September 10, 2026

Why Identity Security Needs AI Agents, Not More Dashboards

Blog
Philip Shteyn
,
Co-Founder & CTO
8
min read
Offroad AI agents navigating a rugged mountain landscape
Table of Contents

Identity security teams do not need another place to look for problems. They need a practical way to resolve them.

Traditional identity tools provide visibility into users, permissions, applications, service accounts, and other non-human identities. But identifying risky access is only the beginning. Someone still has to gather context, determine whether the access is legitimate, find the right owner, secure approval, make the change, and confirm that the risk was actually resolved.

That gap between visibility and resolution is becoming one of identity security’s biggest operational problems.

In a recent CyberBytes conversation at Black Hat 2026, Offroad CTO and co-founder Philip Shteyn discussed why identity environments have become too complex to manage through dashboards and manual workflows alone.

Why is identity security becoming harder?

Modern organizations no longer manage only employee accounts.

Their identity environments include employees, contractors, service accounts, API credentials, OAuth applications, workloads, machines, and increasingly, AI agents. Each identity may have access to multiple systems, with permissions that change as people, applications, and business processes evolve.

The information required to understand that access is rarely found in one system. It is distributed across identity providers, HR platforms, SaaS applications, cloud environments, security tools, activity logs, tickets, and conversations with business owners.

This creates a context problem as much as an access problem.

A permission may appear excessive but be essential to a production workflow. Another permission may look routine but create a dangerous path to sensitive data. Security teams cannot make those distinctions from an entitlement record alone.

They need to understand:

  • Who or what owns the identity?
  • Why was the access granted?
  • Is it still required?
  • How has the identity used that access?
  • What could break if the permission is removed?
  • Who should approve the change?

Without that context, identity teams either leave unnecessary access in place or spend significant time investigating every finding manually.

Why aren’t identity-security dashboards enough?

Dashboards are useful for organizing findings, but they do not complete the work.

A dashboard may show an overprivileged account, an unused permission, or a suspicious application. The security team must then move across multiple systems to validate the issue and determine what should happen next.

That often means opening tickets, contacting application owners, waiting for approvals, making changes, handling exceptions, and checking whether the remediation worked.

The result is a growing queue of technically accurate findings that the team cannot resolve fast enough.

Visibility is valuable, but a finding is not an outcome. Identity risk is reduced only when the underlying access or activity has been investigated and safely addressed.

What is agentic identity security?

Agentic identity security uses AI agents to perform the operational work involved in investigating and resolving identity risk.

Instead of simply presenting another alert, an identity-security agent can collect relevant access, activity, ownership, and business context. It can evaluate the situation against organizational policy and prepare or execute the appropriate response.

A complete workflow can include four stages:

  1. Discover the risk. Identify posture issues and suspicious identity activity across human and non-human identities.
  2. Investigate the context. Determine what the identity can access, how it has behaved, why the access may exist, and who owns the decision.
  3. Resolve or escalate. Take an approved action when the decision is clear, or bring the right person into the process with the necessary context already prepared.
  4. Verify the outcome. Confirm that the intended change occurred and that the risk was addressed without introducing an unexpected operational problem.

This changes the role of identity technology from a system that reports work to a system that helps complete it.

Where should humans remain involved?

Autonomous remediation should not mean removing human judgment from every decision.

Some actions are routine, reversible, and covered by a clear organizational policy. Others affect sensitive systems, production workflows, or access whose business purpose is unclear.

An effective agentic model distinguishes between those situations.

When the evidence is strong and the action is policy-approved, an agent can move the process forward automatically. When the decision requires judgment, it should escalate to the appropriate person with the relevant evidence, impact, and recommended action.

The objective is not autonomy at any cost. It is to remove repetitive investigation and coordination while keeping consequential decisions under the organization’s control.

Why AI changes both sides of identity security

Attackers can use AI to move faster, automate reconnaissance, and operate at a scale that manual security processes struggle to match.

