AI News Feed
Market watch
Companies

At Navigate 2026, SailPoint says standing privilege must go in agentic era

At Navigate 2026, SailPoint says AI agents require real-time, context-aware identity governance, not calendar reviews.

The keynote opened with an orchestra to illustrate what happens when discrete components work in harmony. Chief Executive Mark McClain used the image to describe the chaos when AI agents do not work together. He said that a few years ago enterprises knew exactly who was in their orchestra: employees, contractors and partners. "But today, there's an invisible crowd operating right alongside them," McClain said, describing service accounts, API keys and autonomous agents that, according to a study he cited, outnumber human identities 109 to one.

President Matt Mills said an agent acts on behalf of a human or another agent that traces back to a human. "So, the moment you govern human and agent separately, you lose the thread of who's actually accountable," he said. "We treat human and agent identity as one problem. It's on one graph. It's under one policy." SailPoint said it evolved Identity Security Cloud into Agentic Fabric and Human Fabric, both built on its Atlas platform, according to SiliconANGLE. The company's argument is that agents should not be treated as a standalone inventory problem, because an agent without a human owner is an orphaned account capable of reasoning.

Criteo S.A. Director of Corporate Security Jérôme Robin, a SailPoint customer since 2021, said giving access to an agent for a task means delegating business responsibility. "Technology should enforce the model, not replace it," he said.

Mills also rejected the idea that monitoring can substitute for enforcement. "You cannot fight AI-speed threats with human-speed governance," he said. "Basic monitoring is not security. Simply watching an agent do bad things isn't security. It's just a dashboard that reports all your breaches to you." Executive Vice President and Chief Technology Officer Chandra Gnanasambandam said SailPoint sees 75 million to 150 million agentic interactions per day at an average Global 2000 company. He said the idea that a security admin will review and approve access for autonomous agents making 10,000 tool calls a second is not just outdated but a fantasy.

SailPoint's fifth annual Horizons of Identity Security report, released at the event, found that 79% of organizations run AI agents in production, but only 2% use identity security tools to govern them, and just 15% can provision non-human access in real time. Chief Marketing Officer Wendy Wu said, "You cannot run an AI-speed enterprise with human-speed security."

SailPoint's answer, as described at the event, is a set of Autonomous Agents: red agents detect drift, blue agents analyze it and deprovision access, and green agents handle peacetime work such as certifications. Gnanasambandam said the largest customers have certification campaigns with more than 10 million line items and that 95% of those should be automated. SailPoint argued that access reviews were broken for humans long before agents arrived, and that AI has made the problem impossible to ignore rather than creating it.

Gnanasambandam also took aim at runtime-first security vendors. "An agent kill switch is supposed to kill the bad agents. If you're a runtime control platform without context, and the kill switch can't tell a good agent from a bad one, on what basis will it kill the bad agent?" he said. "It'll end up killing both good and bad agents." According to SiliconANGLE, a kill switch that shuts down legitimate automation is one the business will make security teams turn off. SailPoint's bet is that the identity context it has spent 20 years building enables real-time enforcement, while runtime-only tools will struggle without it.

Editor's Summary SailPoint used its Navigate 2026 keynote to argue that AI agents make standing privilege and calendar-based identity governance inadequate, and that human and agent identities must be governed together in real time. The company cited its Horizons of Identity Security report showing that most organizations run AI agents in production while few govern them with identity security tools, and it described autonomous agents for drift detection, deprovisioning and certification work. The reported message is that runtime controls without identity context may be too blunt to secure agentic enterprises.