THE BUYER'S FIELD GUIDE

AI Agent Identity & Access Management Tools

Products that issue and manage identities and credentials for agents and other non-human principals, and govern their entitlements — least privilege, access reviews, delegated authorization and identity lifecycle.

32 related offerings · 19 primary listings · 13 overlapping listings

Product research snapshot September 6, 2026 · Editorial guide September 7, 2026 · Published by DutyGraph

When to explore this layer

Evaluate this layer when an agent needs an identity or credentials to reach company systems. Begin with the task and resource boundary. A person's broad account access should not automatically become the permissions of every agent they request.

ILLUSTRATIVE EVALUATION · NOT A CUSTOMER RESULT

Put a real task in the demonstration.

A fictional analyst needs an agent to read approved invoice records and prepare an exception list. Request read access to that bounded dataset, then attempt an update and access to a different team's data. Change the analyst's role and test revocation. Record where propagation is immediate and where a token may remain usable.

Questions to bring to the demonstration

  1. Is the agent linked to a responsible human and a specific delegation record?
  2. Can access be limited by action, resource, tenant and duration rather than a broad application role?
  3. How are credentials issued, rotated and revoked, including already-issued tokens?
  4. What happens to agent access when its owner leaves, changes role or loses an entitlement?

Evidence to request

  • An entitlement and resource-scope record
  • Allowed and denied access attempts
  • A lifecycle change with measured revocation behavior

Record what was demonstrated, what was only described, and what remains unknown. Preserve the product version, environment and date beside each observation.

Use the editable Markdown worksheet →

Where this layer stops

Authentication answers which identity is calling. It does not, by itself, explain why a business task was delegated or whether every requested action is appropriate. Runtime authorization and separation-of-duties decisions may live in other systems.

Connect it to the work

Discovery should produce the reason for access before credentials are requested. DutyGraph can describe proposed task boundaries; the connected identity and access systems must enforce actual permissions.

Read our perspective on the demand side of agents →

32 offerings to investigate

Alphabetical, not ranked. Membership includes primary and secondary research categories. These products have different scopes; inspect the evidence profile before comparing capabilities.

Primary category

1Password AI Agent Identity Kit

A developer kit layered on 1Password vaults and SDKs that gives a software agent a verifiable identity tied to a workload, issues short-lived agent tokens instead of shared API keys, scopes what the agent may access and links agent actions to audit trails. It sits within the broader 1Password Unified Access platform.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show an agent receiving a short-lived credential tied to its workload identity, using an approved secret without exposing it, and the audit trail linking the action to a user.

Read sources and limitations →

Primary category

Aembit Workload IAM

A workload identity and access platform that attests the client environment of a workload or AI agent, evaluates a policy at request time, then injects short-lived credentials into the outbound API call so the workload never stores a secret. Discovery and inventory of existing non-human identities is not evidenced.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate an AI agent obtaining a 15-minute credential through client attestation and policy evaluation, and show the access log for a denied request outside business hours.

Read sources and limitations →

Primary category

AGNTCY Identity

Apache-2.0 project from the Linux Foundation-hosted AGNTCY effort that issues and verifies identities for AI agents, MCP servers and multi-agent systems using verifiable credentials and badges, and can onboard existing identities from providers, A2A agent cards or W3C DIDs. Deployment and adoption maturity are unproven.

open_source · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate issuing a verifiable badge to an MCP server and having a relying agent verify it, including how revocation and key storage work.

Read sources and limitations →

Primary category

Akeyless SecretlessAI

Akeyless brokers AI agent connections through its Gateway so agents reach databases, SaaS, cloud services and legacy systems without receiving passwords, API keys or certificates; access is created on demand, scoped by policy, revoked afterwards and recorded in a central audit trail. Requires routing agent traffic through the Gateway.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate an MCP-based agent querying a production database through the Akeyless Gateway with no credential ever entering the agent's context, plus the audit record.

Read sources and limitations →

Also covers this layer

Amazon Bedrock AgentCore

AWS's set of composable services for running agents built with any framework, covering serverless execution with isolated sessions, persistent memory, a gateway that turns APIs into MCP tools, identity and credential management, and built-in observability. Documented governance is strongest on identity and authorization rather than approvals.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me an AgentCore Gateway exposing two Lambda tools where the agent's inbound and outbound authorization is verified per request through AgentCore Identity.

Read sources and limitations →

Also covers this layer

AppOmni Agent Inventory

Capability of AppOmni's SaaS security platform that surfaces AI agents running inside connected SaaS tenants - such as Salesforce Agentforce, ServiceNow Now Assist and Microsoft 365 Copilot - including agents enabled without security review, with their declared tools, identities, permissions and over-privilege findings. Discovery depends on AppOmni's SaaS API connections.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate listing every Agentforce and Now Assist agent in our tenants, flagging which ones were enabled without approval and which hold write or destructive permissions.

