AIToday
AI Safety & AlignmentAI Business & IndustrySiliconANGLE AIPublished: Oct 10, 2026, 01:00 JST

SailPoint's McClain: Secure AI agents at machine speed

SailPoint's McClain: Secure AI agents at machine speed

At SailPoint's Navigate event in Austin, CEO Mark McClain said identity security for AI agents has become a board-level priority. Machine identities now number 109 for every human.

Not sure about something? Ask the AI

Questions and answers are published on this page.

Summaries like this, in your inbox every morning.

Context & Analysis

SailPoint's annual Navigate conference in Austin, Texas, brought together its executives and outside experts to argue that the old perimeter defense model no longer holds. The company's founder and CEO, Mark McClain, explained that its technical team concluded it could not secure agent identities effectively in what he called admin time, and that the company instead has to be in the real-time decision-making cycle of judging whether an agent with its context and intent is doing what is expected.

The event leaned heavily on concrete discovery findings. SailPoint's chief customer officer, Meredith Blanchar, described a Fortune 500 company that insisted it had no agents until discovery turned up 10,000, many with standing admin privileges. Jeff Hickman, senior VP of sales engineering, said production proofs of concept find orphaned or overprivileged access within hours every time, and in one case risk scoring narrowed 100,000 non-human identities down to 72 that needed attention. Half of discovered agents still lack a known owner, according to theCUBE Research's Krista Case and co-host Rebecca Knight.

SailPoint is responding with products and partnerships. Its June acquisition of Entro Security added about 1,200 discovery sources for non-human identities, and Entro's co-founder and CEO, Itzik Alvas, said the latest AI-driven attacks all come down to an exposed credential that an agent found and used to log in. On the cloud side, Madhu Parthasarathy, general manager of Bedrock AgentCore at Amazon Web Services, said tasks on Amazon Bedrock AgentCore grew 15 times over in the first six months of the year, with a new agent created every 4.5 seconds. Whether enterprises can keep up may depend on getting auditors and regulators comfortable, which Matt Mills, SailPoint's president, identified as the main obstacle to letting AI fix problems on its own.

FAQ
What is SailPoint's approach to securing AI agents?
SailPoint is introducing just-in-time authorization, which lets a human owner grant access for a limited time, and its Lineage Map records the full chain from human to agent to tool to data. It is also building level 2 through level 4 autonomous agents for governance, with the Entro integration in limited internal testing and customers slated to get it in November.
How many agents did one company discover?
One Fortune 500 company insisted it had no agents until discovery turned up 10,000, many with standing admin privileges. In another case, risk scoring narrowed 100,000 non-human identities down to 72 that needed attention.
SiliconANGLE AIRead Original Article

AI news that matters for your work, delivered every morning.

Pick your industry and the AI tools you use, and get news related to your work every day.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.

Questions and answers are published on this page.

Related Articles

Next articleNvidia, Broadcom split of $5,000 seen tripling by 2028