For most of its two-decade history, SailPoint Inc. has been the company that tells enterprises who should have access to what. At Navigate 2026 in Austin this week, it argued that it now needs to be the company that stops the wrong access the moment it happens.
The keynote opened with an orchestra to illustrate the harmony that emerges when discrete components work together. When they don’t, the experience is very different. During his portion of the keynote, Chief Executive Mark McClain (pictured) used this analogy to describe the chaos that ensues when AI agents don’t work together. But this shift is bigger than the keynote’s orchestra analogy suggested.
Governance has always run on a calendar: quarterly certifications, annual audits and reviews that arrive weeks after the fact. Artificial intelligence agents run on tool calls, and they make many of them. SailPoint’s bet is that the identity context it has spent 20 years building enables real-time enforcement, and that runtime-only security tools will struggle without it.
Here are my five thoughts that should matter to security and identity leaders:
The workforce is now mostly not human, and accountability is the problem
McClain opened by noting how quickly the enterprise’s composition has changed. “A few years ago, you knew exactly who was in your orchestra. It was your employees, your contractors, your partners. In short, people,” he said. “But today, there’s an invisible crowd operating right alongside them,” he added, describing service accounts, application programming interface keys and autonomous agents that, according to a study he cited, outnumber human identities 109 to one.
In his keynote, President Matt Mills made a key point. “An agent acts on behalf of a human or another agent that traces back to a human,” he said. “So, the moment you govern human and agent separately, you lose the thread of who’s actually accountable. We treat human and agent identity as one problem. It’s on one graph. It’s under one policy.”
This is a key part of SailPoint’s argument, and it’s why the company evolved Identity Security Cloud into two products, Agentic Fabric and Human Fabric, both built on its Atlas platform. Many newer agent-security startups treat agents as a standalone inventory problem.
But an agent without a human owner is just an orphaned account capable of reasoning. Criteo S.A. Director of Corporate Security Jérôme Robin, a SailPoint customer since 2021, did a great job explaining the problem: “Giving access to an agent for a task means delegating your business responsibility.” He concluded with a point every CISO should heed: “Technology should enforce the model, not replace it.”
Human-speed governance can’t keep up with machine-speed identities
Mills was very matter-of-fact about where legacy governance falls short. “You cannot fight AI-speed threats with human-speed governance,” he said. “Basic monitoring is not security. Simply watching an agent do bad things isn’t security. It’s just a dashboard that reports all your breaches to you.”
The numbers certainly support this thesis. Executive Vice President and Chief Technology Officer Chandra Gnanasambandam said SailPoint sees 75 million to 150 million agentic interactions per day at an average Global 2000 company. He added, “The idea that a security admin is going to review and approve access for a group of autonomous agents making 10,000 tool calls a second isn’t just outdated; it’s a fantasy.”
SailPoint’s fifth annual Horizons of Identity Security report, released at the event, found that 79% of organizations run AI agents in production, yet only 2% use identity security tools to govern them, and just 15% can provision non-human access in real time. CMO Wendy Wu concluded: “You cannot run an AI-speed enterprise with human-speed security.”
SailPoint’s answer is a set of Autonomous Agents: Red agents detect drift, blue agents analyze it and deprovision access, and green agents handle peacetime work, such as certifications. Gnanasambandam said the largest customers have certification campaigns with more than 10 million line items and 95% of those should be automated. The reality is that access reviews were broken for humans long before agents arrived. AI didn’t create the problem; it made it impossible to ignore.
Runtime controls without identity context are blunt instruments
If there was one statement from Gnanasambandam that buyers should focus on, it’s this one, aimed squarely at the runtime-first vendors: “An agent kill switch is supposed to kill the bad agents. If you’re a runtime control platform without context, and the kill switch can’t tell a good agent from a bad one, on what basis will it kill the bad agent?” he asked. “It’ll end up killing both good and bad agents.”
It’s a fair point. A kill switch that shuts down legitimate automation is one the business will make you turn off. The new capabilities support the argument.
Agentic Fabric adds shadow AI discovery, runtime authorization, prompt monitoring with policy-based redaction, and a one-click kill switch. Autonomous Identity Security Posture Management identifies dormant accounts, shadow admins and orphaned access, and acts on them rather than just reporting them. Entro Security, acquired earlier this year, adds credential lineage and exposed-secret discovery, with full integration expected in November.
