Alphabetical, not ranked. Membership includes primary and secondary research categories. These products have different scopes; inspect the evidence profile before comparing capabilities.
Also covers this layer
Apache-2.0 project from the Linux Foundation-hosted AGNTCY effort that issues and verifies identities for AI agents, MCP servers and multi-agent systems using verifiable credentials and badges, and can onboard existing identities from providers, A2A agent cards or W3C DIDs. Deployment and adoption maturity are unproven.
open_source · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate issuing a verifiable badge to an MCP server and having a relying agent verify it, including how revocation and key storage work.
Read sources and limitations →
Primary category
Capability of AppOmni's SaaS security platform that surfaces AI agents running inside connected SaaS tenants - such as Salesforce Agentforce, ServiceNow Now Assist and Microsoft 365 Copilot - including agents enabled without security review, with their declared tools, identities, permissions and over-privilege findings. Discovery depends on AppOmni's SaaS API connections.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate listing every Agentforce and Now Assist agent in our tenants, flagging which ones were enabled without approval and which hold write or destructive permissions.
Read sources and limitations →
Also covers this layer
Astrix discovers AI agents, MCP servers, service accounts, OAuth apps, API keys and other non-human identities across cloud, SaaS, CI/CD and vaults, maps each to a human owner in an identity graph, and applies agent policies plus onboarding and offboarding actions. Enforcement depth outside integrated platforms is unclear.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me the identity graph for one shadow agent — its NHIs, credentials, reachable resources and owner — then apply a policy that blocks it and offboard it.
Read sources and limitations →
Also covers this layer
BigID's AI-oriented module inside its data security platform. It inventories AI models, agents, copilots, prompts, vector stores and pipelines, classifies the data feeding training, retrieval and inference, and maps lineage of that data. Claims come from vendor product pages; BigID's technical documentation is not publicly reachable.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate how BigID builds an AI asset inventory that links a vector database to the sensitive datasets embedded in it and the identities allowed to query it.
Read sources and limitations →
Primary category
Registry and monitoring console within Boomi Agentstudio where organisations register, tag, monitor and manage AI agents across providers - agents built in Boomi and third-party environments such as Amazon Bedrock - via configured provider connections. Agents appear because a provider account is connected, so unconnected environments remain invisible.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me registering an Amazon Bedrock provider account and then disabling one of its agents directly from Agent Control Tower, including the trust level and tags applied.
Read sources and limitations →
Also covers this layer
Runtime protection for AI agents that inspects prompts, reference material, tool responses and tool descriptions for injections and manipulation, applies tool allow and deny lists, and flags actions outside an agent's mandate. Also builds an inventory of agents and connected MCP servers across supported agent platforms.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me Check Point AI Guardrails detecting an injection hidden in a tool response and blocking the resulting tool call, plus the agent inventory entry for that agent's MCP servers.
Read sources and limitations →
Primary category
Capability inside Checkmarx One that inventories AI components by scanning source code and configuration files in connected repositories, cataloguing models, agents, MCP servers, AI libraries and SDKs on every commit, then emitting an AI-BOM and enforcing policy in pull requests and CI/CD. Scope is the software pipeline, not employee tool usage.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me an AI-BOM generated from one of our repositories listing every detected model, agent and MCP server with the file and commit where it was found.
Read sources and limitations →
Primary category
Open-source scanner from Cisco's AI Defense team that inspects codebases, container images and cloud environments to produce an AI bill of materials listing models, agents, tools, MCP servers and clients, datasets, prompts, guardrails and secrets. Detection is static analysis plus catalog matching, with optional LLM-based enrichment.
open_source · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate running the scanner against one of our Python repositories and a container image, and show the resulting AI-BOM entries for agents, tools and MCP servers.
Read sources and limitations →
Also covers this layer
Apache-2.0 gateway, registry and proxy from IBM that federates MCP servers, A2A agents and REST or gRPC APIs behind one endpoint, adding authentication, rate limiting, input validation and OpenTelemetry tracing. It centralises tool discovery for MCP clients but does not itself provide threat detection or sandboxed execution.
open_source · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me ContextForge federating two MCP servers plus a REST API behind one endpoint, with a user-scoped OAuth token and rate limit applied to one tool.
Read sources and limitations →
Also covers this layer
Governance workspace where an enterprise records AI use cases, models, agents and third-party AI vendors, runs questionnaire-driven reviews, and tracks control and risk libraries with task assignment. A Python/TypeScript SDK writes the same objects programmatically. Evidence reviewed covers workflow structure, not independent verification of governance outcomes.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me how a new agent use case moves from intake questionnaire through control review to a governance status a regulator-facing auditor could read.
