TL;DR: Traditional perimeter tools, SSPM, and DSPM were built for a more static enterprise, but Vorlon’s session replay argues the active layer has shifted into SaaS and AI execution, where 99.4% of organisations saw a SaaS or AI ecosystem incident in 2025 and 86.8% still cannot see what data AI tools exchange with SaaS apps. The governance problem is now data-in-motion across non-human identities, not just system inventory.
At a glance
What this is: This session replay argues that SaaS and AI execution has become the active enterprise layer, while most security controls still assume a more static environment and therefore miss data movement by AI tools, integrations, and non-human identities.
Why it matters: IAM, IGA, and PAM teams need to understand that governance gaps now sit inside live SaaS and AI execution paths, where visibility, approval, and revocation all need to follow data and identity activity in motion.
By the numbers:
- 99.4% of organisations experienced a SaaS or AI ecosystem incident in 2025.
- 86.8% still cannot see what data AI tools are exchanging with their SaaS applications.
Context
The SaaS and AI execution layer is the part of the environment where applications, integrations, copilots, agents, and automations actually move data and take action. In practice, that layer now carries more operational risk than the static inventory view most identity and posture tools were built to manage, which is why traditional control models are lagging.
For identity governance, the problem is not only whether an account exists, but whether a token, integration, or AI-driven workflow is moving sensitive data with organisational authority. When SaaS, AI, and non-human identities converge, access control and visibility have to follow execution, not just provisioning records.
Key questions
Q: How should security teams govern AI tools that connect to SaaS data?
A: Treat each AI tool as a non-human identity with an owner, a defined scope, and an expiry path. Require approval for every new integration, limit access to the minimum necessary SaaS objects, and review delegated permissions on a recurring schedule. Governance fails when consent is treated as a one-time event instead of a lifecycle.
Q: What breaks when a platform stores customer OAuth tokens and API keys without governance?
A: The platform stops being a neutral integration layer and becomes a delegated access repository with live production reach into customer systems. Without inventory, ownership, and revocation controls, the platform can expose many customer environments from a single compromise, and security teams lose the ability to contain access by customer, tool, or credential type.
Q: What breaks when shadow AI is treated as ordinary SaaS sprawl?
A: Teams miss the real control problem, which is not the app itself but the data it can access and the identities it uses. Shadow AI can transform, summarise, and share sensitive information in ways traditional inventories do not capture, so an app-centric model understates exposure and delays remediation.
Q: What should organisations do first when they cannot see data flow between AI tools and SaaS apps?
A: Start by mapping the highest-risk data paths, not every tool at once. Focus on integrations handling customer, employee, financial, or intellectual property data, then trace the identities and tokens that can move that information. Visibility into those paths creates the fastest reduction in exposure.
Technical breakdown
Why SaaS execution paths evade traditional identity controls
Traditional IAM assumes a bounded subject, a known system boundary, and a reviewable entitlement set. SaaS integrations and AI-driven workflows break that model because they create short-lived, chained, and often unsupervised execution paths across multiple services. The resulting control gap is not simply more accounts, but more ways for non-human identities to act with delegated authority without a clean ownership trail. SSPM can inventory configurations, but inventory is not the same as seeing what actually moves at runtime. That distinction matters when data crosses apps through OAuth, APIs, and automation layers that security teams do not directly govern.
Practical implication: Treat runtime execution paths as a first-class identity problem, not a side effect of application sprawl.
How OAuth tokens and API keys become the real control plane
OAuth grants and API keys are often the durable mechanism behind SaaS-to-SaaS and AI-to-SaaS exchange. Once issued, they can outlive user intent, change hands through integrations, or be reused by downstream services that were never separately assessed. That makes the token, not the user interface, the effective control plane. The article’s focus on compromised OAuth tokens shows why governance has to cover issuance, scope, revocation, and downstream propagation. If you only monitor the front-end app, you miss the actual authority path that attackers and shadow automation use.
