How Saviynt Zuma Secures AI Agents With Zero Trust
Neil C. HughesJuly 29, 202600:34:44

How Saviynt Zuma Secures AI Agents With Zero Trust

How can businesses secure AI agents that read sensitive information, update systems and communicate with other agents on behalf of employees?



In this episode of Tech Talks Daily, I speak with Sachin Nayyar, founder and CEO of Saviynt, about AI agent identity security and the controls businesses need before autonomous systems enter production.



Saviynt manages over 100 million identities for over 700 customers. Sachin explains how enterprise identity has expanded beyond employees to include partners, applications, machines and autonomous AI agents.



An AI agent creates a different access problem because it is both an identity and an application. It can receive permissions, access information and perform actions, but its behavior can also be governed through software while it is being developed and while it is operating.



Sachin uses an HR copilot to demonstrate why context matters. Two employees can ask the same question about salaries but should receive different answers based on their roles, locations and applicable policies. Those decisions must be evaluated while the request is being processed without creating delays that make the system unusable.



The risk grows when an agent crosses from one technology environment into another. An agent built within Microsoft may need to access Salesforce, ServiceNow, Jira or another external system. Sachin warns businesses never to solve this problem by giving an agent a permanent administrative account.



We discuss Zuma, Saviynt’s identity security platform for AI agents and non-human identities. Sachin describes a four-part framework beginning with agent discovery and a central registry. Every agent should then receive one accountable human owner, temporary access for its assigned task and policy enforcement while it acts.



Ownership becomes especially important when an employee leaves. Saviynt’s approach begins an automated reassignment process and blocks actions if an agent attempts to operate without a current owner. The relevant security team can then investigate before allowing further activity.



Sachin also explains why identity controls should enter the development process rather than being added after deployment. Saviynt is working with LangChain and other agent development platforms to make identity policies available while AI agents are being built.



The conversation also covers Saviynt’s partnership with Zscaler. Zscaler provides inline enforcement, while Saviynt contributes identity information about the agent, its owner, existing permissions and expected behavior.



Sachin closes with an optimistic argument. Because businesses can place security controls into the code and enforce them while agents act, AI workloads may eventually become better governed than traditional human access.



Could every AI agent inside your business be traced to one accountable owner, one approved purpose and a limited set of temporary permissions? Please share your thoughts with me.