Read sources and limitations →
Primary category
Telemetry-collection layer of CrowdStrike's AI Detection and Response product. Collectors capture AI activity from the Falcon sensor (browser extension plus network inspection of desktop AI apps and coding assistants), standalone browser extensions, application SDK calls, and supported API gateways. Browser collectors log detections in report-only mode for model responses.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate registering a Falcon endpoint collector and show which desktop AI applications and coding assistants network inspection surfaced that the browser extension missed.
Read sources and limitations →
Primary category
Application-security capability that discovers AI assets across the software development lifecycle - AI infrastructure, models, coding assistants, packages and associated secrets - by scanning connected repositories and pipeline systems, then producing an AI bill of materials for governance. Buyer is AppSec; it does not observe business users' AI tool usage.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate discovering which AI coding assistants and third-party models our developers introduced last quarter, and show the AIBOM entry with the repository and secret associations.
Read sources and limitations →
Also covers this layer
Cyera's AI-focused extension of its data security posture platform. Its AI-SPM capability inventories AI models, applications, agents and knowledge bases including shadow AI, and links them to sensitive-data classifications produced by the underlying DSPM engine. Runtime protection is described at product level without public technical documentation.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me the live inventory of AI agents and knowledge bases Cyera discovered in my cloud accounts and which sensitive data classifications each one touches.
Read sources and limitations →
Also covers this layer
Entro inventories non-human identities, secrets and agentic AI deployments across cloud, code, CI/CD, on-prem and SaaS, links each agent to the NHIs, entitlements and secrets it uses and to a human owner, and monitors agent behaviour for anomalies through its NHIDR detection engine. Credential issuance is not part of the evidenced scope.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me an agent's NHI lineage — creator, secrets used, entitlements, resources touched — and a live NHIDR alert for anomalous agent behaviour.
Read sources and limitations →
Also covers this layer
GitGuardian's module for non-human identity secrets: the ggscout collector inventories secrets and metadata from secrets managers, CI and infrastructure, tracks consumers, rotation dates and permissions, and flags stale or over-privileged credentials. It governs credentials used by machines and agents rather than issuing agent identities.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me every secret outside our vaults, who consumes it, when it was last rotated, and the semi-automated rotation workflow for an over-privileged NHI secret.
Read sources and limitations →
Primary category
Centralized catalog in Gemini Enterprise Agent Platform for registering and governing AI agents, MCP servers, skills and endpoints. Agents can be registered automatically from supported runtimes or manually for custom deployments, and consumers can search the catalog and authenticate to registered tools. It governs registered assets; unregistered agents are out of scope.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me an ADK agent auto-registered from its runtime, then demonstrate searching the registry and binding it to an authenticated endpoint.
Read sources and limitations →
Primary category
Browser-extension product that inventories employee AI usage by monitoring in-browser web traffic: which AI applications are used, whether the session uses a personal or corporate account, embedded AI features in sanctioned SaaS, and AI browsers. It also nudges or blocks sensitive prompt content. Coverage stops where the managed browser does.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me a report distinguishing employees using ChatGPT on personal free accounts from those on our enterprise SSO tenant, and how the extension captured that distinction.
Read sources and limitations →
Also covers this layer
Enterprise platform that inventories AI systems, models, agents and pipelines, then rates each system across risk verticals such as bias, robustness, privacy and transparency on a traffic-light dashboard. Marketed for internal builds and procured AI. Risk ratings are vendor-defined scores, not audits or certifications.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate how a procured third-party model gets an inherent-risk rating and what evidence sits behind the red-amber-green score.
Read sources and limitations →
Also covers this layer
The agentic module of Idira, Palo Alto Networks' identity security platform built on acquired CyberArk technology. It scans SaaS, cloud and developer environments for active agents, enriches them with ownership and permission context, brokers task-scoped access through an agent identity broker and logs agent actions for audit.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me agents discovered across our SaaS and cloud estate with owner and permission context, then a task-scoped grant issued and revoked by the agent identity broker.
Read sources and limitations →
Also covers this layer
KPMG's multi-disciplinary AI governance service suite built on its Trusted AI framework, spanning AI risk assessment, AI systems inventory, governance and policy implementation, AI security and privacy, system cards, and an AI Assurance line offering model validation and independent attestation against defined frameworks such as SOC and HITRUST.
service · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me an AI assurance and attestation engagement scope for an agentic workflow, including which framework you attest against and what the resulting report covers.
Read sources and limitations →
Primary category
Admin control plane for AI agents in Microsoft 365. Its registry lists Microsoft, partner-built, org-published and user-shared agents available to a tenant, and a preview Shadow AI view detects unapproved local agents on managed devices using Defender for Endpoint, with extra usage metadata from Global Secure Access. Registry coverage is Microsoft-ecosystem centric.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate the Shadow AI page detecting an unapproved local agent on a Defender-enrolled device and show which governance action removes its access.
