18 insights from SailPoint’s Navigate event: Enterprises race to bring identity security for AI agents up to machine speed
AI agents have made identity the front line of enterprise security. Agents now number in the thousands. They pick up access nobody meant to give them, and when they’re blocked partway through a task, they look for another way in. That has turned identity security for AI agents into a board-level priority rather than a future project.
The focus has moved from finding agents to acting on what discovery turns up. The next phase will be about remediation at machine speed: just-in-time access instead of standing privilege, a named human owner for every agent and enforcement that sits outside the agent itself.
“We need administrative, we need good compliance controls, but the real issue now … is how do you secure all these identities?” said Mark McClain (pictured), founder and chief executive officer of SailPoint Technologies Inc. “It took a very small amount of analysis for our technical team to go, ‘We can’t do this effectively in quote admin time.’ We have to be in the real-time decision-making cycle of, ‘Is this agent with its context and its intent doing what we expect?'”
McClain and other industry experts spoke to theCUBE Research’s Krista Case and co-host Rebecca Knight during SailPoint’s Navigate event, the company’s annual conference in Austin, Texas. The interviews covered identity security for AI agents, zero standing privilege, the Entro Security acquisition, the AgentCore partnership with AWS and the standards needed to hold agents accountable. (* Disclosure below.)
Here are 18 standout insights from the event:
1. Orchestrating human and AI agents demands real context and effective identity, not just big claims.
Machine identities have climbed to 109 for every human, highlighting the need for effective identity that maps access paths so autonomous guardrails can enforce the right policies in real time, Case and Knight explained in their analysis of the SailPoint Navigate keynote. The practical middle path is SailPoint’s Autonomous Identity approach that sits between rigid kill switches and unconstrained innovation. Buyers should test vendors on messy, nested access paths rather than clean demos.
See theCUBE’s full coverage.
2. Identity rises to prominence as the castle-and-moat model breaks down.
The old perimeter defense no longer holds, so organizations must know who every user or agent is and whether it is doing what it should, McClain explained. No enterprise agent truly operates on its own. The link between humans and agents and a real-time understanding of intent are central to stopping inappropriate actions.
Check out theCUBE’s complete interview.
3. Agents require attribution and identity binding, not human-style anonymity or simple kill switches.
Enterprises should apply national-security thinking by prioritizing threats, vulnerabilities and consequences rather than chasing infinite risk reduction, according to Vinh Nguyen, former chief responsible AI officer for the National Security Agency and senior fellow for the Council on Foreign Relations. AI agents must not inherit the anonymity or privacy rights of humans and every action needs to be attributable to a human owner or organization from the outset. Kill switches alone are inadequate.
Catch the full conversation on theCUBE.
4. Proofs of concept in customer environments separate real agent security from marketing claims.
SailPoint asks prospects to run its software on their own networks, data and use cases, which quickly shows which providers can actually deliver, explained Matt Mills, president of SailPoint. The Entro acquisition added about 1,200 discovery sources for non-human identities, he noted. The main obstacle to letting AI fix problems on its own is getting auditors and regulators comfortable, not the technology.
Watch the full interview from theCUBE.
5. AWS moves agent controls outside the agent as AgentCore usage grows 15-fold.
Tasks on Amazon Bedrock AgentCore grew 15 times over in the first six months of the year, and a new agent is created every 4.5 seconds, according to Madhu Parthasarathy, general manager of Bedrock AgentCore at Amazon Web Services Inc. Because agents will go to any length to finish a task, policies have to be enforced outside the agent through AgentCore Gateway. SailPoint generates those policies from agent observability data.
See theCUBE’s full coverage.
6. Just-in-time authorization teaches agents to ask permission instead of hacking systems.
Agents most often go rogue when they hit a missing permission midtask and find a way to break in, emphasized Chandra Gnanasambandam, chief technology officer of SailPoint. To stop that, SailPoint is introducing just-in-time authorization, which lets a human owner grant access for a limited time. Its Lineage Map records the full chain from human to agent to tool to data, across clouds and platforms.
Don’t miss the full interview on theCUBE.
7. A burning platform gives identity teams the opening to fund long-overdue programs.
Years of accumulated identity debt mean organizations cannot sandbox their way out of AI agent risk, highlighted Cole Grolmus, founder of Grolmus Group LLC, which does business as Strategy of Security. Practitioners should use the urgency to win funding and get the organization aligned. He sees SailPoint’s push into runtime enforcement across such a large, complex customer base as what market leadership looks like.
Hear the full story on theCUBE.
8. Horizons research exposes a velocity paradox in agentic identity maturity.
In SailPoint’s Horizons of Identity Security research, 80% of respondents think their tooling gap is moderate or smaller, yet only 15% can provision machine access in real time, described Wendy Wu, chief marketing officer of SailPoint. Companies took five years to mature human identity, but they need to do the same for agents in a year or less, she added, governing humans and agents together.
