New Orchid Security AI Readiness Controls Give Enterprises Visibility Into Agent Identity Drift and Runtime Risk

Readiness tagging, always-on observability, and orchestrated kill switches at the application layer let enterprises expand agent deployments while retaining authority over them.

New York, London – September 15, 2026 – Orchid Security, which makes safe AI adoption possible by fixing identity at the root, today introduced identity drift detection paired with application-level kill switches built for AI agents. Within seconds, an agent pursuing a sanctioned objective can end up operating well above the privilege tier it started with. No security control has to be defeated and no workflow guardrail has to fail for this to happen. Agents simply locate and exercise the identity debt already sitting inside the enterprise — credentials hard-coded into applications, accounts nobody owns, authentication routes nobody manages, and permissions far broader than any task requires. The company’s new AI readiness controls are designed so that scale and oversight advance together.

Boards Are Setting the Agenda for AI Adoption

The board-level question has shifted. Directors no longer debate whether AI belongs in the business; they want to know how fast it can be rolled out. Saying no is not a security strategy anymore. What security organizations require instead is a defensible operating plan — one that clears the path for adoption while holding autonomous agents inside sanctioned limits.

“AI transformation is exciting. Identity hygiene is not,” said Roy Katmor, co-founder and CEO of Orchid Security. “Boards are no longer asking whether AI will be adopted—they are asking why it is not moving faster, and security cannot answer with a blanket ‘no.’ Enterprises need to observe how agents act, understand when they drift, and govern them immediately, including terminating the authority through which they operate.”

What agents do is rarely the problem. What they inherit is. Exceeding an intended scope requires no exploitation of security controls; agents discover the identity debt already distributed across the environment — embedded credentials, orphaned accounts, unmanaged authentication paths, excessive permissions — and put it to work. Orchid’s Identity Gap 2026 research determined that 57% of enterprise identity sits unseen and unmanaged. Agents can convert that identity dark matter into a live route to elevated access on a timeline measured in seconds or minutes, well ahead of any periodic governance review’s ability to notice or stop it.

That pressure is only intensifying. Pilots that launched as narrow single-task automations are being stitched together into multi-step workflows reaching across applications, data repositories, and outside services — and every handoff picks up credentials and entitlements that were never scoped with autonomous actors in mind. Meanwhile, security leaders are expected to sign off on that expansion using a review rhythm built for quarterly certification of human access, not for machine identities that never stop working.

A Control-Led Model for Deploying AI Agents

Orchid delivers continuous, auditable AI readiness and defensibility across four linked stages — Observe, Understand, Govern, Prove:

  • OBSERVE: Inventory the AI agents in use along with the identities, applications, credentials, tools, and access paths they operate through. Behavior is captured continuously as it actually occurs, not merely as it was declared in the studio.
  • UNDERSTAND: Measure live behavior against the agent’s stated purpose and sanctioned scope. Readiness tags are applied to applications, accounts, and access paths, surfacing hygiene gaps, over-broad entitlements, and environments not yet fit for agentic access.
  • GOVERN: Should behavior or effective authority move outside policy, Orchid drives action through the identity, security, and AI infrastructure the organization already runs. Responses range from trimming permissions, revoking credentials, severing tool connections, and halting workflows to triggering its own application-level kill switch — a capability unique to the platform.
  • PROVE: Orchid produces a defensible record that ties every agent action back to the identity involved, the delegation chain, the access path, the business context, any drift observed, and the governance response that followed.

The framework is built to operate within the stack enterprises have already invested in. Instead of standing up a parallel enforcement tier that agents would need to be redesigned around, Orchid’s Identity Control Plane orchestrates through in-place IAM, PAM, SIEM, and AI platform components — allowing a drift signal observed at runtime to trigger a permission reduction or credential revocation inside the system of record that already owns it.

