In this insightful session from RSAC 2025, Chandra Gnanasambandam, Chief Technology Officer and Executive Vice President of Product at SailPoint, delves into the complexities of identity security in the contemporary digital landscape. Collaborating with Dave Vellante of SiliconANGLE Media, Gnanasambandam explores how SailPoint navigates the rapidly evolving world of agentics and artificial intelligence, highlighting the unique challenges and opportunities present.
Gnanasambandam brings extensive experience in identity security to the discussion, alongside their role at SailPoint. Directed by hosts from theCUBE Research, including Vellante, the conversation touches upon critical aspects such as SailPoint's distinct identity platform capabilities and the pressing identity-related issues faced by modern enterprises. They elucidate the role of agents in current business processes and the profound impact they have on identity security frameworks.
Key takeaways from this conversation emphasize the strategic importance of managing identity complexity and data governance in an era where AI and agentics are increasingly prevalent. Gnanasambandam underscores SailPoint's commitment to addressing these challenges by leveraging its innovative identity graph and agentic readiness strategies. The discussion reveals pivotal insights into operationalizing zero trust principles and the critical need for organizations to strengthen their identity management infrastructures in preparation for the future agentic era.
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
RSAC Conference 2025. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Register For RSAC Conference 2025
Please fill out the information below. You will recieve an email with a verification link confirming your registration. Click the link to automatically sign into the site.
You’re almost there!
We just sent you a verification email. Please click the verification button in the email. Once your email address is verified, you will have full access to all event content for RSAC Conference 2025.
I want my badge and interests to be visible to all attendees.
Checking this box will display your presense on the attendees list, view your profile and allow other attendees to contact you via 1-1 chat. Read the Privacy Policy. At any time, you can choose to disable this preference.
Select your Interests!
add
Upload your photo
Uploading..
OR
Connect via Twitter
Connect via Linkedin
EDIT PASSWORD
Share
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
RSAC Conference 2025. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Sign in to gain access to RSAC Conference 2025
Please sign in with LinkedIn to continue to RSAC Conference 2025. Signing in with LinkedIn ensures a professional environment.
Are you sure you want to remove access rights for this user?
Details
Manage Access
email address
Community Invitation
Chandra Gnanasambandam, SailPoint
In this insightful session from RSAC 2025, Chandra Gnanasambandam, chief technology officer and executive vice president of product at SailPoint, delves into the complexities of identity security in the contemporary digital landscape. Collaborating with Dave Vellante of SiliconANGLE Media, Gnanasambandam explores how SailPoint navigates the rapidly evolving world of agentics and artificial intelligence, highlighting the unique challenges and opportunities present.
Gnanasambandam brings extensive experience in identity security to the discussion, alongside their role at SailPoint. Directed by hosts from theCUBE Research, including Vellante, the conversation touches upon critical aspects such as SailPoint's distinct identity platform capabilities and the pressing identity-related issues faced by modern enterprises. They elucidate the role of agents in current business processes and the profound impact they have on identity security frameworks.
Key takeaways from this conversation emphasize the strategic importance of managing identity complexity and data governance in an era where AI and agentics are increasingly prevalent. Gnanasambandam underscores SailPoint's commitment to addressing these challenges by leveraging its innovative identity graph and agentic readiness strategies. The discussion reveals pivotal insights into operationalizing zero trust principles and the critical need for organizations to strengthen their identity management infrastructures in preparation for the future agentic era.
Chandra Gnanasambandam, CTO and EVP of product at SailPoint, sits down with theCUBE Research’s Dave Vellante at RSAC 2025 for a conversation on identity in the age of AI. Gnanasambandam outlines how SailPoint is adapting to the rise of agentics and redefining identity security in dynamic enterprise environments.
