> Orchid Security Introduces AI Agent Readiness Controls Featuring Continuous Identity Monitoring and Kill-Switch Capabilities
[DATE: 21/09/2026 13:35]
[LANGUAGE: EN]
Readiness tagging for AI, always-on observability, and coordinated kill switches at the application layer give enterprises a defensible route to scaling agents while keeping authority in human hands.
New York, London – September 15, 2026 – Orchid Security, which unlocks safe AI adoption by solving identity at its core, today unveiled a set of AI readiness controls for AI agents, spanning ongoing identity drift detection and kill switches that operate at the application level. Within seconds, an AI agent can carry an authorized task well past the privilege level it started with — and it never has to “break” a security control or a workflow guardrail to get there. What it does instead is discover and exploit the identity debt already sitting inside the enterprise: credentials hard-coded into systems, orphaned accounts, authentication paths nobody manages, and permissions granted far beyond need. The new controls are built so that organizations can expand agent use without ceding oversight.
Boards Are Making AI Adoption a Governance Priority
The board-level conversation has shifted. Directors are no longer debating whether to adopt AI; they want to know how fast it can be scaled across the business. Saying no has stopped functioning as a security strategy. What organizations require is a defensible program that permits adoption while holding autonomous agents within sanctioned limits.
“AI transformation is exciting. Identity hygiene is not,” said Roy Katmor, co-founder and CEO of Orchid Security. “Boards are no longer asking whether AI will be adopted—they are asking why it is not moving faster, and security cannot answer with a blanket ‘no.’ Enterprises need to observe how agents act, understand when they drift, and govern them immediately, including terminating the authority through which they operate.”
The problem was never how agents behave. It is what they inherit. Exceeding an intended scope requires no circumvention of controls — agents simply locate the identity debt that has piled up over years: embedded credentials, abandoned accounts, unmanaged authentication routes, and over-broad entitlements. Orchid’s Identity Gap 2026 research put 57% of enterprise identity in the unseen and unmanaged category. That identity dark matter can be turned by an agent into a live route to elevated access within seconds or minutes — a pace that periodic governance reviews cannot match, let alone contain.
Governance has consequently moved from stated intent to operational proof. Approving agentic AI in a board resolution tells a CISO nothing about which applications an agent may safely touch, which service accounts carry standing privilege, or which delegation chains would hold up under regulatory scrutiny. Converting mandate into measurable control is exactly the point at which most AI programs stall.
A Four-Part Operating Model for Agent Readiness
Orchid delivers continuous, auditable AI readiness and defensibility through four connected stages — Observe, Understand, Govern, Prove:
OBSERVE: Surface the AI agents in use along with the identities, applications, credentials, tools, and access paths they run through. Capture behavior as it actually occurs, not merely what was declared in the studio.
UNDERSTAND: Measure runtime activity against the agent’s stated purpose and sanctioned scope. Orchid attaches AI readiness tags to applications, accounts, and access paths, surfacing identity hygiene gaps, permission excess, and environments not yet fit for agentic access.
GOVERN: Should behavior or effective authority move outside policy, Orchid drives action through the identity, security, and AI infrastructure already in place. That may mean trimming permissions, revoking credentials, cutting off tools, pausing workflows, or uniquely triggering its own application-level kill switch.
PROVE: Orchid produces a defensible record tying every agent action to the identity invoked, the delegation chain, the access path, business context, any drift detected, and the governance response that followed.
Handling agent behavior monitoring as an ongoing loop — rather than a snapshot review — mirrors the way autonomous systems genuinely function. Effective authority is not locked in at deployment; it shifts whenever a tool is attached, a token is reused, or one workflow is chained into another. Continuous observability keeps that authority record current rather than backward-looking.
Evidence Enterprises Need to Produce
Ahead of any large-scale autonomous agent rollout, an enterprise should be in a position to show the following:
Identity Hygiene: Orphaned, dormant, local, and over-privileged accounts are all catalogued and carry a readiness status.
Authorization Guardrails: The organization can establish who or what is permitted to act, on whose behalf, toward what end, and under which conditions.
Runtime Understanding: Observed agent activity is continuously checked against approved intent, granted permissions, and expected access paths.
Universal Auditability: Each action maps back to an identity, delegation chain, application, access path, and business context.
Enforceable Response: Authority behind a drifting agent can be curtailed or shut off on the spot.
Regulatory expectations are landing in the same place. NIST’s draft Cyber AI Profile observes that “regardless of where organizations are on their AI journey, their cybersecurity programs need risk management approaches that support and integrate the realities of advancements in AI.” Across Europe, DORA requires financial entities to evidence control over ICT access and third-party dependencies — a duty that is not suspended simply because the actor happens to be an agent rather than a human being.
Ensuring Continuous Availability
Building on the agentic capabilities added to Orchid’s Identity Control Plane in May, the following are now generally available:
AI readiness tagging spanning applications, identities, and access paths
Identity hygiene and security risk findings covering orphaned, dormant, over-permissioned, and suspicious accounts
Ongoing drift detection comparing an agent’s intended purpose against what it actually does
Orchestrated response, including application-level kill switches that pare back permissions, revoke credentials, sever tool connections, or halt agent workflows
Audit generation capturing agent activity, identity context, drift detected, and the action taken
The company has also broadened its integration ecosystem:
Palo Alto Networks Idira: A certified PAM integration that uncovers privileged accounts previously invisible to Idira and places them under management.
Splunk Enterprise Security: A prebuilt integration feeding identity telemetry into the SOC for correlation, investigation, and incident response.
Since these controls run through infrastructure the enterprise already owns, security teams can broaden agent governance without erecting a separate enforcement stack — a meaningful factor when kill-switch authority has to stay reachable in the middle of a live incident.
Shannon Wilkinson, CIO and CISO at Findlay Automotive Group, framed the pressure from the practitioner’s chair: “The challenge is how to enable the business to move faster and realize the productivity that AI agents bring, but it honestly terrifies a lot of us. At Findlay we’re leaning heavily into AI to build a better customer experience. At the same time we must define guidelines, put guardrails in place and, above all, know what the identities are doing.”
Identity dark matter broadly — and weak identity hygiene specifically — has gone unaddressed for years, which helps explain why adversaries today are far likelier to log in than to hack in. Turning AI agents loose on all that accumulated identity clutter invites disaster.
For more on Orchid Security’s approach to securing autonomous identities, or to request a demo, visit https://www.orchid.security/use-case/guardrails-for-autonomous-identity.
Meet Us at Gartner Security & Risk Management Summit London 2026
Orchid Security will exhibit at the Gartner Security & Risk Management Summit, held at ExCeL London from September 22-24. Team members will be on site to talk through AI readiness and identity dark matter with security and risk leaders. Visit Booth #105 for a live platform walkthrough, or book time ahead via the form to secure a slot with the team.
About Orchid Security
Orchid Security sees straight into the application binary to deliver the industry’s first Identity Control Plane, transforming IAM complexity into clarity, compliance, and control. Its Identity-First Security Orchestration platform continuously discovers enterprise applications, analyzes their native authentication and authorization flows, and accelerates onboarding into governance systems, putting true identity insight in front of security leaders and practitioners, without the months of manual work traditionally required for each task or informational ask. By exposing and remediating the ‘identity dark matter’ hidden across modern environments, Orchid helps enterprises solve identity at its core; reducing risk, lowering operational costs, and achieving compliance at scale.
Media Contact
Chloe Amante [email protected] Montner Tech PR