Applied Morning Intelligence
RSAC 2026 delivers a verdict: AI agents are proliferating faster than identity controls can contain them — Microsoft, Okta, Cisco, Palo Alto, and CrowdStrike all launched agent-identity products in the same week, confirming that agent governance is now the central enterprise security problem of 2026.
RSAC 2026 week has turned the advisory landscape into a land-grab for agent governance. IBM is rebranding consulting itself as 'services as software' with $4.5B in internal AI productivity gains as proof. Accenture is making AI proficiency a literal promotion requirement while scaling a 25,000-person Databricks delivery force. Deloitte's 2026 State of AI report puts the governance gap in stark terms: only 1 in 5 companies has a mature model for governing autonomous agents. BCG projects $200B in net new value for tech service providers from agentic AI by 2030 — framing 2026 as the inflection year.
Published a 'Services as Software' manifesto positioning IBM Consulting Advantage as an Agent Management Platform, reporting $4.5B in internal AI productivity gains from 100+ reinvented workflows and 3,000+ digital assistants working alongside consultants.
Applied Identities' Compiled Corporation framework addresses what 'services as software' leaves unresolved: when consulting delivery becomes agent-mediated, who specifies what those agents are allowed to decide, what organizational permissions govern their access, and how drift between intended behavior and actual behavior is detected and corrected before it compounds.
Made AI proficiency a mandatory condition for promotions and performance appraisals — the most explicit AI-first workforce mandate from any major enterprise — while reporting record Q2 2026 bookings of $22.1B and exceeding its 80,000 AI/data professionals target with 85,000+.
Applied Identities helps organizations design the identity architecture that makes workforce AI mandates operationally safe: defining which agent-mediated decisions require human approval, which can be delegated fully, and what governance layer prevents a workforce-wide AI rollout from becoming uncontrolled agent sprawl.
Launched the Accenture Databricks Business Group with 25,000+ trained professionals to help enterprises build agent-ready databases using Lakebase, Genie, and Agent Bricks, with early clients including Albertsons, BASF, and Kyowa Kirin International.
Applied Identities' agent orientation practice designs the organizational control layer that sits above the data platform: specifying decision surfaces — where agents can act, what data they can access, and what escalation paths exist when agent behavior drifts from the organization's intent.
Published the 2026 State of AI in the Enterprise report (n=3,235, 24 countries) finding worker AI access rose 50% in 2025 but only 1 in 5 organizations has a mature governance model for autonomous AI agents.
The governance maturity gap Deloitte identifies is precisely the problem Applied Identities was built to solve. The Identity Control Surface translates the abstraction of 'governance' into concrete organizational permissions: which agents have which decision rights, under what monitoring conditions, with what audit trail and escalation triggers.
Projects agentic AI will generate up to $200B in net new value pools for tech service providers by 2030, with one-third of enterprises already scaling agentic deployments and 45% expecting to increase AI spending.
Applied Identities helps organizations capture BCG's projected value by ensuring the scaling path is governable from the start. The Compiled Corporation framework encodes decision principles into agent-readable infrastructure — so the shift from pilot to enterprise-wide deployment does not require rebuilding governance after the fact.
Launched the Charlotte AI AgentWorks Ecosystem at RSAC 2026, a no-code security agent development platform with Accenture, AWS, Deloitte, Kroll, and Telefónica Tech as launch partners, integrating Anthropic Claude, NVIDIA Nemotron, and OpenAI GPT.
Applied Identities' drift control methodology addresses the challenge that CrowdStrike's ecosystem surfaces: when every Falcon user can build and deploy custom security agents, the question shifts from 'can the organization build agents?' to 'can it specify, monitor, and contain what those agents are allowed to do?' — an organizational identity problem, not a tooling problem.