The discussion digs into SailPoint’s approach to managing complexity through its identity graph and AI-driven insights. Gnanasambandam and Vellante explore how agentic systems are reshaping business workflows, placing identity at the core of op...Read more
exploreKeep Exploring
What sets SailPoint apart from other identity security platforms in terms of coverage and granularity?add
What is the number one reason for slow AI and agentic adoption?add
What is the fundamental differentiation of SailPoint?add
What can be done with an identity graph?add
What are the different types of agents that SailPoint has in the market, and how do they learn from human interactions to improve their performance?add
What is the significance of democratizing access to identity platforms within a corporation?add
>> Hi everybody. Welcome back to Moscone West. We're here. This is day two of our continuous coverage, live coverage of RSAC 2025. My name is Dave Vellante, I'm here with Chandra, I'm going to try it, Gnanasambandam.
Chandra Gnanasambandam
>> Oh wow, that's well done, Dave. Well done.
Dave Vellante
>> Which in Sanskrit means linked with knowledge.
Chandra Gnanasambandam
>> Exactly right.
Dave Vellante
>> I feel more spiritual just hanging out with you, man.
Chandra Gnanasambandam
>> Yeah, you're talking to the right person.
Dave Vellante
>> Yeah, well this is theCUBE is all about sharing knowledge, so welcome. Really appreciate it.
Chandra Gnanasambandam
>> Thank you. It's great to be here and thanks for having me.
Dave Vellante
>> You bet. Chandra's the CTO and executive vice president of product at SailPoint so we can get deep. But before we get into it, tell us a little bit more about SailPoint for those who might not be familiar with.
Chandra Gnanasambandam
>> Sure. SailPoint is really one of the leading identity security platforms in the world. We are really unique in two different ways, quite frankly, vis-a-vis others. One is really the breadth of coverage of identities we have. Everything from the human workforce to third parties, contractors, machines, increasingly bots and agents. And the depth of coverage, meaning we are very, very fine-grained. We go down to the, not just the application, it's not just access or application, we go down to the entitlement and the data row and column level. And so it's really the breadth of coverage and the depth of it. That is where we are actually quite unique.
Dave Vellante
>> So I love this little line that you guys shared with me because I think it was two or three years ago I wrote a post of why security is facing an identity crisis. And you guys have brought that concept to agentic. And so everybody's doing agentics, a lot of agent washing, it's another threat vector. So why is agentic, why does that bring back this identity crisis?
Chandra Gnanasambandam
>> Yeah, the top line is we think it's a bit of a crisis because it's the number one reason that AI and agentic adoption is slow today. It's really because you can't get identities, governance, and access control right and just security right. And so let me just explain what I mean by that. So I'll start by what do we mean by agents because everyone has their own definition of what an agent is.
Dave Vellante
>> A place to start.
Chandra Gnanasambandam
>> So to us, an agent is autonomous, goal seeking, will use other tools to get things done, is very, very action oriented. And by tools I mean it can use LLMs, APIs, service calls, and so on. And number four, it's executing mission-critical business processes. That is really what constitutes an agent for us. Now, if you were to break it down, every one of them, identity is core to really getting that done. So let me take a few...
Dave Vellante
>> Can I ask you a question please before you go on?
Chandra Gnanasambandam
>> Yeah, please.
Dave Vellante
>> When you say goal-seeking, I infer from that that there's a set of top-down goals that you can impose, I don't know if that's the right term, on the agents and they will adhere to those edicts. Is that...
Chandra Gnanasambandam
>> No, it's solving a business problem. And so let's say that you have an agent for dynamically booking your travel. You will say get me from point A to point B, and you could change your meeting schedule, you could be running late, flights could be running late, it will automatically adjust and do what a travel agent, a manual travel agent would do. Or if you are a bank, you want to automate some part of your loan origination process. And by the way, large banks are using it. They're using agents to automate some part of the loan origination process, in some cases all of it for loans under a particular amount. And in those cases, they will say, here are the boundary conditions for the loan approval and all the policies involved in it. And then it'll say go and see whether we can underwrite this loan. And so it's really solving a business problem. That's really what I mean by goal seeking.