Read sources and limitations →

Also covers this layer

Arcade

Actions runtime that brokers agent tool calls to SaaS systems, handling OAuth and user token storage and applying per-action authorization so an agent acts within both the user's and its own scope. Pre- and post-tool-call hooks allow blocking or redaction, though the hosted tool catalogue is vendor-maintained.

hybrid · Research snapshot 2026-09-06

Ask for a demonstration
Show me an agent calling a Gmail tool through Arcade where the user consents via OAuth, a pre-tool-call hook blocks a send action, and the audit log records the decision.

Read sources and limitations →

Primary category

Astrix Agent Control Plane

Astrix discovers AI agents, MCP servers, service accounts, OAuth apps, API keys and other non-human identities across cloud, SaaS, CI/CD and vaults, maps each to a human owner in an identity graph, and applies agent policies plus onboarding and offboarding actions. Enforcement depth outside integrated platforms is unclear.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me the identity graph for one shadow agent — its NHIs, credentials, reachable resources and owner — then apply a policy that blocks it and offboard it.

Read sources and limitations →

Primary category

Auth0 Auth for GenAI (Token Vault & delegated authorization)

Developer-facing authorization service from Auth0 that lets an AI agent call first-party and third-party APIs on behalf of an authenticated user using OAuth scopes, with Token Vault obtaining, storing and refreshing external API tokens. It governs user-delegated agent access, not enterprise-wide agent inventory.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate an agent obtaining a Google and Slack token from Token Vault after user consent, and show what happens when the agent requests a scope the user never granted.

Read sources and limitations →

Primary category

Britive ARC (Agentic Runtime Control)

Britive registers each AI agent as its own identity with a human owner and permitted access profiles, authenticates it via SPIFFE SVID, OIDC federation or API tokens on every request, and grants just-in-time privileges that are created and destroyed per task so no standing credential remains. Cloud-target coverage varies.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Register an agent with an owner and job function, then show a just-in-time credential created for one task and destroyed at task end, with the access record.

Read sources and limitations →

Also covers this layer

Datawiza Agent Gateway

Identity-aware proxy positioned in front of MCP servers and APIs so that users and agents authenticate through an existing IdP before any tool call proceeds. Product material describes filtering tools/list discovery and gating tools/call invocation by policy; the fetched documentation site provides only high-level confirmation of that scope.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me Datawiza filtering the tools/list response for a low-privilege group and denying a tools/call write action after validating the Entra ID token claims.

Read sources and limitations →

Primary category

Descope Agentic Identity Hub

An identity provider for AI agents and MCP servers that registers OAuth clients (including dynamic client registration), records agentic identities created by user consent or tenant grants, and issues short-lived scoped credentials with policy-based access to protected APIs and MCP resources. Aimed at application builders rather than workforce IT.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me an autonomous agent registering via DCR, receiving a short-lived scoped token, and being denied an MCP tool call by an access policy — with the audit record.

Read sources and limitations →

Primary category

Entro Security NHI & Agentic AI Platform

Entro inventories non-human identities, secrets and agentic AI deployments across cloud, code, CI/CD, on-prem and SaaS, links each agent to the NHIs, entitlements and secrets it uses and to a human owner, and monitors agent behaviour for anomalies through its NHIDR detection engine. Credential issuance is not part of the evidenced scope.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me an agent's NHI lineage — creator, secrets used, entitlements, resources touched — and a live NHIDR alert for anomalous agent behaviour.

Read sources and limitations →

Primary category

GitGuardian NHI Governance

GitGuardian's module for non-human identity secrets: the ggscout collector inventories secrets and metadata from secrets managers, CI and infrastructure, tracks consumers, rotation dates and permissions, and flags stale or over-privileged credentials. It governs credentials used by machines and agents rather than issuing agent identities.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me every secret outside our vaults, who consumes it, when it was last rotated, and the semi-automated rotation workflow for an over-privileged NHI secret.

Read sources and limitations →

Also covers this layer

Google Cloud Agent Registry

Centralized catalog in Gemini Enterprise Agent Platform for registering and governing AI agents, MCP servers, skills and endpoints. Agents can be registered automatically from supported runtimes or manually for custom deployments, and consumers can search the catalog and authenticate to registered tools. It governs registered assets; unregistered agents are out of scope.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me an ADK agent auto-registered from its runtime, then demonstrate searching the registry and binding it to an authenticated endpoint.

