Blog
Getting Started Guide: Agent Identity Security
Author
kirby_fitch
SailPoint
Description
SailPoint has launched Agent Identity Security!
It enables you to discover, secure, and govern AI agents with the same rigor as human identities. SailPoint unifies AI agents and human identities in one control plane, ensures AI agents are owned and reviewed, and that no human can gain more access through them.
New Capabilities
AI Agent Inventory
The first step towards effective AI agent governance is visibility. For example, we see enterprises with an explosion of AI agents being developed by multiple teams across the organization. Team 1 is building AI agents in AWS Bedrock AgentCore, Team 2 in Azure AI Foundry, and Team 3 N8N.
You can manage AI agents on a schedule from agent infrastructure platforms including AWS Bedrock AgentCore, Azure AI Foundry, and Google Cloud Project Vertex AI via a new AI Agent Aggregations capability. You can also manage AI agents on-demand via the user interface or endpoint.
Tool Governance
The second step towards effective AI agent governance is knowing what your AI agents can do. For example, we often see agentic workflows using service accounts as tools to retrieve or take action against ServiceNow tickets.
It’s common for AI agents to use service accounts as tools for these operations. You can leverage a variety of utilities to classify, subtype, and then correlate these service accounts (machine accounts) to the appropriate AI agents (machine identities).
Ownership & Succession Planning
The third step towards effective AI agent governance is knowing who owns your AI agents and keeping that information up-to-date. As we mentioned above, you can expect to have multiple teams across the organization developing AI agents.
You can assign multiple owners to each AI agent, and Identity Security Cloud will keep your owners-up-to-date with succession planning automation.
User Authorization and Over-Permission Prevention
The fourth step towards effective AI agent governance is knowing who is using your AI agents and preventing them from accessing more via AI agents than their personal access.
You can assign user entitlements to each assistive AI agent much like you can assign user entitlements to an IdP application. You can then follow those user entitlement assignments to understand what human identities can use an assistive AI agent. Finally, you can run an over-permission report to understand when human identities have received new entitlements or data resources via AI agent usage.
AI Agent Reviews
The fifth step towards effective AI agent governance is regular reviews of human identities’ access to AI agents, and regular reviews of AI agents’ access to tools.
- You can run human access reviews to approve or revoke the entitlements that enable humans to access AI agents.
- You can also run AI agent access reviews to approve or revoke the entitlements that enable AI agents to access tools.
Problem
Tomorrow’s Today’s workforce is a blend of AI agents and human employees. Most organizations lack a strategy to define roles, responsibilities, and governance for digital workers. Unlike humans, AI agents rarely have standardized onboarding, access controls, or compliance oversight. Without clear processes to grant, monitor, and audit their access, enterprises risk misalignment, over-permissioning, and regulatory exposure. As AI agents become first-class members of the workforce, this gap becomes critical to close.
Solution Deep Dive
AI Agent Inventory
The first step towards effective AI agent governance is visibility. For example, we see enterprises with an explosion of AI agents being developed by multiple teams across the organization. Team 1 is building AI agents in AWS Bedrock AgentCore, Team 2 in Azure AI Foundry, and Team 3 N8N.
AI Agent Aggregation
You can aggregate AI agents on a schedule from authoritative agent sources including AWS Bedrock AgentCore, Azure AI Foundry, and Google Cloud Project Vertex AI via a new AI Agent Aggregations capability.
Here are the relevant connector documentation links to help you get integrated.
AI Agent Aggregations manages AI agents in the same way that Account Aggregations manages them for accounts. The agent infrastructure platforms should be regarded as authoritative sources of AI agent identities. This aggregation method uses connector-specific mappings to load the entities representing AI agents and their tools from each agent infrastructure platform. It then creates, updates, and deletes AI agents, which are represented as machine identities.
Aggregate AI Agents on the AWS SaaS Source
AI Agent CRUD UIs
You can also create, update, and delete AI agents via the UI. This option is useful for managing AI agents manually when a machine account representing an AI agent or its tools is recommended.