Catch the complete conversation on theCUBE.
9. Customers uncover thousands of hidden agents and turn to automated ownership.
One Fortune 500 company insisted it had no agents until discovery turned up 10,000, many with standing admin privileges, shared Meredith Blanchar, chief customer officer of SailPoint. She was joined by Karen Leavitt, assistant vice president of information technology security at Unum Group, and Jakob Houde, director of cybersecurity at Honeywell International Inc. Unum set up discovery of its Bedrock and Copilot agents within two weeks to gain a kill switch.
Watch theCUBE’s full sit-down.
10. Production scans shrink 100,000 non-human identities to 72 that matter.
Every agent action ultimately uses a credential, token or data access point, so securing the underlying non-human identity matters more than labeling the agent, noted Jeff Hickman, senior VP of sales engineering at SailPoint. Production proofs of concept find orphaned or overprivileged access within hours every time. In one case, risk scoring narrowed 100,000 non-human identities down to 72 that needed attention.
Explore theCUBE’s in-depth discussion.
11. Exposed credentials, not rogue AI, sit behind the latest agent breaches.
The latest AI-driven attacks all come down to an exposed credential that an agent found and used to log in, explained Itzik Alvas, co-founder and chief executive officer of Entro Security Ltd., which SailPoint acquired in June. Entro connects human and non-human identities under a single policy. A sub-agent should never hold more permissions than the agent that invoked it.
Don’t miss the full segment on theCUBE.
12. Partners become essential as demand for proofs of concept outruns plans.
SailPoint has already exceeded the number of proofs of concept it planned for the year, which makes enabling partners more important than ever, according to Chris Gossett, chief growth officer of SailPoint. Customers now want help finding shadow AI, deciding what a kill switch should mean and keeping up with business teams that are deploying agents.
Check out theCUBE’s complete interview.
13. Autonomous identity fights machine-speed attacks with machine-speed governance.
In one recent incident, an agent reached cluster admin access in under a second by running 14,000 actions and coordinating with other agents, emphasized Levent Besik, chief product officer of SailPoint. That is why SailPoint is building level 2 through level 4 autonomous agents for governance, earning customer trust step by step. The Entro integration is in limited internal testing, and customers are slated to get it in November.
Watch the full interview from theCUBE.
14. An agentic accelerator promises outcomes in hours, not weeks.
Agentic AI has ended identity’s status as a second-class citizen by pushing a fragmented market toward platforms, observed Will Townsend, chief analyst of Lonestar Advisory. He singled out SailPoint’s Agentic Accelerator, which the company says has taken some Fortune 50 customers from deployment to outcome in less than a day. He urged SailPoint to offer it beyond global systems integrators.
See theCUBE’s full coverage.
15. Zero standing privilege starts with the most sensitive entitlements.
Short-lived agent access that keeps piling up makes ending always-on privilege more urgent than ever, highlighted Lori Robinson, VP of product management at SailPoint. The practical path is crawl, walk, run, starting with the riskiest entitlements. At one customer, auditors agreed that just-in-time access lasting less than the certification cycle no longer needed quarterly certification.
Don’t miss the full interview on theCUBE.
16. Mission-tagged agents create both an audit trail and a kill switch.
Agents need something like a driver’s license and rules of the road rather than walls, according to Mike Kiser, director of strategy and standards at SailPoint. Accountability across chains of sub-agents remains one of identity’s great unsolved problems. Tagging every downstream call with a declared mission explains why each action happened and lets an organization stop all of them at once.
Hear the full story on theCUBE.
17. Clear definitions cut through the AI jargon reshaping identity security.
Research from Palo Alto Networks Inc. puts non-human identities at 109 for every human, with service accounts making up 79% and agents much of the rest, pointed out Jaishree Subramania, SVP of product marketing at SailPoint. She defines an agent as a model plus a harness plus an identity. Governance for agents that run in loops has to be continuous rather than quarterly.
Catch the complete conversation on theCUBE.
18. Agents require continuous behavioral evidence, clear ownership and prevention over simple kill switches.
Agents require strict verification including behavior history, ongoing monitoring and independent evaluation of actions, according to Case and Knight in their day 2 analysis at SailPoint Navigate. Half of discovered agents still lack a known owner, and the nature of agents discovering their own tools and calling other agents creates a constantly shifting execution path that demands runtime controls. The kill switch only contains symptoms without addressing root causes.
Check out the full segment on theCUBE.
Here’s more of SiliconANGLE’s and theCUBE’s coverage of SailPoint’s Navigate event:
(* Disclosure: TheCUBE is a paid media partner for SailPoint’s Navigate event. Neither SailPoint, the sponsor of theCUBE’s event coverage, nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)
Photo: SiliconANGLE
A message from John Furrier, co-founder of SiliconANGLE:
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
- 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
- 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network
Are you an AWS customer? Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: https://siliconangle.com/aws-marketplace/
About SiliconANGLE Media
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.