SailPoint & AWS ally on AI agent identity governance
SailPoint has signed a multi-year strategic collaboration agreement with Amazon Web Services focused on identity governance for AI agents running on AWS, as enterprises increase the use of agentic AI alongside human and machine identities.
The deal positions SailPoint as a preferred identity governance option for agentic AI built on AWS, the companies said. It expands an existing partnership and outlines a plan for a unified governance layer across identities that interact with AWS services.
AI agents are increasingly deployed to act on behalf of users, applications and systems. This shift creates new access pathways in enterprise environments and raises questions about how organisations define ownership, manage permissions and maintain accountability for non-human identities.
Unified governance
The collaboration targets lifecycle governance across human, machine and agent identities. SailPoint and AWS plan a single framework for ownership, certification and decommissioning across AWS environments.
Another focus is "least privilege" access. The companies plan to use real-time usage data from AWS CloudTrail to inform access decisions, reducing reliance on static permissions and scheduled access reviews that can lag fast-changing workloads.
The work also includes a unified identity graph, intended to provide an authoritative view of access relationships across workloads, federated identities, services and data. Identity graphs are a common pattern in identity security products because they map entitlements and relationships across systems and make anomalies easier to spot.
SailPoint said the agreement reflects a shift in the security model required for agentic AI. As more autonomous systems take action across applications and cloud services, enterprises need governance processes that run continuously and at scale.
AgentCore integration
SailPoint has also integrated with AWS AgentCore, which AWS brands as Bedrock AgentCore. The integration discovers AI agents in AgentCore and treats them as identities within SailPoint's governance environment, placing agent and human identities in the same administrative view.
This setup supports lifecycle governance and access reviews for agent identities, along with permission adjustments and policy enforcement. The companies also outlined future product work to add provisioning and access request flows for AgentCore agents through SailPoint.
"The proliferation of AI agents is creating a new class of non-human identities, and each one represents a new attack surface," said Mark McClain, CEO and founder of SailPoint.
"For AI to be a true business accelerant, it must be built on a foundation of security. Our collaboration with AWS is about providing that foundation. By building a unified identity plane, we believe we will give our joint customers the visibility and control they need to manage the complexity of an AI-driven ecosystem, allowing them to innovate boldly and securely."
Commercial push
Alongside the technical roadmap, the agreement includes a commercial element. SailPoint Machine Identity Security and SailPoint Agent Identity Security are now available through AWS Marketplace, which can simplify procurement for AWS customers that prefer to buy through existing cloud spending commitments.
The companies also pointed to joint go-to-market activity, focused on customers moving to software-as-a-service identity platforms and organisations seeking a more automated approach to governance as AI adoption grows.
Large enterprises already face a rapidly expanding number of non-human identities from service accounts, workload identities, automation tools and connected devices. Agentic AI adds another layer because agents can be created, changed and retired quickly. They may also need access across multiple systems to perform tasks, increasing the importance of clear attribution and controlled privilege.
PACCAR was cited as a customer using SailPoint's Identity Security Cloud on AWS. "By leveraging the power of AI through SailPoint's Identity Security Cloud, hosted on the robust infrastructure on AWS, PACCAR has transformed identity into a seamless, automated process," said Michele Anne Schroeder, IAM manager at PACCAR. "This integration facilitates compliance while empowering us to scale securely and efficiently in an increasingly complex digital landscape."
AWS framed the collaboration as part of its broader cloud security and governance approach for customers deploying AI agents. "Agentic AI is unlocking opportunities for growth and innovation across all industries," said Keshav Narsipur, VP of AWS Identity and Access Management, Cloud Governance and Infrastructure as Code. "As customers build transformative new experiences, they need a trusted framework for security and governance. This collaboration brings together SailPoint's leadership in identity with the power of AWS, enabling our customers to confidently deploy and scale their AI agents."
Work under the agreement is expected to expand governance across human and non-human identities in AWS environments, with further additions planned around provisioning and access changes for AgentCore agents through SailPoint.