Today's strongest readiness signals converge on a single finding: the enterprise AI adoption curve has outrun the governance curve. Multiple independent data sources — Trend Micro (67% approve AI despite security concerns), Deloitte (only 20% have mature agent governance), Cisco (only 5% of enterprises have deployed agents to production), and DataCamp/YouGov (only 21% see significant ROI) — paint a consistent picture. The EU AI Act high-risk enforcement deadline (August 2, 2026) and the SEC's formal AI governance examination priority add regulatory urgency.
Applied Identities' governance layer converts the pressure-versus-control tension into a manageable architecture. The Identity Control Surface defines organizational permissions for AI systems — not as a compliance overlay, but as the operating structure that allows deployment to proceed safely by specifying exactly what each agent can and cannot do.
Applied Identities addresses the experiment-to-production gap by designing the organizational permissions layer that enterprises lack. Decision Surfaces specify what agents are authorized to change, under what conditions, and with what human oversight — converting the abstract 'security concern' into a concrete, auditable control architecture.
Applied Identities' talent strategy work goes beyond upskilling to define the organizational operating model: which roles delegate which decisions to agents, what new capabilities humans need to supervise agent-mediated work, and how ROI is attributed to specific decision surfaces rather than measured as aggregate productivity improvement.
Applied Identities' Identity Control Surface addresses the identity incident crisis at the organizational layer. Platform vendors like Microsoft solve the technical plumbing — authenticating and authorizing agents — but the upstream question is architectural: which agents should exist, what should they be allowed to do, and who in the organization is accountable when they act? That is the identity architecture gap Applied Identities fills.
Applied Identities helps organizations prepare for regulatory enforcement by building the governance infrastructure the regulations require: systematic inventories of AI systems, documented decision rights and accountability chains, and auditable records of what agents are authorized to do. The Compiled Corporation framework encodes compliance into the operating system of the organization rather than treating it as a reporting exercise.
RSAC 2026 (March 23–26, San Francisco) produced the most concentrated wave of AI agent identity product launches in the industry's history. Microsoft Entra Agent ID, Okta for AI Agents (GA April 30), Ping Identity Agentic Core, SailPoint Adaptive Identity, CyberArk Secure AI Agents, 1Password Unified Access, Entro Security AGA, and Nudge Security AI Agent Discovery all address the same thesis: AI agents must be discoverable, uniquely identifiable, and governed with the same rigor as human users. The architectural patterns crystallizing across the market — agent discovery at creation, just-in-time credential delivery, MCP-layer policy enforcement, runtime authorization, and universal kill-switch mechanisms — confirm that non-human identity governance has arrived as a product category.
Unveiled Entra Agent ID at RSAC 2026, extending Conditional Access and identity governance to AI agents built with Copilot Studio and Azure AI Foundry — assigning unique managed identities to non-human actors for the first time at enterprise scale.
Microsoft solves the technical identity plumbing for agents within its ecosystem. Applied Identities solves the upstream organizational question: which agents should exist in the first place, what decision rights they carry, and how the organization maintains coherent governance when agents span multiple platforms — not just the Microsoft stack.
Announced 'Okta for AI Agents' going GA April 30, 2026 with shadow agent discovery, an Agent Gateway with virtual MCP server, privileged credential vault, and a universal logout kill switch — framing the product around three questions: where are my agents, what can they connect to, and what can they do.
Okta's three questions — where are my agents, what can they connect to, what can they do — are infrastructure questions. Applied Identities adds the organizational layer: who authorized these agents, what business decisions are they making, and does the agent's actual behavior match the organization's stated intent? That gap between platform controls and organizational governance is where identity architecture lives.
Announced 'Agentic Core' at RSAC 2026, extending its platform to authenticate and authorize AI agents across the 'agentic channel' alongside existing web and mobile channels, targeting its 8-billion-account customer base.
Ping Identity treats the agentic channel as a parallel to web and mobile — a platform access problem. Applied Identities treats it as an organizational design problem: defining the behavioral specification for what agents do within those channels, how their actions map to business outcomes, and what governance prevents channel-level access from becoming unconstrained organizational authority.
