Idira Identity Security Platform: Discover Every Privilege (Part 2)

Aug 04, 2026
10 minutes

Key Takeaway: Identity and privilege discovery continuously maps access risks across human, machine, and agentic identities. Replacing siloed tools with a unified view lets security teams map effective permissions, surface blind spots like shadow AI and dormant credentials, score the risk each identity carries, and surgically remediate access vulnerabilities and identity posture risks before attackers exploit them.


In the last blog, we defined democratizing privilege controls as extending the rigor of privileged access management, or PAM, to every identity that now carries privilege. We also said the identity team now owns three principles end to end: Discover, Control, and Govern. 

Let's start with the first step: Discovering every privilege.

Discovery is the goal, and it applies to every identity in the enterprise: human, machine, and agentic. Not just the accounts in your directory. Every account, every entitlement, every access path, wherever they exist. And not once a quarter. Continuously, because your environment changes by the hour and an attacker can compromise any gap left behind by those changes.

A connected data foundation links every identity, entitlement, resource and privilege.

Finding identities is the starting point, but finding them doesn't get you anywhere by itself. You find them to build complete visibility. You need that visibility to assess the risk each identity carries. You assess risk so you know what to fix and in what order. And you do all of it to remediate proactively, closing identity posture risks before an attacker uses it against you.

This path is the Discover pillar. Stop anywhere along it, and you have a report that nobody acts on. Nearly 90% of Unit 42 investigations trace back to identity weaknesses that already existed. Nobody found them first.

Why Traditional Identity Discovery Tools Fall Short

Most organizations already run discovery. The problem is that every tool discovers its own slice:

  • Directories and identity providers, or IdPs, see federated accounts but miss local accounts, cloud entitlements, and anything provisioned outside their view.
  • Identity governance and administration, or IGA, sees application entitlements for humans, and often only through manual, quarterly access reviews.
  • Cloud infrastructure entitlement management, or CIEM, sees cloud permissions but stops completely at the cloud boundary.
  • Secrets scanners find exposed credentials without knowing which identity owns them or what that identity can reach.
  • Agent discovery tools are being built right now, but remain disconnected from all of the above.

This siloed approach is broken. It leaves identity and security teams with findings they can't connect and can't act on.

The siloed approach is broken. It leaves identity and security teams with findings they can’t connect and can’t act on.

 

How to Discover Privileges Across All Identity Types

Connecting is fast. To build complete visibility, modern discovery must connect to cloud service providers, identity providers, SaaS applications, and developer environments in minutes, using read-only API roles. From there, discovery runs continuously across all three identity types.

Human identities

In our first blog in this series, we laid out the identity security framework and explained that work shifts from modeling who someone is to modeling what they are doing, and on whose behalf. Discovery is where that starts.

The Idira Identity Security Platform finds and correlates accounts across Active Directory, Entra ID, and your IdP, plus everything those systems never see: 

  • Local admin accounts on endpoints and servers. 
  • Break-glass accounts created during an incident and never removed.
  • Accounts that survived offboarding because SCIM deprovisioning failed silently. 
  • Dormant service accounts that never had an owner.

From there, Idira maps what those accounts can actually reach. Not the role name, but the effective permissions. An identity and access management or IAM user with a policy that allows sts:AssumeRole into a production role is a production admin, regardless of what the account is called. A helpdesk account that can reset passwords and assign group membership is a path to domain admin, whether or not anyone modeled it that way. Those chained paths are where attackers operate, and they don't show up in an entitlement report.

The Idira identity inventory shows correlated human records, local account tags, and risk scores.

Machine Identities

Machine identities create a new challenge, because they outnumber humans 109 to 1, and in most organizations no one owns the complete inventory.

Discovery for machines starts with the secrets already sitting in your vaults, across AWS Secrets Manager, Azure Key Vault, GCP Secret Manager, and HashiCorp. These secrets are scanned daily rather than audited once a year. That surfaces the vaults themselves first, because most orgs are running more of them than they think: vaults get stood up by different teams and are never consolidated. Next, we find out what's inside them: the secrets that are idle, the ones nobody has rotated, and the ones nobody owns (including the API key somebody created for a test three years ago and never revoked).

The same inventory covers the workloads on the other side of those credentials. The Discovery Agent collects Kubernetes machine identities, while Idira automatically ingests secrets from Secrets Manager. SaaS data and anything Idira does not reach natively can be pushed through the discovery API.

Each of those credentials opens access to something. Most organizations can't tell you what.

The Idira machine identity inventory highlights certificate lifecycles and service account workload attributions.