Create AI Agent
Update AI Agent
Delete AI Agent
AI Agent CRUD Endpoints
You can also manage AI agents on-demand via the Create machine identity, Update machine identity, and Delete machine identity endpoints. This is helpful for sources that don’t have an out-of-the-box connector (yet) including N8N. Identity Security Cloud is regarded as the source-of-truth for AI agents when this method is used.
You might also use Workflow to call these endpoints following an External Trigger or Form Submitted event to do something like create an AI agent when a form is submitted.
Create AI Agent Endpoint Example:
POST /v2025/machine-identities
{
"name": "New AI Agent",
"description": "A new AI agent's purpose.",
"businessApplication": "New-AI-Agent",
"owners": {
"primaryIdentity": {
"id": "611f11c7333e496789adc7a25b89892a",
"name": "kirby.fitch",
"type": "IDENTITY"
},
"secondaryIdentities": [
{
"id": "d9dc55515af140cdadc617a2c162155b",
"name": "Alan.Bradley",
"type": "IDENTITY"
}
]
},
"userEntitlements": [
{
"entitlementId": "01a8504f79473c0885b400716d577b02",
"sourceId": "4bb6a2dc163b459abe03fde710f8d415"
}
],
"subtype": "AI Agent",
"attributes": {}
}
Update AI Agent Endpoint Example:
PATCH /v2025/machine-identities/:id
[
{
"op": "replace",
"path": "/name",
"value": "Updated AI Agent"
},
{
"op": "replace",
"path": "/description",
"value": ""
},
{
"op": "replace",
"path": "/owners",
"value": {
"primaryIdentity": {
"id": "611f11c7333e496789adc7a25b89892a",
"name": "kirby.fitch"
},
"secondaryIdentities": [
{
"id": "d9dc55515af140cdadc617a2c162155b"
}
]
}
},
{
"op": "replace",
"path": "/userEntitlements",
"value": [
{
"entitlementId": "01a8504f79473c0885b400716d577b02",
"sourceId": "4bb6a2dc163b459abe03fde710f8d415"
}
]
}
]
Delete AI Agent Endpoint Example:
DELETE /v2025/machine-identities/:id
Tool Governance
It’s common for AI agents to use service accounts as tools for these operations. You can leverage a variety of utilities to classify, subtype, and then correlate these service accounts (machine accounts) to the appropriate AI agents (machine identities).
First, establish Machine Account Subtypes that are suitable for categorizing your AI agents (and other machine accounts).
Second, use Machine Account Classification policy to classify accounts that can be identified via simple rules, e.g., all accounts beginning with svc.. Use Machine Account Discovery to find everything else, e.g., accounts following non-standard naming patterns, etc.
Third, use Machine Account Mapping and/or manual Update Account tools to correlate these tools to their subtypes and AI agents.
Fourth, use account disable controls to shut these tools down when it’s time.
Machine Account Subtypes for AI Agent Tools
Visit a source’s Account Subtypes UI to define the types of accounts that exist on the source. For example, AI agent service accounts could be bucketed under a generic Service Account subtype, or set apart in an LLM Service Account subtype. You decide how to organize accounts into subtypes. Your decisions will impact downstream reporting options.
Visit the source’s Mappings UI to map account subtypes via policy using account attributes. You can also view and manually update an account’s subtype in the Account Management UIs.
Manage Machine Account Subtypes
Machine Account Classification for AI Agent Tools
Visit a source’s Classification UI to define policy for classifying machine accounts. For example, all Active Directory accounts where sAMAccountName starts with svc. could be defined as machine accounts.
Visit the Account Management > Machine Accounts UI to review the classified accounts after you save the configuration and use Process Classification.
Manage Machine Account Classification
Machine Account Discovery for AI Agent Tools
Visit the Account Management > Uncorrelated Accounts UI to review the machine accounts that have been recommended to you. You can accept a recommendation by correlating an account to a machine identity. This creates a new machine account.