Read sources and limitations →
Also covers this layer
Microsoft's extension of Entra ID that creates dedicated directory identities for AI agents, built from reusable agent identity blueprints, so agents authenticate with their own credentials and are governed by Conditional Access, lifecycle and cleanup workflows. Evidence covers Microsoft-centric estates; cross-vendor agent coverage is not established.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me how you create an agent identity from a blueprint, bind it to a sponsor and owner, and enforce Conditional Access on that agent's token request.
Read sources and limitations →
Also covers this layer
Microsoft's Purview module that reports on how organizational data is used by Copilot experiences, agents and third-party AI sites, surfaces oversharing risk, and applies ready-made data-loss policies to AI prompts. Coverage of non-Microsoft AI sites depends on device onboarding and a browser extension, so unmanaged endpoints stay invisible.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me the Apps and agents dashboard listing every agent in my tenant, the sensitive data each one accessed, and which Purview policy protected it.
Read sources and limitations →
Also covers this layer
Model and AI lifecycle governance software that maintains a searchable inventory of ML models, generative AI, agents, vendor tools and embedded SaaS AI, routes intake through policy-driven workflows, and maps controls to regulations including SR 11-7, the EU AI Act, NIST AI RMF and ISO 42001.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me a policy-driven workflow blocking a non-compliant model promotion, with the control mapping and captured sign-off evidence.
Read sources and limitations →
Primary category
Module of Netskope One AI Security that discovers AI assets - corporate or personal, managed or shadow, cloud or on-premises - from the vendor's SSE/proxy vantage point and maps them to the identities, data stores and tools they connect to, adding risk correlation and response. Discovery leans on traffic and platform telemetry rather than code scanning.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me the asset-to-identity-to-data-store map for a shadow AI application discovered from our traffic, including any MCP servers it reaches.
Read sources and limitations →
Also covers this layer
Barcelona-based platform combining an agent gateway (TrustGate) with runtime protection over the models, tools, MCP servers and data agents touch. Documented gateway behaviour includes per-user and per-tool RBAC, end-user identity forwarding across hops and cryptographic audit trails, with SaaS, hybrid and air-gapped deployment options.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me TrustGate forwarding end-user identity through two agent hops while denying a payments API tool for that user, plus the cryptographic audit record of each tool call.
Read sources and limitations →
Also covers this layer
Platform that inventories agents, MCP servers, skills and models across endpoints, SaaS agent builders and homegrown AI stacks, maps each agent's permissions and data access, red teams them before production, and evaluates runtime actions to alert, block, mask data or route to a human. Claims rest on vendor pages.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me Noma discovering an unapproved MCP server on a developer laptop, mapping its blast radius, and then routing a risky agent action to a human for approval.
Read sources and limitations →
Primary category
Research-preview capability of Nudge Security that inventories AI agents employees create on platforms such as Copilot Studio, Agentforce, Gemini, OpenAI, n8n, ServiceNow, Databricks, Workato and Tines, surfacing creator, permissions, connected data and MCP connections. Nudge's discovery approach centres on corporate email signals and OAuth grants.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate discovering an n8n or Copilot Studio agent an employee built last week, showing the creator, its OAuth grants, and any unauthenticated MCP connection.
Read sources and limitations →
Primary category
Module of Obsidian's SaaS security platform that builds a continuously updated inventory of AI tools and agents by combining a managed browser extension, API integrations into SaaS tenants, and mapping of agent-to-MCP connections. Aimed at security teams; agent coverage depends on which SaaS tenants and endpoints are instrumented.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me an agent discovered only by your browser extension that never appeared in the SaaS platform's own API-reported agent list, with its creator, permissions, and MCP connections.
Read sources and limitations →
Also covers this layer
Okta's agent-focused offering that discovers known and shadow AI agents, registers them as identities in Universal Directory with a human owner, and brokers short-lived credentials plus secret vaulting for agent access. Discovery evidence in its posture-management documentation is limited to specific connected agent platforms.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me an unmanaged Salesforce Agentforce agent discovered via OAuth consent grants, then register it in Universal Directory with an owner and issue it a short-lived credential.
Read sources and limitations →
Also covers this layer
AI-specific module of OneTrust's privacy and governance suite: central inventory of AI systems, models, datasets, agents and vendors with use-case intake and approval workflows, risk tiering, impact assessments and policy-driven controls intended to produce audit-ready records for security and governance teams.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me the AI use-case intake and approval workflow end to end, and which evidence OneTrust captures automatically versus manually.
