Identity lifecycle management news
Summaries of public announcements, with links to the original source. Updated monthly.
Fourteen announcements from January to September 2026, newest first. Most of the year's news concerns non-human and AI agent identities, two acquisitions (Entro Security by SailPoint, Veza by ServiceNow), and standards work at NIST and the OpenID Foundation.
Okta adds Resource Access Certifications for AI agents
Okta announced new governance features for AI agents. Resource Access Certifications, which review agent permissions over time, are listed as available, and Shadow AI Agent Discovery for Endpoints is planned for Q3 2026.
Source: Okta newsroom
Lumos introduces MCP Governance for agent tool calls
Lumos MCP Governance shows which MCP servers and tools employees' agents use, records each call with the human identity and the policy decision, and blocks risky actions before they run.
Source: Lumos blog
NIST and CISA publish IR 8587 on protecting tokens and assertions
NIST IR 8587, Protecting Tokens and Assertions from Forgery, Theft, and Misuse, was published as final with recommendations for agencies and cloud service providers. The OpenID Foundation noted that it recommends the Shared Signals Framework and CAEP.
Source: NIST CSRC
C1 opens an EU instance with tenant data held in the EU
C1 says European customers can now run C1.ai with tenant data held in the EU, on AWS Frankfurt, with Ireland as the disaster-recovery region.
Source: C1 blog
Orchid Security joins the SailPoint Technology Alliance Partner program
Orchid Security joined SailPoint's Technology Alliance Partner ecosystem. Orchid discovers applications and analyzes how identity works inside them; SailPoint provides the governance layer.
Source: Orchid Security blog
SailPoint makes Agentic Fabric generally available and introduces Human Fabric
SailPoint announced SailPoint Identity Security, combining Agentic Fabric, now generally available for AI and machine identities, with Human Fabric, which SailPoint says evolved from Identity Security Cloud.
Source: SailPoint press release
Saviynt launches Zuma and reports more than $300 million in ARR
Saviynt launched Zuma, an AI identity security platform made up of Zuma Insights, Zuma Access and Zuma Governance, and stated it has surpassed $300 million in annual recurring revenue.
Source: Saviynt press release
SailPoint completes the acquisition of Entro Security
SailPoint completed its acquisition of Tel Aviv-based Entro Security, which secures non-human identities, secrets and tokens across cloud environments and CI/CD pipelines. Financial terms were not disclosed.
Source: SailPoint press release
C1 launches the C1 Autonomous Worker
C1 announced an agent that runs identity tasks end to end, such as revoking unused admin access and building access reviews, using the operator's own permissions with every action auditable. C1 says it is live for all customers.
Source: C1 blog
Orchid Security publishes the Identity Gap: 2026 Snapshot
Orchid's report, based on anonymized telemetry from enterprise applications in North America and Europe between April 2025 and March 2026, states that 67% of non-human accounts are created directly within applications.
Source: Orchid Security
OpenID Foundation responds to NIST on AI agent security
The OpenID Foundation's threat modeling subgroup answered NIST CAISI's request for information on securing AI agent systems, pointing to emerging standards such as transaction tokens and workload identity federation.
Source: OpenID Foundation
ServiceNow completes its acquisition of Veza
Veza's CEO announced that ServiceNow has completed the acquisition of Veza, and that Veza's Access Graph will be integrated across the ServiceNow platform.
Source: Veza blog
Orchid Security launches Identity Audit
Orchid launched Identity Audit, which combines audit data captured inside unmanaged applications with logs from governed IAM systems to give one view of identity activity across the application estate.
Source: Orchid Security
AuthZEN Authorization API 1.0 approved as a Final Specification
OpenID Foundation members approved the AuthZEN Working Group's Authorization API 1.0 as a Final Specification, with 81 votes to approve, 1 to object and 25 abstentions.
Source: OpenID Foundation
Items are selected from vendor newsrooms, vendor blogs and standards bodies, and summarized in our words. Inclusion is not endorsement.