TL;DR: Insider risk is still being handled as disconnected alerts across DLP, UEBA, ITDR, CASB, SIEM, and shadow AI tooling, while legitimate access and agentic workflows create one continuous story that point products cannot reconstruct, according to Above. The real governance gap is not more detection volume, but correlated investigation across human and AI-assisted behaviour before intent becomes loss of data or control.
NHIMG editorial — based on content published by Above: Collapsing the Insider-Risk Stack Into One Investigation
By the numbers:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%).
- 96% of technology professionals identify AI agents as a growing security threat, and 66% believe this risk is immediate.
Questions worth separating out
Q: How should security teams investigate insider-risk cases across multiple tools?
A: They should build one correlated case record that joins identity, application, content, and endpoint events in sequence.
Q: Why do AI agents complicate insider threat governance?
A: AI agents inherit human permissions and can act repeatedly without waiting for approval on each step, so they inherit both access and speed.
Q: What are the signs that insider-risk tooling is failing?
A: A common sign is that analysts can see individual anomalies but still cannot explain the full incident without switching between multiple consoles.
Practitioner guidance
- Build one correlated investigation workflow Join IAM, DLP, UEBA, CASB, SIEM, and NHI telemetry into a single case record so analysts can follow login, export, paste, and delegation in order.
- Include AI agents in insider-risk scoping Map which agents act on behalf of employees, what tools they can reach, and which approvals or logging controls govern those delegated actions.
- Separate anomalous from harmful behaviour Require investigators to record the business context behind deviations such as quarter-end exports, travel, promotions, or launch pressure before escalation.
What's in the full article
Above's full blog post covers the operational detail this post intentionally leaves for the source:
- How the Synthetic Insider Threat Matrix is structured for investigation and case handling across human and agent activity.
- The specific workflow Above describes for joining identity, DLP, CASB, UEBA, and SIEM evidence into one chronology.
- The vendor's explanation of how it distinguishes ordinary deviation from malicious intent using context and sponsorship.
- The details of the authorised role and logging approach used to keep employee-facing coaching defensible for HR and legal.
👉 Read Above's analysis of collapsing insider risk into one investigation →
Insider risk and AI agents: what happens when one shelf is not enough?
Explore further
Insider risk has become an identity correlation problem, not a detection problem. The article is right to reject the shelf-of-tools model because no isolated control can explain a person, their access, and their actions across time. DLP, UEBA, CASB, ITDR, and SIEM each contribute partial evidence, but the discipline is the correlation layer that turns evidence into an investigation. For identity programmes, the lesson is that investigative completeness matters more than alert count.
A few things that frame the scale:
- Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation, according to the AI Agents: The New Attack Surface report.
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including unauthorised system access, sensitive data sharing, and credential disclosure.
A question worth separating out:
Q: Should organisations treat agentic AI separately from insider-risk programs?
A: No. If an AI agent operates on behalf of a person, its access and actions belong inside the insider-risk boundary because the behavioural question is the same: what was done, on whose behalf, and with what evidence. Separate programs tend to duplicate data while missing the sequence that explains harm.
👉 Read our full editorial: Insider risk in the agentic era needs one correlated investigation model