Two enterprise security vendors shipped the same message within days of each other. Agents need guardrails. Almost nobody has them yet.
RSA launched Agent ID at the end of September. Every agent call passes through a policy gateway. Authorization goes down to the tool and the argument. High risk actions like wire transfers, restricted data and payments wait for a named human to approve through a separate phishing resistant channel before anything moves. Each approval creates a record tied to the person who authorized it.
Days later SailPoint expanded its Agentic Fabric to find shadow agents. Agents nobody registered. It applies runtime authorization and can disable one on the spot while legitimate agents keep working.
Their own research explains the urgency. 79 percent of enterprises already run AI agents in production. About 2 percent have identity security tools designed to govern them.
The demand side is settled. The identity vendors are building the contract layer for agents. The open question is the software with no identity team behind it.
That is the layer we are building with HIVE. Permissions designed into the access layer from day one. Not discovered after the fact.
When an agent asks to move money in your product, who says yes. And how would you prove it.
Top comments (0)