Identity governance faces a reckoning as AI agents proliferate across enterprises
SailPoint's Navigate conference will examine how organizations can govern autonomous AI agents that operate at machine speed, raising fundamental questions about access control and accountability in an era of non-human identities.

The emergence of autonomous AI agents is fundamentally reshaping how enterprises think about identity and access control. Unlike traditional employees and machine identities, AI agents can act independently on behalf of people, interact with applications and data, obtain permissions and complete tasks at speeds that outpace conventional governance models. This shift creates an urgent challenge: how can organizations determine what is acting within their systems and whether that entity should retain the authority it possesses?
According to Krista Case, principal analyst and practice lead for cyber resilience and security at theCUBE Research, "Agentic AI turns identity governance into an execution problem. Enterprises need to know who or what is acting, whose authority it carries, what it can reach and whether that authority should still apply as the task changes. Customers should evaluate identity platforms on how well they can maintain that context through the full lifecycle of an agent's work."
These concerns will take center stage at SailPoint's Navigate event, scheduled for October 5–8 in Austin, Texas. The conference, organized around the theme "AI, secured," will explore how identity security must evolve as organizations integrate AI agents into their existing populations of human and machine identities. SailPoint is positioning identity as a critical control mechanism for enterprise security in the age of autonomous systems.
TheCUBE will provide coverage on October 6–7, with Case and co-host Rebecca Knight conducting interviews with executives and identity security leaders about adaptive identity, agent lifecycle governance and the convergence of human, machine and AI agent identities as identity assumes a broader security role.
AI agents expose gaps in traditional identity governance
Conventional identity governance systems were designed around people, job roles and predictable access patterns. Autonomous agents disrupt this model because permissions are no longer static assignments subject to periodic review. Instead, agents execute tasks, communicate with other systems and adapt their actions as circumstances change.
The scale of this challenge is substantial. In recent analysis, Zeus Kerravala, principal analyst at ZK Research, cited SailPoint research indicating that 97% of AI agents have access to sensitive data, yet only 21% of organizations report high confidence in their ability to manage AI agent security risks. A SailPoint proof of concept at a Fortune 500 company uncovered more than 10,000 previously unknown AI agents operating within the organization.
Visibility represents the foundational problem. As Kerravala observed, "You can't govern what you can't see."
SailPoint is pushing the industry toward continuous security rather than periodic compliance reviews. Chandra Gnanasambandam, executive vice president of product and chief technology officer of SailPoint, stated in August that "We are moving the industry beyond static compliance and into an active, continuous security loop. By unifying the ability to discover every identity, govern access lifecycle policies and protect the enterprise through real-time risk remediation, we are giving security leaders the visibility and automation they need to confidently shut down modern attack vectors before they can be exploited."
Governance requires organizational change, not just technology
Finding agents is merely the starting point. Organizations must then determine ownership, identify required permissions and establish when those permissions should be revoked. Agents can accumulate privileges over time, spawn additional agents and leverage credentials across multiple applications and infrastructure components, amplifying the consequences of inadequate access controls.
Agent governance is fundamentally an organizational challenge as much as a technical one. Case emphasized that "The hardest part of agent governance is organizational. Agents can be created and deployed faster than traditional access processes can discover, assign ownership and govern them. Customers need an operating model that connects AI development, identity, security and the business before agent populations reach a scale where governance becomes a cleanup exercise."
As enterprises transition from isolated AI assistants to larger networks of task-focused autonomous agents, this organizational dimension will intensify. Identity teams will require closer collaboration with security operations, application development, AI engineering and business leadership to establish clear accountability before agents operate at scale.
Identity systems occupy a unique position because they supply context that runtime security tools alone cannot provide, according to Kerravala. Sandboxes and containment mechanisms can restrict what an agent does, but they cannot establish who created it, who bears responsibility for it or how long its access should remain valid. For this reason, Kerravala noted that "identity is the system of record everything else relies on."
Identity alone cannot serve as the sole control point
SailPoint is promoting identity as a central control mechanism as enterprises manage overlapping populations of human, machine and agent identities. The company's Navigate agenda reflects a broader industry movement toward positioning identity at the core of enterprise security as AI multiplies the entities requiring system access.
The proliferation of AI agents is expanding the attack surface available to adversaries. Mark McClain, founder and chief executive officer of SailPoint, stated that "The proliferation of AI agents is creating a new class of non-human identities, and each one represents a new attack surface. For AI to be a true business accelerant, it must be built on a foundation of security. Our collaboration with AWS is about providing that foundation. By building a unified identity plane, we believe we will give our joint customers the visibility and control they need to manage the complexity of an AI-driven ecosystem, allowing them to innovate boldly and securely."
However, identity does not function in isolation from the broader technology ecosystem. Case cautioned that "Organizations should be careful with claims that a single platform will become the control plane for agentic AI. Agent governance spans identity, runtime infrastructure, applications, data and security telemetry. The winning architecture will depend on strong integration and clear decision authority across those systems."
This distinction may emerge as one of the most consequential questions in enterprise agentic AI. Identity platforms may establish the record of what an agent is and what it should access, while runtime environments, security tools, applications and data systems provide complementary enforcement capabilities.
The critical challenge lies in connecting these systems with sufficient speed to govern autonomous actions while preserving the velocity and adaptability that make agents valuable. TheCUBE's reporting will examine how SailPoint and its customers navigate this balance as identity governance expands beyond the human workforce. Coverage will address how enterprises discover and classify AI agents, link them to accountable human sponsors, enforce least-privilege access and eliminate permissions when an agent's mission or function changes.
A related question concerns whether organizations can establish unified governance without forcing all identity types into a single operational model. Humans, service accounts, machines and AI agents exhibit distinct behaviors and risk profiles, even when they ultimately access the same applications and data.
SailPoint Navigate arrives as enterprises confront these questions in production environments. The shift toward autonomous systems reframes identity from a mechanism for verifying who logged in to a continuous process of determining who or what possesses authority to take action.
How to follow the coverage
TheCUBE will livestream coverage of SailPoint's Navigate event on October 6–7, with exclusive interviews and analysis available on-demand after the event concludes.
Coverage will be accessible through theCUBE's dedicated website and YouTube channel, with additional reporting available on SiliconANGLE. SiliconANGLE's "theCUBE Pod" is distributed on Apple Podcasts, Spotify and YouTube, featuring hosts John Furrier and Dave Vellante discussing major trends in enterprise technology including AI, cloud, cybersecurity and infrastructure. The outlet also produces "Breaking Analysis," a weekly program where Vellante examines significant developments in enterprise technology, available on Apple Podcasts, Spotify and YouTube.
TheCUBE will interview executives and identity security leaders from SailPoint, Amazon, Eastern Bank, HCLTech, Entro Security and other organizations about how enterprises are governing AI agents, protecting expanding identity populations and reconsidering access models as autonomous systems expand their role in business operations.