TL;DR: A local LLM can search identity data for orphaned SAP accounts, segregation-of-duties issues and provisioning workflow gaps, while keeping data inside the environment and surfacing review context faster than manual analysis, according to Pathlock’s June 17 webinar. The governance question is whether conversational automation improves IGA signal quality or simply accelerates weak access processes.
At a glance
What this is: This webinar explores how Pathlock says agentic AI can help IGA teams find orphaned accounts, SoD issues and provisioning gaps through plain-English interaction.
Why it matters: It matters because IAM and IGA teams need to decide whether conversational automation strengthens access governance or just makes broken workflows move faster across human and non-human identity processes.
By the numbers:
- You have 400 SAP accounts in the review scenario described in the webinar.
- The webinar is scheduled for June 17, 2026, at 10 AM BST.
- The session is presented as a 30 min webinar.
Context
Orphaned accounts in IGA are a governance problem, not just a cleanup task. When access reviews rely on sparse context, reviewers miss dormant accounts, inherited privileges and segregation-of-duties conflicts that should have been resolved earlier in the lifecycle.
This webinar positions agentic AI as an interface layer over identity data rather than a new policy model. The real issue for practitioners is whether conversational workflows improve decision quality, or whether they hide weak process design behind faster search and automation.
Because the article focuses on SAP accounts, reviewer context and provisioning workflows, the topic sits squarely in identity governance and non-human workflow automation rather than general AI adoption.
Key questions
Q: What breaks when orphaned accounts are reviewed through conversational IGA tools?
A: What breaks first is reviewer context. If ownership, lifecycle status and entitlement history are incomplete, a conversational interface can surface cases faster but cannot create governance truth. The result is accelerated triage with the same underlying ambiguity, which means the review process still depends on data quality, policy clarity and accountable ownership.
Q: Why do orphaned accounts create risk in SAP identity reviews?
A: Orphaned accounts create risk because access outlives the person or process that originally justified it. In SAP environments that usually means lingering entitlements, unresolved ownership and missed SoD conflicts. The governance failure is not discovery alone. It is the absence of a reliable offboarding and recertification loop that closes access when accountability disappears.
Q: How do teams know whether AI-assisted IGA is actually working?
A: Look for shorter review cycles, fewer unresolved orphaned accounts, and clearer remediation ownership without an increase in policy exceptions or audit findings. If the system produces speed but not better decision quality, it is only moving the bottleneck. Effective AI-assisted IGA improves both throughput and control fidelity.
Q: What should security teams check before using chat to build provisioning workflows?
A: Check that the workflow generated from chat still enforces requester, approver, and provisioner separation, plus clear exception handling. A natural-language interface can accelerate configuration, but it can also hide weak approval logic or incomplete policy mapping. The output must be reviewed like any other change to access provisioning.
Background and context
Plain-English identity queries over governance data
The webinar describes a local LLM that accepts natural-language prompts and searches identity data for orphaned accounts, SoD violations and access anomalies. Mechanically, that means the model is not the authority on entitlement truth. It is an interpretation layer over underlying identity records, which still have to be complete, current and normalised enough to answer the question correctly. If the data model is inconsistent, the conversation looks fluent while the governance answer remains incomplete. Practical implication: treat conversational search as a retrieval interface over governed identity sources, not as a source of entitlement truth.
Practical implication: validate the underlying identity dataset before relying on any conversational review output.
Agent-assisted reviews and approver context
Pathlock says its agent can flag a privileged session before it reaches the approver and provide context before the review starts. That changes the review flow, but not the governance burden. Approvers still need evidence of who owns the account, why access exists, whether the account is orphaned and whether the entitlement conflicts with segregation-of-duties policy. The technical risk is false confidence when the interface speeds triage but the review criteria remain underspecified. Practical implication: define the decision context before introducing AI into review queues.
Practical implication: predefine review criteria so AI only accelerates decisions that are already well governed.
Chat-driven provisioning workflow generation
The webinar also claims a provisioning workflow can be built from a chat conversation without drag-and-drop or developer effort. In practical terms, that means the agent is translating intent into workflow steps inside the IGA environment. That is useful only if workflow generation inherits the same approval logic, segregation rules, connector constraints and audit logging as manually built flows. Otherwise the organisation risks creating a faster path to an ungoverned process. Practical implication: govern workflow generation as a control surface, not as a convenience feature.
Practical implication: subject generated workflows to the same approval and audit requirements as manually built ones.
NHI Mgmt Group analysis
Conversational IGA does not remove governance uncertainty, it relocates it. The Pathlock scenario shows that plain-English prompts can speed up review discovery, but they do not resolve the quality of the underlying entitlement record. When the governance model is weak, faster search simply reveals weak governance faster. The practitioner conclusion is that conversational access does not equal governed access.
Orphaned accounts are a lifecycle failure before they are an AI use case. The article’s opening scenario, 400 SAP accounts and three reviewers, is a classic governance pressure point: too much entitlement state, too little human context. Agentic AI may help prioritise cases, but the structural problem remains offboarding, ownership and recertification discipline. The practitioner conclusion is that AI should amplify lifecycle control, not substitute for it.
Workflow generation is the new control surface for IGA risk. If a chat interface can create onboarding workflows, then the approval logic, role mapping and audit trace become the real security boundary. That is where identity programmes will either preserve governance integrity or create faster shadow process creation. The practitioner conclusion is to treat generated workflows as governed artefacts, not convenience outputs.
Local inference matters because identity data is sensitive operational material. The webinar’s no-data-leaves-the-environment framing is a governance signal, not just a deployment detail. Identity records, access patterns and SoD findings are exactly the kind of sensitive operational data that should not be casually exposed to public model endpoints. The practitioner conclusion is to align AI deployment choices with identity data residency and internal control expectations.
Agentic AI for IGA should be judged by decision quality, not conversational fluency. The question is not whether a local LLM can answer natural-language questions, but whether it improves orphan detection, reviewer context and provisioning control without weakening auditability. That evaluation belongs in the access governance programme, not in a generic AI pilot. The practitioner conclusion is to measure governance outcomes first and interface novelty second.
From our research library:
- A Harris Poll survey of more than 300 technology decision-makers found that 86% expect agentic AI to deliver positive ROI, yet fewer than half had AI governance policies in place.
- Read next: Agentic AI Identity Guide
What this signals
Identity governance will increasingly be judged by whether AI improves triage without weakening control evidence. The real test is not whether natural language makes the review process easier to use. The test is whether it reduces orphaned-account backlogs, preserves auditability and keeps the approver accountable for the final decision.
Local model deployment is becoming a governance requirement when identity records are sensitive operational assets. When AI touches access history, reviewer commentary and provisioning logic, the residency of that data becomes part of the control design. That is especially true where public models would create unnecessary exposure of identity state.
Agentic AI market optimism is already colliding with control maturity gaps: 86% expect positive ROI, yet fewer than half had AI governance policies in place, according to the 2026 Infrastructure Identity Survey. The governance gap is not whether teams can prompt a model, but whether they can prove the model still operates inside a reviewable, accountable process.
For practitioners
- Audit orphaned account review paths Map where orphaned SAP accounts, SoD exceptions and privileged sessions currently depend on manual reviewer memory rather than explicit policy and owner data.
- Require identity data quality gates Verify that account ownership, entitlement provenance and lifecycle status are complete enough for a conversational review tool to make accurate recommendations.
- Constrain chat-generated workflows Apply approval, segregation-of-duties and audit logging requirements to any provisioning workflow created through natural-language interaction.
- Keep sensitive identity data inside the environment Prefer local inference or equivalent containment when the model will process access history, reviewer notes and identity governance records.
Key takeaways
- Conversational IGA can speed orphaned-account discovery, but it does not fix weak ownership data or unresolved lifecycle gaps.
- The webinar’s example highlights the pressure created when too many accounts and too few reviewers meet incomplete governance context.
- If AI is used for review or workflow generation, approval logic, SoD checks and auditability still have to be enforced in the identity system itself.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | Agentic review and workflow creation touch identity authority and privilege boundaries. |
| Recommendation — Apply ASI03 to keep AI-assisted review and provisioning inside explicit approval and privilege boundaries. | ||
| OWASP Non-Human Identity Top 10 | NHI-10 — Human Use of NHI | Chat-driven access actions can let humans misuse identity automation paths. |
| Recommendation — Restrict human-initiated chat workflows to approved identity actions and log every resulting access change. | ||
| NIST AI RMF | GOVERN — AI Governance and Accountability | The article centres on governance and accountability for local AI in identity decisions. |
| Recommendation — Define governance ownership and accountability before allowing AI to influence identity decisions. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Orphaned accounts and SoD review are direct authorization governance problems. |
| Recommendation — Review entitlements against PR.AA-05 and remove access that no longer has a valid owner or purpose. | ||
Key terms
- Orphaned Account: An orphaned account is an identity that remains active without a clear owner or business purpose. These accounts are dangerous because they often escape review, retain unnecessary access, and provide attackers with low-friction entry points into otherwise governed environments.
- Segregation of Duties: Segregation of Duties is a control principle that prevents one person or role from combining incompatible permissions that could create fraud, error, or undetected change. In ERP environments, it must account for roles, transactions, approvals, and compensating controls across business processes.
- Conversational IGA: A conversational interface for identity governance and administration lets users ask natural-language questions about accounts, entitlements, and access risk. The control value comes from faster evidence retrieval and triage, not from the chat layer itself. Governance still depends on policy, auditability, and approved data sources.
- Local Inference: Local inference means the AI model processes data on the user’s device or a managed endpoint instead of sending it to a remote service. That reduces external exposure, but the endpoint becomes the primary security boundary and must be controlled accordingly.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 2, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org