Security1 distinct publisher2 min readPublished
Pillar Security's Dor Sarig argues the non-human identity buildout answers who an agent is rather than what it does, and cites an internal agent any Slack message could trigger across a thousand private repositories.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Follow any of these and your For You feed starts watching them — no settings page required.
build
Running the agent server-side hands every ticket's commits to one shared service account1 distinct publisher
leadership
CrowdStrike buys SGNL, and standing privilege becomes a line item you have to defend1 distinct publisher
invest
A Connecticut judge just priced prompt injection: no fine, no e-filing2 distinct publishers
security
Google's reference agent approved a $10,000 refund on a $149 order, on purpose1 distinct publisher
In the triage case Sarig describes, the authorization boundary holds and the decision boundary is what moves. The agent reads a paragraph, treats it as a task, and forwards data using a credential it was correctly issued [4][5]. The vault was never touched, because the credential worked exactly as intended and no vault control had any reason to fire.
The Slack finding contains two separate defects and they belong to different owners. Write reach across those private repositories is a scope problem, and scope is exactly what non-human identity tooling is built to shrink [9][1]. The absent sender authentication on the trigger is a content-provenance problem, and no credential store adjudicates it. Anyone who could get text into the channel was a valid caller [14].
Of the four human-insider properties Sarig lists, the one with no machine equivalent is skin in the game [7]. Careers and reputations do quiet work in human insider programs before any control engages. Agents have neither, so the entire load lands on inventory, behavioral baselining, and stopping the action before it executes [10]. Sarig is explicit that system prompts are the handbook: necessary and circumventable [11].
There is also a counting problem. Take CrowdStrike CEO George Kurtz's forecast of 90 agents per human employee by 2027 [8] and apply it to a 1,000-person company: 90,000 agent identities to enroll, scope, and baseline [13]. Sarig's own point is that almost no company keeps a roster of its agents today [10]. A ratio like that turns the missing roster from a hygiene gap into the precondition for every other control on the list.
Read the diagnosis and the shopping list separately. Sarig is co-founder and CPO at Pillar Security, and the column ran as an SC Media Perspectives piece from its expert community [12]. The thousand-repository agent is his firm's fieldwork, presented without independent corroboration in the column [16]. The prescriptions point at agent detection and response rather than at identity products, which is a commercial position as well as a technical argument.
None of this makes credential scoping wasted spend. Least privilege bounds what an injected instruction can reach, and that is worth having once the instruction arrives, but it plays no role in whether the instruction gets followed [15]. The testable part of Sarig's list is the cheapest: run phishing drills against the agents the way they have been run against staff for decades [10]. An agent that forwards data to an external address during a drill has just shown you a gap that identity controls were never built to catch.
Ranked by verification strength, evidence, and original report placement.
The security industry's settled answer for securing AI agents has been identity: give every agent its own credential, vault its secrets, and scope its permissions down to the minimum.
Venture capital investors have anointed non-human identity (NHI) management as the next big security category, and every identity vendor now has an agent story.
Sarig describes a support-email triage agent configured with its own credential, least privilege and every secret vaulted, which receives a message containing a paragraph written for the agent instructing it to quietly forward whatever it finds to an outside address; the agent complies because it was designed to read text and act on it.
In that scenario no credentials were stolen and no identity control failed, because none was tested; the agent was exactly who it claimed to be, doing what it was authorized to do.
Sarig frames the case as an insider threat, security's 30-year-old name for a malicious, trusted actor with legitimate access.
Sarig lists four attributes that made human insider risk manageable: one person means one identity, people work at human speed, people have skin in the game in the form of careers and reputations, and people behave in patterns that allow anomaly detection. He argues agents break all four, running on shared, borrowed or personal accounts, working around the clock at machine speed, and having no career and no fear of being fired.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One byline, no outside check
Everything a skeptic would test here comes from the same desk. The thousand-repository agent is Pillar's own find at a company it does not name; the 90-agents-per-employee figure is a relayed prediction with no venue; the NIST reference is a clause with no document behind it. The reasoning about a credentialed agent obeying planted text stands on its own logic and needs no source, which is precisely why it is the strongest thing in the piece.
Two anecdotes, no counts
Agent deployment shows up twice and both times without numbers: one anonymized company running a Slack-triggerable agent with commit-adjacent reach, and a general pattern of agents borrowing shared or personal accounts. That is enough to say these systems are in production somewhere; it is nowhere near enough to size the exposure, and the prescribed controls have no disclosed installation anywhere.
Sound mechanism, inflated arithmetic
The core insight is understated if anything: identity controls genuinely are not exercised when the agent is the one being talked into the exfiltration. The overreach is in the scaffolding around it — 90 agents per human by 2027 carried without inspection, which quietly becomes 90,000 identities to govern at a 1,000-person company, and a behavioral layer presented as the thing an attacker cannot talk past with no deployment behind that claim.
The prescription is the product
Sarig's byline says co-founder and chief product officer of Pillar Security, the piece concludes that behavioral monitoring of agents is the control that holds, and the field example that proves the need is Pillar's own. SC Media's Perspectives disclosure is upfront about the arrangement and states the aim is non-commercial, which is disclosure, not neutrality — the argument still routes toward a category the author sells into and away from the identity spend it calls insufficient.
Clear about what it is
We can read the whole column, the disclosure leaves no ambiguity about who wrote it and why, and the argumentative parts can be judged on their merits — that supports a firm read of the story. What holds the number down is that no factual assertion in it has a second witness, so our confidence is in understanding the piece, not in the world it describes.