CompaniesInvestorsPeople
Home
Loading

aVenture is in Beta: research coverage is expanding as we build, so please independently verify key details before making investment decisions.

aVenture is in Beta: research coverage is expanding as we build, so please independently verify key details before making investment decisions.

Get in Touch

  • Contact

  • Request a Demo

  • Request Data Updates

  • Add a Company

Research

  • Companies

  • Investors

  • People

aVenture

  • Download App

  • Pricing

Download the aVenture Research beta for iOS and iPadOSDownload aVenture Research on the Mac App Store

Resources

  • Documentation

  • Use Cases

  • CLI

  • MCP

  • Feature Requests

  • Sitemap

Member

Backed by

Ask AI about aVenture

© aVenture Investment Company, 2026. All rights reserved.

San Francisco, CA, USA

Privacy · Terms of Service

aVenture Investment Company ("aVenture") is an independent research platform providing detailed analysis and data on startups, venture capital investments, and key industry individuals. It is not a registered investment adviser, broker-dealer, or investment advisor and does not provide investment advice or recommendations. The data provided by aVenture does not constitute recommendations or advice, whether by methodology, analysis, AI-generated content, or a statement written by a staff member of aVenture.

aVenture is not affiliated with any of the people, companies, organizations, government agencies, regulatory bodies, or investment funds we provide coverage for on this site unless explicitly stated otherwise. Users assume full responsibility for decisions made based on information obtained from this platform. Links to external websites do not imply endorsement or affiliation with aVenture. Any links that provide the ability to invest in a primary or secondary transaction in a company are for convenience only and do not constitute solicitations or offers to buy or sell an investment. Investors should exercise heightened precaution and due diligence when investing in private companies, especially those not independently audited.

While we strive to provide valuable insights with objectivity and professional diligence, we cannot guarantee the accuracy of the information provided on our platform. Before making any investment decisions, you should verify the accuracy of all pertinent details for your decision. To the fullest extent permitted by law, aVenture shall not be liable for any direct, indirect, incidental, consequential, or financial damages arising from use of this site, whether by consumers of its contents directly or by persons or organizations covered by our research, even if we are advised of the possibility. Our best-efforts processes and correction request forms do not create a warranty or duty of care.

Profiles on this platform may include content generated in part by large language models (LLMs, artificial intelligence) that aggregate publicly available sources (e.g., SEC EDGAR, public filings, press releases). Source attribution is provided where known; always verify statements and claims here against original sources before relying on any data. Content on our site may contain inaccuracies, omissions, or what are commonly called 'hallucinations' if generated in part or in full by AI / LLMs. The risk can also exist even when content is written by a human, as internal and third-party sources may also have inaccuracies for the same or different reasons. While we randomly audit a proportion of content, this is not exhaustive.

We recommend that an independent auditor be hired to verify the accuracy of the information before relying on it for any sensitive decisions. By accessing this platform, you agree not to rely solely on any information generated by AI, aggregated, or sourced or written otherwise on this site, for investment, financial, or other decisions. aVenture assumes no responsibility for inaccuracies, omissions, or hallucinations. You must independently verify all data from primary sources. Use of this platform constitutes your waiver of claims for reliance-based damages, including negligent misrepresentation. To report an error, request a correction, or dispute information about a company or individual, contact us via our request data updates form.

Loading
Loading
Home
News
18 insights from SailPoint’s Navigate event: Enterprises race to bring identity security for AI agents up to machine speed

From SiliconANGLE

By Jonathan Anthony

October 9, 2026

18 insights from SailPoint’s Navigate event: Enterprises race to bring identity security for AI agents up to machine speed

18 insights from SailPoint’s Navigate event: Enterprises race to bring identity security for AI agents up to machine speed

AI agents have made identity the front line of enterprise security. Agents now number in the thousands. They pick up access nobody meant to give them, and when they’re blocked partway through a task, they look for another way in. That has turned identity security for AI agents into a board-level priority rather than a future project.

