Identity · CA
SailPoint's Numbers: 97% of Agents Touch Sensitive Data, 21% of Firms Feel Ready
SailPoint's unified Identity Security launch this year came with a data point worth sitting with: the company's own research found that 97% of AI agents have access to sensitive data, while only 21% of organizations are highly confident in their ability to manage AI agent risk. That gap — near-universal exposure against a fifth of organizations claiming real confidence — is the clearest quantified version of a problem most agent-identity vendors have described only in qualitative terms.
The product response folds two previously separate lines, Agentic Fabric and Human Fabric, into one governance layer. Agentic Fabric targets non-human identities specifically: automated accounts, AI agents, and MCP servers. It uses endpoint and browser sensors to find agents that were never registered with IT, applies prompt filtering to catch sensitive data leaking through LLM interactions, and includes a centralized switch that can disable an agent the moment its behavior looks wrong.
What's notable isn't the sensor architecture — plenty of vendors are building similar telemetry — it's the ownership mechanic. SailPoint's agent onboarding lets teams assign named human owners to individual agents and track those service accounts under the same governance rules as employee accounts. That's a direct answer to the accountability question that keeps surfacing across the agent-identity field: when an autonomous system does something wrong, who is on the hook. Assigning ownership at onboarding time, rather than reconstructing it forensically after an incident, changes the default from 'find out who's responsible' to 'know who's responsible before anything happens.'
The timing tracks with a broader shift in how enterprises talk about this problem. SailPoint framed the launch explicitly around moving from periodic compliance reviews to continuous, real-time monitoring — the same logic that's pushed short-lived certificates and kill switches into other vendors' agent products recently. The 97/21 gap is the number that will get cited in board decks over the next year, not because it's dramatic, but because it's the first attempt to size the enterprise agent-governance problem in terms executives already understand: exposure versus confidence.
The open question is verification. SailPoint's figures come from its own research rather than independent audit, and the industry still lacks a shared, third-party methodology for measuring how much sensitive data agents actually touch across a typical enterprise stack. Until that exists, numbers like these are directionally useful but not yet comparable across vendors.