Your Company Has a Million Identities and Only 100,000 Are Human
- By Winston Thomas
- December 14, 2025

It was a room filled with journalists in Singapore, expecting just another security presentation while it rained outside. Then Dan Mountstephen stands up and drops a statistic that stops conversation cold: If you’ve got 100,000 employees, you're actually managing close to a million identities. The ratio of non-human to human identities has hit 82 to 1, and it’s accelerating fast.
“2027 and a half is when agents within APJ will eclipse human identities,” says Mountstephen, who is the senior vice president for APJ at Saviynt, an identity security platform that last week raised USD700M at a Series B growth equity financing round. Your service accounts, API keys, bots, and increasingly, autonomous AI agents, are proliferating faster than your security team can track them.
The problem is that most organizations are sleepwalking through this growing identity crisis. In a survey of 250 CISOs and CIOs conducted by Saviynt, 92% reported limited or no visibility into AI identities within their organizations. “Eight in 10 organizations have detected shadow or unsanctioned GenAI,” Mountstephen reveals. “Most of it is probably not nefarious. These are people who are just trying to be better at their work.”
The third-party time bomb
Mountstephen identifies the single most underestimated risk: third-party identities, both human and non-human. “I think most organizations do a pretty good job managing their employees and their organizational assets,” he says. “I don’t think in general, CISOs across the region have got a good strategy in place for the software supply chain.”
His solution sounds deceptively simple: delegated sponsorship. If you’re working with a large company over 300,000 employees, you obviously can’t vet them all. But you know your relationship manager. Make them accountable. “Through implementing Saviynt to manage your external identities, through this concept of delegated sponsorship, you could eliminate enormous amounts of risk overnight,” Mountstephen says.
The challenge is getting attention. “I don’t think it’s necessarily a budget issue,” Mountstephen insists. “I think we need to do a better job, collectively as identity security professionals, in raising the visibility around this threat factor.”
The AI agent explosion
Marco Zhang, solutions engineering director for APJ at Saviynt, has been in mining facilities where machine identities aren’t theoretical. “I spent two days this week with a very large mining customer in Singapore,” Mountstephen recounts. “All we spoke about” was the exploding machine identity landscape — not their internal employees.
The problem compounds when AI enters the equation. Only 21% of executives report having complete visibility into agentic AI behaviors, permissions, tool usage, or data access within their enterprises. These aren’t just chatbots. They’re autonomous entities that can approve expenses, schedule meetings, analyze data, manage infrastructure, and make financial decisions, often without human oversight.
“The reason it’s so important is the very, very sensitive data,” Mountstephen explains. “We believe that while we all want to embrace these technologies, we need to think very seriously about how we secure them and ensure that we don’t compromise our organizations.”
Zhang emphasizes discovery as the critical first step: “The gaps are always about how effectively you can continue to control all these when there’s new technology plays, new standard.”
Saviynt’s approach involves partnering with network monitoring tools such as Zscaler and endpoint agents such as CrowdStrike to identify AI agents running on laptops and servers. That information feeds into what they call Identity Security Posture Management—think of it as an Apple Watch for your identity ecosystem, continuously monitoring and flagging risky access.
The platform plays
The identity security space has seen frantic consolidation, especially with the likes of Palo Alto acquiring companies and others building expansive platforms. Saviynt’s bet is different: they’ve built everything from a single code base, SaaS-native from day one. “I think some of the consolidation we see within the industry is to capture market opportunity, rather than necessarily provide better solutions to end customers,” Mountstephen says, pointedly.
The technical advantage? When you implement Saviynt for identity governance today and add privileged access management later, the integration work is already done. “A lot of the consolidation that we see within the category has largely been through acquisition, and you don’t get that same professional effect,” he notes. “You’re still going to have to reintegrate these tool sets.”
The company’s growth validates the approach: USD250 million in annual recurring revenue, 35-40% year-over-year growth, all while remaining private. That independence allows them to build what customers actually need rather than chase quarterly earnings or market adjacencies.
What CISOs need to do now
The window for getting ahead of the machine identity crisis is closing. Mountstephen’s prescription is straightforward: visibility first, governance second, then continuous monitoring. “You can’t secure what you can’t see,” he emphasizes.
Start with posture management to understand what your estate actually looks like. Then implement controls. And critically, extend those controls beyond your organization’s boundaries to your entire supply chain.
The organizations winning this fight treat their third-party environment with the same rigor as they do their internal employees. They implement least privilege through just-in-time access, not just for IT admins, but for anyone touching sensitive data, whether they’re employees, contractors, or autonomous agents.
The real shift, though, is conceptual. “I genuinely think people want to move way beyond compliance,” Mountstephen reflects. “I don’t think compliance is the driver here. It’s digital transformation.”
It’s plain to see that identity security isn’t about checking audit boxes anymore. It’s the foundation that determines whether your AI transformation succeeds or becomes your next breach headline. In a world where machines outnumber humans 82 to 1, getting identity wrong doesn’t just slow you down. It takes you out of the game entirely.
Image credit: iStockphoto/Alona Horkova
Winston Thomas
Winston Thomas is the editor-in-chief of CDOTrends. He likes to piece together the weird and wondering tech puzzle for readers and identify groundbreaking business models led by tech while waiting for the singularity.