Read sources and limitations →
Primary category
SASE-delivered product that identifies which generative AI applications employees are using by matching network traffic against a maintained dictionary of GenAI apps grouped into predefined use cases, then applying access-control and DLP policy. It discovers app usage, not internally built agents or AI components in code.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate the Insights dashboard showing the top GenAI apps by user and use case in our traffic, and how a new app appears once it is added to the app dictionary.
Read sources and limitations →
Also covers this layer
Israeli platform covering the AI agent lifecycle: cataloguing agents, models, prompts, MCP servers and coding agents through agentless integrations, then applying runtime guardrails that monitor prompts, tool calls and commands for prompt injection, tool poisoning and data exfiltration. Product claims come from vendor pages, not reference docs.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me Pillar validating that an agent's tool call matches its declared schema, flagging a permission-scope deviation, and blocking a poisoned instruction in an agent-to-agent handoff.
Read sources and limitations →
Also covers this layer
Part of SailPoint Identity Security Cloud, this module aggregates AI agents from AWS, Azure, GCP, Salesforce and Copilot Studio, onboards each as a registered identity with business and access context, and surfaces shadow AI usage. It complements SailPoint's separate machine identity module for service accounts, bots and RPAs.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me every AI agent aggregated from Copilot Studio and Salesforce, each registered with an owner and access context, plus the shadow AI usage report.
Read sources and limitations →
Also covers this layer
ServiceNow application that inventories AI agents, models and MCP servers as configuration items tied to the CMDB, with persona-based views for AI stewards, owners and risk/compliance users, and lifecycle plus risk and compliance oversight for platform customers already using ServiceNow.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate how a discovered third-party AI agent becomes a CMDB configuration item with owner, lineage and a risk assessment task for the AI steward.
Read sources and limitations →
Also covers this layer
Apache-2.0 command line scanner that discovers locally installed agent components — harnesses, MCP servers, skills — and checks tools, prompts and resources for prompt injection, tool poisoning, cross-origin escalation and tool changes, with a proxy mode that inspects live MCP traffic. Some checks call Snyk's hosted API.
open_source · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate scanning our developers' MCP configurations and show what a tool-poisoning and rug-pull finding looks like, plus which checks require the hosted API.
Read sources and limitations →
Primary category
AI-BOM and inventory module of the SPLX platform, now part of Zscaler. It connects to cloud platforms, code repositories and ML/AI platforms to detect LLMs in use, scan repositories to map agents, tools and MCP servers in AI workflows, and run risk assessments on discovered agents. Detection is scan-based, not user-traffic based.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me the agentic workflow map produced from scanning one of our repositories, including each agent, its tools, and the MCP servers it connects to.
Read sources and limitations →
Also covers this layer
Token Security continuously discovers AI agents and non-human identities across on-prem, hybrid and cloud estates, correlates agents, humans, secrets, permissions and data in an identity graph, enforces ownership and governs agents from creation through retirement, decommissioning orphaned identities. Credential issuance is not evidenced.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me a custom GPT agent discovered in our tenant, its owner and blast radius in the identity graph, and the workflow that decommissions it when the owner leaves.
Read sources and limitations →
Also covers this layer
Purpose-built system of record for AI intake: teams capture use cases, models, agents and vendors, get risk-based triage, run risk and impact assessments, track mitigations and incidents, and map to regulatory frameworks with curated risk taxonomies. Framework mappings are vendor-curated interpretations, not regulator-endorsed.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me the intake-to-approval path for a high-risk use case, including which curated framework mappings and audit evidence it produces.
Read sources and limitations →
Primary category
Part of Valence's SaaS security platform: it inventories sanctioned and unsanctioned SaaS and AI applications, and continuously identifies OAuth tokens, API keys, connected apps and service accounts linking business SaaS tenants to third-party AI tools. Detection is API-based against connected SaaS tenants, so unconnected apps stay invisible.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate how you surface an OAuth grant that connects an employee's unsanctioned AI tool to our Google Workspace tenant, including the scopes granted and the granting identity.
Read sources and limitations →
Also covers this layer
Veza's access graph labels non-human accounts across its integrations, shows their effective permissions, supports right-sizing and periodic review, and its agent-focused release maps unmanaged AI agents and service accounts to human owners and enumerates the tools an agent may invoke. Agent capabilities were described as early access.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me every tool and action an AI agent is authorized to invoke in a connected app, with the suggested human owner and a review campaign to revoke unused entitlements.
Read sources and limitations →
Primary category
Workday functional area for cataloguing and administering an organisation's AI agents - Workday's own and third-party - with dedicated security domains for agent management, agent compliance and agent reporting. It is a registry and administration layer configured per tenant; evidence reviewed does not show detection of agents outside what is registered.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate registering a third-party agent in ASOR and show the agent reporting and agent compliance views an auditor would rely on.
Read sources and limitations →