with identical platform access. The same variance pattern is now visible at the organizational level in enterprise AI deployment. Two organizations can deploy comparable numbers of AI agents, with comparable security tooling from vendors like CrowdStrike and Okta, and face dramatically different exposure profiles. The difference is not the tooling. It is whether organizational leaders have developed structural schemas for agent behavior or whether they are operating on folk theories - intuitive impressions of what agents do and how they interact that are accurate enough for routine conditions and catastrophically inadequate when conditions shift.
Gentner's (1983) structure-mapping theory predicts that schema-based understanding transfers across surface differences while procedural knowledge does not. The organizations that will navigate the nonhuman identity problem are not the ones with the most sophisticated agent inventories. They are the ones whose CIOs understand the structural logic well enough to anticipate configurations they have not yet encountered.
What This Means for Organizational Theory
The 90-identities-per-worker figure is a signal that organizational theory needs to extend its coordination frameworks to account for actors that participate in coordination without holding competence, authority, or accountability in any form that existing theory recognizes. Hierarchy assumes accountability chains. Markets assume price-responsive agents. Networks assume relational trust. None of these mechanisms map cleanly onto an agent that executes a permission granted six months ago by a worker who has since changed roles, in a data environment that has since changed shape. That is not a security gap. It is a coordination gap, and closing it requires theoretical work that the current CrowdStrike earnings cycle cannot supply.
References
Gentner, D. (1983). Structure-mapping: A theoretical framework for analogy. Cognitive Science, 7(2), 155-170.
Hatano, G., & Inagaki, K. (1986). Two courses of expertise. In H. Stevenson, H. Azuma, & K. Hakuta (Eds.), Child development and education in Japan (pp. 262-272). Freeman.
Kellogg, K. C., Valentine, M. A., & Christin, A. (2020). Algorithms at work: The new contested terrain of control. Academy of Management Annals, 14(1), 366-410.
Rahman, H. A. (2021). The invisible cage: Workers' reactivity to opaque algorithmic evaluations. Administrative Science Quarterly, 66(4), 945-988.
Roger Hunt