SailPoint Navigate 2026 Launches Identity Controls for AI Agents

SailPoint Navigate 2026 put AI agents at the centre of identity security, but with AI-driven ARR at just over $70 million of a $1.231 billion base, the bet is still more promise than revenue.
By Branka Narancic -
SailPoint Navigate 2026 keynote stage in Austin with a screen showing 79% vs 2% AI agent identity security gap
  • SailPoint's own survey claims 79% of organisations run AI agents in production while only 2% use purpose-built identity tools, a 40-to-1 gap that is a sales thesis rather than independent proof of demand.
  • AI-driven ARR is above $70 million and over 30% of net new ARR, yet it is only about 6% of the $1.231 billion total, so agent products are not yet what the share price rests on.
  • A-ISPM, the Harbor Pilot Policy Agent and the Proofpoint integration all land in Q4 of fiscal 2027 (by 31 January 2027), so the roadmap's credibility will be judged in a single reporting window.
  • Revenue growth slowed to 17% in fiscal Q2 2027 against 25% ARR growth, and a $50.4 million GAAP net loss sits uneasily against the Rule of 40 benchmark.
  • Okta, Microsoft Entra and Saviynt tend to bundle machine-identity features into broader suites, leaving open whether buyers want a specialist or a feature inside a suite they already own.
Summarise with AI:

On 6 October 2026, SailPoint used its Navigate conference in Austin, Texas, to launch a broad set of products that treat AI agents as identities to be governed, much like employees. The release landed alongside a survey finding that 79% of organisations run AI agents in production, yet only 2% use identity security tools built for them.

That survey is SailPoint’s own, and the company is hardly a neutral party. It is a listed identity vendor with annual recurring revenue (ARR, the yearly value of its subscription contracts) above $1.2 billion.

SailPoint Navigate 2026 makes clear the company is staking its next growth leg on a category that barely has buyers yet.

Here is what was announced, how much of it shows up as real revenue today, and which dates decide whether the bet pays off.

Why SailPoint says AI agents are an identity problem the market has not priced in

The headline number is stark. SailPoint’s fifth annual Horizons of Identity Security report, which surveyed 340 senior identity, IT, security and risk leaders and graded them against a five-tier maturity model, found a gap of roughly 40 to 1 between agent adoption and purpose-built controls.

The 40-to-1 gap 79% of organisations run AI agents in production. Only 2% use identity security tools designed to govern them.

The 40-to-1 AI Agent Security Gap

AI agents now make up 22% of all non-human accounts, according to the report. Agents are hard to govern because of how they get access in the first place:

  • Many run on shared service accounts with little lifecycle management.
  • Embedded API keys and long-lived secrets sit in configs, scripts and prompt chains, where they are hard to audit or revoke.
  • Agents often inherit credentials from humans or applications, carrying standing privileges far beyond what the task needs.

The original source reporting on the survey also said UK organisations add as many as 10,000 AI agents and machine identities each month. That figure was not located in the report summaries reviewed for this article, so treat it as that outlet’s claim.

SailPoint frames the gap as structural rather than cyclical: agents are being embedded faster than controls can follow. The more telling figure may be the 85% of organisations still relying on legacy identity tools, which is the pool SailPoint actually wants to sell into.

Governance gaps around shared accounts and long-lived secrets are part of a wider AI agent security problem, in which authorised automation and malicious scripts look almost identical at the network level and binary blocking logic cannot separate them.

For you as an investor, the gap points to a large unserved market. But because SailPoint wrote the survey, it is better read as a sales thesis to test than as independent proof of demand.

What SailPoint actually announced, and which pieces are shipping when

The launch list was long. Sorted by readiness, it becomes much clearer.

Available or rolling out from Navigate are the platform’s core pieces. Agentic Fabric maps the agent footprint, finds “shadow AI” (agents deployed without IT’s knowledge), authorises actions as they happen and adds an agent kill switch. Human Fabric gains an embedded Harbor Pilot Access Request Agent, while Atlas, the underlying platform, adds workflow upgrades.

IdentityIQ 9.0 refreshes the on-premises product. Three classes of Autonomous Agents are designed to trim privileges and fix identity risks without halting automated workflows. Zero standing privilege replaces always-on access with just-in-time access, activated through Slack or ServiceNow.

The harder deliverables sit later. Autonomous Identity Security Posture Management (A-ISPM), which continuously scans for dormant accounts, orphaned access and hidden admins, is due in Q4 of fiscal 2027. So are the Harbor Pilot Policy Agent and a Proofpoint integration.

Capability Status Expected timing
Agentic Fabric (discovery, kill switch) Rolling out From Navigate 2026
Harbor Pilot Access Request Agent Available Now
Zero standing privilege Rolling out From Navigate 2026
A-ISPM Announced Q4 FY27 (by 31 January 2027)
Harbor Pilot Policy Agent Announced Q4 FY27
Proofpoint integration Announced Q4 FY27
Entro integration into Agentic Fabric Nearly complete “Soon”

SailPoint also flagged a South Korea data centre and preparation for FedRAMP High, PCI DSS 4.0 and EU Sovereign Cloud standards. These are preparations, not certifications, and other sources reviewed did not corroborate them.

