Titus argues the problem needs a different frame, not just more manual review. Rule-based governance created the over-entitlement problem because it could only add permissions, not intelligently evaluate whether they still made sense.
70% of organizations rate identity and access management as a top-5 risk, driven by insecure identities and overprivileged accounts. (SentinelOne Cloud Security Report)
Behavioral AI gives organizations something the field has always wanted but never had the telemetry to implement: attribute-based access control, grounded in evidence. You can look at a cluster of identities doing similar functions, identify the outliers with access to systems they shouldn't need, and show a regulator logged data that proves who should have access and why.
"The proof part has always been the problem. Prove it."
— Patricia Titus, Field CISO, Abnormal AI
Britton lands the same problem from the governance architecture side: agents don't come with org charts. "I know Ryan's role, I know his job responsibilities, I know what systems he has access to. When it comes to agents—who owns that agent, what part of the org does that agent work for, what systems should they have access to? It just becomes a lot murkier and more convoluted."
The credential is real. The permissions are real. But there's no person, no role definition, no accountability structure. Without that, there's no baseline against which anomalous behavior becomes detectable.
