Ask a CISO how many employees have access to the finance system and you’ll get a number within minutes. Ask how many AI agents have access to it and you’ll usually get a long pause.
That pause is the opening for one of the most important new categories in security. Agents now read inboxes, query databases, file tickets, move money and change configurations. They do it with credentials, often borrowed from the person who set them up, and often with far more access than the task needs.
Agents break the old identity model
Identity and access management was built for two kinds of actors: people, who log in, and services, which run fixed code. Agents are neither. They make decisions at runtime, chain tools in orders nobody wrote down in advance, and can be steered by the content they read. A service account with broad permissions was a manageable risk when the code behind it was deterministic. Attach that same account to a system that can be talked into things, and the risk changes completely.
Every agent is a new identity with new permissions, and most enterprises can’t yet list them.
What good looks like
The companies we want to back treat agents as first-class identities with a lifecycle of their own:
- Discovery. Find every agent running across SaaS tools, internal platforms and developer environments, including the ones nobody registered.
- Least privilege, per task. Grant short-lived, narrowly scoped permissions for the job at hand instead of standing access.
- Attribution. Link every action to the agent, the person who delegated it and the instruction that triggered it.
- Revocation. Shut down one misbehaving agent in seconds without breaking the workflow around it.
Why this becomes a large company
The number of agents inside a typical enterprise is likely to pass the number of employees within a few years. Each one needs to be provisioned, governed, audited and retired. That is a budget line security teams already understand. They spend heavily on human identity today, and agent identity extends the same logic to a population that is growing much faster.
It is also hard for general-purpose model providers to own. Agent identity has to work across every model, every agent framework and every system of record. Enterprises will want a neutral control plane, not one tied to the vendor whose agents it is supposed to govern.
What we ask founders
When we meet companies in this space, we focus on three questions. Can you find agents the customer doesn’t know about? Does your product fit into the identity and security stack the customer already runs? And can you show a measurable reduction in exposure within the first ninety days? The teams with strong answers to all three are building something security leaders will rely on every day.