Podcast: Play in new window | Download
Subscribe: Apple Podcasts | RSS
Think about every account you’ve ever created and then forgotten about. A login for a gym you canceled two years ago. A free trial you signed up for and never used again. A vendor portal from a job you left. Nobody deletes those things, and nobody circles back to check whether they still work. Now multiply that across every employee at a mid-size company, running for ten or fifteen years, and you’ve got a rough picture of what most identity and security teams were already dealing with before AI showed up.
Roy Katmor, co-founder and CEO of Orchid Security, joins me on this episode of the TechSpective Podcast to talk about exactly that problem, and what happens to it once AI agents get involved. He calls the invisible, unaccounted-for slice of it “identity dark matter” — the accounts, agents, and access grants that exist on a network but stay invisible to the tools meant to track them.
The Old Sprawl Moved at Human Speed
That slowness bought people time. Shadow IT and orphaned service accounts piled up over years, not days, which gave security and compliance teams a fighting chance to run periodic access reviews, dig through the logs, and clean out what they found. It was never a good system, ask anyone who has sat through a 700-line spreadsheet asking whether a given employee still needs access to a given application. But it worked on the timeline that mattered, because the sprawl itself grew slowly enough for people to catch up to it eventually.
Agents Don’t Wait for a Ticket
AI agents broke that timeline. An agent can be created, granted access to a handful of internal systems, and put to work in the time it takes to write a prompt. It doesn’t file a request with IT. It doesn’t sit in an approval queue. And once it’s running, it can turn around and hand off a slice of its own access to a second agent that needs a piece of data it doesn’t have, without anyone signing off on that handoff either. What used to take an organization years to accumulate can now happen in an afternoon, in a dozen departments at once, with nobody in any one of them aware of what the others just built.
Somebody Still Owns What the Agent Does
None of this access shows up out of nowhere, though. A person built the agent, gave it a task, and pointed it at a set of systems, even if that person has since forgotten doing it or left the company entirely. Nobody’s really figured out yet who’s accountable for what an agent does months or years after the person who created it has moved on. “You needed to get your stuff together,” Katmor told me, describing what happens when nobody’s kept a record of who authorized what in the first place. That’s the kind of problem that stays cheap right up until the day it isn’t.
Katmor and I get into how identity dark matter piles up, what it actually takes to find it, and what changes once AI agents start delegating access to each other without anyone signing off.
Watch or listen to the full episode of the TechSpective Podcast to hear the whole conversation.
- Your AI Agents Are Multiplying and Nobody’s Counting - August 26, 2026
- Third-Party Risk Programs Have Plenty of Data and No Way to Measure It - August 24, 2026
- The Attack That Turns Your AI Agent Into A Weapon Against You - August 20, 2026