SailPoint’s completion of its Entro Security acquisition places non-human identity management closer to the centre of enterprise identity strategy. The transaction reflects a market reality: organisations cannot govern modern access by managing employees alone. Secrets, service accounts, certificates, workloads and AI agents now form a large and dynamic identity population.

The problem: fragmented machine identity visibility

Machine identities often emerge inside development, cloud and security tooling rather than through a central identity team. A developer may create a service principal, a pipeline may generate a token, and a cloud workload may receive a role automatically. These identities can be valid and necessary while still lacking an owner, a documented purpose or a reliable expiry date.

Fragmentation also creates blind spots between secrets management, cloud entitlement management and identity governance. A credential may be rotated without reducing its permissions, or an unused account may remain active because no system knows which application depends on it. For CISOs, this expands the attack surface and complicates evidence for compliance.

Why acquisition matters for NHI security

Bringing machine identity capabilities into a broader governance platform can connect discovery with remediation. An identity record becomes more useful when it includes where a secret is used, which workload owns it, what access it enables and whether the related application is still active.

The strategic benefit is not simply a larger inventory. It is the ability to apply policy consistently across human and non-human identities. Certification, risk scoring, ownership assignment and lifecycle actions can become part of the same operating model, while specialised controls continue to handle certificates and secrets.

Implications for Agentic Identity

AI agents increase the urgency because they can create or use machine identities dynamically. A governance platform must distinguish an agent’s identity from its sponsoring user and record delegated authority. Changes to the agent’s tools, model or workflow should be visible to reviewers and reflected in access decisions.

Buyers should therefore assess how well a platform links identity discovery, entitlement context, runtime activity and automated response. The strongest approach will reduce standing privilege, identify orphaned credentials and provide clear evidence of why an automated identity is allowed to act.