SailPoint today announced a new Cursor Enterprise connector aimed at securing AI-driven software development. The connector brings human users and AI agents operating inside Cursor under a single, unified identity governance model, helping organizations close critical security blind spots that arise when autonomous coding agents interact with enterprise systems and codebases.
As AI agents move from assisting developers to actively writing, reviewing, and modifying code, traditional identity and access controls that were built for human users leave significant gaps. Agents can inherit broad permissions, operate with limited visibility, and create new attack surfaces across the software supply chain. SailPoint’s Cursor Enterprise connector is designed to bring these agent identities into the same governance framework already used for human and machine identities.
The announcement continues SailPoint’s broader push into agent identity security, following earlier connectors and the company’s Agentic Fabric initiative. By treating AI coding agents as first-class identities that can be discovered, governed, and controlled, the company aims to give security and identity teams clearer ownership, purpose-based access restrictions, and auditability over agent activity inside popular development environments.
The new connector reflects a growing industry recognition that securing the software supply chain now requires governing both the humans and the AI agents that write the code.
Conditions Driving the Change
AI coding agents are rapidly moving from simple code suggestion tools into active participants that write, modify, and commit code across enterprise development environments, creating new identity and access risks that traditional human-centric controls were not designed to manage.
Popular AI-powered IDEs such as Cursor allow agents to interact with repositories, tools, and systems under developer credentials, often with limited visibility into what the agent is actually authorized to do or has done.
Organizations face growing security blind spots in the software supply chain as AI agents operate with broad or inherited permissions, making it difficult to establish clear ownership, purpose-based restrictions, and audit trails for agent activity.
Security and identity teams need a unified governance model that treats AI agent identities the same way they treat human and machine identities, rather than leaving agent access outside existing identity security frameworks.
The volume of non-human and agentic identities continues to rise, increasing the risk of credential misuse, over-permissioned agents, and unauthorized changes to critical codebases.
Enterprises require the ability to discover AI agents, assign human ownership and accountability, restrict access based on purpose and sensitivity, and gain visibility into agent permissions and associated risk before issues escalate.
Existing identity platforms that only govern human users leave a gap when AI agents begin acting on behalf of developers or operating autonomously inside development workflows.
As AI-driven software development becomes more widespread, organizations are under pressure to extend identity governance into the tools and environments where agents actually write and modify code.
What AI Agent Security Looked Like Before
Before the introduction of purpose-built connectors such as SailPoint’s Cursor Enterprise integration, AI coding agents operating inside popular development environments largely existed outside formal enterprise identity governance. Access was typically inherited from the human developer’s own credentials or managed through fragmented, tool-specific controls that offered limited visibility and weak accountability. Security and identity teams had little systematic ability to discover which agents were active in a given environment, who was responsible for them, what permissions they actually held, or what actions they had taken across source code repositories, internal tools, and connected systems.
Governance remained siloed. Human identities were managed through mature identity security platforms with clear ownership, access reviews, and audit trails. Machine identities and service accounts received growing attention. AI agents that actively wrote, reviewed, and modified code, however, often operated in a gray zone. They could inherit broad developer privileges, execute tool calls, interact with sensitive repositories, and make changes with incomplete logging or purpose-based restrictions. This created material blind spots in the software supply chain: organizations struggled to answer basic questions about agent activity, ownership, and risk.
In practice, many security teams responded by either restricting AI coding tools to low-risk or non-production use cases, or by accepting elevated risk in exchange for developer productivity gains. There was no consistent way to assign human accountability for each agent, limit access according to the agent’s intended purpose or data sensitivity, or gain a unified view of agent permissions alongside human and machine identities. As AI agents moved from simple code completion into more autonomous roles, these gaps became increasingly difficult to ignore.
What AI Agent Security Looks Like Now
With SailPoint’s new Cursor Enterprise connector, AI agents operating inside Cursor can be brought under the same unified identity governance model already applied to human and machine identities. The connector enables organizations to discover agent identities within the development environment, establish clear human ownership and accountability for each agent, and apply purpose-based access restrictions that limit what the agent can reach based on its intended function, data sensitivity, and observed usage.
Security and identity teams gain improved visibility into agent permissions and the risk associated with those permissions. This allows earlier intervention — before overly broad access or anomalous behavior turns into a security or compliance incident. Agent activity can be governed with the same rigor applied to other identities: access can be scoped, reviewed, and audited rather than left as an inherited or uncontrolled privilege.
The result is a more complete control plane for AI-driven software development. Instead of treating coding agents as an external or secondary concern, enterprises can manage them as first-class identities within their existing governance framework. This reduces critical blind spots in the software supply chain, supports safer scaling of AI-assisted development, and aligns agent behavior with organizational policy and risk appetite. The approach continues SailPoint’s broader strategy of extending identity security into the agentic era, ensuring that autonomous systems writing and modifying code are subject to the same standards of ownership, least privilege, and auditability expected of human and machine identities across the enterprise.
Our Take
AI Security Take
SailPoint’s new Cursor Enterprise connector represents a practical and necessary step in securing AI-driven software development. As AI coding agents move beyond simple suggestions and begin actively writing, modifying, and interacting with enterprise codebases, the traditional separation between human identity governance and agent activity creates clear security blind spots. Bringing Cursor agents under a unified identity governance model closes a meaningful gap in the software supply chain.
The core value lies in treating AI agents as first-class identities rather than secondary or invisible actors. By enabling discovery, human ownership, purpose-based access restrictions, and visibility into agent permissions and risk, the connector gives security and identity teams the same control levers they already apply to human and machine identities. This reduces the likelihood of over-permissioned agents, unowned activity, and incomplete audit trails — all of which become more dangerous as agents gain greater autonomy inside development workflows.
For organizations adopting AI coding tools at scale, the implication is straightforward. Leaving agent access outside formal identity frameworks is no longer a sustainable posture. Platforms that can govern human, machine, and agent identities together will be better positioned to support productive AI-assisted development while maintaining least privilege, accountability, and auditability. Those that continue to manage coding agents through ad-hoc or developer-inherited controls will face growing risk as agent capabilities and deployment volume increase.
SailPoint’s move continues a broader industry shift toward agent identity security. Securing the software supply chain now requires governing not only the people who write code, but also the AI agents that increasingly write it alongside them. Connectors that bring popular AI development environments into existing identity governance platforms are an important part of making that governance operational rather than theoretical.