Dave Vellante
>> It has essentially the understanding of that business problem and it executes according to that. Okay, sorry, I threw you off your thought process there. But let's come back to where you were, which is essentially helping people understand. Okay, we understand what agents are, what the characteristics of these agents are, and there's a lot, big spectrum of how people are applying these things.
Chandra Gnanasambandam
>> Exactly.
Dave Vellante
>> And so please carry on.
Chandra Gnanasambandam
>> Let's really break it down because the complexity, the identity complexity is in the detail. Because at the surface level you are like, "Oh, apply some identity governance to it," and then it's done. When you really think of them as reasoning agents that are goal seeking and are independently taking some actions, they are actually nothing but a digital workforce. You know what I mean? And so just like how you manage a human workforce in terms of the applications they can access and the data they can access, you have to manage these, you have to govern and manage these agents because they're actually a digital workforce. And so what it means is you can have an agent, let's say it's your travel agent, booking your travel. It will have access to your calendar. It will have access to the flights you want to book and your accounts, your credit card details. And so it's got to be bound, it's got to be governed. The permissions, it has to be mapped back to you, Dave, and that is really hard to do. I'm making it sound very, very easy. Mapping what an agent can do to the same permission that the human that it is representing, it is a hard engineering problem to solve.
Dave Vellante
>> That's an identity crisis right there.
Chandra Gnanasambandam
>> It's really an identity crisis because if you take a large corporation, a Fortune 100 or a Fortune 500 Global 3000, most of the mission-critical business processes are executing on really older platforms. I don't want to use the word legacy because it makes it sound bad, but these are mission-critical platforms. They are still running on a mainframe. If you are banks, you have core banking platforms running on mainframes. If you are a hospital system, these agents will have to, for clinical decisioning, they're going to access radiology systems, electronic medical record systems that are older platforms. Governing and providing access control and set of permission for them to access, these really involve, you've got to have connectors to connect to all these applications. You know what I mean? And so that is what makes this problem really hard because if it were all about accessing the modern cloud platforms, it is actually an easier problem to solve. All the startups have connectors and have experience in managing access to the modern cloud platforms. When you go to real large corporations, the cloud platforms are a core part of it, but they have lots of older platforms and older applications. And you've got to be able to govern access to them and manage all the complexities. This is where SailPoint comes in. For 20 years, that is what we have been doing. And so that's why we are very, very bullish in how we have a differentiated value proposition instead of solving this identity crisis that is in the agentic world today.
Dave Vellante
>> Organizations clearly aren't prepared for this. Frankly, they're not well-prepared for AI, in my view, because, go back to, they have a data problem. Everybody has a data problem. SailPoint helps with this problem. I triggered something in my brain because you're solving this problem for yourselves, so you have insight as to how organizations can solve it. I would suspect, you're not as complicated of an organization as a 100-year-old bank in terms of your data platform and you've got technologists that can solve this. But how prepared are organizations for this agentic era? And how is SailPoint positioned to help them?
Chandra Gnanasambandam
>> Yeah, I think context is important here in terms of readiness. This is still new. Agentic is still new. AI, we have been talking about it for a long time, but companies seriously doing it and adopting is also newer. So I don't want to make this problem look much bigger than what it is. I think we are still early in the game, but I don't think most companies are well-prepared. So this is where we come in. It's largely just because of the complexity. By the way, agents and data go hand-in-hand. There are really two sides of the same coin. When we talk about agentic, you have to start with data. The question is, do they have their data ready? Which is do they have data security and data governance ready for both structured data and unstructured data? That's step one. Step two then is overlaying the agentic model on it because for agents to do anything, they're going to be able to access data. And so you have to solve for both of them. And the complexity of the readiness, or they're not quite ready today because, one, the maturity of most of the corporations in terms of managing human identity is actually not very good, by the way. If you take the largest 10,000 corporations in the world and we have a maturity framework in terms of where they are, less than 15% of them are in the most advanced mature stage.
Dave Vellante
>> Makes it very hard to automate then.
