AI News Feed
Market watch
Companies

SailPoint Navigate to Focus on Identity Security in the Agentic AI Era

SailPoint’s Navigate conference runs Oct. 5–8 in Austin under the theme “AI, secured,” with theCUBE covering Oct. 6–7. Executives and analysts will discuss how enterprises govern human, machine and AI agent identities.

According to SiliconANGLE, the event comes as agentic AI changes the identity security equation. Enterprises no longer govern access only for employees and traditional machine identities. AI agents can act on behalf of people, interact with applications and data, acquire permissions and execute work at machine speed. That raises the question of how an organization determines who or what is acting and whether that authority should still apply.

“Agentic AI turns identity governance into an execution problem,” Case said. “Enterprises need to know who or what is acting, whose authority it carries, what it can reach and whether that authority should still apply as the task changes. Customers should evaluate identity platforms on how well they can maintain that context through the full lifecycle of an agent’s work.”

SailPoint describes identity as a new control point for enterprise security, with this year’s event bringing that idea into the agentic AI era. Traditional identity governance was built largely around people, roles and relatively predictable access patterns. Autonomous agents challenge that model because permissions are not simply granted to an identity and periodically reviewed. Agents can execute tasks, interact with other systems and change what they are doing as work progresses.

In a recent SiliconANGLE Media guest analysis, Zeus Kerravala, principal analyst at ZK Research, cited SailPoint research showing that 97% of AI agents have access to sensitive data, while only 21% of organizations are highly confident they can manage AI agent security risks. Kerravala also pointed to a SailPoint proof of concept at a Fortune 500 company that discovered more than 10,000 previously unknown AI agents. The problem starts with visibility, he said: “You can’t govern what you can’t see.”

SailPoint is moving beyond periodic governance as identity risk becomes more immediate, according to Chandra Gnanasambandam, executive vice president of product and chief technology officer of SailPoint. “We are moving the industry beyond static compliance and into an active, continuous security loop,” Gnanasambandam said in August. “By unifying the ability to discover every identity, govern access lifecycle policies and protect the enterprise through real-time risk remediation, we are giving security leaders the visibility and automation they need to confidently shut down modern attack vectors before they can be exploited.”

Discovering agents is only the first step. Enterprises also need to establish who owns them, what permissions they require and when those permissions should disappear. Agents can accumulate privileges, create or interact with other agents and use credentials across applications and infrastructure, increasing the potential impact of poorly governed access. That makes agent governance as much an operating model problem as a technology problem.

“The hardest part of agent governance is organizational,” Case said. “Agents can be created and deployed faster than traditional access processes can discover, assign ownership and govern them. Customers need an operating model that connects AI development, identity, security and the business before agent populations reach a scale where governance becomes a cleanup exercise.”

That organizational challenge is likely to become more pressing as enterprises move from individual AI assistants toward larger populations of task-oriented autonomous agents. Identity teams will need to work more closely with security operations, application teams, AI developers and business owners to establish accountability before agents begin operating at scale.

Identity systems have a particular role because they provide context that runtime security alone cannot, according to Kerravala. Sandboxes and other containment technologies can limit what an agent does, but they do not necessarily determine who created it, who is accountable for it or how long its permissions should remain active. Kerravala said identity is the system of record everything else relies on.