Skip to content

TechChannels Network:      Whitepaper Library      Webinars         Virtual Events      Research & Reports

×
Artificial Intelligence (AI) Cybersecurity

Q&A: It’s Complicated: Saviynt President Paul Zalfaghari On Governing Identity in the Age of AI

Teri Robinson

Aug 06, 2026

As enterprises adopt AI agents at scale, identity security is expanding beyond the traditional challenge of governing human users. Organizations must now manage human identities, machine identities, and autonomous agents that can create applications, access systems, consume resources, and act on behalf of employees.

Tech Channels sat down at Nasdaq with Saviynt President Paul Zalfaghari as the company announced it had topped $300 million in annual recurring revenue (ARR) and took the wraps off Zuma, an AI identity security platform that brings together discovery, ownership, runtime controls, and governance. The company has essentially built a common platform “allows people to basically have a broad relationship with us across all identities,” he says.

And it all starts with visibility, a component of Zuma. “One of the first things that it does is provide a kind of end-to-end enterprise visibility,” says Zalfaghari. “If you turn it on, it'll basically tell you where all the agents are, who's developed them, what systems are they running against, and the very first thing is just give you basically some perspective on who's doing what.”

From there, he says, “we can talk through how we manage and govern it. But the first thing is to actually know what's going on.

Zalfaghari believes Saviynt’s approach to coding bolsters its position. “One thing that's atypical about us—I wouldn't say unique, but borderline unique—is that we've written every single line of code ourselves. No M&A, no acquisition, no mergers, everything we've written ourselves,” he says.

As AI makes governance exponentially more complex, underscores the criticality of visibility, and even expands the buying committees for identity security beyond the CISO to include CIOs, CFOs, CTOs, and other enterprise leaders, platforms—and Saviynt—are clearly having a moment. “We just took over the Nasdaq Tower for 20 minutes and had our logo running and our name,” says Zalfaghar. Why would we do that? Because we think a lot of the country, a lot of the world, is now asking who's got a solution for this problem? Who's got good insight?”

Q. How has AI changed the identity-security landscape?

A. Organizations have long known that they need to make sure that whatever role an individual has, that individual is only accessing the systems they should access; they should stay away from the systems they shouldn't access; and should engage in actions that people are comfortable with. So, the concept of organizations wanting to make sure that digital access is consistent with privileges, governance and oversight is a long-standing concept.

What's made it more interesting now is the problem has gotten exponentially more challenging. You have individuals who are launching their own agents. You have the companies that are launching agents. You have agents that are acting on their behalf from some of these core systems. So the problem has gotten exponentially more complicated.

Q. Why can’t organizations manage agents in the same way they manage employees?

A. The entire concept of the way you would manage a human doesn't really map to an agent, and so there's some pretty easy examples. Let's say you take a job as the vice president of marketing at a large company. That job is occupied by a person. You know that person's name. You know when they started. You likely have some pre-existing beliefs about what type of access they should have, granted the day they start. Then as they do their job, maybe they ask for access. It’s a very slow-moving process.

The problem with agents is that the same vice president of marketing might launch a series of agents to operate on their behalf. Those agents are likely acting with a lot more agility. They are being launched to answer a question, but it's not obvious that the answer to the question exists in the permissions that they've been granted up front. It's also not obvious that they should be given access to the information that they would need to answer that question.

Q. What kinds of access risks can AI agents create?

A. Perhaps as vice president of marketing you ask about the financial results of the company, and the agent tries to get it from not just the historical, but from the forecasting system. If you're a public company that's not a great thing. The problem has gotten exponentially more difficult. Saviynt wants to provide a platform, which is agnostic to the company whether or not it's a human identity, a non-human identity, or an agent. We want to give enterprises a single platform that allows them to provide the right level of access and governance to all these types of identities.

Q. Why is it so difficult for organizations to gain visibility into AI agents?

A. The development platform upon which a lot of the agents are developed are new. And a lot of the protocols, the permissions, and the governance are where people have long understood how to secure access to SAP or Oracle or IBM or Workday or Salesforce. Now you have something like Anthropic or OpenAI, so that makes it challenging. Organizations aren't necessarily sure exactly how to allow the promise of AI to occur while simultaneously not allowing it to put the company at risk.

Q. What risks should organizations consider beyond a traditional breach?

A. The risk isn't just cybersecurity risk; it's financial risk. It's operating risk. It's not just all about a breach. Maybe you just run up a ton of costs that you shouldn't run up. Maybe the agent engages in actions that are inconsistent with your company culture, irrespective of whether they're a breach or not. I think what's happening is there's this incredible interest in adopting the value that comes with utilizing AI. But by the same token, and this happens all the time in technology, the kind of the tools for the thoughtful way to manage something new come after.

Q. In seems we’ve heard that story before—security as an afterthought. What historical technology shift is most comparable to enterprise AI adoption?

