SailPoint Autonomous Agents are coming to enterprise security stacks. Announced on October 6 at the company's Navigate 2026 conference in Austin, SailPoint Autonomous Agents form a new fleet of specialized AI agents built to govern the very AI agents that enterprises are deploying at scale.
The announcement lands at a moment when the enterprise is adopting AI agents far faster than it can secure them. According to SailPoint's Horizons of Identity Security report, 79 percent of enterprises are already running AI agents in production, yet only 2 percent have deployed identity security tools designed to govern and secure them.
What SailPoint Autonomous Agents Do
According to SailPoint's official announcement, SailPoint Autonomous Agents monitor runtime agent activity, intercept threats, and continuously right-size permissions. Rather than blunt tools that simply shut down agents when anomalies occur, these agents use identity context to separate legitimate intent from malicious activity, stopping threats while keeping productive agents running.
The capability matters because of speed. As reported by Redmondmag, SailPoint CTO Chandra Gnanasambandam has noted that AI agents can invoke MCP tool calls thousands of times per second, which makes human review of each action impossible. SailPoint Autonomous Agents are designed to govern that machine-speed activity, enforcing zero standing privilege so that no agent retains permanent access it does not actively need.
According to Help Net Security, SailPoint president Matt Mills framed the release around a shift from Zero Trust to what the company calls Autonomous Identity: autonomous machines need autonomous machine defense. The company says the same agents also replace permanent access keys with temporary permissions granted just in time and under defined conditions.
Discovering Shadow AI and Runtime Control
The second pillar of the announcement is SailPoint Agentic Fabric, or SAF, alongside SailPoint Human Fabric, SHF. According to the company's press release, these two purpose-built identity security products give enterprises visibility into hidden AI tools and continuous compliance across both human and machine workflows.
As reported by Redmondmag, the expanded Agentic Fabric is built to discover shadow AI agents operating inside the enterprise, then provide runtime authorization and controls capable of immediately disabling an agent that poses a risk. SailPoint Autonomous Agents give security teams a way to move identity security from a static compliance check into real-time automated defense.
SailPoint also rolled out Just-in-Time provisioning with conditions plus effective privilege visibility, which replaces always-on access for people, service accounts, and AI agents alike. According to Help Net Security, the company's Atlas platform received companion upgrades supporting SailPoint Autonomous Agents, including common services, SaaS plug-ins, and workflow enhancements with versioning, execution history, and serial loops of up to 1,000 iterations.
Why Agent Identity Is Becoming a Category
The SailPoint announcement is part of a broader wave: identity management for AI agents is rapidly becoming its own security category. According to a Business Wire release covered by UK Newshour, RSA unveiled RSA Agent ID at World Summit AI to discover, secure, and govern agents in highly regulated industries such as government and finance. Research from Gartner cited in that coverage projects that a typical Fortune 500 enterprise could run roughly 150,000 AI agents by 2028, up from fewer than 15 in 2025.
That scale explains why startups are racing into the space. Baselayer recently raised a $35 million Series A to build an agentic identity suite that authenticates, authorizes, and audits autonomous agents, according to reporting by Renascence. Hadrian, which uses AI agents for offensive security, raised $40 million in early October to expand its agentic cybersecurity platform, as reported by Tech Startups.
For agent developers, the takeaway is straightforward. Agents that hold credentials, carry entitlements, and act on systems of record need identities that can be issued, reviewed, and revoked. The agent ecosystem is growing up fast, and identity is becoming its foundation. Earlier this week, genznewz covered TM Forum and Accenture's trustworthy AI certification for telecom agents, while OneByZero raised $20 million to scale governed AI agents. Now SailPoint is pushing governance down to runtime, where agents actually act.
Comments 0
No comments yet. Be the first to share your thoughts!
Leave a comment
Share your thoughts. Your email will not be published.