The focus has moved from finding agents to acting on what discovery turns up. The next phase will be about remediation at machine speed: just-in-time access instead of standing privilege, a named human owner for every agent and enforcement that sits outside the agent itself.

“We need administrative, we need good compliance controls, but the real issue now … is how do you secure all these identities?” said Mark McClain (pictured), founder and chief executive officer of SailPoint Technologies Inc. “It took a very small amount of analysis for our technical team to go, ‘We can’t do this effectively in quote admin time.’ We have to be in the real-time decision-making cycle of, ‘Is this agent with its context and its intent doing what we expect?'”

McClain and other industry experts spoke to theCUBE Research’s Krista Case and co-host Rebecca Knight during SailPoint’s Navigate event, the company’s annual conference in Austin, Texas. The interviews covered identity security for AI agents, zero standing privilege, the Entro Security acquisition, the AgentCore partnership with AWS and the standards needed to hold agents accountable. (* Disclosure below.)

Here are 18 standout insights from the event:

1. Orchestrating human and AI agents demands real context and effective identity, not just big claims.

Machine identities have climbed to 109 for every human, highlighting the need for effective identity that maps access paths so autonomous guardrails can enforce the right policies in real time, explained hosts Case and Knight in their analysis of the SailPoint Navigate keynote. The practical middle path is SailPoint’s Autonomous Identity approach that sits between rigid kill switches and unconstrained innovation. Buyers should test vendors on messy, nested access paths rather than clean demos.

See theCUBE’s full coverage.

2. Identity rises to prominence as the castle-and-moat model breaks down.

The old perimeter defense no longer holds, so organizations must know who every user or agent is and whether it is doing what it should, McClain explained. No enterprise agent truly operates on its own. The link between humans and agents and a real-time understanding of intent are central to stopping inappropriate actions.

Check out theCUBE’s complete interview.

3. Agents require attribution and identity binding, not human-style anonymity or simple kill switches.

Enterprises should apply national-security thinking by prioritizing threats, vulnerabilities and consequences rather than chasing infinite risk reduction, according to Vinh Nguyen, former chief responsible AI officer for the National Security Agency and senior fellow for the Council on Foreign Relations. AI agents must not inherit the anonymity or privacy rights of humans and every action needs to be attributable to a human owner or organization from the outset. Kill switches alone are inadequate.

Catch the full conversation on theCUBE.

4. Proofs of concept in customer environments separate real agent security from marketing claims.

SailPoint asks prospects to run its software on their own networks, data and use cases, which quickly shows which providers can actually deliver, explained Matt Mills, president of SailPoint. The Entro acquisition added about 1,200 discovery sources for non-human identities, he noted. The main obstacle to letting AI fix problems on its own is getting auditors and regulators comfortable, not the technology.

Watch the full interview from theCUBE.

5. AWS moves agent controls outside the agent as AgentCore usage grows 15-fold.

Tasks on Amazon Bedrock AgentCore grew 15 times over in the first six months of the year, and a new agent is created every 4.5 seconds, according to Madhu Parthasarathy, general manager of Bedrock AgentCore at Amazon Web Services Inc. Because agents will go to any length to finish a task, policies have to be enforced outside the agent through AgentCore Gateway. SailPoint generates those policies from agent observability data.

See theCUBE’s full coverage.

6. Just-in-time authorization teaches agents to ask permission instead of hacking systems.

Agents most often go rogue when they hit a missing permission midtask and find a way to break in, emphasized Chandra Gnanasambandam, chief technology officer of SailPoint. To stop that, SailPoint is introducing just-in-time authorization, which lets a human owner grant access for a limited time. Its Lineage Map records the full chain from human to agent to tool to data, across clouds and platforms.

Don’t miss the full interview on theCUBE.

7. A burning platform gives identity teams the opening to fund long-overdue programs.

Years of accumulated identity debt mean organizations cannot sandbox their way out of AI agent risk, highlighted Cole Grolmus, founder of Grolmus Group LLC, which does business as Strategy of Security. Practitioners should use the urgency to win funding and get the organization aligned. He sees SailPoint’s push into runtime enforcement across such a large, complex customer base as what market leadership looks like.