Entro: bought, available, not yet fully integrated

SailPoint completed its purchase of Tel Aviv-based Entro Security on 29 June 2026. Entro adds credential lineage, exposed secret discovery and monitoring of prompt intent. Terms were undisclosed, and third-party reports of a value around $200 million are unconfirmed.

Bunching A-ISPM, the Policy Agent, Proofpoint and Entro into one quarter means the roadmap’s credibility will be judged in a single reporting window. Any slippage would show up quickly.

Can the agent roadmap carry the numbers, and who else is competing for it?

The financial base is solid. In fiscal Q2 2027, which ended 31 July and was reported on 9 September, ARR reached $1.231 billion, up 25%. SaaS ARR (cloud subscriptions) rose 36% to $847 million, about 69% of the total.

Quarter Total ARR SaaS ARR Revenue
Q4 FY26 $1.125B (+28%) $746M (+38%) $295M (+23%)
Q1 FY27 $1.163B (+26%) $781M (+36%) $280M (+22%)
Q2 FY27 $1.231B (+25%) $847M (+36%) $308.8M (+17%)

Growth is easing, though. Revenue growth slowed to 17%, well behind ARR, and SailPoint posted a net loss of $50.4 million (GAAP diluted EPS of -$0.09, adjusted EPS of $0.09).

Growth is easing, and investors will weigh it against margins through the Rule of 40, the growth-plus-margin score that drives SaaS valuation premiums and discounts; a GAAP net loss alongside slowing revenue growth sits uneasily against that benchmark.

Total ARR vs Revenue (Q4 FY26 - Q2 FY27)

The only quantified agent metric is AI-driven ARR above $70 million, more than 30% of net new ARR. That tells you agent demand is already visible in bookings. At roughly 6% of total ARR, however, it is not yet what the share price rests on, so the next two quarters matter more than the survey.

Specialist platform or bundled feature?

Okta, Microsoft Entra and Saviynt tend to bundle machine-identity features into broader suites. CyberArk competes on privileged access management (PAM, tools that control high-level admin access), and CrowdStrike is both partner and rival. No competitor was found using SailPoint’s agent-identity framing, which leaves open whether buyers want a specialist or a feature inside a suite they already own.

Risks include execution timing, Entro integration, overlap with customers’ existing PAM and secrets tools, and buyer wariness about vendor lock-in. Watch three signals:

  • AI-driven ARR’s share of net new ARR
  • Delivery of Q4 FY27 features by 31 January 2027
  • Whether larger rivals bundle comparable agent controls

What Q4 fiscal 2027 will settle, and what it will not

The Navigate launches are credible in scope but unproven in revenue. The strongest evidence for demand comes from SailPoint’s own survey, not from independent buyers.

Two tests now matter. The first is delivery: A-ISPM, the Policy Agent, Proofpoint and Entro all need to land by 31 January 2027. The second is commercial: the next earnings update will show whether AI-driven ARR keeps growing its share of new business. Shipping on time would confirm SailPoint can execute, but only the bookings will show whether customers are willing to pay.

Demand for agent controls will also depend on how security budgets are allocated, with Gartner projecting global information security spending of $244 billion in 2026 and most CIOs planning increases, though larger totals do not guarantee spending reaches identity tooling.

This article is for informational purposes only and should not be considered financial advice. Investors should conduct their own research and consult with financial professionals before making investment decisions. Past performance does not guarantee future results, and forward-looking statements are speculative and subject to change.

Frequently Asked Questions

What is AI agent identity security?

AI agent identity security treats autonomous AI agents as identities that need governance, much like employees, covering discovery, access limits and lifecycle control. SailPoint says only 2% of organisations use tools built for this, against 79% running agents in production.

What did SailPoint announce at Navigate 2026?

SailPoint launched Agentic Fabric for agent discovery and a kill switch, zero standing privilege, IdentityIQ 9.0 and an embedded Harbor Pilot Access Request Agent. Autonomous Identity Security Posture Management, the Harbor Pilot Policy Agent and a Proofpoint integration are due in Q4 of fiscal 2027.

How much of SailPoint's revenue comes from AI agent products?

AI-driven ARR is above $70 million, more than 30% of net new ARR but only about 6% of total ARR of $1.231 billion. Agent demand shows up in bookings, yet it does not yet carry the share price.

When will SailPoint's delayed agent features be delivered?

A-ISPM, the Harbor Pilot Policy Agent and the Proofpoint integration are due in Q4 of fiscal 2027, which ends 31 January 2027. Bunching them into one quarter means any slippage will show up quickly.

Is the 79% AI agent adoption statistic independent?

No. The figure comes from SailPoint's own Horizons of Identity Security report, which surveyed 340 leaders. It is better read as a sales thesis to test than as independent proof of demand.

Branka Narancic
By Branka Narancic
Client Success Manager
Branka Narancic is Client Success Manager at StockWireX and Discovery Alert, and an active contributor to the News sections on both platforms, bringing more than a decade of experience across financial journalism, capital markets communications, and investor engagement. A founding contributor and former Editor of Companies and Markets at The Market Herald, she combines deep ASX market knowledge with a commercially focused approach to client success.
Learn More

Breaking ASX Alerts Direct to Your Inbox

Join +20,000 subscribers receiving alerts.

Join thousands of investors who rely on StockWire X for timely, accurate market intelligence.

About the Publisher