Our Boring Agentic Strategy
Let me start with a confession: I am bored of reading about AI Agent Control planes. When a market makes this much noise, buyers stop listening.
And, at least in Europe, I think I know what could happen next.
#1 In all that noise, Europe will simply pick the default
Put yourself in the shoes of a European CISO. Thirty vendors, thirty of everything. At some point you stop evaluating and you say: “Fine. I go with Microsoft. My users are already in Entra, they use Microsoft productivity tools, Copilot is not great but that’s the approved AI… let us control the agents there too.”
C’mon, nobody gets fired for buying Microsoft.
#2 The risk is not who the agent is. It is what it does with a human’s permissions.
An agent is not dangerous because of its own permissions. It is dangerous because it borrows a human’s. OAuth consent is the source of many evils.
An agent acting on behalf of Marco inherits Marco’s entitlements. Marco uses ten percent of them. The agent will use all of them.
So the question that matters is “what damage can this agent do when used by Marco? Who is accountable for it?”
#3 And in Europe, the answer to that question lives in the IGA basement
To answer it you need job titles, entitlements, roles and applications. And, in the large European regulated enterprises we work with, that information lives in highly configured - mostly on-premises - IGA platforms: SailPoint IIQ, One Identity Manager, Oracle Identity Governance, OpenText and their peers, surrounded by ten years of home-grown extensions.
#4 So the real question is deeply unglamorous and, yes, boring
“How do I make the old talk to the new? How do I make sense of my current IGA with the new world of AI Agents?”
It is the question our clients ask us, once the slides are closed.
#5 The industry answer: “we can give you everything - but first, migrate”
Every established IAM vendor now has an Agent something in the portfolio.
The pattern is always identical: the agentic capability lives in their SaaS, and it only becomes useful once your Human IAM data lives in their SaaS too.
Which quietly turns “how do I govern my agents?” into “start a three-year, multi-million migration programme”.
In our sovereign-obsessed Europe, data residency, hosting model and exit strategy are no longer procurement footnotes. The migration is not going to happen. And in the meantime, the agents keep multiplying.
#6 Our boring strategy: correlate, do not replace
We are building our IAMONES agentic control capability as an extension of the IAM estate our clients already own. Four boring principles:
- Agents stay where you registered them. We bet on Microsoft Agent 365, also for non-Microsoft agents. We are not competing for the registry. We have built a very deep integration with EntraID and Microsoft Agent 365.
- We read the Human Identity truth where it already is. SailPoint IIQ, One Identity Manager, Oracle Identity Governance, OpenText. Last but not least, the many home-grown IAM applications. In place, no migration.
- Every agent is tied back to the humans it borrows from. What the agent can reach, which entitlements it inherited from which identity.
- The reasoning happens in Natural Language, because that is the language agents are written in. This is precisely what Born-on-the-LLM means for IAMONES.
IAMONES: What is our agentic strategy? The old IGA world and the new AGENTIC one must talk to each other. That is where we have decided to stand.
