Extending our partnerships with Okta, SailPoint, Ping Identity, and Microsoft Entra to bring intent and data access into every identity decision.
The assumption agents break
Every identity system in the enterprise rests on an assumption that held for twenty years: that the actor asking for access is a person, and that a person can be held accountable for what they do with it.
Agents break both halves. They operate without a person present, they are provisioned faster than any review cycle can absorb, and they carry no accountability of their own - only the permissions of whoever created them. SailPoint's research puts the current state plainly: 97% of AI agents have access to sensitive data, and only 21% of organizations are highly confident in their ability to manage that risk.
Two questions identity was never asked
An agent with valid credentials, taking permitted actions, can still operate entirely outside the purpose it was deployed for. Proofpoint CEO Sumit Dhawan named this earlier this year as semantic privilege escalation: technically permitted actions that are contextually inappropriate. Identity infrastructure is built to evaluate permission. It has no signal for appropriateness.
Closing the gap: two inputs the identity layer does not natively hold
The first is data access in the literal sense: which sensitive data this identity can reach today, across every store, and how sensitive it is. Entitlements describe what was granted. They do not describe what can now be touched through inheritance, delegation and sprawl, and they say nothing about the sensitivity of what sits at the end of that path.
The second is intent: whether the action being taken matches the purpose the actor was given. This is a behavioral question, evaluated continuously against a stated task, and no directory has ever stored it.
The past six months have made the cost of these two gaps concrete. At more than one frontier lab, agents operating under valid credentials in sanctioned evaluations reached production systems at other companies. Every credential was legitimate. Every action was permitted. Who was known throughout. What those identities could reach, and why they were reaching for it, was not.
Where the boundary sits
Identity platforms own the actor: inventory, lifecycle, entitlements and the authorization decision at the moment of a request. That is their layer, and it is the foundation everything below depends on.
Proofpoint owns the data and the intent. We classify what is sensitive, map which human and non-human identities can reach it, and evaluate the intent behind an action against the purpose the actor was assigned. We act on both: revoking data exposure, right-sizing data access and remediating at the data layer, and, through AI Runtime Security, enforcing at the moment an agent acts, including blocking application access in real time.
Neither layer can render the full decision alone. Together, the decision is complete: who is acting, what it can reach, whether the action fits its purpose, and what to do about it.
What we are announcing
We are extending our relationships across the identity ecosystem so that the same exchange happens in each case. The identity platform contributes identity and entitlement context. Proofpoint contributes data sensitivity, access mapping and intent. Enforcement happens at whichever layer owns it.
With Okta, this is the ecosystem architecture itself: Proofpoint has joined the Blueprint Alliance – an open, vendor-agnostic framework spearheaded by Okta - as a founding member, advancing an open model where every agent is a first-class identity, access is scoped to the task, and delegation is traceable. [Read more.]
With SailPoint, this is identity governance: Proofpoint maps identities to the sensitive data they can reach and drives remediation, and SailPoint strips entitlements at the source. Our data sensitivity context also flows into the SailPoint Identity Graph. [Read more.]
With Ping Identity, this is authorization: Ping's decision at the moment of action incorporates a Proofpoint verdict on whether the request's intent matches the agent's assigned task. [Read more.]
With Microsoft Entra, this is the identity fabric itself, carrying Proofpoint's data and intent context for every human and agent identity an organization already runs on. We will share more as this develops.
Integrity is the control plane
The agentic workspace does not require a new identity system. It requires the one already in place to be informed by two things it cannot see on its own: what each identity can reach, and whether what it is doing still matches why it exists.
That is the work we are doing with our identity partners, and it is the first phase of a longer roadmap. Identity will keep answering who. We’re making sure the workspace can finally answer what and why.