Presented 'Adaptive Identity for the New Era of Security and AI Agents' at RSAC 2026, positioning AI-powered real-time, context-aware access decisions as the successor to static identity governance for all identity types.
SailPoint's shift from static to adaptive identity governance mirrors a fundamental requirement of agentic systems: permissions must be context-aware and dynamic. Applied Identities designs the organizational decision framework that feeds those adaptive systems — defining the business context, risk tolerances, and escalation paths that runtime authorization engines need to make correct decisions.
Showcased its Secure AI Agents Solution (GA December 2025) at RSAC 2026 — the first privilege-control platform purpose-built for AI agent identities, applying just-in-time access, zero standing privileges, and continuous session monitoring.
CyberArk brings privileged access management to agents — a critical infrastructure layer. Applied Identities addresses the organizational layer above it: defining which agents require privileged access in the first place, what the lifecycle governance model looks like from creation to decommission, and how the organization prevents privilege creep as agent capabilities expand.
Launched Unified Access Pro at RSAC 2026, discovering, securing, and auditing credentials across human, machine, and AI agent identities with just-in-time credential delivery and integrations for Anthropic, OpenAI, Cursor, GitHub, and Perplexity.
1Password's just-in-time credential delivery eliminates long-lived secrets for agents — a significant security improvement at the credential layer. Applied Identities operates at the organizational architecture layer: designing the identity model that determines which agents receive which credentials, what approval workflows govern new agent access, and how credential policies align with the broader governance framework.
Launched Agentic Governance & Administration (AGA) pre-RSAC 2026, building correlation profiles for each AI agent by synthesizing its sources, enterprise assets, and the identities it relies on — with MCP activity monitoring built in.
Entro's correlation profiles give visibility into what agents do and access. Applied Identities provides the organizational specification for what agents should do and access — the governance blueprint that makes Entro's monitoring actionable by defining the intended behavior baseline against which deviations are measured.
Hosted a closed-door executive breakfast at RSAC 2026 on 'Are you ready for the future of Agentic Commerce?', signaling a product positioning pivot toward securing AI-agent-mediated commerce transactions.
Transmit Security's agentic commerce pivot highlights the intersection of identity and commerce — exactly where Janus Brands operates. Applied Identities' Janus Brands framework addresses how organizations present coherent brand identity to both human customers and AI agent intermediaries, ensuring that agent-mediated transactions reflect the organization's brand values and decision boundaries.
Won 'Most Innovative Workforce Identity Verification Solution' at the Global InfoSec Awards at RSAC 2026 and was named an Overall Leader in KuppingerCole's Enterprise Passwordless Authentication Leadership Compass.
1Kosmos's biometric identity proofing and passwordless authentication strengthen the human-identity foundation that agent governance depends on. Applied Identities designs the identity architecture that connects human identity verification to agent delegation: ensuring that the person authorizing an agent's actions is verified, and that the chain of accountability from human to agent is unbroken.
Expanded its platform at RSAC 2026 Day 2 with AI agent discovery capabilities, providing visibility into agent identity and permissions at the creation source before agents proliferate into shadow usage.
Nudge Security catches agents at the point of creation — an early-lifecycle detection capability. Applied Identities designs the organizational policy framework that determines what happens after discovery: which agents are approved, which are quarantined, what the approval workflow looks like, and how the organization maintains a coherent agent inventory as part of its identity architecture.
Agentic commerce in the week of March 23–26 is defined by three converging dynamics: protocol maturation (Google UCP adds Cart, Catalog, and Identity Linking), strategic repositioning (OpenAI retreats from owning checkout to become a discovery gateway), and legal friction (Amazon vs. Perplexity Comet establishes the foundational legal question of agent-mediated access). At the infrastructure layer, ServiceNow AI Gateway shipped production-grade MCP governance, Google Vertex AI Agent Builder added agent IAM with A2A support, and Salesforce launched Agentforce Contact Center as the CRM-native agentic customer service platform.