But the more fundamental issue remains identity.

As Shteyn explained during the interview, “Attackers don’t hack in. They log in.”

Stolen credentials, excessive permissions, compromised applications, and poorly governed non-human identities can all provide paths into critical systems. AI agents add another category of identities that can operate continuously across applications and data.

Defending that environment requires more than periodic reviews and static inventories. Organizations need a continuous way to understand identity activity, investigate risk, and respond with context.

From identity visibility to identity resolution

Identity security has spent years improving discovery and visibility. Those capabilities remain important, but they are no longer enough on their own.

The next step is operational.

Security teams need systems that can connect fragmented context, investigate what matters, coordinate the appropriate response, and verify the result. That is the role agentic identity security can play.

The goal is not another dashboard with more findings. It is fewer unresolved risks and a faster, safer path from detection to resolution.

Frequently asked questions

What is agentic identity security?

Agentic identity security uses AI agents to investigate and resolve identity risks across human users, machines, applications, service accounts, and AI agents. These agents gather context, evaluate risk, coordinate decisions, and take approved remediation actions.

How is agentic identity security different from identity visibility?

Identity visibility shows which identities and permissions exist. Agentic identity security uses that information, along with activity and business context, to investigate whether access is legitimate and help resolve identified risks.

Can AI agents remediate identity risks automatically?

They can automate actions that are supported by clear evidence and organizational policy. Decisions involving sensitive systems, unclear ownership, or significant business impact should be escalated to the appropriate person with the relevant context.

Why are non-human identities difficult to secure?

Non-human identities can operate continuously, hold broad permissions, and lack a clear human owner. Their credentials and access may also persist after the application or process that created them has changed.

Do AI agents replace identity-security teams?

No. They provide operational leverage by handling repetitive investigation, context gathering, coordination, and approved actions. Security teams retain control over policies, guardrails, exceptions, and decisions that require human judgment.

Identity security teams do not need another place to look for problems. They need a practical way to resolve them.

Traditional identity tools provide visibility into users, permissions, applications, service accounts, and other non-human identities. But identifying risky access is only the beginning. Someone still has to gather context, determine whether the access is legitimate, find the right owner, secure approval, make the change, and confirm that the risk was actually resolved.

That gap between visibility and resolution is becoming one of identity security’s biggest operational problems.

In a recent CyberBytes conversation at Black Hat 2026, Offroad CTO and co-founder Philip Shteyn discussed why identity environments have become too complex to manage through dashboards and manual workflows alone.

Why is identity security becoming harder?

Modern organizations no longer manage only employee accounts.

Their identity environments include employees, contractors, service accounts, API credentials, OAuth applications, workloads, machines, and increasingly, AI agents. Each identity may have access to multiple systems, with permissions that change as people, applications, and business processes evolve.

The information required to understand that access is rarely found in one system. It is distributed across identity providers, HR platforms, SaaS applications, cloud environments, security tools, activity logs, tickets, and conversations with business owners.

This creates a context problem as much as an access problem.

A permission may appear excessive but be essential to a production workflow. Another permission may look routine but create a dangerous path to sensitive data. Security teams cannot make those distinctions from an entitlement record alone.

They need to understand:

  • Who or what owns the identity?
  • Why was the access granted?
  • Is it still required?
  • How has the identity used that access?
  • What could break if the permission is removed?
  • Who should approve the change?

Without that context, identity teams either leave unnecessary access in place or spend significant time investigating every finding manually.

Why aren’t identity-security dashboards enough?

Dashboards are useful for organizing findings, but they do not complete the work.

A dashboard may show an overprivileged account, an unused permission, or a suspicious application. The security team must then move across multiple systems to validate the issue and determine what should happen next.

That often means opening tickets, contacting application owners, waiting for approvals, making changes, handling exceptions, and checking whether the remediation worked.

The result is a growing queue of technically accurate findings that the team cannot resolve fast enough.

