TL;DR
The common belief — MFA on user logins means identity and access are covered — no longer answers the question being asked. ASD's Australian Cyber Security Centre is consulting on evolving the Essential Eight, so the identity expectations Australian businesses are asked to evidence, MFA chief among them, remain live while wording may change [1]. Dark Reading, meanwhile, reports an unauthenticated path into a local model server and a new framework built specifically to constrain AI agents inside networks [2][3]. The evidence gap is no longer just human logins: the matrix below maps eight identity decisions to artifacts you can request this week.
What changed
Three reported items, with sources named beside each. lilMONSTER has not tested any product or framework mentioned; the facts are as reported.
- ASD ACSC announced a consultation on the evolution of the Essential Eight — the framework that includes multi-factor authentication among its eight strategies — intended to "increase flexibility and support stronger cyber resilience" [1]. No replaced control set has been announced.
- Dark Reading reports a networking bug in Nvidia's OpenClaw tooling that lets attackers gain unauthenticated access to the local model server through the Ollama API, paving the way for LLM poisoning and persistent AI agent corruption [2].
- Dark Reading also reports that security expert Jake Williams released the CUSTODY framework, which constrains AI agents inside the network, in the wake of OpenAI attacks on Hugging Face [3].
Why it matters for business trust
lilMONSTER's interpretation, separated from the reported facts: insurers, tender panels, boards, and auditors ask for identity evidence, and the first artifact most businesses produce is an MFA screenshot. That answers the human-login question only. The reported items describe access outside that answer — a service endpoint reachable without authentication [2], and AI agents acting with enough standing privilege that a dedicated constraint framework now exists for them [3]. An auditor who asks "what else can log in or act?" will not find either in an MFA report. If your identity story cannot be evidenced beyond human accounts, the gap stays invisible until scrutiny surfaces it — precisely what evidence requests exist to prevent.
A useful first project
Run the matrix against your environment and you will have an insurer-ready identity evidence pack within a week — built mostly from answers already sitting in your admin consoles.
We verify authority first, minimise access, define scope, and focus on evidence that supports a real business decision.
Tell us what should work better →Evidence to produce now
Identity Evidence Request Matrix — request the artifact, not the assurance:
| # | Decision to evidence | Artifact to request from IT | What "reviewable" looks like |
|---|---|---|---|
| 1 | MFA coverage, human accounts | MFA status report for all enabled accounts | Coverage percentage with named, dated exceptions |
| 2 | MFA on admin and remote access | Privileged account list with MFA configuration | No privileged account without MFA |
| 3 | Non-human accounts have owners | Service account inventory with an owner column | Every row: named owner, purpose, last-reviewed date |
| 4 | Dormant accounts are disabled | Last-logon report (60–90+ days) plus disablement log | Zero enabled accounts past threshold |
| 5 | Leavers lose access on time | Sample of leaver tickets with deprovision dates | Actioned within the stated policy window |
| 6 | Privileged access is reviewed | Quarterly privileged-role review, signed | Dated sign-off naming reviewer and scope |
| 7 | Model and API endpoints require authentication | Endpoint inventory with authentication setting | No unauthenticated endpoints — the failure mode reported in [2] |
| 8 | AI agents are constrained | Agent register: owner, permissions, data scope, logging | Constraints documented, CUSTODY-style [3] |
30-minute first pass: minutes 0–10, pull rows 1 and 4 from your identity provider's console; minutes 10–20, list service accounts and any AI tools holding credentials (rows 3 and 8); minutes 20–30, mark every blank owner as a finding and assign one. You have tested nothing and touched nothing — you have produced evidence.
FAQ
Does the Essential Eight consultation change what we show now? No. The consultation is open and no replacement control set has been announced [1]. Evidence produced today against current expectations stays usable; waiting for new wording is not a position an auditor accepts.
We have MFA everywhere humans log in. Doesn't that close this? It closes the human-login question. The reported OpenClaw issue involved an endpoint reachable without authentication [2], and agents act with standing privileges [3]. Neither appears in an MFA report.
Are AI agents really an identity problem? lilMONSTER's reading of [2] and [3]: an agent that authenticates, holds permissions, and persists in the network is a non-human identity. Treat it like one — named owner, least privilege, reviewable log.
What single artifact starts the conversation with an insurer or client? Row 3: the service and agent inventory with owners. It demonstrates you know everything that can act in your environment — the premise every other identity control rests on.
Conclusion
Three steps, none requiring system access yet: run the 30-minute first pass above; assign an owner to every unowned account and agent it reveals; date-stamp the eight artifacts so your evidence pack has a review cycle. If you want an independent read on what your current evidence would and would not satisfy — insurer questionnaires, Essential Eight-aligned reviews, tender requirements — request a consultation at https://consult.lil.business/. Signed scope, access verification, and rules of engagement come before any credential, tenant access, or live-system look; the first conversation needs only the artifacts you have already produced.