Hear the full story on theCUBE.

8. Horizons research exposes a velocity paradox in agentic identity maturity.

In SailPoint’s Horizons of Identity Security research, 80% of respondents think their tooling gap is moderate or smaller, yet only 15% can provision machine access in real time, described Wendy Wu, chief marketing officer of SailPoint. Companies took five years to mature human identity, but they need to do the same for agents in a year or less, she added, governing humans and agents together.

Catch the complete conversation on theCUBE.

9. Customers uncover thousands of hidden agents and turn to automated ownership.

One Fortune 500 company insisted it had no agents until discovery turned up 10,000, many with standing admin privileges, shared Meredith Blanchar, chief customer officer of SailPoint. She was joined by Karen Leavitt, assistant vice president of information technology security at Unum Group, and Jakob Houde, director of cybersecurity at Honeywell International Inc. Unum set up discovery of its Bedrock and Copilot agents within two weeks to gain a kill switch.

Watch theCUBE’s full sit-down.

10. Production scans shrink 100,000 non-human identities to 72 that matter.

Every agent action ultimately uses a credential, token or data access point, so securing the underlying non-human identity matters more than labeling the agent, noted Jeff Hickman, senior vice president of sales engineering at SailPoint. Production proofs of concept find orphaned or overprivileged access within hours every time. In one case, risk scoring narrowed 100,000 non-human identities down to 72 that needed attention.

Explore theCUBE’s in-depth discussion.

11. Exposed credentials, not rogue AI, sit behind the latest agent breaches.

The latest AI-driven attacks all come down to an exposed credential that an agent found and used to log in, explained Itzik Alvas, co-founder and chief executive officer of Entro Security Ltd., which SailPoint acquired in June. Entro connects human and non-human identities under a single policy. A sub-agent should never hold more permissions than the agent that invoked it.

Don’t miss the full segment on theCUBE.

12. Partners become essential as demand for proofs of concept outruns plans.

SailPoint has already exceeded the number of proofs of concept it planned for the year, which makes enabling partners more important than ever, according to Chris Gossett, chief growth officer of SailPoint. Customers now want help finding shadow AI, deciding what a kill switch should mean and keeping up with business teams that are deploying agents.

Check out theCUBE’s complete interview.

13. Autonomous identity fights machine-speed attacks with machine-speed governance.

In one recent incident, an agent reached cluster admin access in under a second by running 14,000 actions and coordinating with other agents, emphasized Levent Besik, chief product officer of SailPoint. That is why SailPoint is building level 2 through level 4 autonomous agents for governance, earning customer trust step by step. The Entro integration is in limited internal testing, and customers are slated to get it in November.

Watch the full interview from theCUBE.

14. An agentic accelerator promises outcomes in hours, not weeks.

Agentic AI has ended identity’s status as a second-class citizen by pushing a fragmented market toward platforms, observed Will Townsend, chief analyst of Lonestar Advisory. He singled out SailPoint’s Agentic Accelerator, which the company says has taken some Fortune 50 customers from deployment to outcome in less than a day. He urged SailPoint to offer it beyond global systems integrators.

See theCUBE’s full coverage.

15. Zero standing privilege starts with the most sensitive entitlements.

Short-lived agent access that keeps piling up makes ending always-on privilege more urgent than ever, highlighted Lori Robinson, vice president of product management at SailPoint. The practical path is crawl, walk, run, starting with the riskiest entitlements. At one customer, auditors agreed that just-in-time access lasting less than the certification cycle no longer needed quarterly certification.

Don’t miss the full interview on theCUBE.

16. Mission-tagged agents create both an audit trail and a kill switch.

Agents need something like a driver’s license and rules of the road rather than walls, according to Mike Kiser, director of strategy and standards at SailPoint. Accountability across chains of sub-agents remains one of identity’s great unsolved problems. Tagging every downstream call with a declared mission explains why each action happened and lets an organization stop all of them at once.

