ProductNot yet confirmed elsewhere1 publisher3 min readPublished
SailPoint moves identity governance from the quarterly review to the moment an AI agent acts
SailPoint says it will now stop bad access as it happens, citing up to 150 million AI agent interactions a day at an average Global 2000 company. Its own survey finds 15% of organizations can provision non-human access in real time, and removing agents' standing access depends on that capability.
The Product Desk

What happened
- SailPoint's fifth annual Horizons of Identity Security report found 79% of organizations run AI agents in production, but only 2% govern them with identity security tools.
- Chief Executive Mark McClain cited a study putting service accounts, API keys and autonomous agents ahead of human identities by 109 to one.
- SailPoint divided Identity Security Cloud into Agentic Fabric and Human Fabric, two products that run on its Atlas platform.
Why it matters
- constraint With 85% of surveyed organizations unable to provision non-human access in real time, most identity teams cannot yet give an agent access per task and take it back, so standing grants stay until that provisioning exists.
- contradiction SailPoint still assigns certifications to its green agents as routine work, so the quarterly review gets automated and kept; identity teams will run the audit calendar alongside runtime blocking.
- decision Buyers comparing agent-security startups with identity vendors now have to judge whether runtime blocking without an owner graph is enough; SailPoint argues runtime-only tools will struggle without identity context.
Identity governance has run on a calendar, in SiliconANGLE's description of the keynote: quarterly certifications, annual audits and reviews that arrive weeks after the fact [16]. On paper, the certification is the control. At SailPoint's largest customers a single campaign now runs past 10 million line items, and Chief Technology Officer Chandra Gnanasambandam said 95% of them should be automated [10]. If that happens, people still have about 500,000 items to judge in one campaign [21]. The writeup's author wrote that access reviews were broken for humans long before agents arrived [15].
Agents do not work on that schedule. Spread evenly across a day, Gnanasambandam's figure for an average Global 2000 company comes to roughly 870 to 1,740 agent interactions a second [18]. Over a 90-day quarter, that is 6.75 billion to 13.5 billion interactions between one certification and the next [19]. "The idea that a security admin is going to review and approve access for a group of autonomous agents making 10,000 tool calls a second isn't just outdated; it's a fantasy," he said [3].
President Matt Mills ruled out watching as a substitute for stopping. "Basic monitoring is not security. Simply watching an agent do bad things isn't security. It's just a dashboard that reports all your breaches to you," he said [11].
SiliconANGLE's headline on the keynote states the conclusion for identity teams: in the agentic era, standing privilege must go [14]. SailPoint builds its case on ownership first. "An agent acts on behalf of a human or another agent that traces back to a human," Mills said. "So, the moment you govern human and agent separately, you lose the thread of who's actually accountable." [8] Jerome Robin, director of corporate security at Criteo and a SailPoint customer since 2021, said: "Giving access to an agent for a task means delegating your business responsibility." [12]
The keynote coverage does not describe how an agent receives access for a single task and loses it afterward, or what the new products cost.
A team sorting its own agents can apply two tests. The first is whether each agent traces to a named human who answers for it. The second is whether the team can grant and revoke that agent's access in real time, and SailPoint's survey says most organizations cannot [5]. An agent that passes both is a candidate for losing standing privilege: access granted for the task, then removed. Where an agent has an owner but no real-time provisioning, it keeps standing grants for now, scoped narrowly and reviewed more often than quarterly.
Unowned agents come first. I would start there, because assigning an owner needs a list and named sponsors, with no new software. The tradeoff is that every agent keeps its standing grants while real-time provisioning gets built. Without an owner, the SiliconANGLE author wrote, an agent is "just an orphaned account capable of reasoning" [17].
What to watch
- Whether SailPoint documents how Agentic Fabric gives an agent access for a single task and revokes it afterward, and publishes a price.
- Whether the 15% of organizations able to provision non-human access in real time rises in SailPoint's next Horizons of Identity Security report.
- Whether customers such as Criteo report what share of certification line items green agents close without a human reviewer.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence30
- Adoption20
- Hype gap+35
- Incentives80
- Confidence35
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
At Navigate 2026 in Austin, SailPoint argued that it now needs to be the company that stops the wrong access the moment it happens, after two decades of telling enterprises who should have access to what.
- [2]
Chief Technology Officer Chandra Gnanasambandam said SailPoint sees 75 million to 150 million agentic interactions per day at an average Global 2000 company.
- [3]
"The idea that a security admin is going to review and approve access for a group of autonomous agents making 10,000 tool calls a second isn't just outdated; it's a fantasy."
- [4]
SailPoint's fifth annual Horizons of Identity Security report, released at the event, found that 79% of organizations run AI agents in production, yet only 2% use identity security tools to govern them.
ReportedSupportedSource: SailPoint Horizons of Identity Security report, via SiliconANGLEView cited source - [5]
The Horizons of Identity Security report found that just 15% of organizations can provision non-human access in real time.
ReportedSupportedSource: SailPoint Horizons of Identity Security report, via SiliconANGLEView cited source - [6]
Chief Executive Mark McClain described service accounts, API keys and autonomous agents that, according to a study he cited, outnumber human identities 109 to one.
- [7]
SailPoint evolved Identity Security Cloud into two products, Agentic Fabric and Human Fabric, both built on its Atlas platform.
- [8]
"An agent acts on behalf of a human or another agent that traces back to a human. So, the moment you govern human and agent separately, you lose the thread of who's actually accountable."
- [9]
SailPoint's Autonomous Agents: red agents detect drift, blue agents analyze it and deprovision access, and green agents handle peacetime work such as certifications.
- [10]
Gnanasambandam said the largest customers have certification campaigns with more than 10 million line items and 95% of those should be automated.
- [11]
"Basic monitoring is not security. Simply watching an agent do bad things isn't security. It's just a dashboard that reports all your breaches to you."
- [12]
"Giving access to an agent for a task means delegating your business responsibility." Said by Criteo Director of Corporate Security Jerome Robin, a SailPoint customer since 2021.
- [13]
SailPoint's bet is that the identity context it has spent 20 years building enables real-time enforcement, and that runtime-only security tools will struggle without it.
- [14]
SiliconANGLE's keynote analysis is headlined: In the agentic era, standing privilege must go.
- [15]
The SiliconANGLE author wrote that access reviews were broken for humans long before agents arrived.
- [16]
Governance has always run on a calendar: quarterly certifications, annual audits and reviews that arrive weeks after the fact.
- [17]
An agent without a human owner is "just an orphaned account capable of reasoning."
- [18]
75 million to 150 million interactions a day is roughly 870 to 1,740 interactions a second, spread evenly over 86,400 seconds.
- [19]
Over a 90-day quarter, 75 million to 150 million interactions a day totals 6.75 billion to 13.5 billion interactions between quarterly certifications.
- [20]
85% of surveyed organizations cannot provision non-human access in real time.
- [21]
At 95% automation, a 10-million-line certification campaign leaves about 500,000 line items for human review.
Sources
1 independent publisher whose own reporting we read for this story.
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- AI Agent SecurityFollow
- Standing privilegeFollow
- Identity Governance and Access ReportingFollow
- Non-Human and Agentic IdentityFollow