Now, you can understand and remediate risks to your sensitive data within the context of the identities that can access it.
The gap between identity and data
Security and identity teams each see half the picture. Identity teams know who — and what — exists in their environment, but not always what those identities can actually reach, or how sensitive that data is. Data teams know what's sensitive, but not who or what can get to it, or whether that access is even still needed. Non-human identities make the gap worse: service accounts and AI agents multiply faster than either team can track manually, and their secrets often live outside standard identity systems entirely.
In 2020, we introduced our partnership with SailPoint to help joint customers protect their most-attacked people — giving SailPoint the visibility it needed to automatically adjust access when Proofpoint identified risk. Today, we're extending that partnership to close a different gap: bringing SailPoint's identity governance together with Proofpoint's data security, so joint customers can finally see which identities — human, agent, or otherwise — put their sensitive data at risk, and fix it at the source.
"As AI agents and machine identities multiply across the enterprise, understanding what they can actually access is no longer optional — it's foundational to security," said Soumya Banerjee, Head of Product Acceleration, SailPoint. "This integration connects that identity and secrets context directly to Proofpoint's data intelligence, so our joint customers can finally see — and act on — risk that's been sitting in the blind spot between our two platforms."
Why this matters now
Proofpoint already monitors more than 50 million cloud accounts across 8,000 customers for signs of account compromise — and in the past 12 months, 99%+ of monitored organizations were targeted for account takeover, with 71% experiencing at least one compromised account. According to SailPoint's own research, 97% of AI agents have access to sensitive data today, and only 21% of organizations are highly confident in their ability to manage that risk.
Most organizations aren't starting from zero. If you're a SailPoint customer, you already have identity governance in place for every identity in your enterprise. If you’re a Proofpoint customer, you have data governance in place for all your sensitive data. What's been missing is a way to understand which identities, human and non-human, can access that sensitive data. Together, we can help you answer the questions: what is sensitive, who can reach it, and whether that access still makes sense.
How it works
SailPoint governs and inventories every identity in the enterprise, human and non-human — including the secrets tied to service accounts and AI agents, via the SailPoint Identity Security platform. Proofpoint classifies and monitors sensitive data across the enterprise – where it lives, how it’s exposed, and who can reach it – via its Data Security Posture Management (DSPM) and AI Data Access Governance capabilities. Together, data security and identity governance come together to answer a question neither can answer alone: which identities pose the greatest risk to your sensitive data, and how to fix it. This works in two connected steps:
-
Proofpoint classifies and remediates: Proofpoint retrieves the identity inventory and associated risk from SailPoint, then maps that data to the sensitive data each identity can reach – driving its own remediation: revoking org-wide or public exposure, removing stale access, and right-sizing permissions. Proofpoint then hands the action to SailPoint, which can strip entitlements at the source – on the specific application, agent, or non-human identity.
-
SailPoint enriches its identity context SailPoint pulls Proofpoint’s data sensitivity metadata into the SailPoint Identity Graph, so every identity risk profile – human or non-human – now includes detailed context on what sensitive data it can actually reach.

What this means for your organization
For most organizations, the hard part of securing AI agents and service accounts isn't writing new policy — it's connecting the identity governance you already trust to the data it's meant to protect. SailPoint customers get an additional data-sensitivity signal they don't have today; Proofpoint customers get identity and ownership context for every remediation action, so access gets fixed at the source, not just flagged.
This is the first step in a broader roadmap to bring identity and data security together — we'll share more as it develops.
If you're a joint Proofpoint and SailPoint customer, reach out to your account team to learn more.
Frequently asked questions
- What's actually new here? SailPoint's Identity Graph now includes Proofpoint's data sensitivity context, and Proofpoint's remediation flow now includes SailPoint's identity and risk data — so both platforms act with the full picture, not half of it.
- How does this relate to the SailPoint partnership Proofpoint has had since 2020 — does it replace it? No. It extends it. The original partnership applied Proofpoint's risk visibility to human users so SailPoint could adjust their access. This extends that same collaboration to bring data security and identity governance together across every identity, human and non-human.
- What data does SailPoint share with Proofpoint, and what does Proofpoint send back? SailPoint shares identity and non-human identity inventory and risk data, via the SailPoint Agentic Fabric. Proofpoint shares data sensitivity and access mapping, via its DSPM and AI Data Access Governance capabilities, and drives remediation that SailPoint then executes at the identity layer.
- Does this apply to AI agents specifically, or just traditional service accounts? Both. Non-human identities include long-standing service accounts as well as the newer, faster-growing population of AI agents.
- Is this the only integration between Proofpoint and SailPoint? No — this is the first phase of a broader roadmap between the two companies to bring data security and identity governance together. We'll share more as that roadmap develops.
- When can I get started? We expect this to be available to joint Proofpoint and SailPoint customers by the end of 2026 – reach out to your account team to be notified as it rolls out.