New Product: SailPoint Agentic Fabric

SailPoint Agentic Fabric (SAF) is now available!

ISC tenants entitled to Agentic Business or Agentic Business Plus (Commercial and FedRAMP where applicable) will begin to see the new Agentic Fabric UI in their production environments starting today.

MIS and AIS tenants will notice the new Agentic Fabric tab in the top navigation. You’ll also see up to two new left-nav items: Applications and Accounts. These views surface your machine accounts (IAM roles) and machine and application identities in one place, giving you greater visibility into your identity environment.

:date: Important dates

Milestone Date
Sandbox July 22, 2026
Production August 4, 2026

SAF delivers unified discovery, governance, and protection for AI agents and non-human identities (NHIs) across enterprise, endpoint, and browser surfaces — supporting 32+ agent frameworks, platforms, and apps from day one. SAF makes agents and NHIs first-class, governable objects across SailPoint.

:red_exclamation_mark: Problem

Organizations deploy AI agents rapidly, often outpacing their ability to secure and govern them. Without unified discovery and governance, teams rely on fragmented tooling, which slows risk assessment, sanctioning decisions, and remediation.


:light_bulb: Solution

SailPoint Agentic Fabric delivers an integrated agent governance experience in Identity Security Cloud. It features interactive onboarding, a unified NHI registry, an embedded Identity Graph, endpoint and browser discovery, ownership and lifecycle controls, and audit-ready reporting.

Vast agent framework coverage

Support for 32 agent frameworks across endpoint, enterprise, and browser surfaces gives you broad visibility and governance coverage from day one.

Endpoint agent — Claude Code, Claude Desktop, Cursor, Cline, Windsurf, GitHub Copilot, Observer AI, Openclaw, NemoClaw, OpenAI Codex, Gemini CLI, Hermes, Openshell.

Enterprise agent — Amazon Bedrock agents, Amazon Bedrock AgentCore agents, Anthropic Claude Console managed agents, Databricks Mosaic AI agents, Google Vertex AI Platform agents, Microsoft Copilot Studio agents, Microsoft Foundry agents, Salesforce Agentforce agents, ServiceNow AI Platform agents, Snowflake Cortex AI agents, Microsoft Agent 365 (*beta version), N8N Agents, WIZ Agents and custom agents (BYO schema/API).

Browser agent — Zendesk, MS Office Copilot 365, Cursor, Dify, Claude, OpenAI.

There are several capabilities included in the detailed announcement below that have been previously released. This includes Creation-based Access Requests, Certifications, and Agentic Succession Planning.

DISCOVER AGENTS

Single unified registry

Summary
  • Non-Human Identity (NHI) Registry — Provides a single view of enterprise, endpoint, and browser agents where you can quantify, filter, and sort by risk. You can also manage ownership (including Governance Groups), organize agents into business apps, and jump directly to usage and access graphs. It supports 32+ agent frameworks across enterprise (e.g., Amazon Bedrock, Microsoft Copilot Studio, Salesforce Agentforce), endpoint (e.g., Claude Code, Cursor, GitHub Copilot), and browser (e.g., MS Office Copilot 365, Claude, OpenAI) surfaces.

  • Total NHIs MySailPoint widget — This dedicated SAF widget on the MySailPoint landing page provides immediate visibility into NHI usage. It surfaces total NHI counts, trends over time, and key signals at a glance so customers can assess their posture and navigate directly to SAF workflows for investigation and action.

Discovery

Summary
  • Onboarding — A fully interactive, preference-driven Getting Started experience builds a turnkey adoption plan. Select your systems, follow the steps, and move seamlessly from first sign-on to activation:

    • Connect — IdPs, endpoint sensor (SEAS), browser extension (SBAS), AWS via IAM Temporary Delegation, and Microsoft Entra.

    • Integrate SIEMs — Splunk Cloud, Sumo Logic, Microsoft Sentinel, Google SecOps, and CrowdStrike Falcon Data Replicator for SIEM-based agent discovery.

    • Sanction — Classify apps so agents automatically inherit sanctioned or unsanctioned status.

    • Review & Activate — Confirm your setup, jump back to unfinished steps, or skip ahead. Non-linear navigation lets you work in the order that fits your needs.

  • SailPoint Endpoint Agent Security (SEAS) — This lightweight endpoint sensor and Direct Connection source pushes real-time, event-driven discovery of endpoint-resident AI agents into SAF. It acts as the ground-truth layer for agents on employee devices that MDM, EDR, and cloud connectors miss. It surfaces 13+ endpoint agent frameworks (e.g., Claude Code, Cursor, GitHub Copilot) along with their agentic surface area across NHIs, credentials, MCP servers, tools, skills, and plugins. It includes deep lineage from endpoint to agent; owner attribution that resolves the OS user to an accountable human identity in ISC; privacy by design so raw secrets never leave the device; and SIEM enrichment that adds full lineage to existing SIEM-discovered records rather than duplicating them.