Machine Account Mappings are run for each new machine account to promote attributes like owner, machine identity, and subtype per the source’s configuration.
Review & Accept Machine Account Recommendations
Machine Account Mappings for AI Agent Tools
Visit a source’s Mappings UI to define policy for mapping machine accounts to machine identities (AI Agents or Applications).
Machine Account Mappings are processed whenever a machine account is updated via aggregations or when the administrator use Process Classification. When an administrator makes manual updates to an account, we bypass future mapping updates to ensure their changes remain intact.
Here are some Machine Account Mapping configuration tips.
Mapping to Machine Account Owner
You might reference known service account owners in Active Directory’s manager attribute. In this scenario, you would map manager to nativeIdentity using the Account to Account matching option to define Machine Account Owner. Identity Security Cloud will look up an account’s manager value, find the related Active Directory account, and then find the human identity to which it’s correlated. That identity would be linked as the account’s owner.
Mapping to AI Agent (Machine Identity)
You might reference AI agent’s unique identifiers in Active Directory’s employeeNumber attribute. In this scenario, you would select employeeNumber under the Machine Identity mapping to link accounts to the AI agent. The value that you map into the Machine Identity field will be matched against the AI agent’s Business Application value. For example, if an account’s employeeNumber contains agent-123, it will be mapped to the AI agent with a matching Business Application value.
Leave this unmapped if you do not have a reliable attribute for this purpose (many organizations do not). We will auto-create identities for your accounts when this attribute is left unmapped.
Agent Identity Security was designed to complement Machine Identity Security. Machine Identities use a subtype of either AI Agent or Application. You can use this feature to map to either AI agents or application identities.
Mapping to Subtype
You might reference the account’s subtype in Active Directory’s employeeType attribute using values like HUMAN, AI, SERVICE, BOT, TEST, etc. In this scenario, you would select employeeType under the Subtype mapping to link accounts to subtypes.
After You Save Mappings
Visit the Account Management > Machine Accounts UI to review the updated mappings after you save the configuration and use Process Classification.
Always test your mappings in Sandbox before deploying them to Production.
Manage Machine Account Mappings
Manual Updates for AI Agent Tools via the UI
Visit the Account Management > Machine Accounts UI to review your subtype, classification, and mapping outcomes. You can make further updates to machine accounts here. For example, you could manually map an orphaned machine account to an AI agent or subtype.
You can use this feature to map to either AI agents or application identities.
Apply Manual Updates to Machine Accounts
In the same user interface, you can also shut down machine accounts that are no longer needed.
Disable Machine Account
Manual Updates for AI Agent Tools via endpoints
You could also update an account as we did in the previous section via the Update machine account endpoint.
This endpoint is useful for managing machine accounts via automation in addition to Machine Account Mappings.
You might also use Workflow to call this endpoint following an External Trigger or Form Submitted event to do something like ask a manager to select a new account owner following a leaver event.
You can use this feature to map to either AI agents or application identities.
Update Machine Account Endpoint Example
PATCH /v2025/machine-accounts/:id
[
{
"op": "replace",
"path": "/ownerIdentity",
"value": {
"id": "e777493c3df9445481d99b3a31cfdf17",
"type": "IDENTITY"
}
},
{
"op": "replace",
"path": "/description",
"value": "A sample description."
},
{
"op": "replace",
"path": "/environment",
"value": "Production"
},
{
"op": "replace",
"path": "/machineIdentity",
"value": {
"id": "92f13dfd-0467-4b1f-8de9-178e583a1e26",
"name": "Recruiter AI Agent (Assistive)",
"type": "IDENTITY"
}
},
{
"op": "replace",
"path": "/subtype",
"value": {
"id": "f2e46295-d209-41ae-8bb6-e4646735378c"
}
}
]
You could also disable an account as we did in the previous section via the Disable account endpoint.
You might use Workflow to call this endpoint following an External Trigger or Form Submitted event to do something like disable an account per an external signal or a user’s request.