Visibility is valuable, but a finding is not an outcome. Identity risk is reduced only when the underlying access or activity has been investigated and safely addressed.

What is agentic identity security?

Agentic identity security uses AI agents to perform the operational work involved in investigating and resolving identity risk.

Instead of simply presenting another alert, an identity-security agent can collect relevant access, activity, ownership, and business context. It can evaluate the situation against organizational policy and prepare or execute the appropriate response.

A complete workflow can include four stages:

  1. Discover the risk. Identify posture issues and suspicious identity activity across human and non-human identities.
  2. Investigate the context. Determine what the identity can access, how it has behaved, why the access may exist, and who owns the decision.
  3. Resolve or escalate. Take an approved action when the decision is clear, or bring the right person into the process with the necessary context already prepared.
  4. Verify the outcome. Confirm that the intended change occurred and that the risk was addressed without introducing an unexpected operational problem.

This changes the role of identity technology from a system that reports work to a system that helps complete it.

Where should humans remain involved?

Autonomous remediation should not mean removing human judgment from every decision.

Some actions are routine, reversible, and covered by a clear organizational policy. Others affect sensitive systems, production workflows, or access whose business purpose is unclear.

An effective agentic model distinguishes between those situations.

When the evidence is strong and the action is policy-approved, an agent can move the process forward automatically. When the decision requires judgment, it should escalate to the appropriate person with the relevant evidence, impact, and recommended action.

The objective is not autonomy at any cost. It is to remove repetitive investigation and coordination while keeping consequential decisions under the organization’s control.

Why AI changes both sides of identity security

Attackers can use AI to move faster, automate reconnaissance, and operate at a scale that manual security processes struggle to match.

But the more fundamental issue remains identity.

As Shteyn explained during the interview, “Attackers don’t hack in. They log in.”

Stolen credentials, excessive permissions, compromised applications, and poorly governed non-human identities can all provide paths into critical systems. AI agents add another category of identities that can operate continuously across applications and data.

Defending that environment requires more than periodic reviews and static inventories. Organizations need a continuous way to understand identity activity, investigate risk, and respond with context.

From identity visibility to identity resolution

Identity security has spent years improving discovery and visibility. Those capabilities remain important, but they are no longer enough on their own.

The next step is operational.

Security teams need systems that can connect fragmented context, investigate what matters, coordinate the appropriate response, and verify the result. That is the role agentic identity security can play.

The goal is not another dashboard with more findings. It is fewer unresolved risks and a faster, safer path from detection to resolution.

Frequently asked questions

What is agentic identity security?

Agentic identity security uses AI agents to investigate and resolve identity risks across human users, machines, applications, service accounts, and AI agents. These agents gather context, evaluate risk, coordinate decisions, and take approved remediation actions.

How is agentic identity security different from identity visibility?

Identity visibility shows which identities and permissions exist. Agentic identity security uses that information, along with activity and business context, to investigate whether access is legitimate and help resolve identified risks.

Can AI agents remediate identity risks automatically?

They can automate actions that are supported by clear evidence and organizational policy. Decisions involving sensitive systems, unclear ownership, or significant business impact should be escalated to the appropriate person with the relevant context.

Why are non-human identities difficult to secure?

Non-human identities can operate continuously, hold broad permissions, and lack a clear human owner. Their credentials and access may also persist after the application or process that created them has changed.

Do AI agents replace identity-security teams?

No. They provide operational leverage by handling repetitive investigation, context gathering, coordination, and approved actions. Security teams retain control over policies, guardrails, exceptions, and decisions that require human judgment.

Move from identity findings to verified resolution.
Book a demo

More posts

News

We built Offroad to give CISOs their time back

June 4, 2026
5
min read
Blog

Why Access Reviews Fail to Reduce Identity Risk

August 20, 2026
4
min read
Reports

AI Agent Permissions and OAuth Grants: An Enterprise Security Guide

September 3, 2026
11
min read
} } }) } }) }) } } } }) } })