Practical implication: Govern token lifecycle and downstream scope as tightly as you govern human sign-in and privileged access.
Why AI agents can blend into human identity patterns
AI agents do not need to be fully autonomous to create identity risk. When they operate through human-owned credentials, borrowed session context, or familiar SaaS behaviours, they can resemble legitimate users closely enough to bypass behavioural detection. That is a classic identity abstraction failure: the system assumes the actor type is stable, while execution may be machine-led and data-driven. This is why human-centric anomaly models struggle in converged environments. The relevant question is no longer only who signed in, but which non-human workflow is now acting under that identity and moving data at machine speed.
Practical implication: Classify execution actors explicitly so detection and governance can distinguish human activity from machine-led behaviour.
Threat narrative
Attacker objective: The objective is to use legitimate-looking SaaS and AI execution paths to access, move, or exfiltrate sensitive data while avoiding traditional perimeter and identity controls.
- Entry occurs through sanctioned or shadow SaaS integrations, OAuth consent, or exposed API credentials that give an attacker or rogue workflow an initial execution foothold.
- Credentialed access is then abused through tokens, delegated scopes, or service identities that already have authority to read, move, or transform sensitive data across apps.
- The attacker or malicious automation expands reach by chaining downstream connections, using one integration to reach many others while staying inside expected SaaS trust relationships.
- Impact lands in the data plane, where sensitive records, tokens, and operational context are moved, exposed, or manipulated across the converged SaaS and AI ecosystem.
Breaches seen in the wild
- CoPhish OAuth phishing via Copilot Studio: Datadog showed Copilot Studio agents on a Microsoft domain can front OAuth consent phishing and forward stolen tokens; no victims reported.
- DeepSeek database exposure 2025: An unauthenticated DeepSeek ClickHouse database exposed over a million log lines with plaintext chat history and API keys in 2025.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Execution-layer governance is now the missing identity discipline. IAM programmes were built to govern who can sign in, what they can reach, and when access should be removed. That model does not fully cover SaaS integrations, AI copilots, and automation chains that act continuously inside the business process itself. Practitioners should treat execution paths as governed identity surfaces, not as application plumbing.
Data-in-motion has become the practical boundary of identity security. The article shows that the enterprise perimeter is no longer the main question; the decisive risk sits in how data moves through SaaS and AI workflows. That shifts the governance problem from static inventory toward runtime authority, token scope, and downstream sharing across non-human identities. The implication is that identity security now has to follow the transaction, not just the account.
OAuth governance gap: delegated trust outlives operational intent. OAuth and API tokens were designed for delegated access, but delegated access becomes a control failure when scope, ownership, and revocation are not continuously governed. Nearly 90% of CISOs may believe governance is strong, yet compromise through tokens and keys shows that the assumption is weaker than the policy language suggests. Practitioners should regard token governance as a lifecycle discipline, not a one-time approval step.
Shadow SaaS and shadow AI collapse the idea of a fixed attack surface. When any employee can spin up an integration or agent without IT review, the boundary between sanctioned and unsanctioned execution becomes operationally meaningless. That creates identity sprawl inside the workflow layer itself, where controls cannot rely on the old premise that the asset inventory defines the risk surface. Security teams should reframe discovery around active connections and delegated authority.
Agentic identity risk is now an ecosystem problem, not a single-tool problem. The most useful named concept here is the converged SaaS and AI ecosystem, because it captures the shared identity, data, and trust dependencies now driving exposure. Security teams that keep SaaS, AI, and NHI governance in separate workstreams will miss the cross-domain pathways that actually matter. The practical conclusion is to unify governance around execution, not product category.
From our research library:
- Gartner predicts that by 2028, 33% of enterprise software applications will include agentic AI, up from less than 1% in 2024, and that 15% of day-to-day work decisions will be made autonomously.
- Read next: Zero Trust for AI Agents
What this signals
Converged SaaS and AI execution is now the control boundary that matters. Security leaders should stop treating SaaS posture, AI posture, and identity posture as separate operating problems. The combined ecosystem is where data moves, where delegated trust accumulates, and where governance failures become operational incidents.
