TL;DR: Identity security must move from predefined access and periodic review to real-time decisioning and inline enforcement as AI agents, non-human identities, and millisecond-scale risk outgrow static IAM models, according to Fabrix Security. The acquisition underscores how access governance now hinges on runtime context, not admin-time policy alone.
NHIMG editorial — what this means for NHI practitioners
Questions worth separating out
Q: How should security teams handle access that changes faster than review cycles can see it?
A: They should move high-risk access decisions into the request path and treat periodic review as a secondary control.
Q: Why do AI agents and NHIs force IAM teams to rethink preapproved permissions?
A: Because their behaviour is not always stable enough for static role design to remain accurate.
Q: How can organisations tell whether runtime identity controls are actually working?
A: Look for evidence that unsafe access attempts are being blocked, stepped up, or constrained at the point of use.
Practitioner guidance
- Map where access decisions are still admin-time only Inventory the paths where policy is evaluated at provisioning or review time but not at request time.
- Test whether policy output can actually stop access inline Validate that a risk decision can block, step up, or constrain the transaction before the identity reaches the target system.
- Unify context signals across human, machine, and agent identities Correlate identity history, permissions, activity, and asset sensitivity in a single decision flow so that access is judged against current business context rather than role alone.
What's in the full announcement
Fabrix Security's full post covers the operational detail this post intentionally leaves for the source:
- The architecture of the identity-centric AI decisioning engine and living identity knowledge graph
- How inline runtime enforcement is described across human, non-human, and AI agent access flows
- The vendor's own explanation of the Fabrix and Silverfort combination and why the teams say it matters
- The product direction behind real-time access decisions, JIT-by-default enforcement, and execution-path control
👉 Read Fabrix Security's explanation of autonomous identity security with Silverfort →
Silverfort and Fabrix: what runtime identity security changes?
Explore further