Most organizations cannot answer three basic questions about their non-human identities: what exists, what can it access, and who is accountable for it. "Technical" accounts are routinely excluded from access certifications or rubber-stamped by reviewers who cannot see what they actually do a gap that becomes dangerous once AI agents enter the picture. As Matthew Gardiner has argued in his analysis of the agentic enterprise, unlike a static service account, an agent reasons, chains actions across systems, and acts on behalf of many users through pooled, elevated identities. Between two quarterly reviews, a continuously operating agent can take a year's worth of human-equivalent actions, entirely unobserved, and none of it sits outside audit scope, since accounts posting to financial systems are fully within SOX and ITGC regardless of whether a human or a machine touched them.
Matthew Gardiner, Fellow Analyst at KuppingerCole, opens with our independent view on why non-human identities and AI agents demand a shift from point-in-time to runtime governance, walking through how segregation-of-duties failures can span a chain of identities — one agent creates a vendor, a bot posts the invoice, an integration account releases the payment — invisible to per-identity review.
Jason Gzym, VP of Solutions Engineering & Advisory at Pathlock, follows with how enterprises are putting the See–Assess–Enforce framework into practice: building a complete NHI and agent inventory with named ownership, scoring risk by privilege and activity, and enforcing policy at the moment of action with continuous, audit-ready evidence.
Who should attend
Ideal for IAM and IGA leaders, SAP and ERP security teams, GRC and audit owners, and CISOs accountable for identities that do not have a human face.
See All Locations
See All Locations