As AI agents begin to perform multi-step work, the assumptions behind conventional access management are under pressure. An agent may retrieve information, invoke tools and change records in rapid succession. The call at SailPoint Navigate to move away from standing privilege reflects a core identity governance challenge: permissions designed for stable human roles can be too broad and persistent for autonomous systems.
Why permanent access is a poor fit
Standing privilege gives an identity access continuously, whether or not it is currently needed. For human users, this can already create unnecessary exposure. For agents, the risk is amplified by speed, scale and delegated actions. A compromised or misdirected agent could use every permission available to it before a human notices. The difficulty is compounded when organisations cannot tell which agent initiated an action, which person or process authorised it, and what business purpose it served.
IGA programmes have historically centred on employees, roles and periodic access reviews. Agentic systems introduce identities that may be created dynamically, operate across application boundaries and depend on other identities. Without an inventory and ownership model, these accounts can become orphaned just like forgotten service accounts.
From standing access to governed access
Reducing persistent privilege starts with identity lifecycle management for agents. Each agent should have a unique identity, a named accountable owner, documented purpose and an approved scope. Its permissions should be linked to the workflows it is allowed to perform, rather than inherited from a broad administrator account.
Just-in-time access offers one practical pattern. An agent receives a limited entitlement for a defined task, subject to policy checks, and loses it when the task or approved window ends. High-impact actions can require human approval, while lower-risk operations may proceed under tightly bounded policies. The objective is not to place a person in every loop, but to make the degree of oversight match the consequence of the action.
Controls must extend through delegation. If an employee asks an agent to act, governance should preserve the relationship between the initiating user, the agent identity and the downstream action. Logs that capture this chain make investigations and audit reviews more useful. Where an agent can create other agents or credentials, those capabilities require explicit constraints and monitoring.
Putting controls into practice
Security teams can begin with discovery: identify AI agents, service accounts and the entitlements they hold. They can then remove unused access, establish ownership and classify permissions by risk. Access certifications should be event-driven where possible, triggered by changes to an agent, its owner, its connected tools or its business purpose, rather than relying only on a quarterly calendar.
Technical enforcement also matters. Short-lived credentials, policy-based approvals, separation of duties and rapid revocation can limit the blast radius of errors. IGA teams should collaborate with AI platform owners to ensure that access decisions are evaluated at the point of action and that exceptions are recorded.
For CISOs and IAM practitioners, the keynote’s central issue is operational: identity governance administration must adapt from managing static accounts to governing a changing population of human and machine identities. Moving away from standing privilege gives organisations a way to make agent access narrower, attributable and responsive to context.