IMAGE CREDITS: COREWIRE / AI ILLUSTRATION

Orchid Security tackles the AI agent identity gap: 67 percent unmanaged

Orchid Security’s new Agentic Enrichment tools map AI agents back to their inherited permissions. The company’s own research found 67 percent of nonhuman accounts are unmanaged, the gap agents are now moving into.

Orchid Security extended its identity platform on May 28 with tools built specifically for AI agent governance, a narrower and arguably more urgent problem than the general enterprise AI security coverage most outlets give it. The company’s pitch: as agents inherit permissions from the humans and systems that spawn them, most identity and access tools have no way to see, let alone govern, what those agents can actually do.

The launch matters less for the product news than for the number behind it. Orchid’s own research, published as “The Identity Gap: 2026 Snapshot,” found that 67 percent of nonhuman accounts inside the organizations it studied are local or entirely unmanaged, invisible to the identity and access management stack meant to control them. That is the gap AI agents are now moving into at scale.

What is actually new

The centerpiece is a feature Orchid calls Agentic Enrichment, which maps each AI agent back to its originating identity, its owner, the applications it touches, and the permissions it has inherited along the way. That mapping is the missing layer in most enterprise AI deployments: an agent built to automate a finance workflow can end up holding access no single human in that workflow was ever granted directly, because it inherits from multiple systems at once.

Orchid, founded by Roy Katmor, raised a $36 million seed round in January 2025 co-led by Team8 and Intel Capital, with Capital One among the investors, a detail worth noting given Capital One’s own scale as an enterprise identity buyer. The company already counts Costco and Repsol as customers, and positions its Identity Control Plane as a layer that sits alongside existing IAM and IGA tools rather than replacing them.

What this means for security and IT budgets

This is the governance half of a problem we have covered from the adoption side before. In shadow AI is the new shadow IT, and blocking it will not work, the conclusion was that employees will keep bringing in ungoverned AI tools regardless of policy. Orchid’s data suggests the same is quietly true of the agents built on top of approved tools: the access sprawl happens even when the deployment itself is sanctioned, simply because nobody mapped what the agent inherited.

For security leaders, the practical takeaway is to treat agent identity mapping as a prerequisite for scaling agentic AI, not a follow-up project. That lines up with the procurement checks in our buyer’s guide to agentic AI lock-in: knowing where an agent’s access lives is as important as knowing where its data lives, and both should be answerable before a contract is signed, not after an incident.

What to watch

Watch whether the major identity platforms, Okta, Ping, and Microsoft Entra among them, move to build agent-mapping features natively rather than leaving the space to specialists like Orchid. Non-human identity has quietly become one of the most crowded categories in enterprise security funding, and agent-specific governance is the newest wedge inside it.

Get the Signal

AI and business tech news, verified by a physician who reads the filings. One email a week, no noise.

Dr. Joseph Joshua

Dr. Joseph Joshua is the founder and editor of Corewire. A medical doctor by training, he brings the evidence-first discipline of clinical medicine to technology journalism: claims get checked against primary sources before they get published. He has produced technology and B2B content for companies across…

View Bio

Keep Reading