Back
Third-Party Agents Expose Gaps in Enterprise Identity Security
SiTech AI Team3 min read

Third-Party Agents Expose Gaps in Enterprise Identity Security

Roughly 1,280 third-party products now embed AI, but only about 282 sit behind single sign-on. The remaining thousand are invisible to identity infrastructure, creating a security gap that traditional controls cannot reach.

Agents Arrive Without a Decision Point

For several years, AI security solved a first-party problem. The company chose the model, deployed it behind a gateway, and pointed controls at what the business had adopted. Agents do not arrive that way. They arrive inside software the enterprise already runs, and they arrive without a decision.

In environments studied for the 2026 State of Agent Security Report, roughly 1,280 third-party products now embed AI. About 282 of them sit behind single sign-on. The other thousand are invisible to identity infrastructure by default, not because anyone hid them, but because an identity stack can only govern what authenticates through it, and most agents never do.

Salesforce's Slack Code, launched in August 2026, illustrates the shift. A user can tag a coding agent into any conversation, and the agent reads shared context, writes code, and opens a pull request, inheriting Slack's permissions and admin controls. For a security team, that means an autonomous actor with reach into GitHub and production infrastructure whose governance is a chat tool's channel membership.

Three Launch Vectors, One Destination

Security leaders tend to sort agents into two buckets, bought and built. There is a third, and it is the largest. Inherited agents ship inside existing platforms via product updates. Configured agents are an enterprise's own prompts and logic running on someone else's runtime, model, and connectors. Built agents are open frameworks on infrastructure the enterprise owns end to end.

The first two account for the overwhelming majority of adoption and are growing exponentially as every major application becomes an agent platform. The third is the smallest and slowest growing, and it is the only one with a repo to scan and a build to gate. Regardless of origin, agents end up in the enterprise application layer, reading data warehouses, writing to ticketing systems, and holding tokens into tools such as Salesforce, Slack, and Drive.

Four Questions for Any Agent

Every agent has two parts: the model that reasons and the scaffolding that turns a model into an actor. Almost none of the risk lives in the model. It lives in the scaffolding and the ecosystem around it. Four areas cover the risk. Identity asks whether the agent is registered anywhere and whether a named human claims it. Permissions asks what it is allowed to do and whether it inherited more OAuth scopes and roles than needed. Connectivity asks what it can reach directly and transitively, the blast-radius question that is rarely answerable from the agent's own configuration screen. Activity asks what it is actually doing, judged by behavior rather than its prompt description.

Buyers and Regulators Respond

Patrick Opet, global CISO of JPMorgan Chase, told the software industry in 2025 that the third-party supply chain had become a systemic risk, citing incidents serious enough that the bank had to isolate compromised suppliers. He has since applied the same scrutiny to agents, arguing that an agent should get an identity but no entitlements by default, with IT confirming who it acts on behalf of before it touches anything outside that boundary.

Regulators are moving on the same assumption. The EU AI Act's obligations phasing in through 2026 presume an enterprise can inventory its AI systems, name their owners, and evidence oversight. An organization that cannot enumerate its agents cannot comply. Platforms such as Reco Graph now connect every human and non-human identity, application, permission, and agent action into a single live view, making reach rather than configuration the unit of analysis.

Sources: The Hacker News

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.