04/13/2026 | Press release | Archived content
For years, security strategies were built around perimeters, networks, and static roles. That approach worked when environments were simpler and privileged access was easier to define.
That world has changed.
Today, privilege governance sits at the center of modern security. Trust is no longer implicit - it must be continuously assessed, governed, and enforced.
In modern enterprises, access decisions are not just about who someone is. They depend on whether an identity - human or non-human - should be trusted in that moment, for that action, and with that level of privilege.
This shift changes everything.
Privilege can no longer be treated as a back-office security function. It is now a strategic capability that underpins operational resilience, audit readiness, cloud control, and secure innovation.
The challenge is not theoretical. It is structural.
As organizations modernize, privileged access management (PAM) and identity governance are colliding with automation, cloud platforms, and AI-driven workflows. Traditional models struggle to keep pace.
One of the biggest drivers of change is the explosion of non-human identities.
Service accounts, APIs, certificates, secrets, workloads, and automation platforms now vastly outnumber human users in many environments. Yet many of these identities were never designed to be governed with the same discipline applied to workforce access.
This creates risk.
If organizations cannot reliably discover and control machine identities, privilege becomes persistent, opaque, and difficult to defend. Machine identity security is no longer optional - it is foundational to effective access control.
Agentic AI introduces an even more fundamental shift.
AI agents do not simply access data. They initiate actions, chain tools together, and operate with delegated authority. This blurs the line between identity and intent.
When an AI agent performs an action, organizations must be able to answer a critical question:
What are we trusting, and what evidence supports that trust?
Without strong privilege governance, automated decision-making expands faster than control.
Despite these changes, governance models still tend to focus on humans. PAM implementations often emphasize sessions and credentials rather than context and outcome.
The real challenge lies at the convergence point - where identity, privilege, trust, and action meet.
That is why identity must be treated as the control plane.
Modern identity governance and administration (IGA) defines policy intent, access justification, and evidence. PAM enforces that intent in real time by reducing standing privilege and constraining execution at the point of action.
Together, they transform trust from assumption into operational discipline.
When trust becomes measurable, privilege becomes defensible.
When privilege becomes precise, blast radius shrinks.
When control is continuous rather than periodic, audit response improves.
This is not simply better security architecture. It is smarter business architecture - enabling organizations to move faster without surrendering control.
Too often, the market still treats governance, privilege, non-human identity, and AI security as separate challenges solved by separate tools.
The enterprise does not experience risk that way.
A compromised service account, an over-privileged cloud role, a stale certificate, or an unchecked AI agent all point to the same underlying issue: trust has been extended further than control.
That is the conversation I will be bringing to CyberArk IMPACT this year.
This session is not about fear or hype. It is about how the threat landscape is redefining trust - and what security leaders must do now to govern privilege across human identities, machine identities, and autonomous systems.
Because the organizations that succeed will not be the ones that accumulate more controls.
They will be the ones that learn how to turn trust into a strategic asset.
David (DJ) Morimanno is the Field CTO at Xalient, where he helps organisations design and deliver identity-centric security strategies for complex, fast-evolving environments. With over 20 years of experience, he brings deep expertise across identity governance, privileged access, access management, and broader identity security programs. As a practitioner, advisor and strategist, he supports clients in translating identity into practical, scalable capabilities.
His work focuses on modern identity challenges, including non-human and machine identities, AI governance, cloud entitlements, identity threat detection and response, and Zero Trust. DJ advises senior leaders and Fortune 500 organisations across sectors such as energy, healthcare, manufacturing, and financial services, helping them turn emerging trends into clear operating models and measurable security outcomes.