What 20 Fortune 500 IAM Leadership Titles Reveal About the Agent Authorization Gap
Identity and access management has grown up inside the Fortune 500. The function now reports through global heads, corporate vice presidents, and chiefs of staff, and it has split into specialized lanes for cloud, privileged access, and customer identity. Yet across twenty of these senior leaders, one problem fits no existing job description: deciding what an AI agent may do at the moment it acts. Gartner has named policy-driven authorization for machine actors a security priority for 2026. For CISOs and identity architects in regulated industries, the open question is who owns that decision before an agent with standing access makes it for them.
Look at how large enterprises staff identity today and a pattern shows up fast. The people who run access at AIG, Vanguard, MetLife, Goldman Sachs, and Cigna carry senior titles that did not exist a decade ago:
- Srinath Chigullapalli at Vanguard
- Christopher Nawrocki at New York Life
- Arturo Cordoba at MetLife
- Stephen Washington at Cargill
- Rakesh Sankannavar at Vanguard
- Sean Hayes at Vanguard
- Matthew Weinberg at Cigna
- Vineet Makhija at BMO
- Balu Arumugam at CVS Health
- Jim Marsden at Liberty Mutual
- Jason Abrahamson at CVS Health
- Mary Eranackal at Airbus
- Leila Abadie at Airbus
- Patrick Rogge at Deutsche Bank
- Haley Denton at AIG
- Rohit Singla at AIG
- Jonathan Root at MetLife
- Mikolaj Maciejak at Goldman Sachs
- Ryan Convy at BMO
So the discipline has matured. It has specialized, climbed the org chart, and moved into security operations. But the newest access problem, the one agentic AI introduces, does not map cleanly onto any of these charters. The gap is worth walking through.
Identity Became an Executive Job

A decade ago, access administration sat several layers below the CISO. Now it reports at the officer level:
- Srinath Chigullapalli holds the title of Principal and Global Head of Identity and Access Management at Vanguard.
- Christopher Nawrocki is a Corporate Vice President of IAM at New York Life.
- At MetLife, Arturo Cordoba runs IAM strategy and business enablement as a chief of staff.
- Stephen Washington is Global Head of IAM at Cargill.
The pattern says something about how these organizations now weigh access. When a bank or an insurer gives identity a global head, it treats authorization as a board-relevant control, not a helpdesk queue.
For a CISO under active regulatory supervision, the reason is practical: the audit committee wants a clean answer to who can access what, why, and under what conditions. Someone senior has to own that answer. So the title climbs.
And the climb changes what these leaders buy. An officer-level owner evaluates authorization as an enterprise control plane, with audit defensibility and consolidation in view, not as a point tool for one application. Keep that lens in mind as the other shifts come into focus.
The Function Split Into Specialized Lanes

As identity grew, it also divided. One leader no longer covers the whole surface:
- At Vanguard, Rakesh Sankannavar owns cloud IAM and privileged access, while Sean Hayes runs risk, control, and governance for the same function.
- Matthew Weinberg leads customer identity and access management at Cigna.
- Vineet Makhija owns IAM controls and governance inside BMO’s financial crimes unit.
- Balu Arumugam heads IAM architecture, engineering, and operations at CVS Health.
Each of those titles marks a discipline that used to be one line on a job description. Privileged access became its own program. Customer identity separated from workforce identity. Governance split from engineering.
The question this raises for an architect is coverage: when four leaders own four slices of access, how do you keep one policy model across all of them? Fragmented authorization logic, hard-coded into each application, is the audit nightmare regulated teams already know well.
Specialization creates a second-order need: a common policy language that spans the lanes. Hold that thought, because agentic AI will test it directly.
Identity Moved Inside Security Operations

The wall between identity and security has largely come down. Access is now a security-operations concern, and the titles show it:
- Jim Marsden leads IAM within global cybersecurity at Liberty Mutual.
- Jason Abrahamson runs IAM and cybersecurity operations at CVS Health.
- At Airbus, Mary Eranackal heads cybersecurity for identity, and Leila Abadie leads IAM overall.
- Patrick Rogge pairs IAM subject-matter ownership with a divisional information-security-officer role at Deutsche Bank.
The message is consistent: identity leaders now sit inside the security organization, accountable for threat exposure, not only for provisioning and recertification.
For these leaders, an access decision is a security decision. Over-provisioned identities are attack paths. A credential with standing privilege is a liability waiting for an incident. Bessemer’s read on the market captures the fear plainly: most agents today inherit broad permissions with no zero-trust boundaries.
So the people who run identity are already thinking like defenders. And a defender’s first question about any new actor is simple: what is it allowed to do, and who decided that?
Regulated Sectors Built Deep Identity Benches

In the most regulated industries, identity is not one leader. It is a bench:
- AIG fields multiple vice presidents of IAM, including Haley Denton and Rohit Singla.
- MetLife carries an assistant vice president for enterprise IAM in Jonathan Root, plus a row of identity directors.
- Goldman Sachs runs core IAM services under a vice president and executive director, Mikolaj Maciejak.
- Ryan Convy heads enterprise IAM at BMO.
Depth like that is a signal. Banks, insurers, and health payers do not staff five senior identity roles unless access control carries material compliance weight.
The driver is regulation. Frameworks such as DORA put ICT risk controls under active supervision, with reporting timelines measured in hours. When a regulator asks who could access a system and under what conditions, the answer cannot take three weeks of evidence gathering.
The benches exist to make access defensible on demand. And every new identity type that enters the estate, human, non-human, or agent, lands on their desk. Which brings the story to the newest arrival.
The Leaders Already See the Agent Problem Coming
The senior identity community is not waiting to be told about agentic AI. Several of these leaders are already naming the shift, including Srinath Chigullapalli of Vanguard who has discussed security modernization on a public stage and taken part in executive conversations on where AI actually returns value.
The concern they are circling is specific: an AI agent acts on a user’s behalf. It reads a prompt, retrieves data, calls tools, and generates a response. Every one of those steps is an access event.
For an identity leader, an agent is a new kind of identity with real reach and weak boundaries. It authenticates with legitimate credentials, so it looks trusted. Then it moves.
Martin Sandren, who leads identity and access management at IKEA, put the shift plainly on the Identity at the Center podcast, recorded at the 2026 European Identity and Cloud Conference. He relayed a financial institution’s goal of one general rule so an agent could never move large sums to a sanctioned country, a control aimed at what the agent does, one that weighs intent at the moment it acts. In his read, agents could become “the compelling event that really breaks through policy based access.” And a policy that resolves at runtime, weighing the human, the agent, the action, and the context together, is where authorization has to sit.
The leaders see the actor. What they lack is the control point built for it. The next section is where the gap sits.
The Access Decision No Current Charter Owns
One through-line connects all twenty leaders. Identity has become senior, specialized, security-aligned, and deep. Yet no existing charter cleanly owns the decision of what an AI agent may do in the moment it acts.
Gartner has put language to it, naming policy-driven authorization for machine actors a priority for 2026. The reason the old model falls short is mechanical. OWASP’s work on agentic threats makes the point that standard access controls do not block a misbehaving agent, because the agent uses valid credentials the whole time.
The Novo Nordisk breach showed the shape of the risk. Attackers moved through the environment using a machine credential nobody governed as an identity. They broke no perimeter. They carried valid credentials the whole way.
So authentication proves who the agent is. It does not decide what the agent should be allowed to retrieve, execute, or expose. The decision is authorization, and for agents it has to happen at runtime, with context and intent evaluated at the point of action.
PlainID provides runtime authorization across the full agent flow. The platform controls which prompts can proceed, which data an agent can retrieve, which tools it can call, and which sensitive elements to mask in the response. It binds the human identity to the agent identity, so both are evaluated together under a Zero Standing Privileges model.
Policies live in one control plane and enforce close to each system, including a native MCP Gateway and a LangChain integration that intercept tool calls in flight. Gartner has recognized PlainID as a representative vendor for agent identity and authorization management, and enterprise architects at Wells Fargo, Accenture, and Cisco use the platform in production.
Where Runtime Authorization Fits in Your Agent Plans
If your identity program already answers who can access what for humans and service accounts, agents are the next actor to bring under the same policy model. And they are arriving faster than the org chart is adapting.
PlainID sits downstream of your identity provider, so Okta, Ping, and Entra investments stay in place. The platform adds the runtime authorization layer the IdP does not provide, across applications, APIs, data, and agentic AI, under one policy language and one audit trail.
The value for a regulated enterprise is a defensible answer, on demand, to who can access what, why, and under what conditions, for humans, non-human identities, and AI agents alike.
Talk to PlainID about mapping your agent use cases to runtime authorization control points, and see the enforcement model against your own environment.