Analyst(s): Fernando Montenegro
Publication Date: October 9, 2026
At Navigate 2026, SailPoint extended just-in-time access, discovery, and autonomous agents across its Agentic and Human Fabrics, alongside IdentityIQ 9.0 for on-premises customers. We see a well-positioned bet on governing agents through the identity controls buyers already fund, with open questions on runtime authorization and on which agents’ identities reach.
What Is Covered in This Article:
- The announcements: SailPoint added autonomous agents, agent discovery, conditional just-in-time access, and a kill switch across its Agentic and Human Fabrics, as well as IdentityIQ 9.0 with an automated upgrade tool.
- A well-positioned bet: SailPoint is extending identity controls buyers already fund to agents, and 38% of surveyed decision-makers rank upgrading identity and access management (IAM) and privileged access management (PAM) to govern the identities agents use as one of their top three AI security priorities.
- Three families of agents: SailPoint’s authority controls bind most tightly to agents built in-house, while agents that work for a person or come with an application fail in different ways.
- Business logic moves into identity: an agent’s right scope depends on what it is for, which pulls IAM teams closer to application development.
- Contested ground: a kill switch targets a session rather than the actor; other identity vendors and security platforms compete for the same governance layer; and the on-premises base competes for engineering time.
The News: At its Navigate 2026 conference in Austin, SailPoint announced updates across SailPoint Agentic Fabric and SailPoint Human Fabric, the two products in its Identity Security offering, both built on the SailPoint Atlas platform. The company describes the release as “autonomous identity security.”
The headline addition is Autonomous Agents, three classes of SailPoint AI agents that enforce policy, right-size privileges, and protect systems, which the company says use identity context to separate legitimate agent activity from malicious activity. Agentic Fabric adds discovery of AI agents, Model Context Protocol (MCP) servers, and credentials through endpoint and browser sensors, security information and event management (SIEM), extended detection and response (XDR) telemetry, and vault and pipeline scanning. It also adds prompt monitoring, runtime authorization, one-click lifecycle controls, an agent kill switch, and Agent Audit, which exports framework-aligned evidence reports. Conditional just-in-time provisioning extends zero standing privilege to people, service accounts, and AI agents.
Human Fabric gains a re-platformed certification engine, separation-of-duties checks at the time of request, and conversational access requests from chat tools. IdentityIQ 9.0, the on-premises product, adds time-based access for roles and entitlements, a rebuilt technical foundation, and an automated upgrade tool.
Capabilities roll out starting at Navigate. A-ISPM (identity posture management with automated remediation), the Harbor Pilot Policy Agent, and a Proofpoint integration are expected in Q4 of fiscal 2027, sometime between November 2026 and January 2027. Integration of Entro Security, acquired in June, is due to complete soon.
SailPoint Bets on Identity to Govern AI Agents at Navigate 2026
Analyst Take: Nearly every identity vendor has an agent story this season, so the useful question about Navigate is what kind of bet SailPoint is placing. We read it as well-positioned. Rather than asking buyers to fund a new “agent security” category, SailPoint is extending the controls identity programs already run (ownership, lifecycle, certification, and now just-in-time access) to a new class of principal.
That aligns with where buyers say the money is going: in the Futurum 1H 2026 Cybersecurity Decision-Makers Survey (N=904), 38% of respondents ranked upgrading IAM and PAM to govern the non-human identities used by AI agents among their top three priorities for architecting and funding AI security over the next 12 to 18 months. SailPoint’s own Horizons figure (79% running agents in production, 2% with identity tooling built for them) is vendor-sourced but points the same way.
Which Agents Does Identity Govern?
Where we would push is on scope. We sort agents into three families by who decides what the agent is for: agents that work for a person (a coding assistant or AI browser pointed at whatever the user chooses), agents that come with an application (the assistant that a software-as-a-service (SaaS) vendor that switches on in software already deployed), and agents that the organization builds in-house. They look alike on an inventory screen, yet each fails differently, and a different party can fix each.
SailPoint’s core strengths (a human owner for every agent, conditional just-in-time access, lifecycle controls, audit evidence) bind hardest on the third family, where the organization controls the architecture and authority is the lever it holds. For agents that work for a person, the binding constraint is input (whatever the user points the agent at), and the endpoint and browser sensors, plus prompt monitoring reaches that family largely as filters, the weakest form of that control, since a filter has to recognize an attack to stop it.
Agents that come with an application are a visibility and inherited-permission problem, with the real controls in the application vendor’s hands, so the buyer’s lever is procurement, not policy.
Discovery matters in all three, since no control applies to an agent nobody has found, and the Navigate discovery sources are the right kind of first step. The authority story, the heart of the release, lands mostly in one family. We think that is fine, as long as buyers know it.
Governing Agents Means Governing Business Logic
An agent’s permissions only make sense against what it is supposed to do, and what it is supposed to do is a business construct (a process, a decision, a mandate) rather than a technical attribute. A service account has a fixed job; an in-house-built agent has a goal, and the right scope of its access depends on the business semantics that live with the teams who build it.
