Business Problem
Customers are adding non-human identities at scale: AI agents, service accounts, bots, and workloads with access to sensitive systems. Human access review is well understood (and legislated and standardized). Agent access review is not.
Teams struggle to decide what should be in scope (agent ↔ entitlement only, or also credentials, endpoints, owners, and runtime context), who should review, and what data makes a decision defensible. We are researching Certification of Agents as part of SailPoint Agentic Fabric and want to learn how you would like to govern and certify agent access today and where the process breaks down.
Sound familiar?
If you run certification programs, govern non-human identities, or partner with security and audit on access reviews.
Book discovery time with our Product team: Schedule a discovery session
How you can help
We want to understand how you certify agent and non-human identity access today and how you would like to do it in the future.
Schedule a 1:1 to discuss:
- A recent agent or NHI access review: what you needed and where it stalled
- Who should own these reviews in your org
- Whether human and non-human identities belong in the same campaign
- What evidence and remediation you expect after a decision
Schedule here: Schedule a discovery session