Disable Machine Account Endpoint Example
POST /v2025/accounts/:id/disable
Ownership & Succession Planning
You can assign multiple owners to each AI agent, and Identity Security Cloud will keep your owners up-to-date with succession planning automation.
Update AI Agents’ Owners
Visit the Identity Management > AI Agents UI to manage AI agent ownership. You can use Update Identity in either the list or control panel to make changes. The primary owner designates the person who is directly responsible for the AI agent. The additional owners serve as fallback options when the primary owner is unavailable.
You can also update AI Agents’ owners via Update Machine Identity.
Apply Manual Updates to AI Agent’s Owners
Execute AI Agent Succession Planning When Primary Owner Leaves
Identity Security Cloud executes a succession check whenever a human identity moves to identityState:INACTIVE_LONG_TERM or is deleted. The succession check updates the leaver’s owned machine identities, removing the leaver, and promoting an additional owner. The leaver’s manager will be promoted when there are no additional owners.
Example Succession Planning Flow
User Authorization and Over-Permission Prevention
Let’s cover assistive agents vs. autonomous agents and the methods by which a human might become over-permissioned when working with AI agents. To do that, we’ll need to focus on these core topics:
- Types of AI agents
- Types of Entitlements
- Types of Tool Authorization Methods
Assistive Agents vs. Autonomous Agents
Agent Identity Security governs both assistive and autonomous agents. Our concerns change based on which it is. Here’s an overview of each:
- Assistive AI agents act with input from human identities. You can think of them as helpers who only move when someone hands them a key. A human provides the key by invoking the agent, and the agent uses it to open doors and carry out tasks. The main concern is whether the agent only unlocks the doors the human is allowed to open and only performs the actions the human is authorized to take.
- Autonomous AI agents act on their own, without input from human identities. Unlike assistive agents, no one hands them a key. They carry their own set of keys and decide when and how to use them. Because a human never directly invokes these agents, the concern is not about whether a person is authorized, but about whether the agent’s keys are properly governed and controlled.
User Entitlements vs. Access Entitlements
User entitlements will determine what human identities are authorized to use an AI agent. Access entitlements will determine what an AI agent can do. Here’s an overview of each:
- User entitlements: Human identities are authorized to use assistive AI agents via user entitlements. For example, human identities with the
Recruiter AI Agent (Assistive)entitlement are authorized to use theRecruiter AI Agent (Assistive)shown in the example below. Human identities can request user entitlements or receive them via roles and access profiles. Some agent infrastructure platforms do make user entitlements available for aggregation. User entitlements can be managed from the AI agent list or on the AI agent’s control panel under theDetailstab. Autonomous AI agents will not have user entitlements. - Access entitlements: AI agents’ are authorized to retrieve data and take actions via access entitlements. Access entitlements are found on the service accounts (machine accounts) the AI agents use as tools. Access entitlements can be viewed from the AI agent’s control panel under the Access tab. Both assistive and autonomous AI agents can have access entitlements.
Methods for Authorizing Human Users to AI Agents’ Tools
Human identities with the Recruiter AI Agent (Assistive) entitlement gain access to the Recruiter AI Agent (Assistive) and its tools. You can think of the entitlement as the lock on the office building’s front door. Once you are inside, different kinds of keys control access to the tools inside.
Three-Legged Authorization
This method is like using your own employee badge to open individual rooms inside the building. The Recruiter AI Agent (Assistive)’s tools ask you to present your personal credentials. Because you can only enter rooms your badge already allows, you are never granted more access than you should have. This keeps people from wandering into areas they are not cleared for.
Agent-Scoped Authorization
This method is like the company giving the Recruiter AI Agent (Assistive) its own master key. Anyone who is allowed to work with the Recruiter AI Agent (Assistive) gets to use that master key to open doors to the agent’s tools. It makes movement easier and more consistent, but it also means the master key must be carefully controlled, since it can open more than a regular badge might.
