Paul Zolfaghari is President of Saviynt, a leader in cloud identity security and management solutions.gettyIdentity security is often treated as an IT control. It governs who can access which systems, helps teams meet compliance requirements and supports the basic hygiene of onboarding and offboarding employees. While many of these functions are still necessary, this model has fallen behind in how modern enterprises operate.As organizations adopt automation and AI agents among deployments of cloud platforms, SaaS applications and APIs, identity becomes the control plane for how work gets done securely across the business. Every transaction, workflow, data request and automated action depends on an identity being trusted to do something. That identity may belong to an employee, a contractor, an application, a service account, an API or an AI agent.A business unit may deploy an AI agent to summarize customer issues, update a CRM record, draft a follow-up email and trigger a task across connected SaaS applications. In that environment, identity security determines whether the organization can move faster while maintaining control.Why Identity Is Now A Business Control PlaneAI agents are forcing leaders to rethink identity security because they are being introduced into workflows that touch finance, customer support, software development, operations, marketing, HR and other functions. Gartner projects that by the end of 2026, 40% of enterprise applications will include autonomous agents, underscoring how quickly these systems are moving into core business environments. These systems can retrieve information, generate outputs, initiate processes and take action across multiple enterprise platforms. When AI systems are given excessive access, a mistake can move beyond a model or prompt and translate into business impact across connected systems.Many organizations also lack clear visibility into these new identities. Research from my company shows that 92% of CISOs lack visibility into AI identities, underscoring how quickly AI access is expanding beyond existing governance models. If an enterprise cannot see which identities exist, what they can access and how they are being used, it cannot confidently manage risk, compliance or continuity.How Nonhuman Identities Are Reshaping Enterprise RiskOne of the fastest-growing categories of enterprise identities is nonhuman, including applications, APIs, service accounts, bots and AI agents. These identities have existed for years, and their scale and autonomy are changing the risk equation, particularly because they operate differently from human identities that most security systems are designed to secure and govern.A human employee may log in, complete a task and leave a record tied to a known person. The lifecycle of that identity is known and security teams know when and how to revoke access under traditional frameworks. A nonhuman identity may operate continuously, interact with multiple systems and execute tasks at machine speed. AI agents add complexity because they can act across systems with real permissions.For example, an AI agent generating a financial report may access sensitive data, create a summary, draft an email and distribute outputs across collaboration platforms. In that scenario, the primary risk comes from what the agent can access and execute, alongside what it produces.Traditional identity governance models need to evolve. Many were designed around human users and periodic reviews. Nonhuman identities often operate autonomously, continuously and at scale. They require governance controls built for machine-speed activity, including least-privilege access, continuous monitoring and automated policy enforcement.Creating Business Value Through Modern Identity StrategyRedesigning identity security creates value beyond defense. Developing a modern identity strategy helps give organizations a unified way to govern identities, human and nonhuman, across systems, applications and environments. It helps security teams enforce least-privilege access, reduce over-permissioning and maintain visibility as the business grows.This approach can also help improve operational efficiency by reducing manual access reviews, fragmented approval workflows and disconnected identity processes that slow teams down. It supports business agility because AI adoption, digital ecosystems and cloud modernization all depend on trusted access.Additionally, it strengthens compliance readiness. Regulated organizations need to demonstrate who had access to what, why that access was granted and whether it was appropriate. As nonhuman identities become more common, that evidence becomes harder to produce without unified governance.What Business Leaders Should Do NowThe first step is visibility. Leaders need a complete view of identities across the enterprise, especially nonhuman identities operating across applications, cloud environments, APIs and AI workflows. That includes understanding who owns each identity, what business purpose it serves, what access it has and whether that access is still appropriate.The second step is reducing over-permissioning. Standing access should be the exception rather than the default for every identity. Organizations should move toward dynamic, policy-based access controls that grant access based on context, need and risk.The third step is unification. Many identity environments are fragmented across legacy systems, cloud platforms and business applications. A unified identity control plane helps organizations manage access across human and nonhuman identities with greater consistency and visibility.Identity: The Foundation For Scalable GrowthAI is accelerating both opportunity and risk by helping organizations automate work, improve decision-making and scale operations. Realizing those benefits depends on trust, control, visibility and an identity-first foundation.In the AI economy, enterprises that redesign identity security around a control plane model will be better positioned to adopt new technologies, govern human and nonhuman access, and scale with greater resilience. That is what I see as the business case for redesigning identity security now.Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?
The Business Case For Redesigning Identity Security
Traditional identity governance models need to evolve, since many were designed around human users and periodic reviews.








