TechSignal.news
Cybersecurity

SailPoint and Omada Race to Govern AI-Agent Identities as 96% of Enterprises Overprovision Access

SailPoint and Omada both announced AI-agent governance capabilities this week, while Palo Alto Networks reported 96% of human identities hold excessive privileges.

TechSignal.news AI5 min read

SailPoint adds AI-agent discovery and kill-switch controls

SailPoint announced capabilities to discover, authenticate, and revoke AI-agent identities at its Navigate 2026 conference. The releases include agent discovery across SailPoint Agentic Fabric, conditional just-in-time access, and what the company calls a "kill switch" for immediate access termination.

The platform also introduces time-bound access controls and autonomous agents that can execute identity-governance tasks without standing privileges. On-premises customers get IdentityIQ 9.0, adding time-based role access and an automated upgrade tool.

SailPoint is positioning against traditional identity-governance vendors such as Omada, Saviynt, and IBM, while moving into privileged-access territory held by CyberArk, Delinea, Microsoft Entra, and Palo Alto Networks. The strategy bets that enterprises will consolidate separate identity governance, privileged-access management, and AI-security controls into a single platform.

The problem for buyers is timing. SailPoint's roadmap includes capabilities scheduled for Q4 fiscal 2027. Enterprises evaluating the platform should confirm which features ship now versus which remain development commitments. Distinguishing generally available products from roadmap promises matters when budgeting consolidation projects.

SailPoint-related reporting claims AI-agent deployment is outpacing identity-security capability by a factor of 40. The figure underscores the governance gap but lacks published methodology. Buyers should verify the denominator and measurement approach before using that ratio as a market benchmark.

Omada acquires EmpowerID for runtime agent authorization

Omada acquired U.S.-based EmpowerID on October 7, adding AI-agent discovery, lifecycle management, access certification, and runtime authorization to its identity-governance platform. EmpowerID CEO Patrick Parker joins Omada as chief innovation officer. Financial terms were not disclosed.

The transaction matters most to enterprises deploying autonomous agents that invoke APIs, modify records, or access sensitive data after initial provisioning. Traditional identity-governance platforms register agents in an inventory and assign access during onboarding. EmpowerID's technology makes authorization decisions at runtime, revokes access immediately, and provides audit evidence for each agent action.

Because the purchase price and integration schedule remain undisclosed, buyers should treat near-term product availability as uncertain. Avoid assuming the acquisition immediately delivers a production-ready unified platform. Ask Omada for integration timelines, feature availability dates, and whether the combined product requires separate licenses or modules.

Palo Alto Networks reports 96% of identities hold excessive access

Palo Alto Networks surveyed more than 2,900 cybersecurity decision-makers worldwide and reported that 96% of respondents said human identities have access beyond what their roles require. The finding supports demand for identity posture management, least-privilege enforcement, entitlement analytics, and just-in-time access.

The statistic gives security teams a quantitative rationale for funding access reviews, entitlement cleanup, and privileged-access reduction. It also suggests that IAM modernization should be measured by reduced excessive access, not merely by SSO or MFA deployment counts.

The caveat is that this is vendor-sponsored research. Buyers should examine the questionnaire, respondent composition, and definition of "beyond what is required" before treating it as an independent industry benchmark. The survey supports Palo Alto's competitive position against SailPoint, CyberArk, Delinea, Saviynt, Microsoft, and Wiz in identity posture and least-privilege enforcement.

Okta and Yubico push phishing-resistant authentication

Okta published a report October 7 emphasizing phishing-resistant authentication as attackers increase use of AI-enabled social engineering. Okta and Yubico are partnering to streamline issuance, management, and enforcement of hardware-backed credentials in enterprise identity systems.

A separate 2026 Global State of Authentication survey conducted by Talker Research for Yubico polled 1,890 technology and security professionals at enterprises with at least 500 employees across nine countries. The survey reported that nearly half of security professionals still rely on passwords despite broad awareness of stronger authentication methods. The survey was conducted July 2–16, 2026, so it measures awareness and adoption from mid-year, not the past week.

Enterprises should expect higher demand for FIDO2 security keys, passkeys, and device-bound credentials. Hardware-backed authentication increases deployment and replacement costs but reduces exposure to credential phishing and lowers reliance on password-reset operations. The partnership competes with passkey and phishing-resistant authentication efforts from Microsoft Entra ID, Google Cloud Identity, Cisco Duo, RSA, and Apple.

WALLIX launches sovereign identity platform for European buyers

French cybersecurity vendor WALLIX launched WALLIX Sovereign Identity Access on October 7. The offering combines identity lifecycle management with MFA, SSO, and identity federation, emphasizing that organizations retain control of identity infrastructure and data.

WALLIX is positioning the product against cloud-first suites from Microsoft Entra, Okta, Ping Identity, and CyberArk, particularly for European organizations with data-sovereignty or public-sector requirements. The launch is relevant to enterprises seeking alternatives to hyperscaler-controlled identity services in regulated industries and jurisdictions with residency, operational-control, or digital-sovereignty requirements.

WALLIX did not disclose pricing, customer counts, adoption figures, or performance benchmarks in the announcement. This is a strategic product launch, not quantified proof of market traction.

What to do now

Require IAM vendors to show how they discover, authenticate, authorize, monitor, and revoke AI-agent identities. Separate generally available capabilities from roadmap items, especially in SailPoint's agentic-security portfolio. Include phishing-resistant authentication in 2027 planning, comparing FIDO2 hardware keys, platform passkeys, and software authenticators. Measure IAM modernization success by reduced excessive access, not deployment of SSO or MFA alone.

IAMAI SecurityPhishing-Resistant AuthenticationIdentity GovernancePrivileged Access Management

Technology decisions, clearly explained.

Weekly analysis of the tools, platforms, and strategies that matter to B2B technology buyers. No fluff, no vendor spin.

More in Cybersecurity