AI Business

Identity governance faces new test as AI agents proliferate across enterprises

Autonomous AI agents are forcing organizations to rethink how they manage access and permissions at machine speed. SailPoint's Navigate conference will explore how identity security must evolve to handle this expanding population of non-human actors.

·6 min read
What to expect at SailPoint’s Navigate event: Join theCUBE Oct. 6–7
What to expect at SailPoint’s Navigate event: Join theCUBE Oct. 6–7

The rise of autonomous AI agents is upending how enterprises think about identity and access control. These systems can perform tasks, communicate with applications and infrastructure, request permissions and operate at speeds that outpace traditional governance models. This shift raises a fundamental challenge: organizations must determine not just who or what is taking action, but whether the authority granted to that actor should persist as circumstances change.

According to Krista Case, principal analyst and practice lead for cyber resilience and security at theCUBE Research, "Agentic AI turns identity governance into an execution problem. Enterprises need to know who or what is acting, whose authority it carries, what it can reach and whether that authority should still apply as the task changes. Customers should evaluate identity platforms on how well they can maintain that context through the full lifecycle of an agent's work."

These questions will take center stage at SailPoint's Navigate conference, running Oct. 5–8 in Austin, Texas. The event, themed "AI, secured," examines how identity security must adapt as organizations deploy AI agents alongside their existing populations of human and machine identities. SailPoint frames identity as a critical control point for enterprise security in an era when autonomous systems are becoming operational fixtures.

TheCUBE will provide coverage on Oct. 6–7, with Case and co-host Rebecca Knight conducting interviews with executives and security leaders about adaptive identity, agent lifecycle governance and the convergence of human, machine and AI agent identities.

The visibility and governance gap

Traditional identity governance evolved around people, roles and predictable access patterns. Autonomous agents break this model because permissions are no longer static assignments reviewed periodically. Instead, agents execute tasks, interact with other systems and shift their activities as work progresses.

The scale of the challenge is substantial. Research cited by Zeus Kerravala, principal analyst at ZK Research, shows that 97% of AI agents have access to sensitive data, yet only 21% of organizations feel confident managing AI agent security risks. In one proof of concept at a Fortune 500 company, SailPoint discovered more than 10,000 previously unknown AI agents.

As Kerravala observed, "You can't govern what you can't see."

SailPoint is pushing the industry toward continuous security rather than periodic compliance checks. Chandra Gnanasambandam, executive vice president of product and chief technology officer of SailPoint, stated in August that "We are moving the industry beyond static compliance and into an active, continuous security loop. By unifying the ability to discover every identity, govern access lifecycle policies and protect the enterprise through real-time risk remediation, we are giving security leaders the visibility and automation they need to confidently shut down modern attack vectors before they can be exploited."

Organizational challenges outpace technology

Finding agents is merely the starting point. Organizations must also identify who created and owns each agent, what access it needs and when that access should expire. Agents can accumulate privileges over time, spawn additional agents and share credentials across systems, amplifying the risks of inadequate access controls.

Agent governance is as much an organizational issue as a technical one. Case explained: "The hardest part of agent governance is organizational. Agents can be created and deployed faster than traditional access processes can discover, assign ownership and govern them. Customers need an operating model that connects AI development, identity, security and the business before agent populations reach a scale where governance becomes a cleanup exercise."

As enterprises scale from individual AI assistants to larger fleets of task-focused autonomous agents, identity teams will need closer collaboration with security operations, application developers, AI engineers and business stakeholders to establish clear accountability before agents operate at production scale.

Identity systems play a unique role because they supply context that runtime security tools alone cannot provide. Sandboxes and containment technologies can restrict what an agent does, but they cannot necessarily establish who built it, who is responsible for it or how long its permissions should remain valid. Kerravala noted that "identity is the system of record everything else relies on."

The limits of a single control plane

SailPoint is positioning identity as an increasingly central control point as enterprises manage human, machine and agent identities together. The company's Navigate agenda reflects a broader industry movement toward placing identity at the core of enterprise security as AI multiplies the entities needing access.

The expansion of AI agents is also widening the identity attack surface. Mark McClain, founder and chief executive officer of SailPoint, stated: "The proliferation of AI agents is creating a new class of non-human identities, and each one represents a new attack surface. For AI to be a true business accelerant, it must be built on a foundation of security. Our collaboration with AWS is about providing that foundation. By building a unified identity plane, we believe we will give our joint customers the visibility and control they need to manage the complexity of an AI-driven ecosystem, allowing them to innovate boldly and securely."

However, identity does not function in isolation. Case cautioned: "Organizations should be careful with claims that a single platform will become the control plane for agentic AI. Agent governance spans identity, runtime infrastructure, applications, data and security telemetry. The winning architecture will depend on strong integration and clear decision authority across those systems."

This distinction may prove crucial in enterprise agentic AI deployments. Identity platforms can maintain records of what an agent is and what it should access, while runtime environments, security tools, applications and data systems provide other enforcement components. The real challenge lies in connecting these systems rapidly enough to govern autonomous actions without sacrificing the speed and flexibility that make agents valuable.

TheCUBE's coverage will examine how SailPoint and its customers balance this equation as identity governance expands beyond the human workforce. Topics include how enterprises discover and categorize AI agents, link them to accountable human owners, enforce least-privilege access and remove permissions when an agent's purpose changes.

A related question is whether organizations can build a unified governance model without forcing every identity type into the same operational framework. Humans, service accounts, machines and AI agents exhibit different behaviors and risk profiles, even when they ultimately access the same applications and data.

SailPoint Navigate arrives as enterprises confront these questions in production environments. The shift toward autonomous systems reframes identity from proving who logged in to continuously verifying who or what has the authority to act.

Coverage and viewing options

TheCUBE will cover SailPoint's Navigate event on Oct. 6–7, with exclusive interviews and analysis available on theCUBE's website and YouTube channel. Content will also be available on demand after the event.

SiliconANGLE's "theCUBE Pod" airs on Apple Podcasts, Spotify and YouTube, featuring hosts John Furrier and Dave Vellante discussing major trends in enterprise technology, including AI, cloud, cybersecurity and infrastructure. The outlet also produces "Breaking Analysis," a weekly program where Vellante examines significant developments in enterprise tech using insights from theCUBE and spending data from Enterprise Technology Research, available on Apple Podcasts, Spotify and YouTube.

TheCUBE will interview executives and identity security leaders from SailPoint, Amazon, Eastern Bank, HCLTech, Entro Security and other organizations about how enterprises are governing AI agents, securing expanding identity populations and rethinking access as autonomous systems play a larger role in business operations.