SailPoint Shifts Focus to Real-Time Access Control at Navigate 2026
For most of its 20-year history, SailPoint Inc. has been a leading authority on determining who has access to enterprise resources. However, during this week’s Navigate 2026 event in Austin, the company emphasized its need to prevent unauthorized access in real-time.
The keynote address featured a live orchestra to symbolize the harmony achieved when disparate components work jointly. In his segment, Chief Executive Mark McClain illustrated the challenges that arise when artificial intelligence (AI) agents fail to collaborate effectively. This shift in focus goes beyond mere metaphor, highlighting significant changes in cybersecurity dynamics.
The traditional governance approach has often been time-based—relying on quarterly certifications and annual audits that provide feedback weeks or even months after events occur. However, AI operates on immediate action through numerous tool calls. SailPoint posits that its extensive two-decade investment in identity context enables real-time enforcement, contrasting sharply with runtime security tools that lack this foundational insight.
Here are several key insights that are crucial for security and identity leaders:
The Workforce Composition is Changing, and Accountability Issues Arise
During the keynote, McClain noted the rapid transformation in the enterprise workforce. “A few years ago, you had a clear understanding of who was in your orchestra—your employees and contractors. Today, however, there exists an invisible contingent alongside them,” he stated, referring to service accounts, API keys, and autonomous agents. According to a study cited, these non-human identities now outnumber human identities by 109 to one.
President Matt Mills emphasized the significance of accountability. “An agent acts on behalf of a human or another agent linked to a human,” he explained. “When you govern humans and agents separately, you lose track of accountability. We approach human and agent identities as a unified problem, governed under one policy.” This perspective underpins SailPoint’s decision to evolve its Identity Security Cloud into two distinct products: Agentic Fabric and Human Fabric, both leveraging its Atlas platform.
This shift contrasts with many newer security startups, which often view agents as isolated inventory challenges. As Criteo S.A. Director of Corporate Security Jérôme Robin pointed out, granting an agent access to complete a task effectively delegates business responsibility. He warned that “technology should enforce the model, not replace it,” underscoring the importance of accountable access management.
Legacy Governance Fails to Match the Pace of Machine Identities
Mills addressed the shortcomings of traditional governance. “You cannot combat AI-speed threats with outdated, human-speed governance,” he asserted. He further noted, “Basic monitoring does not equate to security; merely tracking an agent’s detrimental actions isn’t security—it’s a dashboard chronicling your breaches.”
The statistics support this claim: SailPoint estimates that Global 2000 companies experience between 75 million to 150 million agent interactions daily. “The notion that a security admin could manually review and authorize access for autonomous agents making 10,000 tool calls per second is not only outdated; it’s fantastical,” added Executive Vice President and Chief Technology Officer Chandra Gnanasambandam.
SailPoint’s recently released Horizons of Identity Security report found that 79% of organizations deploy AI agents but only 2% utilize identity security tools to govern them. Additionally, a mere 15% can provision non-human access instantly. Chief Marketing Officer Wendy Wu concluded that “operating an AI-speed enterprise without an adequate security framework is untenable.”
The Limitations of Runtime Controls in the Absence of Identity Context
One poignant observation from Gnanasambandam was aimed at runtime-first vendors: “An agent kill switch is designed to deactivate harmful agents. However, if your runtime control lacks context and cannot distinguish between a beneficial agent and a harmful one, how will it know which to deactivate?” He cautioned that such a capability risks disabling both good and bad agents indiscriminately.
This concern is pertinent; organizations are unlikely to tolerate a kill switch that inadvertently disrupts legitimate automation. SailPoint’s new capabilities bolster this argument, with Agentic Fabric introducing shadow AI discovery, runtime authorization, and a one-click kill switch among its features.
Gnanasambandam noted a significant discovery during a Fortune 500 proof of concept, which identified over 10,000 unknown agents within just one week. Eric Burnett, Director of Identity and Access Management at University of Chicago Medical Center, echoed this blind spot, remarking that “we recognize there is a great deal of AI present in our environment that we are not aware of.”
Targeting standing privilege as the Primary Threat
“In a near-agentic world, standing privilege is obsolete,” stated Gnanasambandam, highlighting that 98% of current access is rooted in standing privilege. Despite being an objective for decades, the principle of least privilege has yet to become operationalized. He described the issue as the “iceberg problem,” where much of a user’s actual access is hidden beneath the surface, often through nested groups and service accounts.
SailPoint is now utilizing machine learning to map effective privilege for each identity, integrating this data into certification processes. Furthermore, the company is introducing conditional, just-in-time provisioning, where agents can proactively request access from human owners on an as-needed basis.
Despite these advancements, some industry leaders remain skeptical. “Throughout my career, I have yet to meet a client that has fully implemented least privilege in their organization,” lamented Sanjeev Shukla, Global Lead for Identity and Trust at Accenture. He noted that even tier-one banks, which have invested heavily in cybersecurity, often report only 65% coverage of privileged access.
The Importance of Long-Term Stewardship in Cybersecurity
Mills cautioned attendees against succumbing to hype, including SailPoint’s. He recounted a Fortune 500 CIO’s description of the cybersecurity market as overcrowded with “vendors boasting big promises without substantial results.” Mills urged organizations to “demand evidence over empty promises,” emphasizing the need for practical proof-of-concept evaluations.
This challenge also extends to SailPoint’s existing client base, many of whom still rely on its IdentityIQ product for on-premises solutions. The company recently announced IdentityIQ 9.0, featuring enhancements such as time-based access and an upgraded Human Fabric certification engine. Gnanasambandam remarked that many vendors present customers with a choice between growth and stewardship, asserting that SailPoint’s initiative addresses both.
SailPoint also acknowledged areas for improvement, admitting that its user experience has not kept pace with its product capabilities. The company plans to prioritize essential features, such as certifications and the separation of duties, to strengthen its foundations while also advancing innovative solutions like Agentic AI.
Key Takeaways for Prospective Buyers
SailPoint has positioned identity management as the cornerstone of agent accountability. It now faces the challenge of demonstrating its capability to enforce policies in real-time rather than merely governing through outdated methods. For information technology and cybersecurity leaders, the following points are critical:
- Conduct initial discovery assessments. If a single week can uncover 10,000 unknown agents within a Fortune 500 company, it’s likely that your inventory is inaccurate.
- Assign ownership for every agent. If an agent lacks an accountable human owner, its access should be restricted.
- Evaluate the efficacy of your kill switch. Require any vendor, including SailPoint, to demonstrate how it differentiates between beneficial and harmful agents using your datasets.
- Address effective privilege for human users. Nested groups and overly permissive service accounts contribute to the vulnerabilities that agents inherit.
- Implement zero standing privilege as an ongoing initiative. Start by ensuring just-in-time access for the most sensitive systems, gradually expanding coverage.
McClain emphasized that SailPoint may not compose the music, but its customers do. For the first time, the company is pledging to interrupt operations if any wrong access occurs mid-execution—a significantly more challenging task that it must prove accountable for moving forward.