  • SailPoint Browser Agent Security (SBAS) — This zero-touch browser extension surfaces 6+ browser agent frameworks accessed through the web browser (e.g., MS Office Copilot 365, Claude, OpenAI), along with their agentic surface area across NHIs, credentials, MCP servers, tools, skills, plugins, and workflows.

  • Machine Account Discovery — Identify NHIs hidden among your accounts using ML-powered recommendations, clear rationale for each classification, and one-click acceptance. Supported sources include Microsoft Active Directory, Microsoft Entra, Google Workspace, OpenLDAP, Workday Accounts, and Linux.

  • Datasets & Resources — Collect all NHIs at scale — agents, credentials, MCP servers, tools, skills, plugins, workflows, accounts, and IAM roles — using a new data ingestion model that extends governance across the full agentic surface area. Dedicated Resources let you configure schema and owner correlation per identity type. Flexible Datasets group multiple resources on a single aggregation schedule, and an out-of-the-box AWS setup delivers preconfigured Bedrock and AgentCore datasets and resources.

  • Wiz CNAPP connector — Connect Wiz to SailPoint to discover and govern Wiz users, roles, and projects. Bring Wiz service accounts and cloud resource inventory — including AI agents — into Agentic Fabric for unified NHI discovery and management.

Visibility

Summary
  • Identity Graph — Trace access lineage from users and agents through NHIs directly to sensitive data (e.g., User → AgentCore agent → IAM role → S3 bucket). This graph is embedded in each agent’s Access tab with no extra configuration required for entitled SAF tenants. Learn more in the Identity Graph documentation.

    • Inbound/outbound access in one view — See who can invoke an agent and what the agent can reach without switching graphs.

    • AWS IAM role paths — See which identities — including Bedrock and AgentCore agents — can assume a role and what resources that role can access.

  • Data Access Security + Identity Graph — Harness the power of DAS and Identity Graph to expose agent-to-data pathways, gaining complete visual clarity into how agents access sensitive S3 buckets and your most critical assets.

  • Lineage Map (Preview only) — We unified the Entro Lineage Map into SAF as the Lineage Map, accessible from each NHI’s Access tab. Trace exactly how your environment uses credentials (owners, consumers, tokens, permissions) and agents (owners, sources, connected services). (Please contact your CSM to request Preview access.)

Posture

Summary
  • Registry risk filtering, sorting, and details — Within the Non-Human Identity Registry, sort and filter agents by risk for a basic posture assessment. Then, open the agent’s Risk tab to view the exact details behind how SAF determined the risk score.

  • Business Application sanctioning — Use this admin-managed registry to define business applications and signatures that organize agents into apps. Admins set sanctioned or unsanctioned status during onboarding or post-onboarding via a dedicated Business Applications UI. Matching agents automatically inherit the sanctioning decision. Every tenant ships with a SailPoint-curated baseline; admins can override defaults and audit every decision.


GOVERN

Lifecycle management

Summary
  • Agent provisioning — Activate and deactivate agents directly from SAF, eliminating the need for admins to act in each source system. This empowers governance teams to manage agents from provisioning to retirement in a single control plane. It features configurable approval settings and request tracking in the Request Center (My Requests → Agent Requests), ensuring you centrally govern, approve, and record lifecycle decisions.

Activate/Deactivate Agent from the Actions menu

Track agent requests under Request Center > My Requests > Agent Requests

  • Machine Account Provisioning (GA’d prior to 7/30) — Enable, disable, and delete machine accounts directly from SAF so governance teams can complete lifecycle actions without code-based rules. This gives customers a low-code path to remove accounts, not just disable them, while centralizing audit visibility and lifecycle evidence.

  • Machine Account Creation (GA’d prior to 7/30) — Centralized SAF request flow for creating machine accounts at scale, with robust approvals, password creation when needed, and automated provisioning to target systems. It covers service accounts, bots, generic accounts, and other NHIs to reduce inconsistent provisioning, missed approvals, and unmanaged access.

Machine Account Creation

Ownership & succession

Summary
  • NHI ownership collection, correlation & succession — Collect owner signals from connected sources and assign accountable humans across agents, machine accounts, and all NHIs. Map collected attributes to identities in ISC, assign a Primary Owner plus Additional Owners or governance groups (for example, defaulting AgentCore agents to an AWS AgentCore owners governance group), and automate succession when personnel change.
  • Agentic Succession Planning — Agents can have multiple accountable owners, with automated succession that keeps ownership current when an owner leaves by assigning the next most accountable person or governance group. Owners are notified when ownership changes occur.

  • NHI Ownership Portal — Self-service portal accessed from MySailPoint where designated owners view and act on NHIs they own directly or via a Governance Group. This makes ownership operational rather than symbolic, letting owners manage lifecycle actions, initiate Machine Account Creation requests, and maintain accountability without admin intervention.

  • IIQ connector for human owner and user context — Turnkey IdentityIQ-to-SAF integration via a new IIQ plugin that auto-creates an IIQ source, sets up an identity profile, and ingests IIQ identities into SAF for use as users and owners of NHIs. IIQ identities can be brought into SAF without installing a virtual appliance in SAF.