Identity programmes need a runtime lens, not just a provisioning lens. Access reviews built around static accounts will miss tokens, automations, and copilots that act inside business workflows. The question is not whether an identity exists, but whether it is still moving data with authority the organisation intended.
Agentic AI governance is moving into the mainstream faster than many programmes can absorb: 33% of enterprise software applications will include agentic AI by 2028, up from less than 1% in 2024, and 15% of day-to-day work decisions will be made autonomously. That shift means security teams need governance models that can follow machine-led execution, not just human-led approval chains.
For practitioners
- Map the converged execution layer Inventory sanctioned and shadow SaaS connections, AI tools, and automations, then trace where data actually moves between them.
- Govern OAuth grants and API scopes continuously Review delegated access, token lifetime, and downstream propagation as living controls rather than one-time approvals.
- Classify non-human identities by runtime behaviour Separate service accounts, bots, copilots, and agents in monitoring and access review so machine-led activity is not treated as ordinary user behaviour.
- Prioritise data-in-motion visibility Focus monitoring on sensitive data movement across SaaS and AI workflows, especially when integrations cross business-critical or regulated records.
Key takeaways
- The article shows that the real governance gap is in SaaS and AI execution, where delegated identities and automations move data beyond the reach of static posture tools.
- The evidence points to a widespread problem, with nearly all organisations reporting a SaaS or AI ecosystem incident and most still unable to see AI data exchange with SaaS apps.
- Security teams should shift from inventory-based control to runtime governance of tokens, integrations, and data-in-motion across the converged ecosystem.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-02 — Secret Leakage | OAuth tokens and API keys are central to the delegated trust failures described here. |
| NHI-03 — Vulnerable Third-Party NHI | Third-party SaaS integrations and downstream connections expand the trust surface in this article. | |
| NHI-05 — Overprivileged NHI | The article highlights broad OAuth scopes and excessive machine authority across connected apps. | |
| Recommendation — Scan and revoke exposed tokens and keys before they can be reused across SaaS integrations. Assess third-party SaaS connections for delegated access, scope creep, and offboarding gaps. Reduce non-human identity permissions to the minimum scope needed for each workflow. | ||
| OWASP Agentic AI Top 10 | ASI02 — Tool Misuse | AI tools and agents are moving data across SaaS applications in ways that can exceed intended use. |
| Recommendation — Constrain agent tool use to approved actions and monitor for unexpected cross-app execution. | ||
| MITRE ATT&CK | TA0006; TA0008 — Credential Access; Lateral Movement | The incident pattern centers on token abuse and movement through connected SaaS environments. |
| Recommendation — Map token abuse and downstream SaaS chaining to credential access and lateral movement detections. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is fundamentally about delegated access and entitlement governance across the execution layer. |
| Recommendation — Continuously review delegated permissions and entitlement scope for SaaS and AI integrations. | ||
Key terms
- Converged SaaS and AI Ecosystem: The combined operating environment where SaaS applications, AI tools, copilots, agents, and automations exchange data and act on behalf of the business. In identity terms, it is the runtime layer where delegated authority, data movement, and machine-led execution intersect and must be governed together.
- Execution Layer: The execution layer is the operational point where identity policy becomes system change. It is where approvals, provisioning, revocation, and session controls either complete successfully or fail in ways that create drift. For practitioners, this is where governance is proven, not merely documented.
- OAuth Governance: OAuth governance is the discipline of controlling delegated app access after consent is granted. It covers ownership, scope, review, revocation, and downstream propagation, because the real risk often emerges after the initial approval when connected systems inherit trust.
- Data-in-Motion: Data-in-motion is sensitive information while it is being transferred between systems, identities, or applications. For SaaS and AI programmes, the main concern is not only where data is stored, but which identities can move it, transform it, or expose it during transit.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org