SailPoint’s new Cursor Enterprise connector illustrates how identity governance is extending into AI-assisted software development. As coding agents become part of engineering workflows, enterprises need the same discipline around identity, access and accountability that applies to human developers and production applications.

The core problem is that an AI coding assistant can operate across repositories, tickets, development tools and cloud services while appearing to be an extension of a human user. If permissions are inherited broadly, a single agent session may expose source code, modify configuration or trigger deployment activity beyond the original task. Conventional joiner, mover and leaver processes do not fully address that level of delegated and contextual access.

A connector into an enterprise coding platform gives IGA teams a way to bring development identities and entitlements into governance workflows. Identity correlation can link a user, team or agent to authoritative employment and organisational data. Entitlement discovery can show which repositories, projects and actions are available, while policy rules can identify combinations that create unacceptable risk.

The connector is also relevant to least privilege. AI-assisted development should not rely on permanent broad access simply because an engineer may occasionally need it. Time-bound permissions, approval for sensitive repositories and separation between code contribution and deployment authority can reduce the blast radius of a compromised account or misdirected agent.

Access reviews must account for both direct and delegated access. A reviewer may need to distinguish a developer’s own repository permission from the permissions available to an AI tool acting on the developer’s behalf. That distinction becomes essential when an agent can read secrets, open pull requests, change infrastructure files or call CI/CD workflows.

For IGA programmes, engineering integrations should produce usable evidence rather than merely populate another inventory. Teams should be able to trace access from the authoritative identity through the coding platform and into approvals, policy exceptions and activity logs. With that chain in place, identity governance administration can support secure AI adoption without slowing every development workflow through manual approvals.