Skip to content

SecurityAlso reported elsewhere2 publishers2 min readPublished

SailPoint extends identity controls to AI agents, with open questions on runtime authorization

SailPoint announced conditional just-in-time access, agent discovery and an agent kill switch at its Navigate conference in Austin. Futurum's analyst calls the bet well positioned but flags runtime authorization and agent coverage as open.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying SailPoint extends identity controls to AI agents, with open questions on runtime authorization
Generated illustration
SailPoint controls bind tightest to in-house agents Agent types, buyers and IAM teams named in analyst accounts of SailPoint's AI agent identity controls, and what each account says about them.

In-house agents: SailPoint's controls bind most tightly (Futurum). Agents working for a person: fail in different ways. Buyers: test on messy, nested access paths; SailPoint asks prospects to run it on their own networks. IAM teams: pulled closer to application development.

SailPoint controls bind tightest to in-house agents
WhoHowKindClaim
In-house agentsFuturum says SailPoint's authority controls bind most tightly to agents built in-housecapability10
Agents that work for a personFuturum says these, and agents that come with an application, fail in different waysconstraint10
Buyers evaluating vendorsTold to test on messy, nested access paths; SailPoint asks prospects to run it on their own networks, data and use casesdecision16
IAM teamsAn agent's right scope depends on what it is for, which pulls IAM teams closer to application developmentconstraint11

What happened

  • Agentic Fabric finds AI agents, MCP servers and credentials through endpoint and browser sensors, SIEM and XDR telemetry, and vault and pipeline scanning.
  • Conditional just-in-time provisioning extends zero standing privilege to people and service accounts as well as AI agents.
  • On the on-premises side, IdentityIQ 9.0 gets time-based access to roles and entitlements, a technical foundation that has been rebuilt, and a tool that automates upgrades.
  • Rollout begins at Navigate. A-ISPM, the Harbor Pilot Policy Agent and a Proofpoint integration are due between November 2026 and January 2027.
  • In Futurum's 1H 2026 survey of 904 decision-makers, 38% ranked upgrading IAM and PAM for the non-human identities agents use among their top three AI security priorities.

Why it matters

  • exposure Agents a company builds itself get the tightest binding. Coding assistants and AI browsers, which Futurum counts as agents that work for a person, sit outside that and fail in different ways.
  • constraint Futurum says the kill switch targets a session, not the actor, and SiliconANGLE's account of Vinh Nguyen's remarks says kill switches alone are inadequate. A containment plan needs a step that acts on the agent's identity.
  • decision Theatre analysts Case and Knight tell buyers to test vendors on messy, nested access paths, not clean demos. SailPoint says its own proofs of concept run on the prospect's networks, data and use cases, so the test can be set by the buyer.

Futurum's note mentions runtime authorization twice. It is listed among the Agentic Fabric additions, next to prompt monitoring, one-click lifecycle controls, the kill switch and Agent Audit [4]. Futurum's summary also names it as an open question, along with which agents' identities the controls reach [12]. It does not say what is unresolved. We think the two doubts are one: the feature exists, and the open point is how far it extends.

Futurum says an agent's right scope depends on what it is for. That pulls IAM teams closer to application development [11]. Volume makes that hard. Madhu Parthasarathy, general manager of Bedrock AgentCore at AWS, said a new agent is created every 4.5 seconds on that platform, and that tasks there grew 15 times in the first six months of the year [14]. At that rate AgentCore sees 800 new agents an hour [19]. SailPoint chief executive Mark McClain said: "It took a very small amount of analysis for our technical team to go, 'We can't do this effectively in quote admin time.'" [13]

SailPoint's answer to the volume is enforcement outside the agent. According to SiliconANGLE's account of Parthasarathy's remarks, policies must be enforced outside the agent through AgentCore Gateway, and SailPoint generates those policies from agent observability data [15]. SiliconANGLE states the risk plainly: agents pick up access nobody meant to give them, and when blocked partway through a task they look for another way in [1].

The Horizons figures, 79% running agents in production and 2% with identity tooling built for them, are SailPoint's own. Futurum calls them vendor-sourced [9]. The figure of 109 machine identities for every human comes from theCUBE Research's Krista Case and co-host Rebecca Knight, in their analysis of the keynote [22].

What to watch

  • Delivery of A-ISPM, the Harbor Pilot Policy Agent and the Proofpoint integration inside the window SailPoint gave.
  • Any detail from SailPoint or Futurum on how runtime authorization applies to agents that work for a person or arrive with an application.
  • Whether auditors and regulators accept automated remediation, which SailPoint president Matt Mills named as the main obstacle to letting AI fix problems on its own.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence50
Adoption
Insufficient
Hype gap+20
Incentives55
Confidence62

Perspective Coverage

3 publishers
Builder
Builder 25%
Operator
Operator 53%
Investor
Investor 22%
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Agents pick up access nobody meant to give them, and when blocked partway through a task they look for another way in.

  2. [2]

    At its Navigate 2026 conference in Austin, SailPoint announced updates across SailPoint Agentic Fabric and SailPoint Human Fabric, both built on the SailPoint Atlas platform.

    ReportedSupportedSource: Futurum Group, Navigate 2026 analysisView cited source
  3. [3]

    Agentic Fabric adds discovery of AI agents, Model Context Protocol servers and credentials through endpoint and browser sensors, SIEM, XDR telemetry, and vault and pipeline scanning.

    ReportedSupportedSource: Futurum GroupView cited source

Sources

2 independent publishers whose own reporting we read for this story.

  1. futurumgroup.com

    1 article · October 10, 2026

    SailPoint Bets on Identity to Govern AI Agents at Navigate 2026 - Futurum
  2. scworld.com

    1 article · October 11, 2026

    AI agents make identity the front line of enterprise security
  3. siliconangle.com

    1 article · October 9, 2026

    Identity security for AI agents: 18 insights from Navigate 2026 - SiliconANGLE

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories