By NHI Mgmt Group Editorial TeamBased on Pathlock: “Orphaned Accounts, Privilege Abuse & Broken Workflows: How Pathlock’s Agentic AI Handles All Three” (May 29, 2026)

TL;DR: Pathlock's June 10 webinar says a local LLM can surface orphaned SAP accounts, Segregation of Duties risks, and privileged sessions in seconds while also building provisioning workflows from chat, shifting the IGA question from manual review speed to whether identity governance can safely absorb runtime decisions inside the environment.


At a glance

What this is: Pathlock's webinar explores how agentic AI can accelerate IGA reviews, detect orphaned SAP accounts and privilege issues, and generate provisioning workflows from natural language.

Why it matters: It matters because IAM, IGA, and PAM teams need to decide whether conversational automation changes the control model or simply compresses the time available to review identity decisions.


Context

Agentic AI for identity governance changes the operating model when a system can interpret a question, search identity data, and act on the result inside the same workflow. In this case, the central issue is not chat as an interface, but whether review, provisioning, and privileged access decisions can be delegated without losing control over what the system sees and does.

Pathlock frames that problem through SAP account review, Segregation of Duties analysis, and workflow creation. The practical governance question is whether IGA programmes built around human-paced approvals can still govern identity actions when the analysis happens in seconds and the workflow is generated from conversation.

For regulated environments, the data-handling constraint matters as much as the automation itself. If identity data cannot leave the environment, then the control boundary shifts from the LLM model choice to the governance around its runtime access, output, and action scope.


Key questions

Q: How should teams govern agentic AI inside IGA workflows?

A: Start by limiting the agent to evidence discovery and workflow drafting, while keeping approval authority and policy changes under human control. The model may speed up review, but it should not be allowed to silently convert findings into access decisions. Governance should focus on who can query data, what the agent may generate, and which steps remain mandatory for approvers.

Q: What breaks when AI agent access is reviewed only after the fact?

A: After-the-fact review leaves a gap between action and containment. If an agent can already reach a dataset, API, or SaaS system, the damage may be done before a human sees the alert. Runtime checks reduce that gap by stopping unauthorized actions before they execute.

Q: When should organisations prioritise local deployment for identity data?

A: Prioritise local deployment when identity records, entitlements, or review evidence cannot leave the environment because of regulatory, contractual, or internal policy constraints. If the agent has to inspect live identity data, the residency boundary becomes part of the control design, not a deployment detail. That is especially true in regulated enterprises handling sensitive SAP access.

Q: What is the difference between conversational IGA and conventional workflow automation?

A: Conversational IGA lets a user ask for analysis or a workflow in natural language, while conventional workflow automation follows predefined forms, rules, and paths. The key difference is that agentic systems may infer intent and assemble steps, so governance must verify the generated logic instead of only checking a fixed configuration.


Background and context

Plain-language identity search across governed data

The webinar describes a local LLM that can answer questions over identity data in plain English. Technically, that means the model is not just generating text, but operating as an interface over indexed governance data, likely combining retrieval with task-specific reasoning. The important distinction is that the model is being used to narrow search and interpret context, not to replace the underlying identity source of record. That matters because IGA value depends on evidence quality, traceability, and whether the model can surface the right account, entitlement, or violation without obscuring where the answer came from.

Practical implication: treat conversational search as an access path to governance evidence, not as the system of record.

Privileged session review before approval

Flagging a privileged session before it reaches the approver points to runtime triage rather than retrospective reporting. In identity terms, this shifts the control point closer to event time, where a system can surface a risky session while the decision is still actionable. That is materially different from batch recertification, which assumes a privilege remains visible long enough to be reviewed later. The article's emphasis on pre-approval context shows why reviewer fatigue and incomplete evidence are central IGA failure modes, especially when the number of accounts outpaces human review capacity.

Practical implication: move high-risk session review earlier in the workflow when approvers can still intervene.

Conversational provisioning workflow creation

Building a provisioning workflow from chat means the system is translating intent into structured identity workflow logic without drag-and-drop design. That can compress implementation time, but it also moves control risk into interpretation, because the generated workflow must still enforce correct approvals, entitlements, and separation of duties. In IGA, workflow creation is not just automation of tasks. It is the encoding of policy, so any agent that drafts workflow steps is influencing governance logic, not merely assisting with administration.

Practical implication: validate generated workflows against approval paths, SoD rules, and entitlement scope before use.


NHI Mgmt Group analysis

Agentic AI changes IGA from workflow execution to governance interpretation. The webinar's core point is that the system is not only automating identity work, but interpreting questions, evidence, and workflow intent in one interaction. That matters because IGA controls were designed to separate review, decision, and execution into distinct steps. When those steps collapse into a single conversational path, the governance model has to account for who is effectively deciding what the system searches, surfaces, and builds.

Runtime review is now the decisive control boundary. The article shows why waiting for scheduled certification is often too late when a privileged session can be surfaced in seconds. That does not make recertification obsolete, but it does mean the highest-value control point moves toward event-time detection and intervention. For practitioners, the implication is that review cadence alone no longer defines control effectiveness.

Identity data residency becomes a governance requirement, not just a privacy preference. Pathlock's local LLM positioning highlights a familiar enterprise constraint in a new form: regulated teams often cannot permit identity data to leave the environment. The named concept here is the identity data boundary, the line between useful model inference and unacceptable disclosure exposure. Once agentic AI enters IGA, that boundary must be explicit or the programme inherits avoidable risk.

Workflow generation is policy generation. A chat-created provisioning flow is not a convenience feature in governance terms. It is a machine-assisted encoding of approval logic, role assignment, and exception handling. That means the agent's output has to be treated as a governed artifact, with the same scrutiny applied to any other change in access policy. The implication is that AI-assisted workflow design belongs inside change control, not beside it.

This points to a broader shift in identity operations. The market is moving toward identity systems that can reason over policy and data in real time, but most governance programmes still certify static artefacts. That mismatch creates operational drift between how access is actually handled and how assurance is recorded. Practitioners should expect the next control debate to centre on whether identity governance can keep pace with agentic decision support.

From our research library:

What this signals

Identity data boundary: Regulated teams now need a clear line between conversational assistance and data exposure, because the value of agentic AI in IGA depends on inspecting live entitlements without exporting them. That boundary belongs in architecture reviews, vendor risk decisions, and workflow design before the first production use.

The practical test is no longer whether a model can summarise an identity event. It is whether the programme can preserve approval integrity when the same interaction also drafts the workflow, identifies the risk, and accelerates execution.


For practitioners

  • Define the local model boundary Confirm which identity datasets the agent may query, which outputs it may generate, and which actions still require explicit human approval inside the workflow.
  • Separate evidence retrieval from approval Make sure the system can surface orphaned accounts, SoD violations, and privileged sessions without collapsing those findings into automatic provisioning or access changes.
  • Review generated workflows as governed artifacts Treat chat-built onboarding flows like any other policy change, with approval path review, entitlement validation, and exception handling checked before deployment.
  • Keep regulated identity data in environment Use deployment and access controls that prevent identity data from leaving the tenant or estate when the agent is used in regulated environments.

Key takeaways

  • Agentic AI changes IGA by compressing evidence search, workflow drafting, and review support into a single interaction.
  • The control challenge is not just speed. It is preserving approval integrity, data residency, and separation of duties when the agent sees live identity data.
  • Practitioners should treat generated workflows as governed artifacts and keep high-risk decisions inside explicit human approval paths.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article centers on agentic AI acting on identity data and workflows.
Recommendation — Restrict agent-generated identity actions so privilege decisions remain explicitly governed.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe local agent needs tightly scoped access to identity data and workflow actions.
Recommendation — Scope the agent's access to the minimum identity data and functions it needs.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article raises governance, accountability, and deployment boundary questions for AI in IGA.
Recommendation — Define ownership, approval authority, and escalation rules for agentic identity workflows.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article focuses on access review and authorization decisions in IGA workflows.
Recommendation — Review entitlements and authorizations before agent-driven workflows can change access.

Key terms

  • Agentic IGA: An identity governance model where an agent can choose how to execute identity lifecycle actions against target applications. The core difference from classic IGA is runtime decisioning about mechanism, which makes execution evidence and accountability part of the governance problem, not just policy approval.
  • Identity Data Boundary: The identity data boundary is the line that defines which identity records, entitlements, and review artifacts a system may inspect, retain, or expose. In agentic environments, it becomes a control boundary as well as a privacy boundary because the model can infer and assemble sensitive governance context from live data.
  • Workflow Generator: A workflow generator is a tool that helps create structured automation flows from conversational prompts or guided inputs. In identity programmes, it reduces setup effort and can surface inefficiencies, but the resulting workflow still needs review for policy alignment, edge cases, and unintended access paths before production use.
  • Segregation of Duties: Segregation of Duties is a control principle that prevents one person or role from combining incompatible permissions that could create fraud, error, or undetected change. In ERP environments, it must account for roles, transactions, approvals, and compensating controls across business processes.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 3, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org