Security1 publisher2 min readPublished
SailPoint's agent tools trade permanent access keys for temporary permissions
SailPoint added AI agent discovery and automated access cleanup to its identity platform, aimed at the 79% of enterprises it says run agents in production. Existing customers can bring agent credentials under the platform that governs their staff, on SailPoint's evidence alone so far.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- A new fleet of SailPoint-built AI agents, called Autonomous Agents, monitors what other agents do at runtime and intercepts the threats it detects.
- Discovery draws on new endpoint and browser sensors, SIEM and XDR telemetry, and scans of vaults and pipelines to find MCP servers, tools and non-human credentials.
- A new posture module, A-ISPM, looks for dormant accounts, partially offboarded identities, orphaned access, shadow admins and privileged outliers buried in access paths.
- SailPoint showed the features at its Navigate event alongside IdentityIQ 9.0 and new automation workflows in its Atlas engine.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- capability A SailPoint shop can now run agent credentials found in vaults and pipelines through the same dormant, orphaned and shadow-admin checks it applies to staff identities.
- exposure Once enforcement is fully automated, a wrong intent call by SailPoint's agents disables a working production agent, and the identity team inherits that outage.
- decision Each customer has to choose where to set remediation, from one-click approval to full automation, and the only evidence for trusting the automated end so far comes from SailPoint.
Of everything SailPoint announced, the replacement of permanent access keys with temporary permissions bears most directly on an intrusion [4]. The company says its Autonomous Agents will right-size permissions to enforce zero standing privilege at machine speed [5]. An agent with a lapsing permission leaves less for a thief to replay than one carrying a key that works until someone revokes it.
Chandra Gnanasambandam, SailPoint's chief technology officer, said the idea of a security admin who will "review and approve access for a group of autonomous agents making 10,000 tool calls a second" is "a fantasy" [6]. The 10,000 figure is his illustration. "The only way to govern autonomous machines is with autonomous machine defense," he said [6].
That argument puts a detection claim at the center of the product. SailPoint says its agents read identity context to judge whether an agent's intent is legitimate or malicious, so they can block threats without interrupting agents doing useful work [7]. Every detector trades missed attacks against false alarms. Here a false alarm has a direct cost, because A-ISPM remediation runs from one-click fixes, including disabling an AI agent, up to fully automated policy enforcement [10]. A wrong call at the automated end shuts off a working agent in production.
For current customers, the agent tooling sits on the platform they already run. Both fabrics are built on SailPoint Atlas [1], and A-ISPM draws on the live identity context in Atlas [9]. The release states the case for keeping agents inside that store: an agent, credential or data store that never reaches the identity program "becomes access no one owns" [11]. SailPoint sells Agentic Fabric and Human Fabric as two separate products [1]. The announcement does not include pricing, ship dates, detection rates, or whether a customer on one fabric must buy the other to govern agents.
The South Korea data center and the compliance list matter to specific buyers. The company says it is opening the data center and preparing to meet FedRAMP High, PCI DSS 4.0 and EU Sovereign Cloud standards [15]. For a federal buyer, preparing to meet FedRAMP High is a roadmap item until an authorization is issued.
The demand case rests on SailPoint's own survey. Its Horizons of Identity Security report counts AI agents in production at 79% of enterprises and purpose-built agent identity tooling at 2% [c12, c13]. SailPoint, which reports that 77-point gap [16], is also the company selling the tooling to close it.
What to watch
- SailPoint pricing for Agentic Fabric, and whether current Atlas and IdentityIQ customers need a new license to govern agents.
- A FedRAMP High authorization for the platform, as distinct from the preparation SailPoint describes.
- Customer or independent reports on how often Autonomous Agents block legitimate agents once automated enforcement is switched on.