IT Brief India - Technology news for CIOs & IT decision-makers
India
BeyondTrust adds AI identity controls to Pathfinder

BeyondTrust adds AI identity controls to Pathfinder

Wed, 5th Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

BeyondTrust has introduced the first wave of native features on its Pathfinder platform, extending its identity security tools to non-human and AI-linked identities.

The additions include PathfinderAI and MCP Server, AI Agent Security, NHI Governance and the newly announced Workload Credentials tool. Together, they are intended to help organisations discover, prioritise, govern and protect privileged access across human users, machines, workloads and AI agents.

The launch reflects a broader shift in cyber security: privileged access is no longer limited to human administrators. Service accounts, application programming keys, workload identities and autonomous software agents now hold access rights across corporate systems, creating a larger attack surface for security teams to monitor.

The latest Pathfinder features build on the visibility and intelligence already provided through BeyondTrust's Identity Security Insights product. The aim is to bring human and non-human identities onto one platform so security teams can trace access relationships and reduce what the company describes as standing privilege.

BeyondTrust's research unit found enterprise AI agents grew by more than 460% year on year. At the same time, security researchers have documented rapid growth in machine and non-human identities across enterprise environments, many without clearly assigned owners or regular access reviews.

That expansion has drawn attention from attackers, who increasingly exploit trusted identity relationships rather than relying only on conventional malware or direct account compromise. OAuth integrations and workload credentials have become routes for lateral movement and access to sensitive data without necessarily triggering older security controls.

Four additions

PathfinderAI is designed to let security analysts investigate identity risks using natural-language queries inside the Pathfinder platform. Its companion, MCP Server, extends that data outward so AI agents can connect to BeyondTrust's identity intelligence through the Model Context Protocol.

BeyondTrust named Microsoft Copilot, OpenAI and Claude among the systems that can connect this way. The goal is to let AI tools draw on privilege-related identity data while maintaining policy controls around that access.

AI Agent Security focuses on what AI agents are allowed to do on endpoints in real time. It is intended to help organisations discover, inventory and govern AI agents across the enterprise while separating the visibility of AI identities from the human users associated with them.

That includes monitoring for shadow AI, reviewing associated privileges and identifying paths to privilege that may emerge when agents inherit or accumulate access rights. The product is also meant to show security teams where AI agents exist and what systems or data they can reach.

NHI Governance is aimed at non-human identities, including service accounts, API keys, OAuth clients, workload identities and AI agents. The tool is intended to move organisations beyond discovery by assigning ownership, reviewing privileged access, automating lifecycle management and applying governance controls to identities that often sit outside standard governance processes.

Workload Credentials, the fourth addition, is a cloud-native secrets management tool for non-human identities behind CI/CD pipelines, Kubernetes services, containers and AI agents. Instead of storing and rotating static secrets, it issues short-lived credentials on demand and allows them to expire automatically after use.

In practice, a workload authenticates with an OIDC identity token, after which a policy engine evaluates the request and issues a scoped credential. The credential then expires without manual rotation.

Security shift

The expansion underlines how identity security vendors are adjusting to a market where automated systems now act with privileges once reserved for people. For many companies, the challenge is not only to find those identities, but also to understand who owns them, what they can do and whether their access is still justified.

Marc Maiffret, Chief Technology Officer at BeyondTrust, said the company sees that change as a continuation of its longstanding focus on privileged action rather than a move into a separate AI category.

"We are not a privileged access company adding AI," said Marc Maiffret, Chief Technology Officer at BeyondTrust. "We are the company that has long defined how to secure privileged action. For twenty years, that meant people with administrative rights, and we built the category for securing them. Today, that actor is just as likely to be an AI agent or autonomous workload. The actor has changed. Our job has not."

PathfinderAI, Pathfinder MCP Server, AI Agent Security and NHI Governance are currently available through BeyondTrust's early access programme. Early access for Workload Credentials is due to open soon.