Enterprise AI permissions do not fail only at launch. They drift after launch.
The support agent gets a temporary CRM write scope for a pilot. The HR assistant inherits a broader document collection during migration. A service account remains active after a workflow is retired. A connector adds a new destructive action under an existing integration. Nobody sees the problem because the original security review was treated as a project milestone, not as a recurring control.
An access review for enterprise AI agents is the recurring process that proves each agent still needs each data source, tool action, delegated scope, memory store, model route, and approval bypass it can use. The review should not ask, “does this app still exist?” It should ask, “is this exact authority still justified by current business use, current evidence, current risk, and a named owner?”