Chandra Gnanasambandam
>> Exactly. And so even for the human workforce, which we have had for as long as mankind has existed, the identity governance or identity security and management is not very advanced. Now we are adding data to it. We are adding agents to it. We are adding machines to it. And by the way, when I say machines, I don't mean manufacturing machines, I mean APIs, service calls, bots, and so on. And so the complexity of the identities we are governing, these large corporations are governing, is actually exploding. And when you think about machines and agents, by the way, its apply a multiplication factor to actually the human identities. To start with, human identities aren't managed well. We are adding machines and agents to it, which has a multiplier effect. And so we are starting with the foundation that's not strong and we are adding more and more to it.
Dave Vellante
>> I interviewed with George Gilbert, my colleague, Marc Benioff the other day. And when I was prepping for the interview, I read his Wall Street Journal article. It was an op-ed or whatever, but the title of it was something to the effect of, I will be the last generation of CEOs managing human-only employee workforce. And my question to him, which it was an awesome interview, but I actually don't think I got an answer to this, so I'm going to put it into a security context. My question to him was, "What have you learned in managing all these agents that you're building with Agentforce, you what they're doing, and how are you managing differently?" And I'm not sure I got an answer. So my question is, how, in this new world, we're not just managing humans, we're managing machines, how are organizations going to be managed and managers going to be managing differently?
Chandra Gnanasambandam
>> Yeah, I think there are some similarities and some differences. By the way, they're not that dissimilar is what I would say. That is why we are actually quite bullish on taking our learning and our expertise instead of managing.
Dave Vellante
>> They're not that dissimilar. You mean managing humans versus managing humans and agents?
Chandra Gnanasambandam
>> Exactly.
Dave Vellante
>> It's like Democrats and Republicans. More similarities than differences, I always say.
Chandra Gnanasambandam
>> Exactly. That is really our point of view on that. And there are nuances that are actually exactly not the same, but they are not that dissimilar. Here is a way to think about it conceptually. Humans mostly access applications for a long time and applications access data. For the longest time, as long as you manage the human to application chain and governed it, you are quite secure, from an identity perspective. Now, increasingly humans are accessing data, not going through applications. If you're a data scientist, if you are a machine learning scientist, you're not necessarily going through a application to access data, you're going straight to data. If you're a machine, for training, if you're a foundation model being trained, you're not going through an application, you're going straight to data. And increasingly so machines and agents go straight to data. And so you have to now govern the human to application chain, human to data chain, machine to data chain, agent to machine to data chain. You know what I mean?
Dave Vellante
>> I do because...
Chandra Gnanasambandam
>> Conceptually, that is really the problem you have to solve.
Dave Vellante
>> I think of agentic as flipping the whole model of applications on its head. Whereas traditionally applications are hard-coded. The processes and applications are hard-coded. Here's how we do it, code it and that's how we do it. You live by that process. And in the future we're going to go directly to data. We're going to create processes essentially on-the-fly to meet the market conditions. But that's an infinite number of possibilities there that have to be governed and secured. I understand it correctly, Chandra, you're saying the responsibility of securing those processes lived inside of the application, or securing that data lived inside of the application, it was the responsibility of the application, it was a comfort domain and now it's wild west all over again.
Chandra Gnanasambandam
>> I would say it was a joint responsibility, not just the application of the identity platform that actually governed that application, by the way.
Dave Vellante
>> You would be able to speak to that application in a way that was integrated.
Chandra Gnanasambandam
>> Exactly. That was our strength. Now, the most critical piece in this chain is linking these agents and machine back to the identity because all of the machines and agents are acting on behalf of a human. If you are executing, let's say, an agent booking travel for you, it is acting on your behalf. And so it has to be mapped to you as an identity. If it's underwriting a loan for a bank, it is acting on behalf of an underwriter. It has to be linked to the identity of that underwriter. And this is a linkage that's really, really hard to solve. This is where we come in because what we understand best is the human identity. Now, what we are doing is we are linking that human identity to the machines that are representing those humans and those agents that are representing the humans, in executing any of the mission-critical business processes. By the way, this is really the fundamental differentiation of SailPoint.