Agentic Identities 

Agentic identities are the newest and least-mapped attack surface. An agentic identity is an AI-driven entity that uses delegated authority to perform autonomous tasks on behalf of humans. While boards push for rapid AI adoption, agents are often granted broad privileges and deployed informally like cloud-native workloads, creating the "Shadow AI" risks keeping CISOs up at night. The challenge is that while these agents demonstrate aspects of human reasoning, they operate at machine scale and speed.

Discovering and onboarding these privileged, ephemeral actors requires moving as fast as they do.

Idira solves this today by providing seamless integration with key agentic platforms like Microsoft Copilot Studio, AWS Bedrock, and AgentCore, allowing organizations to discover and onboard agents into a centralized agent registry. It provides clear ownership and context information about these agents, tying them back to the human workforce. Additionally, Idira leverages cross-platform integrations across Cortex and Prisma to extend agent discovery and onboarding capabilities.

Idira leverages modern SPIFFE standards for machine workloads to issue cryptographically verifiable identities for discovered agents, ensuring not just strong authentication but also visibility and traceability of their actions across non-deterministic paths.

The Idira dashboard gives a centralized view of AI agents, ownership gaps, and posture risk across environments.

Finally, Idira's unified platform approach also enables organizations to seamlessly tie agentic workflows to human identities for delegated flows and to the machine credentials, such as secrets and API keys, described in the previous sections.

Moving from Identity Inventory to Posture Risk Management 

Each source reports its own accounts. The same identity shows up as a cloud role, an IdP login, a local account, and an agent deployment, with nothing linking them. Idira unifies all of it into a single record per identity, on one data model that covers human, machine, and agentic identities. One person, every account they hold, every path those accounts open. One workload, every secret and certificate attached to it. One agent, its owner, its permissions, its action history.

You need the complete identity before you can say anything useful about risk. A fragment tells you an account exists. The unified record tells you what that identity can actually do in your environment.

A fragment tells you an account exists. The unified record tells you what that identity can actually do in your environment.

That record is what Idira's risk management runs on. Every identity gets scored on the factors that determine real exposure: how much privilege it holds, how far that privilege reaches, and how easily it could be compromised. It follows the same logic as the Idira Identity Security Blueprint, which assesses privilege level, scope of influence, and ease of compromise, then ranks work by risk reduction per unit of effort. The output isn't a queue. It's a risk picture: which identities carry the most exposure right now, what makes them risky, and where to start.

An unmanaged local admin account on a production server sits at the top. A dormant OAuth grant still holding mail read scopes sits below it. A non-privileged account with stale metadata is hygiene. Scoring runs continuously, so the picture reflects your environment today, not its state at the last access review. 

How to Remediate Identity Posture Risks 

Idira remediates identity posture risks proactively, before the access is abused. Remove the standing entitlement nothing has used in months. Decommission the local account nobody claims. Rotate the secret that's been sitting in a public repo. Revoke the OAuth grant for the agent whose owner left the company.

Every fix carries the inventory and risk context that surfaced it, so remediation is surgical instead of a batch cleanup that breaks production. Then discovery runs again, the risk picture updates, and the next set of fixes is already prioritized.

Why Discover Comes First

Go back to how we defined democratizing privilege controls: the right privilege control, on the right action, at the right moment, for every identity. None of that works in an environment you haven't mapped. You can't apply zero standing privilege to an entitlement you haven't found. You can't scope an agent you didn't know was deployed. You can't govern an identity lifecycle you can't see.

Idira connects discovery, privilege controls and governance across every identity and target.

That's why Discover comes first, and why it has to run end-to-end on one platform, not via five tools and one spreadsheet holding the gaps together.

Next in the series: Control, where privilege meets the moment of action. Then Govern, where every access decision becomes a proactive, orchestrated flow.

Want to see where your identity risk actually sits? Start with the Rapid Risk Reduction playbook, a 60-day action plan built on the Blueprint, or learn more at paloaltonetworks.com/idira.

FAQs

What is an agentic identity? 

An agentic identity is an AI-driven actor (such as an AI assistant or automated agent) that uses delegated authority to execute tasks on behalf of a human. These identities operate at machine scale and speed, requiring continuous discovery and governance to prevent privilege abuse.

Why do traditional identity discovery tools fail? 

Traditional tools operate in silos. Directories only see federated accounts, IGA tools review application entitlements during slow quarterly cycles, and CIEM stops at the cloud boundary. This fragmented approach leaves blind spots across local accounts, shadow AI, and unmanaged secrets.

What is the difference between human and machine identities? 

Human identities represent actual employees or contractors logging into systems, whereas machine identities represent workloads, applications, or scripts (often authenticating via secrets, API keys, or certificates). In modern environments, machine identities outnumber human identities by roughly 109 to 1.