SecurityAlso reported elsewhere2 publishers2 min readPublished
SailPoint extends identity controls to AI agents, with open questions on runtime authorization
SailPoint announced conditional just-in-time access, agent discovery and an agent kill switch at its Navigate conference in Austin. Futurum's analyst calls the bet well positioned but flags runtime authorization and agent coverage as open.
The Watch · Security desk

In-house agents: SailPoint's controls bind most tightly (Futurum). Agents working for a person: fail in different ways. Buyers: test on messy, nested access paths; SailPoint asks prospects to run it on their own networks. IAM teams: pulled closer to application development.
- capability In-house agents Futurum says SailPoint's authority controls bind most tightly to agents built in-house, claim 10
- constraint Agents that work for a person Futurum says these, and agents that come with an application, fail in different ways, claim 10
- decision Buyers evaluating vendors Told to test on messy, nested access paths; SailPoint asks prospects to run it on their own networks, data and use cases, claim 16
- constraint IAM teams An agent's right scope depends on what it is for, which pulls IAM teams closer to application development, claim 11
| Who | How | Kind | Claim |
|---|---|---|---|
| In-house agents | Futurum says SailPoint's authority controls bind most tightly to agents built in-house | capability | 10 |
| Agents that work for a person | Futurum says these, and agents that come with an application, fail in different ways | constraint | 10 |
| Buyers evaluating vendors | Told to test on messy, nested access paths; SailPoint asks prospects to run it on their own networks, data and use cases | decision | 16 |
| IAM teams | An agent's right scope depends on what it is for, which pulls IAM teams closer to application development | constraint | 11 |
What happened
- Agentic Fabric finds AI agents, MCP servers and credentials through endpoint and browser sensors, SIEM and XDR telemetry, and vault and pipeline scanning.
- Conditional just-in-time provisioning extends zero standing privilege to people and service accounts as well as AI agents.
- On the on-premises side, IdentityIQ 9.0 gets time-based access to roles and entitlements, a technical foundation that has been rebuilt, and a tool that automates upgrades.
- Rollout begins at Navigate. A-ISPM, the Harbor Pilot Policy Agent and a Proofpoint integration are due between November 2026 and January 2027.
- In Futurum's 1H 2026 survey of 904 decision-makers, 38% ranked upgrading IAM and PAM for the non-human identities agents use among their top three AI security priorities.
Why it matters
- exposure Agents a company builds itself get the tightest binding. Coding assistants and AI browsers, which Futurum counts as agents that work for a person, sit outside that and fail in different ways.
- constraint Futurum says the kill switch targets a session, not the actor, and SiliconANGLE's account of Vinh Nguyen's remarks says kill switches alone are inadequate. A containment plan needs a step that acts on the agent's identity.
- decision Theatre analysts Case and Knight tell buyers to test vendors on messy, nested access paths, not clean demos. SailPoint says its own proofs of concept run on the prospect's networks, data and use cases, so the test can be set by the buyer.
Futurum's note mentions runtime authorization twice. It is listed among the Agentic Fabric additions, next to prompt monitoring, one-click lifecycle controls, the kill switch and Agent Audit [4]. Futurum's summary also names it as an open question, along with which agents' identities the controls reach [12]. It does not say what is unresolved. We think the two doubts are one: the feature exists, and the open point is how far it extends.
Futurum says an agent's right scope depends on what it is for. That pulls IAM teams closer to application development [11]. Volume makes that hard. Madhu Parthasarathy, general manager of Bedrock AgentCore at AWS, said a new agent is created every 4.5 seconds on that platform, and that tasks there grew 15 times in the first six months of the year [14]. At that rate AgentCore sees 800 new agents an hour [19]. SailPoint chief executive Mark McClain said: "It took a very small amount of analysis for our technical team to go, 'We can't do this effectively in quote admin time.'" [13]
SailPoint's answer to the volume is enforcement outside the agent. According to SiliconANGLE's account of Parthasarathy's remarks, policies must be enforced outside the agent through AgentCore Gateway, and SailPoint generates those policies from agent observability data [15]. SiliconANGLE states the risk plainly: agents pick up access nobody meant to give them, and when blocked partway through a task they look for another way in [1].
The Horizons figures, 79% running agents in production and 2% with identity tooling built for them, are SailPoint's own. Futurum calls them vendor-sourced [9]. The figure of 109 machine identities for every human comes from theCUBE Research's Krista Case and co-host Rebecca Knight, in their analysis of the keynote [22].
What to watch
- Delivery of A-ISPM, the Harbor Pilot Policy Agent and the Proofpoint integration inside the window SailPoint gave.
- Any detail from SailPoint or Futurum on how runtime authorization applies to agents that work for a person or arrive with an application.
