Security2 publishers3 min readPublished
Orchid ships drift detection and a kill switch for agents that inherit unmanaged identity
The new controls compare an agent's runtime behaviour against its authorized scope and can revoke the credentials underneath it. The 57% unmanaged-identity figure behind the pitch is Orchid's own, and neither publisher gives the method.
The Watch · Security desk

What happened
- Orchid Security added identity drift detection and application-level kill switches to its Identity Control Plane, so a team can revoke an agent's authority when its behaviour leaves approved parameters.
- The mechanism Orchid describes is inheritance: agents locate hard-coded credentials, orphaned accounts, unmanaged authentication paths and excessive permissions, and exceed intended scope without breaking a control.
- The platform now tags applications, identities and access paths with an AI readiness status, flags risky accounts, and monitors agent behaviour continuously for drift.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint Containment work moves out of the directory and into individual applications: if only about a third of nonhuman accounts are visible to standard IAM, the other two thirds are revoked by whoever owns the app.
- exposure The accounts at issue are reachable today by anyone who already holds that access. Agent programmes change how fast the route gets used, not whether it exists.
- contradiction Two publishers carry the same vendor survey in different words, one as a percentage and one as a ratio, and neither gives sample or method, so a buyer cannot check the size of the gap being priced.
- decision With boards asking how fast AI can scale, what a security team is deciding is sequencing: the account inventory has to come first, because the kill switch needs something enumerated to cut.
No CVE and no incident, and nothing here carries a patch deadline. What the announcement describes is a mechanism, and the mechanism is old: hard-coded credentials, orphaned accounts, unmanaged authentication paths and excessive permissions [4]. Anyone who has run an access review has met those accounts, and an agent is a new consumer of them.
The figure carrying the pitch is the vendor's own. Orchid's Identity Gap 2026 report puts 57% of enterprise identity as unseen and unmanaged [5]. SC World, citing Silicon Angle, reports the same survey finding that invisible identities outnumber visible ones, with two-thirds of nonhuman accounts provisioned inside applications and beyond the reach of standard identity and access management tools [6]. At 57% unseen against 43% managed, that is roughly 1.3 unmanaged identities for every managed one [7]. Neither publisher gives a sample size, a sector split, or how "unseen" was counted.
The two-thirds number is the operationally useful one. If two-thirds of nonhuman accounts live inside applications, about one third sits where a directory-level revocation can reach it [8]. That is the gap the application-level kill switch is aimed at [1].
Orchid says agents can turn unmanaged identity into an active path to elevated access in seconds to minutes, faster than periodic governance reviews can detect or contain it [11], and that agents can complete authorized objectives beyond their initial privilege level within seconds [3]. Neither source cites telemetry, logs, or a case behind those intervals [18].
"AI transformation is exciting. Identity hygiene is not," said Roy Katmor, CEO of Orchid Security [9]. Enterprises, he said, need to "observe how agents act, understand when they drift, and govern them immediately, including terminating the authority through which they operate" [10].
The regulatory hooks in the announcement are general. NIST's draft Cyber AI Profile says that "regardless of where organizations are on their AI journey, their cybersecurity programs need risk management approaches that support and integrate the realities of advancements in AI" [15]. On Europe, the announcement's reading of DORA is that financial entities must demonstrate control over ICT access and third-party dependencies, and that the obligation does not pause when the actor is an agent [16].
Orchid's own precondition list is the part a defender can act on without buying anything: every orphaned, dormant, local and over-privileged account identified and assigned a readiness status before autonomous agents are deployed at scale [19]. That is an access review. It has to exist before a kill switch has anything to cut.
The response actions Orchid lists run from reducing permissions and revoking credentials to disconnecting tools and suspending workflows, with the application-level kill switch as the terminal option [12]. Integrations with Palo Alto Networks' Idira and Splunk Enterprise Security are available, according to SC World [14]. The capabilities follow agentic enhancements Orchid made to its Identity Control Plane in May [20].
What to watch
- Whether Orchid publishes the Identity Gap 2026 methodology: sample size, sector split, and how an identity was counted as unseen.
- A documented case, with logs, of an AI agent using an orphaned or application-local account to escalate, filed by a responder.
- Whether NIST's Cyber AI Profile leaves draft with agent-specific identity requirements, and whether DORA supervisors start asking financial entities for agent delegation chains.