When AI Agents Inherit Your Identity Dark Matter
Enterprises can see less of their identity environment every year, and agentic AI is about to make it dramatically worse. Roy Katmor, CEO and Co-Founder of Orchid Security, joins Alan Shimel on Techstrong TV to walk through Orchid’s 2026 Identity Gap report — a snapshot of what they call the “identity dark matter” hiding inside modern enterprises. Only 57% of enterprise applications are actually visible to a central identity provider, 67% of non-human identities authenticate locally outside any IdP, 40% of accounts are orphaned, and 70% of apps carry excessive privilege. Now layer on agentic AI — fast, improvising, and acting on behalf of humans and services — and the traditional “who has access” question collapses. Roy explains why identity has to move from static entitlements to continuous, intent-aware delegation, and how Orchid’s identity orchestration and control plane is built to operationalize that across humans, non-humans, and AI agents.
Transcript
Hey everyone, welcome back here to Techstrong TV. I haven't had my next guest on, I think the last time he was here, they said it was February. It seems even longer.
Time dilates in these AI era. Let me introduce you to Roy Katmor, or reintroduce you to Roy Katmor. Roy is the co-founder and CEO of Orchid Security.
Roy, welcome back to Techstrong TV. Man, it's good to see you. Same here.
Thanks for having me. Ah, my pleasure. So Roy, I don't know, I'm sure everyone saw the last time you were on, but just in case there are a few stragglers out there who didn't see you the last time you were on Techstrong TV, give people a sense of your journey.
Absolutely. I came from the software side. More than 20 years in security.
Did almost everything in the network. Continued with another company at the endpoint. Worked corp, worked the small startups, and now again back to the trenches with Orchid as the identity orchestration and control plane for identity company.
But always happy to be back in the smaller teams. Absolutely. I'm a startup person myself, so I hear you.
So Roy, when did you launch Orchid? Orchid was founded in January 2024. We're a two and a half years old company, almost 70 people today.
A lot of it came from an ideation, so a company that actually grew straight from the market, with the market, for the market. So, two and a half years old, still young and kicking. Absolutely.
You're just getting started. But Roy, at two and a half, you guys already saw AI on the horizon. Right?
I guess my question is, did you see the rise of agentic AI rather than generative AI? And then, of course, what that would mean in terms of identity. Absolutely.
When we started, just to go back on the ideation process of Orchid, which stands for Orchestration of Identity, the point was that identity, as opposed to others, has an onboarding process to it. Which means if you buy an identity solution, and I'll give you a day-to-day example. When you're trying to log into the bank, and you're getting the six digits, that it's a little memory game for you to see if you can actually pull it together and put it in your browser.
Think what it meant for the bank to do this. It actually meant three things for them. It meant that they knew that there is an app out there that can authenticate customers.
It meant that they knew that there is an authentication flow, and there are more than one, I promise you that. And they also knew to integrate that course with the vendor that actually sent you that password. That created what we like to call, or we coined, the identity dark matter.
Those applications that you were not aware of, those authentication flow tokens and others that you were not aware of or didn't have the right ROI to integrate. And of course, the non-integrated, which means you're doing it locally, and that created the gap. And we knew this from day one.
" And in 2025, when we did the gap, the first gap analysis, we showed that only 57% of the enterprise identity are actually visible to the organization. In 2026, we showed 57%. And how all of these data, so onboarding created fragmentation, has to do with AI.
If in the years before, the drivers to actually accommodate those identity dark matter was compliance and security, we knew from day one that if you will try to put an agent who is very efficient and doesn't want to interact with you in the sake of autonomous, it's going to create a mess. It's going to create a mess because it's going to use that dark matter, and that's, I think, what you're going to find in the 2026. An advantage of actually starting a company in 2024 is double.
One, because we use a lot of agents ourselves to find, to be able to accelerate our internal development, and actually make them available for customers to be able to remediate things on their end. But also, the other side of the coin of this is, how would an enterprise use those agent AIs or agentics? There are many of those.
We knew it's going to be a chaos, and I think the 2026 Identity Gap report shows how it actually comes to play. And what do we see, and why is it actually a multiplier for the problem of the dark matter? Agreed.
Before we go further, though, you gave a little history there on Orchid Orchestration ID. For people who want to just go jump on the site, what's the website? security.
security. Wasn't a hidden question or a loaded question. I just wanted to get it out there for people.
Now, Roy, you kind of jumped into it already, but you guys have been, in addition to having both feet and both hands in the market, you've been doing surveys now and research pretty much continuouslyYou have a new report out for 2026, though, and you started giving us some of the stats on it. But let's step back and step up a little bit. What's the purpose of-- What was some of the goals for this year's report?
What were you looking for? As I mentioned, we started a company because we understood that there is an infrastructure issue with identity that does not exist, now you know my background, does not exist in network or endpoint. If you want to do something on Alan's computer, I'm going to push something with usual, I would say, tools that distributes it across the enterprise, and they're going to work.
I'm not going to ask Alan to do anything for me. In identity, as I mentioned, you need to onboard, which makes it, you do what you know. You're obviously not going to do what you don't.
And we wanted to see what drives this identity dark matter across the years, and how does the non-human, which is not just the service account and bots, and which are now in a very high ratio comparing to the workforce. We wanted to see now that everybody's talking AI agents, and wanted to see how this new actor, who is just yet another non-human, but it's interesting because it acts differently. So before, we had humans, we were, I would say, improvising.