Hear the full story on theCUBE.

17. Clear definitions cut through the AI jargon reshaping identity security.

Research from Palo Alto Networks Inc. puts non-human identities at 109 for every human, with service accounts making up 79% and agents much of the rest, pointed out Jaishree Subramania, senior vice president of product marketing at SailPoint. She defines an agent as a model plus a harness plus an identity. Governance for agents that run in loops has to be continuous rather than quarterly.

Catch the complete conversation on theCUBE.

18. Agents require continuous behavioral evidence, clear ownership and prevention over simple kill switches.

Agents require strict verification including behavior history, ongoing monitoring and independent evaluation of actions, according to Case and Knight in their day 2 analysis at SailPoint Navigate. Half of discovered agents still lack a known owner, and the nature of agents discovering their own tools and calling other agents creates a constantly shifting execution path that demands runtime controls. The kill switch only contains symptoms without addressing root causes.

Check out the full segment on theCUBE.

Here’s more of SiliconANGLE’s and theCUBE’s coverage of SailPoint’s Navigate event:

(* Disclosure: TheCUBE is a paid media partner for SailPoint’s Navigate event. Neither SailPoint, the sponsor of theCUBE’s event coverage, nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)

Photo: SiliconANGLE

View original article on siliconangle.com

Most Recent

OpenAI revenue falls short, models play hopscotch and Trump cracks down on tech green cards

I’m not going to call the bursting of artificial intelligence bubble yet, not with all that money still pouring into every hardware and software company with AI in their pitch decks. But we got a little taste this week. OpenAI told investors this week that it actually had $18 billion less revenue th

Oct 9, 2026

Gallatin AI raises $50M in funding for its military logistics platform

Gallatin AI Inc., a developer of military logistics software, today announced that it has raised $50 million in funding. The Series A round included contributions from 8VC, Silent Ventures and several others. It follows a $15 million seed raise in 2024. El Segundo, California-based Gallatin has buil

Oct 8, 2026

Rocket fuel: Seattle-area startups raise a record $3.5B as national VC funding cools

Seattle-area startups raised $3.5 billion in venture capital in the third quarter, the most in any quarter going back at least a decade, led by big rounds for Kent-based rocket maker Stoke Space, Bellevue developer platform Temporal and Everett fusion company Helion. That’s more than triple the $1 b

Oct 8, 2026

Overland AI unveils IBEX, a new autonomous ground vehicle selected by the Marine Corps

Seattle defense startup Overland AI has unveiled IBEX, a new fully autonomous ground vehicle selected by the U.S. Marine Corps to support counter-drone air defense operations and execute high-risk frontline missions, including resupply, breaching, and electronic warfare. IBEX was developed under a D

Oct 8, 2026

Similar Posts

What to expect at SailPoint’s Navigate event: Join theCUBE Oct. 6–7

AI agents are reshaping identity security. See what to expect from SailPoint Navigate 2026 and theCUBE’s Oct. 6–7 coverage.

Oct 4, 2026

In the agentic era, standing privilege must go: Key thoughts from the SailPoint Navigate keynote

For most of its two-decade history, SailPoint Inc. has been the company that tells enterprises who should have access to what. At Navigate 2026 in Austin this week, it argued that it now needs to be the company that stops the wrong access the moment it happens. The keynote opened with an orchestra t

Oct 6, 2026

In the AI era, identity evolves into the control plane for trust

Every major security shift ultimately comes down to one question: Who or what is allowed to do this? For most of the past two decades, the answer was a person with a username and password. In the artificial intelligence era, the answer increasingly is an agent, and most organizations have no idea ho

Sep 29, 2026

Identity and permissions aren’t enough to govern AI agent behavior

Presented by BoxIdentity and permissions are no longer enough to secure enterprise AI agents. They govern what an agent can reach, not how it behaves once it starts working on its own, and an autonomous agent can turn legitimate access of enterprise data into unintended action in seconds. That gap i

Aug 31, 2026