Evidence Enterprises Need to Produce

Ahead of any large-scale autonomous agent rollout, organizations should be positioned to show:

  • Identity Hygiene: All orphaned, dormant, local, and over-privileged accounts have been found and given a readiness status.
  • Authorization Guardrails: The enterprise can state who or what is permitted to act, on whose behalf, toward what purpose, and under which conditions.
  • Runtime Understanding: Observed agent activity is checked continuously against approved intent, granted permissions, and expected access paths.
  • Universal Auditability: Each action traces back to an identity, a delegation chain, an application, an access path, and a business context.
  • Enforceable Response: Authority relied upon by a drifting agent can be curtailed or cut off without delay.

Regulatory expectations are landing in the same place. NIST’s draft Cyber AI Profile observes that “regardless of where organizations are on their AI journey, their cybersecurity programs need risk management approaches that support and integrate the realities of advancements in AI.” Across Europe, DORA requires financial entities to evidence control over ICT access and third-party dependencies — a duty that holds whether the actor in question is a person or an agent.

Ensuring Reliable AI Agent Availability

Building on the agentic upgrades delivered to Orchid’s Identity Control Plane in May, the following capabilities are generally available:

  • AI readiness tagging spanning applications, identities, and access paths
  • Hygiene and security risk findings covering orphaned, dormant, over-permissioned, and suspicious accounts
  • Ongoing drift detection between an agent’s declared purpose and its observed activity
  • Orchestrated response, including application-level kill switches that pare back permissions, revoke credentials, sever tool connections, or halt agent workflows
  • Audit generation capturing agent activity, identity context, detected drift, and the action taken

The company has also broadened its integration ecosystem:

  • Palo Alto Networks Idira: A certified PAM integration that surfaces privileged accounts previously unknown to Idira and places them under management.
  • Splunk Enterprise Security: A prebuilt integration feeding identity telemetry into the SOC for correlation, investigation, and incident response.

Shannon Wilkinson, CIO and CISO at Findlay Automotive Group, framed the dilemma from an operator’s vantage point: “The challenge is how to enable the business to move faster and realize the productivity that AI agents bring, but it honestly terrifies a lot of us. At Findlay we’re leaning heavily into AI to build a better customer experience. At the same time we must define guidelines, put guardrails in place and, above all, know what the identities are doing.”

Identity dark matter broadly — and weak identity hygiene in particular — has gone unaddressed in enterprises for years, which helps explain why adversaries today are likelier to sign in than to break in. Turning AI agents loose on top of that accumulated identity clutter invites failure.

Availability here means something larger than a ship date. An agent that cannot be trusted while it runs is an agent that gets suspended, reverted, or pulled out of the workflows it was built to handle — and the productivity argument disappears along with it. Combining sustained agent behavior monitoring with an enforceable response path, the controls announced today aim to keep sanctioned agents live in production instead of stalled in review queues.

To learn more about Orchid Security’s approach to securing autonomous identities or request a demo, visit https://www.orchid.security/use-case/guardrails-for-autonomous-identity.

Meet Us at Gartner Security & Risk Management Summit London 2026

Orchid Security will be on the ground at the Gartner Security & Risk Management Summit, held at ExCeL London from September 22 to 24. Team members will be available throughout the event to talk through AI readiness and identity dark matter with security and risk executives. Visit Booth #105 for a live platform walkthrough, or reserve time in advance via the form to secure a slot with the team.

About Orchid Security

Orchid Security sees straight into the application binary to deliver the industry’s first Identity Control Plane, transforming IAM complexity into clarity, compliance, and control. Its Identity-First Security Orchestration platform continuously discovers enterprise applications, analyzes their native authentication and authorization flows, and accelerates onboarding into governance systems, putting true identity insight in front of security leaders and practitioners, without the months of manual work traditionally required for each task or informational ask. By exposing and remediating the ‘identity dark matter’ hidden across modern environments, Orchid helps enterprises solve identity at its core; reducing risk, lowering operational costs, and achieving compliance at scale.

Media Contact

Chloe Amante camante@montner.com Montner Tech PR