Dave Vellante
>> Okay. So that gets me to a topic that I love, which is knowledge graphs or maybe I should call them identity graphs here. You think about knowledge graphs, they bring the expressiveness of a graph, graphical expressiveness and the query, but the query flexibility, you have to go back 15 years. But it's always worked in security because you've got technical expertise and you can solve that problem. Now, there are a lot of companies today that are bringing in SQL-like capabilities with knowledge graphs, so I get very excited about that. Apply that to identity graphs because when I think of agentic, the data has to be harmonized and that to me speaks to knowledge graphs or identify. So how are you doing that? Maybe it's part of the secret sauce. How does it apply in this world?
Chandra Gnanasambandam
>> It's actually a fundamental part of our secret sauce and it's a core part of what we call the Atlas platform, which is our identity platform. So we are building, I'll say with confidence, we are building the world's largest identity graph. And it has two components to it. Component one is all identity data inside a company in one place. And so if you are a large bank, you are a large hospital system, a large media company, you have the workforce, you have third-party employees and contractors, you have APIs, bots, LLMs, large language models, small language models, agents. Having all of that, all of the identity for all of that in one place, that's really part one of the graph. And that's what we have today. And that's in the platform. It's in one place. Part two of the graph is where, Dave, it gets really, really interesting, which is that is you could call static data or admin time data, which is I have your identity, I have all the permissions you have to all the applications inside a corporation. What about real-time? Which is really the layer we are adding on the graph, that is what you have permission for. But is that really the way you are actually using it? Are you doing more than what you have permission for? Are you doing less than what you have permission for? Let's say that you are permissioned to do something but you have not used it in three months. Should you still have permission for it? Or should that be revoked till you start using it again? And so that requires a real-time view in terms of what you access patterns are inside an application. At an entitlement level, at a very fine grain level, we are adding that real-time dynamic layer as well. And so that is what constitutes an identity graph. The question is, so what? Okay, fine, you have this graph. What do you do with it?
Dave Vellante
>> It's because you can do policy enforcement at machine speeds. That's the so what, isn't it?
Chandra Gnanasambandam
>> Yes, and let me build on that.
Dave Vellante
>> The how you do it, I don't know.
Chandra Gnanasambandam
>> Oh, no, no, no. The what, there are really two different parts here, Dave, that are actually very, very interesting.
Dave Vellante
>> Yeah, let's stick with the what then.
Chandra Gnanasambandam
>> Yeah. Part one of the what is really this concept that standing privilege, it's just not relevant anymore. Meaning more than 90% of the identities have standing privilege. Meaning once you have permission to do something inside an application, inside your company, that's static, you'll have it forever. That is very risky in today's world because the threat vectors are so much. We can't really afford to have you have standing privilege or static privilege for most of your applications. Instead, if you have the graph, we can do just-in-time privilege. We can do just-in-time access. And so we would say, you are accessing a mission-critical, let's say, asset or a resource inside your company. When you are inside the building accessing it from the VPN, you're actually good-to-go. But you are here now, in RSA, you are accessing it from public Wi-Fi, we will say it's not that secure. And we will say, we're not going to let you do that, although you have the permission. That's what I mean by just-in-time. To do that well, you need signals, real-time signaling, which is what we have feeding into the graph. The first what of having the graph is the ability to solve or provide just-in-time privilege. And this goes back to this concept of zero trust. You know what I mean?
Dave Vellante
>> Yeah, of course.
Chandra Gnanasambandam
>> Which has been a philosophy so far. We are operationalizing it.
Dave Vellante
>> And that's the big gripe on zero trust is how do I operationalize it.