- Whether auditors and regulators accept automated remediation, which SailPoint president Matt Mills named as the main obstacle to letting AI fix problems on its own.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+20
- Incentives55
- Confidence62
Perspective Coverage
3 publishers- Builder
- Builder 25%
- Operator
- Operator 53%
- Investor
- Investor 22%
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Agents pick up access nobody meant to give them, and when blocked partway through a task they look for another way in.
- [2]
At its Navigate 2026 conference in Austin, SailPoint announced updates across SailPoint Agentic Fabric and SailPoint Human Fabric, both built on the SailPoint Atlas platform.
- [3]
Agentic Fabric adds discovery of AI agents, Model Context Protocol servers and credentials through endpoint and browser sensors, SIEM, XDR telemetry, and vault and pipeline scanning.
- [4]
Agentic Fabric also adds prompt monitoring, runtime authorization, one-click lifecycle controls, an agent kill switch, and Agent Audit, which exports framework-aligned evidence reports.
- [5]
Conditional just-in-time provisioning extends zero standing privilege to people, service accounts, and AI agents.
- [6]
IdentityIQ 9.0, the on-premises product, adds time-based access for roles and entitlements, a rebuilt technical foundation, and an automated upgrade tool.
- [7]
Capabilities roll out starting at Navigate; A-ISPM, the Harbor Pilot Policy Agent and a Proofpoint integration are expected in Q4 of fiscal 2027, between November 2026 and January 2027.
- [8]
In the Futurum 1H 2026 Cybersecurity Decision-Makers Survey (N=904), 38% of respondents ranked upgrading IAM and PAM to govern the non-human identities used by AI agents among their top three priorities for architecting and funding AI security over the next 12 to 18 months.
- [9]
SailPoint's Horizons figure of 79% running agents in production and 2% with identity tooling built for them is vendor-sourced, according to Futurum.
- [10]
Futurum sorts agents into three families by who decides what the agent is for; SailPoint's authority controls bind most tightly to agents built in-house, while agents that work for a person or come with an application fail in different ways.
- [11]
An agent's right scope depends on what it is for, which pulls IAM teams closer to application development.
- [12]
Futurum's summary names runtime authorization, and which agents' identities the controls reach, as open questions on an otherwise well-positioned bet.
- [13]
Mark McClain, founder and CEO of SailPoint, said: "It took a very small amount of analysis for our technical team to go, 'We can't do this effectively in quote admin time.'"
- [14]
Tasks on Amazon Bedrock AgentCore grew 15 times over in the first six months of the year, and a new agent is created every 4.5 seconds.
ReportedSupportedSource: Madhu Parthasarathy, general manager of Bedrock AgentCore at AWS, per SiliconANGLEView cited source - [15]
Policies have to be enforced outside the agent through AgentCore Gateway, and SailPoint generates those policies from agent observability data.
- [16]
Case and Knight advise buyers to test vendors on messy, nested access paths rather than clean demos; SailPoint asks prospects to run its software on their own networks, data and use cases.
ReportedSupportedSource: theCUBE Research's Krista Case and Rebecca Knight; SailPoint president Matt Mills, per SiliconANGLEView cited source - [17]
Futurum's examples of agents that work for a person are a coding assistant and an AI browser.
- [18]
The main obstacle to letting AI fix problems on its own is getting auditors and regulators comfortable, not the technology, Matt Mills, president of SailPoint, said.
- [19]
At one new agent every 4.5 seconds, AgentCore sees 800 new agents an hour.
- [20]
Futurum lists as contested ground that a kill switch targets a session rather than the actor.
ReportedContestedSource: Futurum Group2 sources— create a free account to open themView cited source - [21]
In SiliconANGLE's account of remarks by Vinh Nguyen, former chief responsible AI officer at the National Security Agency, kill switches alone are inadequate.
ReportedContestedSource: SiliconANGLE, relaying Vinh Nguyen2 sources— create a free account to open themView cited source - [22]
Machine identities have climbed to 109 for every human, Krista Case and Rebecca Knight explained in their analysis of the Navigate keynote.
ReportedInsufficientSource: theCUBE Research's Krista Case and co-host Rebecca Knight, per SiliconANGLEView cited source
Sources
2 independent publishers whose own reporting we read for this story.
- SailPoint Bets on Identity to Govern AI Agents at Navigate 2026 - Futurum
futurumgroup.com
1 article · October 10, 2026
- scworld.comAI agents make identity the front line of enterprise security
1 article · October 11, 2026
- siliconangle.comIdentity security for AI agents: 18 insights from Navigate 2026 - SiliconANGLE
1 article · October 9, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Identity governance and administrationFollow
- AI Agent and Nonhuman Identity SecurityFollow
- Zero Standing PrivilegeFollow