{
    "success": true,
    "data": {
        "id": 1938265,
        "msgid": "sailpoint-identity-security-must-protect-ai-agents-and-non-human-identities-1787579686",
        "date": "2026-08-24 19:49:00",
        "title": "SailPoint: Identity Security Must Protect AI Agents and Non-Human Identities",
        "author": "",
        "source": "ANTARA_ID",
        "tags": "",
        "topic": "Technology",
        "summary": "SailPoint has urged companies to extend identity security beyond human users to cover AI agents, machines, applications, APIs, and tokens as organisations become increasingly autonomous. The company advocates shifting from static identity management to Adaptive Identity Security, including Zero Standing Privilege and Just-in-Time Privilege for AI agents. It also highlights the risks of shadow AI and the need for visibility, governance, and auto-remediation across the entire digital workforce.",
        "content": "<p>The development of artificial intelligence (AI) is pushing companies\ntowards increasingly autonomous organisations. This shift means identity\nsecurity management can no longer focus solely on humans, but must also\nencompass AI agents, machines, applications, APIs, tokens and other\nnon-human identities.<\/p>\n<p>SailPoint Senior Vice President and General Manager for Asia Pacific,\nChern-Yue Boey, said non-human identities can work on behalf of humans,\nmake decisions and execute actions at machine speed. \u201cCompanies are no\nlonger just talking about digital transformation; they are talking about\ntransforming their companies from automated enterprises into autonomous\nenterprises,\u201d Boey said in Jakarta.<\/p>\n<p>According to Boey, companies moving towards autonomous organisations\nneed to ensure visibility across the entire digital workforce, be able\nto control the requests and actions of those identities, and have the\ncapability to perform auto-remediation when inappropriate actions occur.\n\u201cThe fundamental control point here is identity,\u201d he said.<\/p>\n<p>He said the previously static approach to identity security needs to\nshift towards Adaptive Identity Security. Access, particularly for AI\nagents, should not be granted permanently. The concepts of Zero Standing\nPrivilege and Just-in-Time Privilege allow AI agents to obtain access\nonly when needed to perform a task.<\/p>\n<p>SailPoint divides identity ecosystem management into three pillars:\ndiscovery, governance, and protect and remediate. At the discovery\nstage, companies need to identify all human and non-human identities\nwithin their digital ecosystem. Those identities must then be recorded\nin a registry and have clear, immutable human ownership.<\/p>\n<p>On the governance aspect, companies need to ensure identities can be\nmanaged and audited, including when an AI agent passes work on to\nanother agent, application or data. Meanwhile, protect and remediate\nencompasses the ability to detect anomalous actions and either halt the\nactivity or escalate it to a human to determine the next step.<\/p>\n<p>Boey also highlighted the risk of shadow AI, namely the use of AI\ntechnology that is unknown to or not authorised by the company. One risk\nis employees entering confidential company information into AI services\nwithout oversight. In addition, tokens and API keys used by AI agents to\naccess applications and data can also become an attack surface.<\/p>\n<p>\u201cIdentity security is no longer enough if it only looks at access to\napplications; it needs to extend to the data level, including the chain\nof relationships from humans, digital workers, agents and applications\nto data,\u201d he said.<\/p>\n<p>To anticipate these risks without hampering innovation, SailPoint\nencourages the adoption of shift-left security by integrating security\naspects from the application and AI agent development stage. \u201cManaging\nand controlling human identities alone is no longer enough. Securing\nnon-human identities such as AI agents and machines is now equally\nimportant,\u201d he said.<\/p>\n<p>Boey stressed that AI agents have no morals or ethical intuition and\nmerely execute commands to complete tasks. Therefore, companies need to\nensure every digital identity can be identified, has a clear owner, and\nis controlled throughout its activity lifecycle.<\/p>\n<p>\u201cThe core principle is simple: you can only control what you know,\u201d\nhe concluded.<\/p>",
        "url": "https:\/\/jawawa.id\/newsitem\/sailpoint-identity-security-must-protect-ai-agents-and-non-human-identities-1787579686",
        "image": ""
    },
    "sponsor": "Okusi Associates",
    "sponsor_url": "https:\/\/okusiassociates.com"
}