SailPoint is expanding its identity security platform to address a workforce increasingly made up of human users, machines, and AI agents, unveiling new autonomous security capabilities alongside updates to Human Fabric and the release of IdentityIQ 9.0 at its Navigate 2026 conference.
The announcements include autonomous agents designed to enforce policy and reduce excessive privileges; real-time identity security posture management; expanded controls for discovering and governing AI agents; and zero standing privilege for both human and machine identities. SailPoint is also modernizing its cloud-native Human Fabric platform and IdentityIQ for organizations with hybrid, on-premises, and highly regulated environments.
For channel partners, the broader shift could expand opportunities in identity modernization, AI governance, privileged access, and compliance as enterprises look to control not only employee access but also the growing number of autonomous agents operating across their environments.
SailPoint expands Human Fabric for enterprise identity governance
The capabilities for SailPoint Human Fabric, its cloud-native identity security product, include three major updates:
- Access certifications enhancements: This re-platformed certification engine is built to handle enterprise-scale access reviews without record limits or data delays. It removes the need for administrators to manually split large campaigns and includes a faster, more intuitive reviewer interface and cryptographic, GxP-compliant sign-off for regulated industries.
- Proactive Separation of Duties (SoD): SailPoint’s enhanced SoD engine will provide real-time evaluation that proactively blocks toxic access combinations at the moment of request. It flags conflicts caused by other pending requests still in flight, preventing violations before they occur.
- Conversational Access Requests: This new AI-powered agent allows users to make access requests in natural language directly from their chat tools. It supports custom forms, allowing employees to seamlessly provide necessary business justifications and compliance details within the chat flow.
“Most vendors ask their customers to choose between a growth story or a stewardship story, but the reality of the modern enterprise is not that simple,” said Chandra Gnanasambandam, EVP and CTO, SailPoint.
“Today, we are delivering on both fronts. We are advancing the frontier of cloud identity security with Human Fabric while also demonstrating our commitment to the customers who rely on IdentityIQ for identity security. This is one modernization effort on two fronts, ensuring every customer has a path forward without compromise,” Gnanasambandam continued.
IdentityIQ 9.0 targets hybrid and regulated environments
IdentityIQ 9.0 is designed for customers with extensive data residency requirements, strict regulatory constraints, or deeply customized programs.
The latest solution provides a parallel modernization path for hybrid and on-premises deployments, centered on stronger governance, including granular, time-based access for roles and entitlements, and a rebuilt technical foundation running on modern application servers, with a refreshed user experience that streamlines access reviews and application definition.
SailPoint is also offering an automated upgrade tool with this release. It scans a customer’s environment and automates the manual work required to update, addressing the primary risk that stalls on-prem upgrades and proving that customers can evolve their existing deployments.
Autonomous agents bring AI identity security into focus
SailPoint’s expansion of product innovations across its unified platform is designed to deliver real-time defense for discovering, governing, and protecting all human, machine, and AI agent identities.
Other key announcements that SailPoint made at Navigate 2026 include:
- Introducing SailPoint Autonomous Agents: SailPoint is debuting three classes of Autonomous Agents that enforce policy, right-size privileges, and protect systems without disrupting legitimate business automation.
- Autonomous Identity Security Posture Management (A-ISPM): New A-ISPM uses the live identity context in SailPoint Atlas to continuously uncover critical exposures across all identity types, then closes the loop with real-time remediation.
- Expanded SailPoint Agentic and Human Fabrics: The Agentic Fabric is expanding to map the entire AI agent surface area, enabling shadow AI discovery, runtime authorization, and instant ‘kill switch’ controls, while simultaneously advancing its Human Fabric with next-generation certifications and segmented identity data to provide enhanced access governance.
- Zero standing privilege for humans and machines: New Just-in-Time provisioning (JIT-P) with conditions – plus effective privilege visibility – replaces always-on access for people, service accounts, and AI agents alike.
SailPoint’s new Autonomous Agents are built to govern and protect the agentic ecosystem. They use identity context to distinguish legitimate intent from malicious activity and govern the agentic lifecycle, which includes: continuously monitoring runtime actions, intercepting threats, and right-sizing permissions to enforce zero standing privilege at machine speed.
“Autonomus agents are no longer just experimental copilots; they are becoming the primary execution layer of modern enterprises,” said Matt Mills, President of SailPoint. “Enterprises cannot afford to slow down AI innovation out of fear, nor can they afford ungoverned access chaos.”
“Moving beyond Zero Trust to Autonomous Identity allows organizations to master the converged human-plus-AI workforce, eliminate invisible risk, and innovate with complete confidence,” Mills continued.
SailPoint adds real-time remediation and zero standing privilege
The new A-ISPM continuously detects dormant accounts, partially offboarded identities, orphaned access, shadow admins, and privileged outliers hidden deep in access paths. The solution then closes the loop on each organization’s terms, with remediation ranging from one-click fixes.
Further, SailPoint is delivering four core customer outcomes through new innovations:
- Comprehensive discovery: New endpoint and browser sensors, SIEM and XDR telemetry, and vault and pipeline NHI discovery bring MCP servers, tools, credentials, and data stores into view. Data Access Security adds classification integrations with Microsoft Purview and BigID plus new connectors for Atlassian Confluence, Google BigQuery, and AWS Redshift.
- Enabling compliance: New Agent Audit by SailPoint will turn agent inventory and governance activity into framework-aligned evidence reports that can be exported in one action, customized, or scheduled, making audit preparation repeatable.
- Strengthening security posture: JIT-P from SailPoint grants access only when needed, with conditions such as business justification, reauthentication, and activation via Slack or ServiceNow. Agentic Fabric, meanwhile, delivers prompt monitoring with policy-based redaction and blocking, as well as behavioral risk detection. Human Fabric also features a CrowdStrike Foundry App and SecOps containment actions.
- Streamlined operations: Human Fabric will now also offer next-gen access requests with an embedded Harbor Pilot Access Request Agent. The agent – which is upcoming – will let admins explain and draft access policies for people and agents in plain language, and Agentic Fabric provides one-click agent lifecycle controls and an agent kill switch.
Additionally, SailPoint announced that the Entro Security integration into SailPoint Agentic Fabric will soon be complete.
This integration includes Entro-powered credential lineage, exposed secret discovery, and prompt-intent monitoring into Agentic Fabric.