That puts the IAM team far closer to application development than it has ever been. Certifying a person’s access could happen at arm’s length from the code; right-sizing an agent’s privileges, or drafting its policy in plain language with something like the upcoming Harbor Pilot Policy Agent, requires knowing what the workflow is meant to accomplish. We reckon the value from releases like this one shows up first, where identity and platform engineering already share design reviews, which is an operating model change no product ships with.
What Does a Kill Switch Stop?
SailPoint deserves credit here. Its pitch is not to shut an agent down when something looks wrong, but to use identity context to stop the threat while legitimate agents keep running, which, correctly in our view, concedes that a blunt off switch is a poor primary control. A kill switch contains a session, and a goal-directed agent is not its current session: the same intent can come back through another credential or path.
That leaves the question we would put to any vendor claiming “runtime authorization.” Is the check prospective, blocking an action that falls outside what the agent was delegated before it executes, or detection and response after the fact, however fast? Both are useful, and they are different products. The need is clear: in the same Futurum survey (N=929), 55% of respondents agreed that, despite having AI usage policies, they lack the technical ability to detect or contain a compromised AI agent operating at machine speed.
An Identity Field Converging From Several Directions
The competition is coming at agents from different layers. At Oktane in late September, Okta announced an Agent Gateway that sits in the execution path between agents and their tools, with a gateway-level kill switch planned for later this year, which puts enforcement in the path first. Palo Alto Networks’ Idira (the former CyberArk) brings zero standing privilege from the privileged-access side, and Saviynt, a direct identity-governance rival, launched Identity Security for AI in March with an agent access gateway of its own.
CrowdStrike (with SGNL) and Cisco (with Astrix) fold agent and non-human identity into security platforms with their own telemetry. Microsoft has made Entra Agent ID generally available, primarily for agents built on its own platforms, and 1Password is moving the credential vault toward a broker role for agents with Unified Access, among others.
CrowdStrike shows how tangled this gets: SailPoint ships a CrowdStrike Foundry App and a Falcon Next-Gen SIEM integration, while CrowdStrike is adding its own runtime access layer through SGNL. Partner on Monday, compete on Tuesday is normal in security, but the cross-platform governance layer SailPoint is building is contested ground. SailPoint leads with governance over an identity graph (while also claiming inline runtime controls), Okta with sitting in the path, and the platform vendors with telemetry, and we would not call which one buyers trust most for agents yet.
Two Fronts, One Engineering Budget
The modernization half of Navigate is easy to skip and should not be. IdentityIQ 9.0, with an upgrade tool aimed at the manual work that has long stalled on-premises upgrades, is a commitment to an installed base with data-residency, regulatory, or customization reasons to stay put, a base that also helps fund the agentic roadmap. Compliance teams will notice the rebuilt certification engine and request-time separation-of-duties checks well before any agent feature.
There is a tension, though. SailPoint’s agentic message calls static reviews “outdated the moment they finish,” the same day it announced a rebuilt certification engine. Both can hold, since regulated buyers will run certifications for years, but customers on each front will want to know which roadmap gets the engineers when the two compete.
What to Watch:
- Will “runtime authorization” prevent or only detect? The test is whether SailPoint blocks an agent action that exceeds its delegation before it executes. Buyers should ask for a demonstration, not a datasheet.
- Who owns agent policy when IAM meets application development? Right-sizing an agent’s access needs input from the teams who build it. Shared design reviews between identity and platform teams are a good sign; policy drifting back to developers by default is a bad one.
- Can discovery reach agents that come with an application? SailPoint can inventory vendor-enabled assistants, but the controls for those assistants belong to the SaaS vendor. Watch whether integrations push policy into those platforms or stop at visibility.
- Does governance over a graph beat enforcement in the path? Okta’s Agent Gateway and the platform vendors’ telemetry compete with SailPoint’s graph-led approach. The early signal is which one buyers place on the critical path for agent actions first.
For more information, read the full announcement from SailPoint here. Read the Human Fabric and IdentityIQ 9.0 announcement here.
Disclosure: Futurum is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.
Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of Futurum as a whole.
Other Insights From Futurum:
The Hard(er) Challenge in Agent Governance Is Authorization
So This Is How AIs Attack: Observations From the OpenAI & Hugging Face Incident
A Loud Floor and a Quiet Gap: Security Summer Camp 2026
SailPoint’s New Connector Addresses Security Gaps in AI-Driven Development
Author Information
Fernando Montenegro serves as the Vice President & Practice Lead for Cybersecurity & Resilience at The Futurum Group. In this role, he leads the development and execution of the Cybersecurity research agenda, working closely with the team to drive the practice's growth. His research focuses on addressing critical topics in modern cybersecurity. These include the multifaceted role of AI in cybersecurity, strategies for managing an ever-expanding attack surface, and the evolution of cybersecurity architectures toward more platform-oriented solutions.
Before joining The Futurum Group, Fernando held senior industry analyst roles at Omdia, S&P Global, and 451 Research. His career also includes diverse roles in customer support, security, IT operations, professional services, and sales engineering. He has worked with pioneering Internet Service Providers, established security vendors, and startups across North and South America.
Fernando holds a Bachelor’s degree in Computer Science from Universidade Federal do Rio Grande do Sul in Brazil and various industry certifications. Although he is originally from Brazil, he has been based in Toronto, Canada, for many years.