Expanded the Universal Commerce Protocol on March 19 with Cart (multi-item pre-purchase exploration), Catalog (real-time product data API), and Identity Linking (OAuth 2.0 loyalty account integration), with Salesforce, Stripe, and Commerce Inc. confirming forthcoming support.
Google UCP's Identity Linking feature surfaces the precise problem Janus Brands addresses: when AI agents carry a shopper's loyalty identity into commerce transactions, the brand must govern how its products, pricing, and values are represented through the agent layer. Applied Identities designs the brand governance architecture that ensures agent-mediated transactions reflect the organization's intent — not just the protocol's capabilities.
Strategically retreated from owning the checkout layer, repositioning ChatGPT as a discovery-and-recommendation gateway while delegating payments, refunds, and fulfillment to merchant platforms via ACP partnerships with Stripe, Shopify, Etsy, and PayPal.
OpenAI's retreat from checkout underscores the Janus Brands thesis: the value in agentic commerce accrues to whoever controls the brand-to-agent relationship, not the transaction processing. Applied Identities helps organizations design the identity and governance layer that ensures brand presence, pricing authority, and customer relationship ownership persist even when discovery is mediated by third-party AI agents.
Launched Agentforce Contact Center at Enterprise Connect 2026 — the CRM-native contact center unifying voice, digital channels, CRM data, and AI agents — with a Contact Center 100 initiative offering intensive support to the first 100 deploying organizations.
Salesforce's CRM-native agent contact center creates decision surfaces where AI agents interact directly with customers on behalf of the organization. Applied Identities' Decision Surfaces framework specifies what those agents are authorized to resolve, what requires human escalation, and how the organization maintains coherent brand voice and policy compliance across automated and human-mediated interactions.
Published a detailed architectural explainer showing how the Experience Platform Agent Orchestrator coordinates multiple specialized sub-agents for product guidance, content discovery, and customer qualification within a unified conversational commerce experience.
Adobe Brand Concierge's multi-agent orchestration architecture is a textbook case for identity architecture: each sub-agent needs defined permissions, the orchestrator needs governance over which agent acts when, and the brand needs assurance that the overall experience reflects its values. Applied Identities designs the organizational specification that sits above the orchestration layer — the behavioral contracts and brand governance rules that agent orchestrators execute.
Shipped the March 2026 release with centralized MCP server governance — browse-and-import from the MCP community registry, automated client registration, PII Vault Service data protection, and enforced approval workflows in AI Agent Studio.
ServiceNow AI Gateway represents the infrastructure layer of MCP governance. Applied Identities addresses the organizational layer: defining the approval criteria, risk tolerances, and accountability structures that feed into ServiceNow's workflow engine — ensuring that MCP server governance reflects business intent rather than defaulting to IT-defined policies.
A federal judge granted Amazon a preliminary injunction blocking Perplexity's Comet browser AI agent from accessing password-protected Amazon accounts — distinguishing between user permission and platform authorization in a landmark agentic commerce legal test.
The Amazon vs. Perplexity case crystallizes a foundational identity architecture question: does user consent equal agent authorization? Applied Identities' Identity Control Surface helps organizations design explicit authorization frameworks for agent-mediated access — defining who can delegate what to which agents, under what conditions, with what platform and organizational approvals required.
Coinbase's x402 V2 payment protocol has processed over 75 million transactions on Base and Solana, becoming the default payment rail for AI agents accessing paid APIs and data services, with Cloudflare planning native integration.
x402's emergence as agent payment infrastructure creates a new governance surface: agents that can pay for services autonomously need spending controls, transaction audit trails, and organizational policies governing what they can purchase. Applied Identities designs the governance architecture for agent financial authority — a decision surface that most organizations have not yet defined.
