Standing credentials
Keys and service accounts issued once and used indefinitely, often outside normal joiner and leaver process.
IdentityAn AI system or agent inherits whatever it is connected to. Once it holds standing credentials and a permanent route into your data and tooling, its reach is only as small as the last configuration change. Physical Control puts the boundary somewhere an agent cannot rewrite.
Need → Control → Blueprint → Modules

AI systems are connected to make them useful. The exposure comes from what remains connected after the useful work has finished.
Keys and service accounts issued once and used indefinitely, often outside normal joiner and leaver process.
IdentityAn agent given access to a share or system can usually read far more of it than the task required.
DataAgents that can act, not just read, can change systems at machine speed and without a person in the loop.
ActionInstructions can arrive inside the content an agent processes, so intended limits are not always the limits that apply.
BehaviourWhen something goes wrong, the record of what the agent reached is frequently incomplete.
AuditProprietary models, weights and curated training sets sit online with the same reach as ordinary files.
AssetsThe pace of adoption is the point. The consequence is that access is granted to get something working, then inherited by everything that follows.
Nobody decides that an agent should hold indefinite access to a production system. It happens because the credential worked and nothing forced it to expire.
Control the path, protect the asset.Access granted for an experiment is rarely reissued when the experiment becomes a dependency.
Most systems grant access at the level of a share, a database or an account, not the level of a task.
An agent can take thousands of actions between the change control meetings meant to govern it.
AI integrations often sit between engineering, data and the business, so no one holds the access register.
Control starts by writing down the specific paths between AI systems and the systems and data they reach.
Physical Control does not attempt to reason about intent. It governs whether a route exists at all.
Access is configured and trusted to stay configured.
Access exists only inside a window that has been opened.
Software can be told to deny a connection. Physical Control removes the connection itself, so the denial does not depend on the system behaving as configured.
Every incident that spreads does so along a connection that was already there. Control begins by naming that connection in plain language, before anyone talks about products.
A path that exists only when it is needed cannot be used at three in the morning by someone who should not have it. Disconnection is the resting state, not the emergency response.
When work genuinely needs a connection, Control opens it for a named person, a stated purpose and a fixed period, then closes it again without anyone having to remember.
A policy says the path should be closed. Physical control shows that it is. That difference is what auditors, insurers and boards are actually asking about.
Governing AI access uses the same architecture as third-party access, with compliance evidence alongside it.
Give third parties access without giving them a permanent doorway.
Applied to time-bounded vendor and supplier access. The Blueprint page carries the architecture, the zone detail and the deployment sequence.
Compliance becomes stronger when control can be demonstrated, not just documented.
Open CP-06 Also relevantAI access patterns are set out in the AI Control Blueprints playbook, which covers agent access, tooling rights and oversight in more depth than a single numbered Blueprint.
Open the playbookThis page is about the routes an AI system can take. Protecting the models, weights and training material themselves is a different job, and Offline Secure Storage holds those copies physically outside the connected environment.
Protect models and training data offlineThe practical questions that come up once agents move from pilot to production.
The AI Control Blueprints show how agent access is validated, time-bound and evidenced without slowing the work down.