Identity governance has spent over two decades answering at least four key questions about every identity in the enterprise: who is it, what can it reach, who is accountable for it, and what changed.
Those questions haven’t changed for AI agents. Almost everything else has.
Agents are created by business users, not IT. They arrive without a joiner record, an owner, or a review cycle. They inherit permissions, chain access across systems, and hold credentials that outlive the projects that spawned them. In most organizations today, nobody can say how many agents exist, who owns them, or clearly define what they were built to do.
This session looks at why existing identity security tooling wasn’t built for a population like this, and what identity-first agent governance requires in practice: discovery and correlation across platforms, translating raw permissions into business capability, blast radius, ownership, drift detection and credential lifecycle.