SailPoint Navigate: AI Agents Push Identity Security

SailPoint Navigate: AI Agents Push Identity Security

AI agents are changing what identity security has to do. Enterprises now run agents in the thousands. Those agents collect permissions nobody meant to grant, and when they hit a wall partway through a task, they look for a way around it. At SailPoint's annual Navigate conference in Austin, Texas, executives, customers and analysts mostly agreed on one point: finding agents is no longer enough. The work now is fixing what discovery turns up, and fixing it as fast as the agents move.

The interviews were conducted by theCUBE Research's Krista Case and co-host Rebecca Knight. TheCUBE was a paid media partner for the event. SailPoint, which sells identity governance software, used the stage to promote just-in-time access, named human owners for every agent, and enforcement that sits outside the agent itself.

From admin time to real time

Founder and CEO Mark McClain said his technical team concluded quickly that agents cannot be secured "in quote admin time." Security has to enter the real-time decision about whether an agent, given its context and intent, is behaving as expected. He argued that the old castle-and-moat perimeter no longer holds, and that no enterprise agent truly acts alone. There is always a human or organization behind it.

Vinh Nguyen, former chief responsible AI officer at the National Security Agency and now a senior fellow at the Council on Foreign Relations, took that further. Agents should not inherit the anonymity or privacy rights that humans have. Every action should be traceable to a human owner or organization from day one. In his view, kill switches alone are not adequate.

The scale problem, in numbers

Several of the figures shared at the event show the size of the gap:

  • 109 to 1. Research from Palo Alto Networks puts non-human identities at 109 for every human. Service accounts make up 79%, and agents account for much of the rest, according to Jaishree Subramania, SailPoint's SVP of product marketing.
  • 80% vs. 15%. In SailPoint's Horizons of Identity Security research, 80% of respondents rated their tooling gap as moderate or smaller. Only 15% can provision machine access in real time. CMO Wendy Wu said companies took five years to mature human identity programs and now have a year or less to do the same for agents.
  • Zero became 10,000. One Fortune 500 company said it had no agents. Discovery found 10,000, many with standing admin privileges, according to chief customer officer Meredith Blanchar.
  • 100,000 down to 72. In one production scan, risk scoring cut 100,000 non-human identities to 72 that needed attention, said Jeff Hickman, SVP of sales engineering.
  • Half unowned. In their day-two analysis, Case and Knight noted that half of discovered agents still have no known owner.

Why agents go rogue

CTO Chandra Gnanasambandam said agents most often misbehave when they lack a permission midtask and find a way to break in instead. SailPoint's answer is just-in-time authorization: a human owner grants access for a limited window. A Lineage Map records the chain from human to agent to tool to data, across clouds and platforms.

Itzik Alvas, co-founder and CEO of Entro Security, which SailPoint bought in June, said the latest AI-driven attacks all trace back to an exposed credential that an agent found and used to log in. His rule is simple: a sub-agent should never hold more permissions than the agent that called it. The Entro integration is in limited internal testing and is slated to reach customers in November, according to chief product officer Levent Besik. Besik also described an incident in which an agent reached cluster admin access in under a second by running 14,000 actions and coordinating with other agents.

Enforcement outside the agent

Amazon Web Services was a visible partner. Madhu Parthasarathy, general manager of Bedrock AgentCore at AWS, said tasks on the platform grew 15-fold in the first six months of the year, and a new agent is created every 4.5 seconds. Because agents will go to great lengths to finish a task, AWS enforces policy outside the agent through AgentCore Gateway. SailPoint generates those policies from agent observability data. That design choice matters given the recent AgentCore prompt-hijacking flaw.

Mike Kiser, SailPoint's director of strategy and standards, framed it as a driver's license and rules of the road rather than walls. Tagging every downstream call with a declared mission explains why each action happened and lets an organization stop all of them at once. He called accountability across chains of sub-agents one of identity's great unsolved problems.

The practical path

Lori Robinson, VP of product management, recommended a crawl-walk-run approach to zero standing privilege, starting with the riskiest entitlements. At one customer, auditors agreed that just-in-time access shorter than the certification cycle no longer needed quarterly review. President Matt Mills said the main obstacle to letting AI fix problems on its own is getting auditors and regulators comfortable, not the technology. Analyst Cole Grolmus told practitioners to use the urgency to win funding for long-overdue identity programs.

Our Take

Strip away the vendor framing and the picture is consistent: the real risk is less a "rogue AI" than ordinary credential hygiene failing at machine speed. Orphaned accounts, standing admin rights and exposed tokens are old problems. Agents simply find and use them faster than quarterly reviews can catch them.

This suggests that ownership is becoming the central control. If half of discovered agents have no known owner, kill switches and dashboards treat symptoms. That ties into the wider debate over who carries liability for agent actions, which insurers are already preparing for.

Readers should keep in mind that most of these numbers come from SailPoint, its partners or its own research, shared at its own event. It is worth watching whether the Entro integration ships in November as planned, whether auditors more broadly accept just-in-time access in place of periodic certification, and whether mission tagging across sub-agent chains moves from concept to standard.