AI Agents Get Identity and Access Control
SailPoint is expanding its Agentic Fabric with AI-agent discovery, temporary access, real-time monitoring and automated control what autonomous AI agents can access and do.
Source: https://www.helpnetsecurity.com/2026/10/06/sailpoint-agentic-fabric-innovation/

AI Agents Now Need Identity and Permissions
AI agents are becoming capable of doing much more than answering questions. They can call APIs, interact with enterprise applications, access databases and perform multi-step tasks with limited human intervention. As these systems become more autonomous, companies face a new security problem: how do you control what an AI agent is allowed to access and do?
SailPoint has expanded its Agentic Fabric with new identity-security capabilities designed specifically for AI agents. The updates include AI-agent discovery, temporary access, runtime monitoring, automated remediation and autonomous defenses. Help Net Security
The basic idea is simple: every AI agent needs an identity and clearly defined permissions.
Traditional access management often relies on permanent credentials and manual approval processes. But that approach becomes difficult when autonomous agents can make large numbers of tool calls at machine speed. SailPoint says its new Autonomous Agents can continuously monitor runtime activity, identify potentially malicious behavior and adjust permissions while keeping legitimate activity running. Help Net Security
Another important feature is Just-in-Time provisioning. Instead of giving an agent permanent access to a system, access can be granted only when it is required and under specific conditions. This supports the principle of reducing “standing privilege,” where an account or agent always has access even when it is not needed. Help Net Security
SailPoint is also adding capabilities to discover hidden or “shadow” agents, credentials, MCP servers, tools and data stores. This matters because security teams cannot properly protect AI systems they cannot see. The platform also includes agent auditing, policy-based prompt monitoring, behavioral risk detection and an agent kill switch. Help Net Security
The bigger trend is that AI-agent identity is becoming a security layer of its own. As businesses deploy more coding agents, research agents, customer-service agents and workflow agents, simply authenticating a human user will no longer be enough.
The future model could look like:
AI Agent → Identity → Permission → Tool → Action
For Indian startups, enterprises and developers, this means AI security will increasingly involve controlling not only who can access a system, but also which AI agent can access it, why it needs access, how long it can use it and what actions it is allowed to perform.