TL;DR: Traditional perimeter tools, SSPM, and DSPM were built for a more static enterprise, but Vorlon’s session replay argues the active layer has shifted into SaaS and AI execution, where 99.4% of organisations saw a SaaS or AI ecosystem incident in 2025 and 86.8% still cannot see what data AI tools exchange with SaaS apps. The governance problem is now data-in-motion across non-human identities, not just system inventory.
Editorial analysis by NHI Mgmt Group, based on content published by Vorlon: “The Front Door Is Locked. The Engine Room Is Wide Open.”.
By the numbers:
- 99.4% of organisations experienced a SaaS or AI ecosystem incident in 2025.
- 86.8% still cannot see what data AI tools are exchanging with their SaaS applications.
Key questions
Q: How should security teams govern AI tools that connect to SaaS data?
A: Treat each AI tool as a non-human identity with an owner, a defined scope, and an expiry path.
Q: What breaks when a platform stores customer OAuth tokens and API keys without governance?
A: The platform stops being a neutral integration layer and becomes a delegated access repository with live production reach into customer systems.
Q: What breaks when shadow AI is treated as ordinary SaaS sprawl?
A: Teams miss the real control problem, which is not the app itself but the data it can access and the identities it uses.
Practitioner guidance
- Map the converged execution layer Inventory sanctioned and shadow SaaS connections, AI tools, and automations, then trace where data actually moves between them.
- Govern OAuth grants and API scopes continuously Review delegated access, token lifetime, and downstream propagation as living controls rather than one-time approvals.
- Classify non-human identities by runtime behaviour Separate service accounts, bots, copilots, and agents in monitoring and access review so machine-led activity is not treated as ordinary user behaviour.
Bottom line: The article shows that the real governance gap is in SaaS and AI execution, where delegated identities and automations move data beyond the reach of static posture tools.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Execution-layer governance is now the control plane that matters. Legacy categories like SSPM and ITDR are still useful, but they do not fully describe how SaaS, AI, and NHI authority actually moves across systems. Once AI agents and integrations can browse, query, and transfer sensitive data inside the enterprise, the security boundary is no longer the application owner. Practitioners need to treat runtime data movement as the governance object, not an after-the-fact log artifact.
A few things that frame the scale:
- 92% agree governing AI agents is critical to enterprise security, yet only 44% have implemented any policies to do so, according to AI Agents: The New Attack Surface report.
- 96% of technology professionals identify AI agents as a growing security threat, and 66% believe this risk is immediate.
A question worth separating out:
Q: What should organisations do first when AI agents and shadow integrations are spreading?
A: Start with discovery, then rank connections by data sensitivity and delegated authority. The immediate goal is to identify which non-human identities can access regulated or confidential data, because those paths define the highest containment priority when an incident occurs.
👉 Read our full editorial: The SaaS and AI execution layer is outpacing IAM controls
Execution-layer governance is now the control plane that matters. Legacy categories like SSPM and ITDR are still useful, but they do not fully describe how SaaS, AI, and NHI authority actually moves across systems. Once AI agents and integrations can browse, query, and transfer sensitive data inside the enterprise, the security boundary is no longer the application owner. Practitioners need to treat runtime data movement as the governance object, not an after-the-fact log artifact.
A few things that frame the scale:
- 92% agree governing AI agents is critical to enterprise security, yet only 44% have implemented any policies to do so, according to AI Agents: The New Attack Surface report.
- 96% of technology professionals identify AI agents as a growing security threat, and 66% believe this risk is immediate.
A question worth separating out:
Q: What should organisations do first when AI agents and shadow integrations are spreading?
A: Start with discovery, then rank connections by data sensitivity and delegated authority. The immediate goal is to identify which non-human identities can access regulated or confidential data, because those paths define the highest containment priority when an incident occurs.
👉 Read our full editorial: The SaaS and AI execution layer is outpacing IAM controls
Execution-layer governance is now the missing identity discipline. IAM programmes were built to govern who can sign in, what they can reach, and when access should be removed. That model does not fully cover SaaS integrations, AI copilots, and automation chains that act continuously inside the business process itself. Practitioners should treat execution paths as governed identity surfaces, not as application plumbing.
A few things that frame the scale:
- Gartner predicts that by 2028, 33% of enterprise software applications will include agentic AI, up from less than 1% in 2024, and that 15% of day-to-day work decisions will be made autonomously.
A question worth separating out:
Q: What should organisations do first when they cannot see data flow between AI tools and SaaS apps?
A: Start by mapping the highest-risk data paths, not every tool at once. Focus on integrations handling customer, employee, financial, or intellectual property data, then trace the identities and tokens that can move that information. Visibility into those paths creates the fastest reduction in exposure.
👉 Read our full editorial: The SaaS and AI execution layer is outpacing IAM controls