A. I've used this analogy a couple of times. It reminds me of when people started bringing smartphones to work. Individuals just started showing up, saying they wanted to access things through their phones. And what did they use? They used their web browser and would type their credentials in through the browser then go right into their SAP system, which was fine until you realize that that same person then went out at night in New York and left their phone at the bar. And somebody that picked it up was suddenly accessing the SAP system. The initial adoption of smartphones at companies was already ubiquitous as they tried to figure out how to put controls in place.

Q. Why is AI making shadow technology more widespread?

A. It used to be when you talked about shadow IT, it was limited to the people who were developers because you're talking about developing an application. So now you've got people in regular jobs who are able to develop applications. They can literally use Claude code. They can develop an application and it can have access to systems because they build it without having to delegate to their IT department.

In the past, they would have gone to their IT department and said, “Hey, I want to do this,” and they’d say, “you can't do that.” Well, now they can do it themselves. This shows that the problem is demonstrably more complicated.

Q. How is AI changing enterprise technology spending?

A. It’s incumbent on companies, as it always is, to ensure whatever cost you're incurring has an offsetting business case. The challenge with the AI is that companies are essentially running up costs without knowledge, meaning when individuals build something they are essentially creating a bill for the company that the company doesn't necessarily know is coming. So, it's not about throttling AI; it's about expenses and spending.

You want to actually have an understanding that if an individual at the company is going to be running up third-party costs, you have some ability to make sure it's consistent with the budget, consistent with the operating plans for the company.

Q. Why is AI spending difficult to forecast and control?

A. One of the things about visibility is it gives people an ability to say, “Are we okay with the fact these 15 people are using Claude code and they're generating X amount of tokens, and it's causing Y in terms of monthly subscription burn.”

I think people are starting to come to grips with that. It’s a little bit antithetical to typical IT spending. Most IT spending is upfront and you budget for it. This is different. People don't necessarily control it and they don't even know what the costs are going to be. So part of the visibility value propositions will be giving them a little bit of insight.

Q. Why might AI initially make enterprise operations more expensive?

A. Another value proposition being discussed regarding the adoption of AI is the eventual reduction in human headcount. But if you basically have maintained the same employee count and you're just giving them access to these tools, you haven't had that offsetting cost savings yet. There’s going to be this period of time where the humans are still in their jobs and those humans are running up all these costs. Over time, that will change.

Q. Are you seeing different stakeholders now becoming involved in identity-security decisions?

A. Yeah, we are for sure. At a company now, identity security might be something that comes through the CISO's office as part of normal audit and compliance and risk and governance. We're also now seeing a tremendous amount of interest in identity security coming directly out of the CIO's office because this is their innovation budget. This is their AI budget. This is essentially the business case they have to build to justify the adoption of AI broadly, maybe with the hope of reducing their overseas software development or their overseas call center or their onshore marketing resources.”

Q. Which executives now have a stake in AI identity governance?

A. This provides a very strong value proposition for the CFO. This provides a very strong value proposition for the CSO, for the CIO, but also the CTO because as they're developing applications, some are externally facing and they're using AI. They need to make sure they can build and deploy it in a secure manner.”

What’s little understood is that if you went back five or six years ago, identity security was uniquely in the domain of the CISO, who in most companies rolled directly up to the CIO, and in many companies the CIO went directly to the CEO.

Q. Why has identity security become relevant to more parts of the enterprise?

A. Often, now, people are funding identity with their AI budget. You can't be an AI first company unless you can say “we can do it securely, and we can still provide the right insights to our auditors. They have to make sure that they’re consistent with their financial obligations and all the other stuff. Saviynt has found now that what we do is important to a lot more people.

Q. How does vendor consolidation influence identity-platform decisions?

A. Just to go to human nature for a minute, CIOs are not walking around saying, “I want to have more relations with more companies. That’s not a thing. But they do have to pick and they do have to start new relationships with new companies, if they need the innovation from some place they're not currently getting it from. But even with us, they want to put as much of the workload on us.

AI has transformed identity security from a specialized access-management function into an enterprise-wide governance issue. Agents move faster than human users, operate through emerging platforms, create unpredictable costs, and may seek access far beyond the permissions originally anticipated.

“Often, now, people are funding identity with their AI budget. You can't be an AI first company unless you can say ‘we can do it securely, and we can still provide the right insights to our auditors,’” says Zalfaghari. “They have to make sure that they’re consistent with they’re financial obligations and all the other stuff. Saviynt has found now that what we do is important to a lot more people.”

And visibility is the essential first step. Organizations cannot govern agents, manage spending, or demonstrate compliance until they understand what agents exist, who created them, which systems they use, and what actions they perform. As AI adoption expands, identity security will increasingly require coordination across security, technology, finance, audit, governance, and innovation teams—not only the CISO’s office.



 

Share on