SailPoint’s multi-year strategic collaboration with AWS points to a change in identity governance: AI agents and cloud workloads must be governed alongside employees. As enterprises deploy autonomous tools that read data, call APIs and initiate workflows, identity governance and administration becomes essential for assigning ownership, limiting permissions and recording machine actions.
Cloud identity systems often make access easy to grant but difficult to explain. Permissions may be inherited through roles, policies, groups and workload relationships. An AI agent can create a chain of downstream actions across services, making it difficult to determine which authority enabled an event.
An IGA lens adds business context. Governance teams need to connect cloud identities to an owner, application, use case and lifecycle state. They also need repeatable processes for requesting, approving, reviewing and revoking access. Collaboration between an IGA provider and a cloud platform can bridge infrastructure permissions and business accountability.
The first requirement is inventory. Organisations cannot govern identities they cannot discover. Identity lifecycle management should capture workloads, service roles, automation credentials and agent registrations, then identify stale, duplicated or unowned access.
The second requirement is least privilege with flexibility. AI agents may need temporary access, but standing administrator permissions create exposure. Time-bound entitlements, scoped roles and approval workflows reduce privilege while allowing automation to function. Policies should account for delegated actions, not only the identity starting a workflow.
Finally, governance needs evidence. Access certifications, exceptions and revocation events should support incident response and compliance reviews. Cloud activity can help prioritise reviews when an agent behaves differently from its approved purpose.