But very slow on the actions. You still need to type things. And we had the non-human in its traditional fashion of bots and services and machines, who were, I would say, worked very fast, but were very deterministic and bounded to code.
Now we got a newcomer who is an agent AI that is kind of a hybrid. It's, on the one hand, it's very fast, but it will improvise. And we wanted to see if this improvisation, how does that actually affect the dark matter?
And we got our answers. So what did we see in this Ident 2026 report that was not in the 2025? Bearing in mind what our thesis as the company was, there is an identity dark matter.
Now there is a multiplier to that problem that is not only now driving compliance and security, it also now driven by an abuser. Again, not out of malicious, out of efficient, and see how our readiness got impact, and the identity gap snapshot actually shows that we see less year over year, which means there's more and more pieces of visibility that we cannot see anymore. We see that the non-human, 67% of it, is actually created indirectly within the apps.
We do not see that. So they're not being sent outside. They're not creating audit that is centralized.
We're not aware of those. And 70% of those apps are excessive privilege accounts. That means we see less.
They're more privileged, and they're more non-human, which all of it makes a lot of sense when you see the data, and it's really what we thought. We want to see how fast it goes. And from my forecast, 2027 is going to continue that.
And that is exactly the point that we want to make, and that's, I'm sure we're going to talk more about Orchid and what Orchid does about that. But that's the trend, and that's what we think we're going to continue seeing in the future. I think the other thing on it, too, that doesn't make it urgent, but really compounds it, is what I call AI scale.
Right? It's one thing to track every person in an organization. It's another thing to say, okay, every person has an agent, so we just doubled the identities I got to track.
When you could have up to 100 agents a person, well, the scale of the problem just went off the charts. And a solution that worked for humans or early machine-type identities doesn't scale to a full-on agentic workforce. And that is going to really, for identity solutions that were built for a previous to agentic era, it's over.
I don't know if you could just scale up without redesigning your whole app. You need applications that were built for that kind of scale. And that brings me to Orchid, right?
You're only two and a half years old. So you were built with this in mind. Let's talk about how can Orchid help?
Orchid was built to be in, if I need to give a very short pitch of it, and continuing with the onboarding identity dark matter, now with a multiplier of AI, Orchid was built in a way that will be able to operationalize enterprise identity. What does that even mean? Think about it.
What did we just say? We said, like, "Look, Alan, we see less and less every year. We see more and more non-human every year.
We see more privilege," which makes sense. We see more AIs, and they need to do more on behalf of ours, on behalf of our services, on behalf of humans. And all of it changes the entire identity space in a way of what?
Think about it. " That was the question. Now, isDifferent questions.
It's the why, it's the what authority is delegated, who is working on behalf of who, right? Under what condition? What is the blast radius, and why is it this way?
How much risk does it hold in store? And where are these guys going on? Because they are abusing the dark matter, which is the majority of our environment.
And so think about it. If you were a CISO today, think how operationalizing identity meets you in the day-to-day. I'm going to ask you a question.
You just bought a PAM solution, a privilege access management, and the first question, you bought the shiniest armor out there. " "Great. " You know what the answer is going to be.
" Why? "I don't see 57% visibility of my environment. " Or go to IT, go to the immediate suspects, right, to the DevOps, go to the IT- Mm-hmm ...
people and put some executive that are careless, right? That is not an answer. That is a good guess at the best.
Think about it. You bought the best IGA, identity governance administration. They're going to say, "Oh, great.
" And, "We need to do a workflow for authorization. " Onboard who? " Mostly used.
That doesn't mean exposability. That doesn't mean hygiene. That doesn't mean- No ...
privilege level. That doesn't mean anything. The fact that you're aware doesn't make them the immediate suspect.
So, as I mentioned, the AI readiness and delegation authority have moving from the static of who has to the continuous of what authority is delegated. Under what conditions is it? On behalf of who are you working, and what is the intent of you trying to do?
That becomes your day-to-day, and that becomes completely dynamic per the request. Not anymore as a static rule of who has the most privileges. We're not selling them by the weight.
We're selling them by the business context of where you're about to do, and what are you about. What is your intent when you're asking for that? And who are you, after all?
Don't forget, Ellen is not Ellen anymore. Ellen could be Ellen who's running on his behalf an agent that has ran on his behalf another agent. That is the reality.
Agreed. Agreed. Roy, we're running low on time, but for people who want to grab, well, two things.
Number one, you guys are going to be at Identiverse. When's it, next week? This week?
Next week. Next week. But the report's already out.
People can get to the full report? security. You can find it.
You can see the trends. You can figure out how we do, how do we operationalize, how can you ask us any type of question, like you're going to ChatGPT, and we can do this with a full data sovereign. And how can we fix it with your own solutions and within our solutions, and govern and provide you a full control plane that is completely good for humans, good for non-humans, definitely can govern AI out of the box.
And all of it going back to the origin, to the source, the humans, the machines, and the AI, wherever they work, governed or ungoverned, in one place, so you can make informed decisions, and on the spot, and even better with us. Love it. " Are you guys going to be at Black Hat, maybe?
We'll be in Black Hat as well, of course. Maybe we'll see you in person there. Sounds like a plan.
Thank you, Ellen, as always. Pleasure is all mine. All right, my friend.
Roy Katmor, co-founder, CEO, Orchid Security, with their new report on identity. They'll be at- Identiverse ... Identiverse next week.
Check it out. security right now to get the report. We're going to take a break.
We'll be back in a moment.