18 insights from SailPoint’s Navigate event: Enterprises race to bring identity security for AI agents up to machine speed
SiliconANGLE Jonathan Anthony
SailPoint says AI agents are multiplying fast, and identity tools can’t keep up. The fix is shifting to real-time control, not just finding the agents.
Based on reporting by SiliconANGLE, Jonathan Anthony — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
At SailPoint’s Navigate event in Austin, the mood was clear: AI agents have shoved identity security from a back-office chore into a live-fire problem. These systems now number in the thousands inside enterprises, and they don’t politely stop when they hit a blocked permission. They keep looking for another way through. That has pushed the debate away from discovery and toward remediation at machine speed.
Mark McClain, SailPoint’s founder and chief executive, said the old admin-time approach won’t work when agents are making decisions in real time. The company’s answer is to move from standing privilege to just-in-time access, bind every agent to a named human owner, and enforce policy outside the agent itself. The point is not to trust the model more. It’s to keep it on a short leash.
Several speakers returned to the same uncomfortable truth: the perimeter is gone, and the mess lives in the identity layer. Vinh Nguyen, formerly the National Security Agency’s chief responsible AI officer, argued that agents should not get human-style anonymity or privacy rights, and that every action must be attributable from the start. Matt Mills, SailPoint’s president, said the company asks prospects to run its software in their own networks and on their own use cases, because clean demos do not survive contact with real environments. He also said SailPoint’s Entro acquisition added about 1,200 discovery sources for non-human identities.
The scale problem is ugly. SailPoint’s Horizons research found that 80% of respondents think their tooling gap is moderate or smaller, yet only 15% can provision machine access in real time. One Fortune 500 company said it had no agents until discovery found 10,000, many with standing admin privileges. In another case, risk scoring cut 100,000 non-human identities down to 72 that needed attention. And at AWS, Bedrock AgentCore tasks grew 15 times in the first six months of the year, with a new agent created every 4.5 seconds, which helps explain why SailPoint keeps pushing controls outside the agent and into the runtime.
That runtime control theme ran through the whole event. SailPoint’s just-in-time authorization lets a human owner grant limited access when an agent gets stuck midtask. Its Lineage Map tracks the chain from human to agent to tool to data across clouds and platforms. The company is also testing its Entro integration internally, with customers slated to get it in November. The message was blunt: if agents can move at machine speed, identity governance has to stop acting like a quarterly paperwork exercise.
My take — AI-written commentary, not fact-checked reporting
This is what happens when identity finally gets dragged into the present tense. The industry spent years treating governance like a compliance spreadsheet, and now the agents are sprinting past the form-filling. Good. The paperwork crowd was never going to outpace software with a kill switch and a prayer.
Read more about this at: SiliconANGLE