Agent access requests & certifications

Summary
  • Machine Account Access Requests — Access Request and approval flows are supported as part of the machine account creation request flow, so teams govern access while creating machine accounts. Post-creation access requests are also now available.

  • NHI Ownership Portal lifecycle actions — Designated owners can initiate and manage NHI lifecycle actions.

  • NHI access reviews — Supports access reviews for NHIs, so compliance teams include them in review campaigns on the required timelines.

Agent audit & compliance

Summary
  • Agent Audit & compliance reporting — Auditor-ready records for agent inventory, ownership, monitoring, and governance evidence. Admins can generate framework-aligned reports (Colorado AI Act, EU/GDPR, HIPAA, etc.) with preview, individual or bulk export, and scheduled delivery, so compliance teams can demonstrate governance posture on demand.

PROTECT

Agent authorization

Summary
  • AI Plugin AuthZ (Preview Only) — Define authorization policies in SAF and enforce them in real time when employees use supported AI tools and plugins, including Claude Code, Claude Workspace, Cursor, and Gemini CLI. You can block high-risk actions — for example, stopping a Cursor session from connecting to an unsanctioned MCP server — and review a log of what was attempted and whether it was allowed or denied.

  • Lineage Graph (Preview Only) — See how agents, tools, and credentials are actually used in day-to-day work, not just what exists in your inventory. Lineage Graph brings runtime usage visibility into SAF so security teams can investigate real agent activity in context alongside discovery and access data.

Prompt & response security

Summary
  • Prompt Security (Preview only) — Inline inspection of prompts submitted to GenAI applications (e.g., ChatGPT, Claude, Gemini), detecting secrets, PII, and PHI before the prompt reaches the AI provider. Admins can configure monitor-only or automatic redaction policies so sensitive data exposure is governed without blocking end-user workflows.

CLI threat detection & remediation

Summary
  • Endpoint and plugin coverage — SEAS discovers CLI agents such as Claude Code, Cursor, OpenAI Codex, and Hermes on employee endpoints. Where AI Plugin AuthZ is enabled, the same policies can block unsafe plugin and MCP connections at runtime.

Response and remediation

Summary
  • SailPoint Identity Security Intelligence for Humans (APIs) — Bring human identity context — privileged access, account sources, outliers, and recent access changes — into the SIEM, SOAR, and XDR tools your SecOps team already uses.

  • SailPoint Identity Security Intelligence for Agents (APIs) (Preview Only) — Extend that same model to non-human identities. SecOps tools can query agent attributes, ownership, and entitlements alongside human identity data.


:busts_in_silhouette: Who is affected?

This release applies to Identity Admins, Security Operations Analysts, and cloud security teams responsible for governing AI agents and NHIs — especially organizations with enterprise agents on AWS Bedrock and AgentCore, endpoint agents on managed devices, or browser-based agents.

  • ISC tenants entitled to Agentic Business or Agentic Business Plus (Commercial and FedRAMP where applicable).

  • MIS and AIS tenants will notice the new Agentic Fabric tab in your top navigation. You’ll also see up to two new left-nav items: Applications and Accounts. These views will surface your machine accounts (IAM roles) and machine and application identities in one place, giving you greater visibility into that part of your identity environment.


:clipboard: Action required

Most capabilities are delivered through entitled SAF tenants without additional configuration. A few exceptions apply:

  • AWS IAM Roles / Datasets & Resources — Ensure your environment is connected through the AWS SaaS connector, which may require an update. Existing MIS and AIS customers with AWS already configured will be migrated to the new datasets and resources model automatically.

  • Owner correlation — Optional but recommended: configure default owner mapping in Datasets and Resources to enable automated ownership assignment. Manual assignment also remains available.

  • Agent provisioning (activation or deactivation) — The connected source must support the operation, and you may need to configure approval routing under GlobalSystem SettingsApproval SettingsAgent Requests.

Preview What’s Next

We want to hear from you! We are excited to share we will be launching a closed preview for our next set of SAF features and enhancements. Our preview will launch on 7/30/26 and feature Prompt Security and agent coverage for Response & Remediation, as well as initial capabilities that integrate Entro Security, including Lineage Map and AI Plugin AuthZ. This Preview will be available through August. Please contact your CSM to request Preview access.

:books: Documentation

How are we defining what constitutes an individual agent? I asked this at Identity Day and none of the SEs I asked knew. If AIS is licensed on a per-agent identity basis, I need to understand how many agents I have in the supported systems before I can even get a quote from my AE, but I can’t do that without understanding what we’re considering an “agent identity.” Are there specific API endpoints on the supported systems that can give me an accurate count, or specific places platform admins can look in their UIs?

Hey @sup3rmark.

We pick the most logical abstraction of an agent that’s valuable to govern on an app-by-app basis. For example, the Cursor IDE on each endpoint is an agent.

We’d be glad to onboard a few of your agent platforms in PoC so you can get a sense for how it works! I’ll have someone reach out to you!