HomeinterviewsPathlock Named Overall Leader in 2026 KuppingerCole Identity Governance Report

Pathlock Named Overall Leader in 2026 KuppingerCole Identity Governance Report

As AI agents and SaaS applications take on more enterprise work, controlling who—or what—can access critical systems is becoming a workforce technology problem as much as a cybersecurity one. Pathlock says it has been named an Overall Leader in KuppingerCole Analysts AG’s 2026 Leadership Compass for Identity and Access Governance, highlighting the growing importance of identity governance that can extend beyond employees to privileged users, partners and non-human identities.

Pathlock Recognition Highlights the Expanding Role of Identity Governance in the AI Era

Enterprise identity management is entering a more complicated phase. The question is no longer simply whether an employee has access to an application, but whether that access remains appropriate as workflows, privileges, applications and increasingly autonomous software agents change.

That shift is at the center of Pathlock’s latest announcement. The company said KuppingerCole Analysts AG has recognized it as an Overall Leader in the 2026 Leadership Compass for Identity and Access Governance (IAG), the highest designation in the report.

The analyst evaluation looks at vendors and products across areas including access risk management, compliance, analytics, governance automation and policy-based controls. According to Pathlock’s announcement, KuppingerCole specifically highlighted the company’s ERP-focused governance, segregation-of-duties (SoD) controls, continuous compliance monitoring and policy-driven governance across workforce identities, privileged users, partners and non-human identities.

The recognition is notable because identity governance is increasingly moving beyond traditional employee lifecycle management.

In a conventional identity governance model, an organization determines what applications a worker can access, reviews those permissions periodically and removes access when the employee changes roles or leaves. That model becomes harder to maintain when enterprises operate hundreds of SaaS applications, complex ERP environments and automated workflows.

AI agents add another layer.

An AI agent may be granted credentials or permissions that allow it to retrieve information, initiate transactions or interact with enterprise applications on behalf of a person or business process. Unlike a human employee, however, an agent can potentially execute actions at machine speed and operate continuously.

That creates a governance challenge: permission management must increasingly account for what an identity can actually do, not simply which system it can enter.

Pathlock’s positioning is built around this convergence of identity governance, application security and governance, risk and compliance (GRC). Its platform is particularly oriented toward environments involving enterprise resource planning systems, where excessive privileges or conflicting permissions can have direct financial and operational consequences.

KuppingerCole Senior Analyst Nitish Deshpande said in the announcement that Pathlock’s recognition reflects a market move toward combining identity, application and privileged-access governance under a unified policy framework.

That direction puts Pathlock into a competitive market that includes broader identity platforms from companies such as Microsoft, Okta and SailPoint, as well as cybersecurity and access-management providers expanding into identity governance. Large enterprise software ecosystems including SAP, Oracle, Salesforce and Microsoft also have a stake in how permissions are administered across business applications.

The distinction for buyers is often architectural rather than simply functional. General-purpose identity governance platforms can provide broad identity lifecycle, access certification and entitlement-management capabilities. Pathlock’s differentiation is its emphasis on ERP-centric governance and the connection between identity permissions, application controls and compliance processes.

For HR and workforce technology teams, that distinction matters because employee identity data increasingly feeds security and access decisions. A worker’s role, department, manager, employment status and organizational changes can influence what systems they should access. As organizations automate HR processes, those signals increasingly need to connect reliably with identity governance platforms.

The AI transition makes the problem more urgent.

McKinsey’s 2025 global AI survey found that 62% of respondents said their organizations were at least experimenting with AI agents, while 23% reported that their organizations were already scaling an agentic AI system somewhere in the enterprise. At the same time, nearly two-thirds said their organizations had not yet begun scaling AI across the enterprise.

That gap gives enterprises an opportunity to establish governance before agent deployments become deeply embedded in business processes.

Gartner is also warning of a much larger agent-management challenge. The research firm predicts that the average Fortune 500 enterprise could have more than 150,000 AI agents in use by 2028, compared with fewer than 15 in 2025, and says only 13% of organizations believe they currently have the right AI-agent governance in place.

For CIOs, CISOs, HR technology leaders and compliance teams, the implication is straightforward: identity governance is becoming part of the infrastructure required to scale AI responsibly.

The Pathlock announcement therefore represents more than another vendor ranking. It reflects a broader change in enterprise security architecture, in which workforce identities, privileged accounts, application permissions and machine identities increasingly have to be governed together.

For enterprises evaluating identity governance software, the important question will be whether a platform can translate policies into enforceable controls across the applications that actually run the business—and continuously demonstrate that those controls are working.

Market Landscape

Identity Governance and Administration (IGA) is evolving from a largely human-centric discipline into a broader control layer for digital workforces.

Gartner’s 2025 Market Guide for Identity Governance and Administration describes the IGA market as dynamic, with organizations evaluating capabilities according to different business drivers and requirements.

The next phase is being shaped by three overlapping trends:

AI agents: Autonomous software increasingly needs credentials, permissions and access boundaries. Gartner says IAM capabilities are already evolving as organizations deploy more AI agents.

SaaS and application sprawl: Employees can accumulate permissions across cloud applications, ERP systems and business platforms, making periodic access reviews less effective without automation and risk intelligence.

Continuous compliance: Enterprises increasingly need evidence that access policies remain effective throughout the year, rather than relying exclusively on point-in-time audits.

This creates room for both specialists and platform vendors. Microsoft, Okta, SailPoint and other identity providers compete around identity lifecycle and governance, while security vendors increasingly incorporate privileged access, application security and machine-identity controls.

Pathlock’s strategy is differentiated by its concentration on ERP security, cross-application access controls and GRC automation. The approach may be particularly relevant to large enterprises where SAP- or Oracle-centered business processes create complex combinations of roles and segregation-of-duties requirements.

The larger industry direction, however, is clear: identity governance is moving toward continuous, policy-driven control across humans and non-human identities.

Top Insights

  • Pathlock was named an Overall Leader by KuppingerCole, underscoring growing enterprise demand for identity governance spanning ERP systems, workforce identities and non-human identities.
  • AI agents are expanding the identity attack surface, forcing HR, security and IT teams to govern machine permissions alongside traditional employee access and privileged accounts.
  • ERP-centric governance remains strategically important, particularly for enterprises managing segregation-of-duties conflicts, financial controls, compliance requirements and complex cross-application permissions.
  • Enterprise AI adoption is moving toward agentic workflows, but McKinsey research shows most organizations remain early in scaling, giving governance teams time to establish controls.
  • Identity governance is becoming continuous infrastructure, connecting workforce data, application permissions, compliance policies and AI-agent activity rather than treating access reviews as periodic audits.

Join thousands of HR leaders who rely on HRTechEdge for the latest in workforce technology, AI-driven HR solutions, and strategic insights