Risks of Agent-Scoped Authorization
Agent Identity Security focuses on the risks introduced by the agent-scoped model. When many human users share the same “master key,” it becomes harder to track accountability, prevent misuse, and enforce least privilege. Highlighting these problem areas helps organizations see where stronger governance and monitoring controls are needed.
Let’s show some practical examples of how this works!
Assign User Entitlements to an Assistive AI Agent
Agent Identity Security will aggregate user entitlements from the agent infrastructure platforms that make them available. Administrators will need to define user entitlements during the AI agent creation flow depending on the connector.
We assume that the Recruiter AI Agent (Assistive) entitlement authorizes access to the Recruiter AI Agent (Assistive)’s front door when working in this AI agent’s control panel.
Define an Assistive AI Agent’s User Entitlements
List Human Identities That Can Access an AI Agent
We can click an assistive AI agent’s user entitlements to view the human identities that are authorized to use them.
For example, following the Recruiter AI Agent (Assistive) entitlement from Recruiter AI Agent (Assistive) informs us that 8 human identities are authorized to use this assistive AI agent.
View an Assistive AI Agents' User Entitlements
View an Assistive AI Agents' User Identities
Review an AI Agent’s Access Entitlements
We can click an AI agent’s Access tab from their control panel to view the entitlements are found on the service accounts (machine accounts) the agent uses as tools. This is important information to know for both autonomous and assistive AI agents.
You want to know what access an autonomous AI agent has via its tools because that needs to be reviewed on a regular basis in line with other non-human access review requirements.
You really want to know what access an assistive AI agent has via its tools to prevent human users from becoming over-permissioned. The Access interface in this scenario tells us what entitlements a human user might gain via the assistive AI agent.
To build on the previous example, following the Recruiter AI Agent (Assistive) entitlement from Recruiter AI Agent (Assistive) informs us that 8 human identities are authorized to use this assistive AI agent. Visiting the Recruiter AI Agent (Assistive)'s Access interface tells us that 8 human identities are able to access two accounts: SVC_IIQ and SVC.SNOW. We know the NonHumans entitlement is benign, but did we mean to authorize 8 human identities to work with SailPoint_Catalog in ServiceNow?
Understanding how 8 users got stepped up to use SailPoint_Catalog on a single assistive AI agent is great! In the next section, we’ll show you how to derive the same insights across all assistive AI agents and their users.
View an AI Agent’s Entitlements
Review Human Identities That Are Over-Permissioned By Assistive AI Agents
You can use the Identities Overpermissioned by Agents report to run the analysis you saw in the previous section for all human identities, AI agents, entitlements, and data resources at once.
Running the Identities Overpermissioned by Agents Report
Visit the Global > Reports UI to run Identities Overpermissioned by Agents.
Insights Available for All Sources
This first sample report represents the insights you can derive for every source. Here we can see those same 8 identities we observed in the previous section, and the entitlements gained via their access to Recruiter AI Agent (Assistive). You cold keep scrolling to see how other human identities are overpermissioned by other AI agents.
AI Agent Reviews
Human Access Reviews for AI Agents
You can run human access reviews to approve or revoke the entitlements that authorize humans to access AI agents.
Review Human Identities With Access to Recruiter AI Agent (Assistive)
AI Agent Tool Reviews
You can also run AI agent access reviews to approve or revoke the entitlements that enable AI agents to access tools.
Review Recruiter AI Agent (Assistive)'s Access
Compliance
Rest assured knowing that all critical changes to AI agents, tools, and Agent Identity Security configurations are fully-audited. This information could then be forwarded to your SIEM tools. Here is an overview of the most important Agent Identity Security audit events:
Create Machine Identity Passed
Create Machine Identity Passed
Update Machine Identity Passed
Update Machine Identity Passed
Delete Machine Identity Passed
Delete Machine Identity Passed
Update Machine Account Passed
Update Machine Account Passed
Update Machine Account includes all creations, updates, and re-correlations of machine accounts.
To ask questions and learn more please visit the Developer Community.