AI Identity Security Needs More Than Technical Depth to Manage Risk and Accountability 

Published
Written by:
Vishwa Pandagle
Vishwa Pandagle
Cybersecurity Staff Editor
Key Takeaways
  • AI agents can act independently across cloud services, applications, and endpoints, making continuous oversight essential.
  • Wu says security teams need a complete inventory of every AI agent and non-human identity in their environment.
  • SailPoint places identity at the center of AI security by tracking who or what has access, and who is accountable.
  • Connecting the governance of employees, AI agents, and machine identities gives defenders complete security context.
  • Every AI agent should have a clear owner, defined permissions, an established risk level, and suitable access controls.

Wendy Wu, Chief Marketing Officer at SailPoint, brings a career shaped by a nontechnical education and a Microsoft role that disappeared before she started. Wu previously served as Box’s Vice President of Marketing, led global and regional marketing programs for Google Cloud, and held Microsoft roles spanning government technology, healthcare, and market research.

In this LeadHer in Security interview, Wu explains why the current AI shift presents a different security challenge from earlier moves to cloud, mobile, and SaaS. AI agents are operating across applications, cloud systems, and devices at machine speed, while many organizations still lack visibility into them or clarity over who is responsible for their actions. 

Her observations address cybersecurity, identity, and compliance teams working to prevent unauthorized access without obstructing useful AI adoption. Wu reflects on the experiences that shaped her career.

With degrees in English, public policy, and cultural anthropology, Wu offers encouragement to women and other professionals entering technical industries from different backgrounds. 

She says credibility begins with understanding customers, risks, accountability, and business consequences.

Vishwa: You have worked through several major technology transitions, from cloud adoption to today's AI wave. What feels different about this moment?

Wendy: Every major technology shift I've worked through in my career, from cloud adoption to mobile and SaaS, has come with a learning curve and adjustment period. Organizations resisted, adapted, and then ultimately thrived. 

AI, specifically agentic AI, feels categorically different for one reason: the speed at which it is dissolving boundaries. With cloud, enterprises had years to develop governance frameworks before things got complicated. When it comes to AI, the complexity arrived before the guardrails did. 

At SailPoint, we think about this constantly because AI doesn't just change how people work, it changes who and what is doing the work. You now have AI agents operating autonomously across cloud environments, applications, and endpoints, acting at machine speed and often without clear ownership or oversight. 

Non-human identities now vastly outnumber human ones, and most security programs weren't built for that reality. The identity perimeter is expanding faster than most teams can track. 

What makes this moment so consequential is that the opportunity and the risk are scaling at the same time, while the window to put the right governance in place is much smaller than it was in prior technology cycles. 

That's precisely why SailPoint created the Agentic Fabric, to give enterprises a way to discover, govern, and protect every AI agent before that gap becomes a breach.

Vishwa: Many leaders talk about AI in terms of opportunity or risk. Which side of that conversation do you find organizations struggle with more?

Wendy: It’s both, depending on where you sit. Business leaders often move quickly toward the upside – automation, efficiency, scale – without fully thinking through access, accountability, and control.

Security and compliance leaders see those risks clearly, but they can sometimes become so focused on what might go wrong that they slow down meaningful progress.

The organizations navigating this well aren’t treating AI adoption and AI security as separate conversations. They understand that security should enable innovation, not constrain it. 

And in this environment, identity has to be the foundation: knowing who has access, what they can access, and who is accountable when something goes wrong. 

Like our CEO Mark McClain always says, we act like the brakes in an F1 car – allowing enterprises to go fast without being reckless. 

Vishwa: You've spent much of your career helping enterprises understand complex technologies. What have you learned about earning trust when people are skeptical of a new technology shift?

Wendy: I spent eight years at Google Cloud building demand generation for a platform that, early on, many enterprises didn't believe they needed. I saw the same dynamic at Box during the content cloud era. 

What I've learned is that skepticism usually isn't about the technology – it's about the consequences people can’t yet see. 

The best way to earn trust is to make the invisible visible; it makes a huge difference to show people concretely what's at stake, what's protected, and what they gain by moving forward. At SailPoint, that's not just a philosophy – it's how our solutions work.

You cannot secure what you cannot see. Whether it's a human workforce or an expanding universe of AI agents and machine identities, our job starts with giving enterprises complete visibility into every identity so that enterprises can seamlessly govern and secure every identity, every access point, and every relationship between agents, data, and the humans responsible for them.

When the unknown becomes understandable, trust follows. 

Vishwa: Security leaders are being asked to make decisions about AI while the technology is still evolving rapidly. How do you think organizations can avoid becoming either overly cautious or overly reactive?

