Announcing C1 Transform 2026
blog

Introducing agentic security and intelligence: close identity risk with C1

Maarten BuisMaarten Buis, Principal Product Marketing Manager

Share

Introducing agentic security and intelligence: close identity risk with C1

C1 Launch Week closes today with the final post in our series on the building blocks organizations need to implement and secure AI agents. The first three covered visibility, credential security, and runtime governance. Day 4 adds the intelligence to detect identity risk and route remediation.

TL;DR: Most identities in your environment are now non-human, and every new agent adds risk faster than teams can review by hand. Today we're adding agentic security and intelligence to C1. It helps security teams detect and remediate machine identity risk — service accounts, workloads, integrations, and AI agents — across connected systems, and routes remediation through C1 governance or the tools your team already uses. Day 4 completes C1 Launch Week.

Detect identity risk automatically#

For decades, identity governance focused on people. Today, most identities in the enterprise are non-human: service accounts, workloads, and the AI agents teams deploy every week. Each agent authenticates, holds access, and acts at machine speed. Machine identities also appear and disappear faster than any review cycle. An agent launches without an owner. A service account is misclassified. An account name shadows a real account. Manual review cannot keep pace with these ownership gaps, misclassifications, and shadow accounts as agent volume grows.

The ratio is what makes this unmanageable by hand. Palo Alto Networks' 2026 Identity Security Landscape found organizations now manage 109 machine identities, including AI agents, for every human identity — up from 82:1 the year before.

Today, C1 is launching agentic security and intelligence to manage the risk of these new identities. C1 goes beyond inventory by identifying the identities that need attention. Across connected systems, C1 raises a finding for conditions such as an agent or service account without an owner, an account misclassified as human, a name shadowing a real account, or a connector with anomaly detection switched off. Each finding names the affected identity, explains the reason for the flag, and shows the severity.

C1 combines each finding with identity context instead of leaving the problem buried in a list. The intelligence graph shows an identity's reach across apps, accounts, and entitlements, including the service accounts used by agents. Each finding links to the affected identity's access graph, allowing security teams to assess the potential impact.

C1 can also ingest findings from other security tools through the API. Imported findings enter the same queue and receive the same routing, tagging, and audit trail as findings raised by C1. This context and visibility is the first step to lowering risk across the organization.

An agent's access graph, showing its blast radius across apps, accounts, and entitlements

Remediate findings through existing governance#

Once you have the visibility, the next step is remediation. Teams can assign an owner or route an access change through the same request, approval, and audit path used for other access decisions. Revoke and right-size actions follow existing grant policies and approvers, right in the app. For an unowned account, the finding resolves after an owner is assigned and C1 verifies that the ownership gap has cleared, improving security posture across the organization. Every remediation carries an audit trail showing who made the change and when, meeting compliance needs.

Route findings to your team's tools#

Automations can resolve straightforward findings on the spot, while routing rules ensure sensitive actions are sent to the right owner for approval through existing governance. And when the right next step is human workflow, webhooks can automatically create tickets in the ITSM and incident response tools teams already work in, whether that's ServiceNow, Jira, or PagerDuty, so critical findings land in the right queue in the expected format, without manual re-entry.

Routing rules sending findings to the right owner, queue, or external tool

C1 connects detection and response in one continuous workflow. C1 raises a finding, routes the finding to the appropriate owner or queue, and records the remediation with an accountable owner and audit trail. The continuous workflow helps security teams keep pace as agents create new risk.

The finale: the Agentic Control Plane#

Day 4 completes the Agentic Control Plane. Across four releases, C1 discovers unsanctioned AI, secures agent credentials, governs tool calls at runtime, and detects and remediates remaining identity risk. C1 brings human and AI identities into one governed plane where security teams can see access, enforce policy, and route remediation. When an identity develops a risky condition, C1 raises a finding and sends the issue through a governed workflow.

Fearless AI adoption means giving agents access to sensitive systems while retaining the ability to detect risk, intervene, and document the resolution through trusted governance processes.

See the Agentic Control Plane in your environment. Book a demo at c1.ai.

Adopt AI, fearlessly.


FAQ#

What is agentic security and intelligence?#

C1 now detects risky conditions across people, service accounts, other non-human identities, and agents. Teams can remediate each finding through existing C1 governance or route the finding to another tool.

How does C1 detect identity risk for AI agents?#

C1 detects identity risk by continuously evaluating identities across connected systems and raising findings when risky conditions appear (for example: an agent or service account without an owner, an account misclassified as human, name shadowing, or a connector missing anomaly detection). Each finding includes context about the affected identity and its reach across apps, accounts, and entitlements so teams can quickly assess potential impact before taking action.

How is this different from what shipped on Day 1?#

Day 1 discovers unsanctioned AI in the environment. Day 4 identifies ownership gaps, misclassifications, shadow accounts, and other risky conditions across known identities, then routes remediation. Day 1 answers, "What's running here?" Day 4 answers, "Which identities need attention, and how do I remediate the risk?"

Does it produce audit evidence?#

Yes. Each finding and remediation becomes part of the same audit trail as access reviews. The record shows how the finding was created, who acted, what changed, and when. The audit record feeds existing reviews and reporting.

Can I bring in findings from my own tools?#

Yes, through the API. Imported findings receive the same routing, tagging, and audit trail as findings raised by C1.


Sources#

Ask AI to write a summary of this post

Stay in touch

The best way to keep up with identity security tips, guides, and industry best practices.

Explore more articles

Introducing agent runtime governance: intent-based access control for AI agents

Introducing agent runtime governance: intent-based access control for AI agents

Introducing Agentic Vault: govern every secret like an identity

Introducing Agentic Vault: govern every secret like an identity

Introducing shadow AI discovery: find the AI you didn't sanction

Introducing shadow AI discovery: find the AI you didn't sanction