Just because someone (or something) has access to your enterprise IT systems doesn’t mean they should automatically qualify for a free pass everywhere. Instead, companies need to ask what those granted access can actually do.
Protocols like MFA, SSO, and more, answer the who aspect of the question well, but what they can do with the access remains a mystery.
IT sprawl shares some of the blame. Between cloud platforms, SaaS applications, data warehouses, and on-prem systems, it’s difficult enough to just keep tabs on who is given access. The average worker holds a staggering 96,000 entitlements, according to the 2026 State of Identity & Access report from ServiceNow. With such volumes in play, it's impossible to determine what's good access and what must be limited, defeating the very principle of least privileges.
Excessive privileges, forgotten permission, and dormant accounts create an authorization gap, a blind spot between authentication and effective permissions. The result is an unprotected attack surface that adversaries can exploit to access critical resources and sensitive data.
Riding on the back of the authentication gap, identity-based breaches are a headlining concern for CISOs and CIOs. Along with AI governance and control, IAM is a key cybersecurity imperative in 2026. And it’s why Forester predicts related spending will reach approximately $27.5 billion by 2029.
Why the difference between authentication and authorization matters
Attribute-based access control (ABAC) promised a fix through dynamic, context-aware policies, but it's harder to implement, audit, and scale as rules and attributes multiply over time. In addition, role-based authentication has been a part of cybersecurity protocols for a while but the approach does not work in today’s environment because an employee’s need for access evolves over time with new roles or even job changes.
Too often, the employee’s role might morph but their permissions don’t, a point which the ServiceNow report illustrates well – 38% percent of identity-provider accounts had remained active even after at least 90 days of inactivity. The report groups problematic permissions into four categories: over-privileged, residual, ungoverned, and policy-violating, all of which add to significant identity debt.
It’s becoming apparent that simply referencing a directory of who has permissions is not enough. An access graph shows the full permission chain — users, groups, roles, policies, and resources — and ties identity and access to constant oversight and added context.
Machine identities multiply the challenge
Non-human identities (NHIs), which include API keys, service accounts tokens, certificates, secrets, bots, scripts, and machine/workload identities, only multiply the security issues, as do AI agents.
It’s not immediately clear what assets they access and control — and when. Just 0.01% of identities analyzed for the ServiceNow report controlled 80% of cloud resources.
And because NHIs like AI agents might also have authority to perform autonomous actions with weighty consequences, they especially need a more controlled approach to access. Governance is important too, because it’s humans who own the AI identities and dictate its behavior regarding what it can and cannot do.
Data about visibility into an agent’s potential blast radius, ownership, least privilege, and lifecycle governance, become increasingly important as AI adoption accelerates.
Move to continuous identity security
Instead of sporadic point-in-time certifications that may not fully capture changing access authorizations, enterprises need to graduate to continuous identity security. Part of a robust IAM strategy, such an approach would involve mapping effective access; identifying excessive or dormant permissions; prioritizing the riskiest access; and automating revocation and remediation as appropriate.
The key here is to make the process a continuous loop, especially as identities, applications, and permissions change. The result is end-to-end visibility, governance and automated remediation across the full identity attack surface. Compliance, too, is easier with continual identification and access management.
The goal is to map the full extent of permissions for all identities, whether they’re human, non-human, or AI agents. Organizations can enable smarter approvals by prioritizing cases for review depending on the extent of the potential damage unauthorized access can cause. By connecting with systems that enterprises use, like the cloud, SaaS, on-prem or custom applications, security teams can revoke unauthorized access and automate the process with workflows.
Expect IT sprawl to continue well into the future, extending beyond an enterprise’s perimeter to include the cloud, API calls, SaaS programs, and more. Add to this the long list of identities, including from machine operations and AI agents, it becomes apparent that a static permission protocol will not do. Companies need to know both who gets permissions to access their systems and what exactly they’re accessing.