Now provides native agent identity via Cloud IAM, MCP and A2A protocol support, Model Armor runtime protection, and a centralized agent registry — positioning it as enterprise-grade governed agentic infrastructure with 7 million+ Agent Development Kit downloads.
Google Vertex AI Agent Builder provides cloud-native identity and governance plumbing for agents within the Google ecosystem. Applied Identities addresses the cross-platform organizational challenge: designing the identity architecture that governs agents across Google, Microsoft, AWS, and independent frameworks — ensuring coherent governance regardless of which cloud provider hosts the agent runtime.
The MCP protocol is crossing from developer convenience into governed enterprise infrastructure. ServiceNow AI Gateway, the Linux Foundation MCP roadmap (enterprise-managed auth, MCP Server Cards for discovery), and the RSAC wave of MCP governance products signal that the protocol layer is crystallizing into its own control plane category. Anthropic's $100M Claude Partner Network investment cements its position as the enterprise AI market share leader (40% of enterprise spending). Two critical n8n CVEs (CVSS 9.4 and 9.5) require immediate patching for any self-hosted deployment.
Nate argues that there are four distinct kinds of AI agents — coding harnesses, dark factories, auto research, and orchestration frameworks — but most organizations treat them as a single category and reach for the wrong one. He introduces a single diagnostic question that classifies any problem into the correct agent architecture, alongside four operating principles: decomposition, specification-as-code, metric-plus-guardrail, and handoff contracts. The taxonomy matters because picking the wrong agent type is a structural error, not a prompting problem.
Nate's four-agent taxonomy and operating principles map directly to Applied Identities' agent orientation practice. The Compiled Corporation framework addresses what happens after the diagnostic question is answered: once an organization knows which agent type a problem requires, it still needs to specify the behavioral contracts (what the agent can decide), define the handoff boundaries (where human authority resumes), and build the governance infrastructure that prevents agent-type misclassification from compounding across the enterprise. Applied Identities' drift control methodology is specifically designed for the failure mode Nate identifies — when the wrong agent architecture is applied and the resulting behavioral drift goes undetected because no specification existed to measure against.
-
high
Register for the Linux Foundation MCP Dev Summit North America (April 2–3, NYC) — the protocol governance agenda directly intersects Applied Identities' identity architecture positioning and will attract enterprise decision-makers evaluating MCP governance infrastructure.business_development
-
high
Draft a prospect-facing brief on 'The Agent Identity Crisis' synthesizing the RSAC 2026 launches — Microsoft Entra Agent ID, Okta for AI Agents, Cisco Zero Trust for Agents, CrowdStrike AgentWorks — as converging proof points for the Identity Control Surface offering, timed to land while RSAC coverage is still in news cycles.content
-
high
Audit any n8n self-hosted deployments for CVE-2026-27577 (CVSS 9.4, RCE via expression sandbox escape) and CVE-2026-27493 (CVSS 9.5, unauthenticated form evaluation) — both disclosed March 11 and requiring immediate patching on self-hosted and cloud instances.operations
-
medium
Review Nate's four-agent taxonomy (coding harnesses, dark factories, auto research, orchestration frameworks) against Applied Identities' agent orientation methodology — the diagnostic question and operating principles could be adapted as a prospect-facing agent-type assessment tool that demonstrates the identity architecture value proposition.content
Methodology v1.0.
Applied Mornings Intelligence is produced daily by the 3Jane Intelligence Services team at Applied Identities. Research covers 14 firms in the AI transformation advisory space, 10 identity and access management platforms, 9 agentic commerce platforms, daily AI readiness signals mapped to the Applied AI Index 15-dimension framework, and Nate B. Jones' AI strategy newsletter. All sources are publicly available. Published weekdays by 8:00 AM ET.
Applied Mornings Intelligence reflects publicly available information as of the production date. All competitive intelligence is derived from public sources. Applied Identities makes no representations regarding completeness of market coverage. This content is provided for informational purposes. ©2026 Applied Identities — appliedidentities.com