Your 2027 AI budget may include new security tools, changes to existing applications and more time from the teams that govern access. The order of those investments depends on what your AI use cases can do and how well your current IAM capabilities control them.
An IAM Maturity Assessment can change the identity and access portion of that budget. It can show which gaps need attention first, where existing systems need work and which responsibilities require ongoing funding.
Many security leaders are still unsure which AI agents they have and what those agents can do. In Okta’s 2026 survey of 306 security leaders, 47% said they were confident they could identify all AI agents in their environment.
Confidence in controlling what agents could access was 46%; confidence in authorising their actions was 45%. These are reported levels of confidence, rather than results of technical testing. Your budget decision needs to account for the agents and controls in your own organisation.
Begin with what each AI use case can do
An assistant that retrieves policy documents raises a question about document access: can the person making the request see every document the assistant retrieves? In one published Auth0 implementation, Fine-Grained Authorization filters retrieved documents against the user’s permissions before passing them to the model.
An agent that updates supplier records raises further questions. Which identity does it use? Who authorised the change? Are its permissions limited to the approved actions? Does a person need to approve a sensitive change before it happens?
NIST’s February 2026 draft concept paper raises questions about agent identification, delegated authority, authorisation and auditing. NIST is asking for feedback on how to address them. Its proposed project concerns action-taking agentic systems and excludes retrieval-only architectures.
Start with AI use cases already in production and those planned for 2027. For each one, record its purpose, business sponsor, connected systems, data access, permitted actions and authentication method. An agent that can already make consequential changes may need an access review now, alongside the wider budget exercise.
Pay particular attention to whose authority an agent uses. It may have its own identity, act on behalf of a user or rely on an existing service account. Auth0 Token Vault, for example, lets an agent obtain a token for an external API on a user’s behalf without storing that provider’s long-lived refresh token in the agent. The organisation still needs to decide how the agent’s actions are authorised, approved where necessary and recorded.
Assess the capabilities behind that access
Our IAM Maturity Assessment examines policies, processes, technology and governance. It identifies existing capabilities with your teams, compares them with required capabilities and evaluates possible responses at a high level. Agree which AI use cases and identity questions should be included in the assessment scope.
Four capability areas can then inform the funding discussion:

A product feature can support one part of this work. SailPoint Agent Identity Security, for example, allows a primary human owner and additional owners to be assigned to an AI agent. If the primary owner becomes inactive, ownership passes to the first active additional owner. The business still needs a process for reviewing the agent’s purpose and access over time.
The assessment identifies capability gaps and possible responses. An exhaustive agent inventory, detailed permission analysis or live control test would need its own technical scope.
Let the findings change the funding order
Consider three different findings:
- Agents lack consistent registration or ownership. An intake and sponsorship process may need funding before the organisation can rely on regular access reviews. Technical discovery may also be needed to establish where agents already have production access.
- Agents are known but use shared accounts or broad permissions. Identity and access design moves up the list. That work may involve IAM, application and API teams using systems the organisation already has.
- Ownership and permissions are defined, but consequential actions cannot be reviewed or access withdrawn quickly enough. Funding shifts towards evidence, approval and response processes.
Rank proposed work against the impact of each agent’s permitted actions, the size of the current control gap, its production date and the dependencies needed to make the change. This gives CISOs a reason for the investment order and CTOs a view of the teams and systems required to deliver it.
A budget line should be specific enough to review. For example: an agent that updates supplier records uses a broadly privileged shared account. The proposed work might include a defined identity and access path, narrower API permissions, approval for sensitive changes and action logging. Name the IAM and application owners, estimate the initial design and integration work, and include recurring access reviews. Specify how the teams will check that a change can be attributed to the agent and its authority, and that access can be withdrawn within an agreed time.
Include the cost of operating the controls
Agent access will need people to approve it, review it and respond when something goes wrong. Those responsibilities belong in the funding request alongside integration and implementation costs.
ENISA’s 2025 survey of 1,080 organisations in high-criticality sectors found cybersecurity spending shifting towards technology and outsourced services, while organisations continued to report difficulty attracting and retaining security staff. The findings concern cybersecurity investment broadly, but they reinforce a practical budgeting question: who will run the controls after implementation?
For each proposed initiative, record the business use case, accountable team, initial work, recurring work and measure of progress. Keep the measures precise. Registration coverage across named platforms needs a defined population of agents on those platforms. Ownership among registered agents is a separate measure. Permission review completion and the time taken to withdraw access can show whether the processes work in practice.
Cloudcomputing’s IAM Maturity Assessment produces a strategic alignment matrix, a map of existing capabilities, a gap analysis, high-level resolution options and an implementation plan with reference costs for market solutions. Bring the AI use cases already in operation and those planned for 2027 to the scoping discussion.
Together, we can establish which identity decisions the assessment should inform and where further discovery or testing is needed.
Your 2027 budget can then put each IAM investment against a defined use case, a documented gap and the work required to address it.