Direct answer: Every request should start with enterprise identity, not a separate AI user store. SAML or OIDC login, group membership, role-based access control, and environment scope decide which agents, tools, models, and knowledge sources the user can reach.
The identity layer is the first control point because every downstream action inherits the actor, team, purpose, data classification, and approval policy. In regulated deployments, this layer should integrate with Entra ID, Okta, Keycloak, LDAP, privileged access management, and the organization's existing joiner-mover-leaver process.
Core controls
- SSO: Entra ID, Okta, Keycloak
- RBAC and ABAC policies
- Team, role, and environment scope
Evidence to retain
- Actor and group ID
- Allowed agents and tools
- Data-source entitlement decision