Mills offered a data point highlighting the problem’s magnitude. In a Fortune 500 proof of concept, SailPoint surfaced more than 10,000 unknown agents within a week. Eric Burnett, director of identity and access management at University of Chicago Medical Center, acknowledged the same blind spot: “We know that there’s a lot of AI out there in our environment that we’re not aware of.”
Runtime vendors counter that identity platforms don’t sit in the traffic path. SailPoint knows this, which is why it’s integrating with network proxies, CrowdStrike Holdings Inc.’s Falcon marketplace, and data security tools such as BigID and Microsoft Purview. Whether context outweighs an inline position is the competitive question in this market, and buyers should test it rather than take either side at its word.
Standing privilege is the real enemy, and the hardest one to kill
“In a near-agentic world, standing privilege is dead,” Gnanasambandam said, noting that 98% of access today is standing privilege and that least privilege has been the goal for decades without ever being operationalized. Of all the news from the event, he called effective privilege the most interesting. Certifications review only directly granted entitlements, but much of a user’s real access comes indirectly through nested groups and service accounts.
“I call this the iceberg problem,” he said. “We got away with it because at human speed, no one knew. But at machine speed, these machines are able to find everything.” SailPoint is now using machine learning to model effective privilege for every identity and feed it into certifications.
The other practical change is conditional just-in-time provisioning for people, service accounts, and agents. Gnanasambandam described an agent that discovers mid-task that it lacks access and, rather than hunting for an exposed admin credential, requests access from its human owner, who grants it briefly and then revokes it. That’s the right thought process, but a partner reality check followed.
“I’m yet to meet one client in my entire career who has least privilege fully employed in their organization,” said Sanjeev Shukla, global lead for identity and trust at Accenture. He added that some tier-one banks that have spent hundreds of millions of dollars still have only about 65% privileged access coverage. Declaring standing privilege dead is easy. For most companies, getting there is a multiyear cleanup.
Stewardship matters as much as the shiny new thing
Mills spent much of his time telling the audience not to believe the hype, including SailPoint’s. He shared a Dallas-based Fortune 500 chief information officer’s description of the cybersecurity market as “full of vendors with big hats and no cattle.” “Demand proof over promise,” Mills said. “Make us and every vendor you meet show you the cattle.” In other words, don’t buy anything until you run a proof of concept and see the solution work.
That’s a great challenge for a vendor executive to make, and the first test is SailPoint’s installed base, much of which still runs IdentityIQ on-premises. The company announced IdentityIQ 9.0, featuring time-based access, a rebuilt foundation, an automated upgrade tool, a rebuilt Human Fabric certification engine, and proactive separation-of-duties checks. “Most vendors ask their customers to choose between a growth story or a stewardship story,” Gnanasambandam said in the announcement. “This is one modernization effort on two fronts.”
He also made two admissions that aren’t often heard on stage. SailPoint’s user experience has lagged its capabilities, and core roadmap items, such as certifications and separation of duties, needed to be pulled forward by two quarters. Agentic AI is the exciting story, but identity programs live or die on the basics, so fixing the blocking and tackling now will help SailPoint long term.
What this means for buyers
SailPoint made the case that identity is where agent accountability must live. Now it must prove it can enforce in real time, not just govern on a schedule. For information technology and security leaders, I’d focus on the following:
- Run discovery first. If one week turned up 10,000 unknown agents at a Fortune 500, assume your inventory is wrong.
- Assign a business owner to every agent. If no one is accountable for an agent’s actions, it shouldn’t have access.
- Test the kill switch in your own environment. Make any vendor, SailPoint included, show how it tells a good agent from a bad one using your data.
- Fix effective privilege for humans. Nested groups and overpermissioned service accounts are what agents inherit.
- Treat zero standing privilege as a program, not a product. Start with just-in-time access for the most sensitive systems, then expand.
McClain told the audience that SailPoint doesn’t write the music; its customers do. But for the first time, SailPoint is promising to stop the band mid-song if someone plays the wrong note. That’s a much harder job, and it’s the one customers should hold the company accountable for.
Zeus Kerravala is a principal analyst at ZK Research, a division of Kerravala Consulting. He wrote this article for SiliconANGLE.