Chandra Gnanasambandam
>> This is our view. And the foundation for doing that is actually the graph. The second what is actually threat intelligence. Once you have the graph, Dave, now just imagine, let's say that there is a breach. Let's say your account has been breached. By the way, our view is that the bad actors are not breaking in anymore, they're actually logging in. And you've got to assume if you're a large corporation, there is a breach on, at any given point in time. Anyone that says, I have no breach inside my corporation, I don't think it's true. You've got to assume that is always a breach that's on. Now, what happens when you have a breach. You have a SOC, you're doing analysis to find out who has breached. The dwell time, by the way, is close to 60 days, meaning once a breach is in, the bad actor is in the network for 60-ish days. So you've got to know what is a blast radius of this bad actor, of this role that has been breached? What are the access pathways through which they can get access to critical resources. If you have the graph, it is a foundation for answering those kinds of questions, which is massive intelligence from an identity perspective inside a SOC. So those are the two whats. Those are two mission-critical problems, security problems you can solve as a see-saw if you have the graph, which is what we are building.
Dave Vellante
>> This just-in-time privilege is actually quite fascinating, Chandra. You can do policy enforcement and also you're situational. The example that you gave of an open Wi-Fi, for instance, like the one at RSAC. Ironic, isn't it? But also, but access approval in real-time. In fact, you know it's safe. And ideally you can limit the false positives or the false negatives.
Chandra Gnanasambandam
>> That's exactly right. And by the way, you can still have a human in the loop, meaning it doesn't have to be adjudicated automatically. So let's say that we find some access to be risky. We could actually trigger an event to your manager or to your colleague or to a security professional saying, "Hey, this seems risky. Should Dave still be allowed to access this?" And they can say, "Yes." And by the way, the trick in this is doing this in real-time. So what it requires is millisecond, microsecond respond time. Because you don't want to be waiting there saying, "I want to get into this application, what is it doing?"
Dave Vellante
>> I know we're over time here, but can the human-in-the-loop example, if there's an exception or you have to go to the human-in-the-loop, can the agents or will they at some point in time be able to learn from the reasoning traces of the humans such that the next time that episode occurs, the agents will be able to handle it?
Chandra Gnanasambandam
>> Totally. And so in fact, we have two different agents in the market. We are one of the few security vendors that have any agents in the market. We have two in the market today, by the way, that our customers are using. Which is one is a search agent. So think of us as a Google search for identities inside a corporation that use our platform. The second one is what we call the workflow builder. So you can conversationally say, "Hey, SailPoint agent, build this workflow for me to go execute this action inside."
From an identity perspective, it'll build a workflow and it will execute the action for you. And so those, by the way, continuously learn. Based on the questions you are asking it every day, it's learning. So it'll get smarter and smarter in answering the question. For instance, if you are a manager, you can ask it the questions like, "Hey, how many of my people have entitlements they have not used in the past month?" It will answer the question. You don't have to go run a report, you don't have to write a script and run a report. And the more you ask the question, it'll get very smart about answering that.
Dave Vellante
>> And that workflow, that example that you just gave, that's a dynamic process. You've got essentially building blocks from data, from process logic.
Chandra Gnanasambandam
>> Exactly.
Dave Vellante
>> That's not static process anymore.
Chandra Gnanasambandam
>> Bingo.
Dave Vellante
>> It fits the situation. That's exciting times. I'm going to have to have you back and get into that.
Chandra Gnanasambandam
>> Exactly. We've got some basic predicates to build a workflow, but it'll dynamically compose it. And the beauty is, it's plain English. You are telling it in plain English. So this is another big, this is a massive innovation, which is you no longer have to be a security or an identity admin to build these workflows. You can be a user. So we are actually democratizing access to these identity platforms because a manager can say, "I would like you to build this workflow and execute this action." And the platform will go do it for you. So that's what an agent does. So we are democratizing access to identity platforms for all users inside a corporation and not just admins.
Dave Vellante
>> Chandra, great conversation. Would love to have you back.
Chandra Gnanasambandam
>> Thank you, Dave. I really appreciate you having me here.
Dave Vellante
>> We really appreciate your time. You're very welcome. All right, and thank you for watching everybody. This is Dave Vellante for John Furrier, Jackie McGuire, and John Oltsik. You're watching RSAC 2025 on theCUBE. And we'll be right back right after the short break.