Wendy: I’d encourage leaders not to wait for perfect clarity, because it’s not coming. The technology will keep evolving. What shouldn’t change is your foundational approach to security.

The questions that matter (who has access, what can they do with it, what's the risk level, and who is accountable if something goes wrong) are not new questions. They're identity questions that enterprises have been wrestling with for years. 

What AI does is dramatically increasing the scale and complexity of the answer. You now must ask those questions not just for your human workforce but for AI agents and machine identities that are multiplying faster than most teams can track. 

Gartner predicts that 25% of breaches will happen through agent-based attack surfaces due to poor machine identities and lack of context-aware policy controls by 2028. That's not a future problem – it's a now problem. 

My advice to organizations is to anchor your AI security strategy to your identity program by breaking down the silos between human and machine identities. Securing the modern enterprise requires a unified approach, one that connects the dots between your workforce and your AI agents to give you full security context. 

Start with three things: visibility into every agent and non-human identity in your environment, clear governance and ownership, and the ability to respond in real time when something goes wrong. 

If you have that foundation, you don’t need to predict every turn in the market – you just need controls that can scale with it.

Vishwa: You have worked across Microsoft, Google, Box, and SailPoint. What leadership lesson has remained consistent regardless of company or technology cycle?

Wendy: No matter the company, market moment, or technology cycle, the thing that determines whether a team succeeds is usually the same: clarity of mission and trust in each other.

I joined SailPoint because the mission resonated with me immediately – identity security is not a nice-to-have, it's the control plane for the modern enterprise – and the people at the company believe that deeply. 

That kind of conviction is hard to manufacture. It shows in how teams make decisions, how they treat customers, and how they perform under pressure. 

True industry leaders win through continuous innovation that anticipates and solves their customers' most critical needs. It requires the agility to evolve and the willingness to disrupt your own technology before the market forces you to. 

You can see this continuous evolution in SailPoint's own journey. We disrupted ourselves to transition from on-premise governance to the cloud. We evolved our core capabilities from traditional IGA into comprehensive identity security. 

And most recently, we've expanded our focus from strictly human identities to securing all identities, building the foundation to secure the new frontier of AI agents.

Vishwa: What advice would you give women who want to build credibility in highly technical industries without coming from deeply technical backgrounds?

Wendy: My degrees are in English, public policy, and cultural anthropology, so I did not come up through engineering or computer science. However, I’ve spent my career inside highly technical companies, and what I’ve learned is that technical credibility is not the same as technical depth.

The root for success resides in deep understanding of the market and the customers, their needs, challenges, and relentless focus on helping them solve their needs. 

You do not need to understand every line of code to understand the customer problem, the value of the product, or where the gaps are.

Wendy Wu

My advice is to learn the domain, not just the vocabulary. Understand what customers are trying to solve. In many cases, the most important questions are not purely technical – they are questions of trust, accountability, risk, and business impact.

Wendy Wu
Chief Marketing Officer, SailPoint

That perspective is incredibly valuable.

Vishwa: Looking back, were there moments in your career where taking a less traditional path ultimately became an advantage?

Wendy: Right out of grad school, I was hired as a Public Sector Product Marketing Manager at Microsoft. But before I even started, I got a call from my new manager. He explained that my original hiring manager had left, and there wasn't a defined job for me anymore. 

I had basically lost the job I was hired for before my first day. But this turned out to be the ultimate blessing in disguise. Instead of letting me go, my new manager handed me a blank canvas. 

He asked me what I wanted to do and what I had experience in. I pitched him an idea: I had a background in market research from my previous work in China, and I could help build a dedicated market research practice for our Public Sector team from the ground up.

He was incredibly supportive, and I became the team's first Market Research Manager. Suddenly, I was working directly with leadership on various research projects, using data to analyze performance and guide critical business decisions. 

That curveball hardwired a data-driven mindset into me from the very beginning of my marketing career – a foundation that still defines exactly how I operate today as a CMO.

Vishwa: As your responsibilities grew over the years, how did your understanding of leadership evolve? Were there any experiences that impacted your perspective?

Wendy: Early in my career, I thought leadership was about being the most capable person in the room – knowing the most, working the hardest, having the best answers. 

What I've come to understand is that leadership at scale is almost the opposite. Your job is to create the conditions where other people can do their best work. 

That means being clear about where you're going and why, being honest about what you don't know, and trusting the people you've hired to fill those gaps better than you could.

At SailPoint, we're doing something genuinely ambitious by trying to redefine how enterprises think about security in an era where AI agents are becoming part of the workforce. 

That requires a team that can hold a big vision and execute with precision at the same time. My job is to hire the best talent, enable them, and guide them with clarity and vision to achieve collective success.


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: