Ask an IT team what takes up the majority of its time, and the answer likely won’t be enormous projects. More often, it is hundreds of smaller jobs. A new employee needs access to six applications. Someone moves teams and needs three more. A contractor finishes, and someone needs to close all their accounts. A director submits another access request, then another. The problem is the volume, and this is only set to increase. With new employees, contractors and AI agents joining the workforce, the number of identities and complexity of environments is exploding. For IT service providers, this kind of work can consume capacity and leave room for mistakes. Access gets added quickly, while removal can fall to the bottom of the list. Over time employees can accumulate permissions they no longer need. This has always been an identity management problem. But with Gartner predicting that, by 2028, the average Fortune 500 company will have over 150,000 AI agents, up from 15 in 2025, the challenge is set to hit unprecedented levels. It is simply impossible for businesses to add autonomous identities alongside employees, contractors and administrators, and manage every change through a ticket. MSPs and VARs must identify repeated tasks, establish lifecycle rules and automate responsibility. Unchecked access sprawl creates unnecessary risk Most organisations are reasonably good at giving people access when they need it but taking that access away is harder. Someone joins the finance team and gets the appropriate applications. Two years later they moved into operations. Their new access is added, but what happens to everything they had before? Sometimes it is removed immediately or sometimes it stays. The same problem appears with temporary permissions, contractors and employees who leave the business. The result is a gradual build-up of accounts and privileges that no longer match what people actually do. For partners, there is also a cost every time they have to fix this manually. Provisioning a user, changing group membership or removing access might only take a few minutes. Multiply those few minutes across every customer, user and application, however, and they become a sizable workload. This is where lifecycle automation starts to matter. Instead of treating each access change as a separate service desk task, IT service providers can help customers establish rules for what happens when somebody joins, moves or leaves. A new starter can receive access according to their role. If they move departments, some permissions can be removed as others are granted. When they leave, deprovisioning can begin automatically rather than depending on somebody remembering to raise a ticket. It sounds straightforward and it can remove a large amount of repetitive work. Onboarding alone will not solve the lifecycle challenge Onboarding is usually the obvious place to start because the pain is visible. A new employee arrives on Monday morning and cannot work because their accounts are not ready. Everyone notices, requests and messages come through, and changes are made. The problems created by somebody changing roles are less obvious. So are unnecessary permissions that remain in place for months. That is why automation needs to cover the whole identity lifecycle. For partners looking to turn this into an actionable programme, there are four practical places to begin:
Partners should ask: which applications generate the most requests? What happens when an employee changes teams? Are temporary permissions ever reviewed? How many steps are involved in offboarding somebody? Who owns each part of that process? Those questions tend to expose the repetitive work that is worth automating. There is a practical benefit for the customer: people get the access they need more quickly, and old access is less likely to linger. There is an equally practical benefit for MSPs and VARs. If technicians no longer need to carry out the same provisioning tasks hundreds of times, that capacity can go elsewhere. That might mean solving more complex customer problems, improving security or taking on additional managed services rather than simply working through another queue of access tickets. AI agents multiply the lifecycle challenge This becomes more urgent when the identity in question is not a person. AI agents may need to open files, use applications, query databases, call APIs or take actions in other systems. To do those things, they need access, and that means they also need an identity lifecycle. Consider an agent created to perform a specific finance workflow. It receives access to the systems and data required for that job, but six months later the workflow changes. The agent may need additional access, less access, or may have been replaced entirely. Without a clear answer to who removes the old permissions, businesses could recreate the same access problems they already have with people, except at machine speed and potentially much greater scale. An unused AI agent with valid credentials is not fundamentally different from an old employee account that nobody disabled. Both represent access that exists without a clear business reason. This is where Agentic IAM needs to connect with the lifecycle processes partners are already building. Partners can apply the same lifecycle discipline to AI agents from the outset. It’s possible to do this by giving every agent a named owner, document its specific purpose, grant only the access needed for that purpose, review that access when its workflow changes and remove its credentials when it is retired. An agent should have an identifiable owner and a defined purpose. Its permissions should reflect that purpose. If its role changes, its access should change too. When the agent is retired, its credentials and permissions should disappear with it. Human oversight still matters, particularly for sensitive actions. What cannot happen is for every routine change to depend on somebody manually administering it. As organisations manage a growing mix of human and autonomous identities, there may simply be too many identities for that approach to remain sustainable. Lifecycle automation creates a stronger service opportunity There is a commercial opportunity here for IT service providers , but it does not require turning identity automation into another product pitch. Start with the operational problem. A customer struggling with provisioning may also have disconnected directories, inconsistent access policies, ageing infrastructure or little connection between identity and device management. Fixing the lifecycle often reveals those wider issues. A lifecycle review can therefore become a practical first engagement:
From there, partners can build recurring services around monitoring, policy reviews and the ongoing management of both human and AI identities. That gives partners somewhere useful to go next. They can advise customers on how to standardise their identity processes, modernise their workflows or underlying infrastructure and manage those controls on an ongoing basis. As AI adoption grows, partners can advise customers on securely integrating AI identities into their environment, expanding to cover the lifecycle of autonomous identities as well as human ones. The attraction is that both sides benefit. Customers get more consistent control over access. Service providers and resellers reduce repetitive service desk work while creating room for more valuable advisory, and managed services. Creating an account, changing routine permissions or removing access when an identity disappears should not require manual labor, but simply human oversight.
- Map the highest-volume access tasks. Identify which applications, teams and customer accounts generate the most access-change and offboarding requests. These are usually the clearest early automation opportunities.
- Set joiner, mover and leaver rules. Agree what access each role should receive, what must change when somebody moves teams, and which accounts and permissions must be removed when they leave.
- Find and address exceptions. Review temporary permissions and access that has no clear owner or business purpose. These are often where access sprawl takes hold.
- Measure the operational impact. Track the number of manual tickets, time to provision and time to deprovision, then use those results to identify the next workflows to automate.
- Map the current joiner, move and leaver processes.
- Identify the systems that are disconnected.
- Prioritise the highest-volume manual tasks.
- Create a phased plan to automate them.