SailPoint’s completion of its acquisition of Entro Security highlights how identity security is expanding beyond employees and contractors. The strategic logic is closely connected to the rise of non-human identities: cloud workloads, applications, secrets and AI agents now represent a large and increasingly valuable access population. Bringing discovery and governance capabilities together reflects the pressure on enterprises to make that population visible and controllable.
The NHI visibility gap
Machine identities often sit outside traditional identity governance processes. A secret may be created by a developer, copied into a pipeline and used by several services without a durable owner. A cloud workload may inherit permissions that remain long after its deployment changes. These conditions make it difficult to answer basic questions about access: what exists, who is responsible and what would break if it were rotated or removed?
Point tools can identify exposed secrets or unusual activity, but discovery without governance leaves remediation fragmented. Security teams need to connect technical findings to policy, ownership and lifecycle decisions.
Why integration matters
An integrated approach can reduce the gap between finding a machine identity and managing its risk. Inventory data becomes more useful when it is enriched with entitlement context, business ownership, usage patterns and the applications that depend on a credential. That context supports prioritisation instead of forcing teams to treat every secret or service account as equally urgent.
Lifecycle automation is another important capability. Rotation, revocation and access certification must account for dependencies across cloud services and production applications. A governance workflow that cannot safely change a credential may produce compliance evidence while leaving the underlying exposure untouched.
Implications for AI agents
Agentic Identity makes the problem more dynamic. An agent may use several identities during a task or request access to a new tool based on its interpretation of an instruction. Governance must therefore cover the agent, its delegated credentials and the actions performed through them. Static ownership records are necessary, but runtime authorisation and detailed audit trails are equally important.
CISOs evaluating the market should look beyond acquisition headlines and ask how well a platform joins discovery, entitlement analysis and enforcement. NHI security programmes gain value when they can turn a machine identity finding into a measured action: assign an owner, reduce privilege, rotate safely or block use. The strategic direction is clear—identity governance is becoming a control system for machines as much as for people.