TL;DR: AI can accelerate software creation, but enterprise SaaS value still depends on service, support, platform depth, and domain expertise, according to C1.ai. The security implication is that AI-driven platforms raise governance demands around authorization, integration boundaries, and agent access rather than eliminating the need for identity controls.
NHIMG editorial — based on content published by C1.ai: Is Enterprise SaaS Dying?
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface.
- NHIs outnumber human identities by 25x to 50x in modern enterprises.
Questions worth separating out
Q: How should security teams govern AI tools that connect to SaaS data?
A: Treat each AI tool as a non-human identity with an owner, a defined scope, and an expiry path.
Q: Why do chained MCP workflows create extra identity risk?
A: Chained workflows multiply trust boundaries because each MCP server may forward the request to another server.
Q: What breaks when platformized SaaS grows faster than access governance?
A: The control model falls behind the number of integrations, roles, and delegated permissions, so access accumulates faster than teams can review it.
Practitioner guidance
- Map agent-to-service authorization paths Identify where AI agents or automation could call enterprise tools through APIs, MCP connectors, or service accounts, then document the exact permissions each path requires.
- Reduce standing privilege in platform integrations Review every integration that gives an application or agent broad access to customer data, configuration, or workflow engines.
- Separate human UX from machine UX governance Set different control expectations for human users and AI agents.
What's in the full article
C1.ai's full blog covers the operational detail this post intentionally leaves for the source:
- How the vendor frames MCP-based UX for AI agents in enterprise software
- The specific business assumptions behind platformization and data gravity
- The article's examples of how SaaS differentiation shifts from feature velocity to service depth
- The vendor's own view of how human interaction may shrink as machine interaction grows
👉 Read C1.ai's analysis of how AI is reshaping enterprise SaaS →
AI, MCP, and enterprise SaaS: what changes for security teams?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
AI does not kill SaaS so much as it relocates the control plane. The competitive moat moves from feature code to the operational and identity layer around software: authorization, integrations, support, and lifecycle management. That means the next wave of enterprise differentiation will be decided as much by governance as by engineering speed. Practitioners should expect the software product to become an identity-managed service fabric.
A question worth separating out:
Q: When should organisations require human approval for an AI agent action?
A: Require human approval when the action could change infrastructure, expose sensitive data, move laterally across systems, or trigger a business-critical workflow that is hard to reverse. Approval is also warranted when the agent’s decision depends on ambiguous input or external data that cannot be trusted at face value. High-consequence actions need a human stop point.
👉 Read our full editorial: AI is reshaping enterprise SaaS, but service still drives value