Read sources and limitations →

Primary category

Idira Secure AI Agents

The agentic module of Idira, Palo Alto Networks' identity security platform built on acquired CyberArk technology. It scans SaaS, cloud and developer environments for active agents, enriches them with ownership and permission context, brokers task-scoped access through an agent identity broker and logs agent actions for audit.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me agents discovered across our SaaS and cloud estate with owner and permission context, then a task-scoped grant issued and revoked by the agent identity broker.

Read sources and limitations →

Also covers this layer

Immuta

Data access governance platform that centralizes classification, policy authoring and query-time enforcement across warehouses and lakehouses, and can onboard RAG indexes and storage platforms as governed data sources. Its AI-specific evidence is limited to that onboarding capability; retrieval-time enforcement inside AI applications is not documented.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate onboarding a RAG index as an Immuta data source and enforcing a row-level policy so the AI application cannot retrieve restricted records.

Read sources and limitations →

Also covers this layer

Knostic

Israeli vendor whose platform maps enterprise content into a policy-aware knowledge graph, tests what enterprise LLM assistants will reveal, and adjusts access so answers respect need-to-know. Evidence comes from vendor product pages rather than technical documentation, and enforcement examples centre on Microsoft 365 Copilot content.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate how Knostic detects that a Copilot answer exposed salary data to a user without need-to-know, and show the control change it applies.

Read sources and limitations →

Primary category

Microsoft Entra Agent ID

Microsoft's extension of Entra ID that creates dedicated directory identities for AI agents, built from reusable agent identity blueprints, so agents authenticate with their own credentials and are governed by Conditional Access, lifecycle and cleanup workflows. Evidence covers Microsoft-centric estates; cross-vendor agent coverage is not established.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me how you create an agent identity from a blueprint, bind it to a sponsor and owner, and enforce Conditional Access on that agent's token request.

Read sources and limitations →

Also covers this layer

Microsoft Foundry Agent Service

Managed Microsoft platform for building, deploying and scaling agents, offering prompt agents configured in a portal, hosted container agents from frameworks such as Agent Framework and LangGraph, and direct Responses API use. Each hosted agent receives a dedicated Microsoft Entra identity plus managed endpoint, scaling and observability.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me a hosted agent deployed from a container that receives its own Entra identity, and the end-to-end trace of one of its runs.

Read sources and limitations →

Also covers this layer

MintMCP

Managed MCP gateway for enterprises that curates which MCP servers and tools each role may reach, issues per-agent credentials, and logs every tool call. An agent monitor captures file reads, command execution and tool calls so teams can write rules that block risky behaviour. Self-hosting requires vendor contact.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me two role-based MintMCP endpoints where a destructive tool is switched off for one role, plus the agent monitor rule that blocks a risky command.

Read sources and limitations →

Also covers this layer

Nudge Security AI Agent Discovery

Research-preview capability of Nudge Security that inventories AI agents employees create on platforms such as Copilot Studio, Agentforce, Gemini, OpenAI, n8n, ServiceNow, Databricks, Workato and Tines, surfacing creator, permissions, connected data and MCP connections. Nudge's discovery approach centres on corporate email signals and OAuth grants.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate discovering an n8n or Copilot Studio agent an employee built last week, showing the creator, its OAuth grants, and any unauthenticated MCP connection.

Read sources and limitations →

Primary category

Oasis Agentic Access Management (AAM)

Oasis places an access layer between AI agents and SaaS, cloud, on-prem and data systems: it converts each agent request into a structured intent, evaluates it against policy with optional human escalation, and provisions ephemeral least-privilege session identities with prompt-level audit trails. Enforcement depends on agents routing through Oasis.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate an agent request converted into structured intent, denied by policy, then approved with human-in-the-loop and executed under a just-in-time session identity.

Read sources and limitations →

Primary category

Okta for AI Agents

Okta's agent-focused offering that discovers known and shadow AI agents, registers them as identities in Universal Directory with a human owner, and brokers short-lived credentials plus secret vaulting for agent access. Discovery evidence in its posture-management documentation is limited to specific connected agent platforms.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me an unmanaged Salesforce Agentforce agent discovered via OAuth consent grants, then register it in Universal Directory with an owner and issue it a short-lived credential.

Read sources and limitations →

Also covers this layer

OpenFGA

Apache-2.0 relationship-based authorization engine whose documentation models agents as first-class principals with narrowly scoped, revocable, optionally time-limited grants, including MCP tool-level checks and permission-filtered retrieval. It answers authorization questions but does not intercept traffic, so an application or gateway must call it.

open_source · Research snapshot 2026-09-06

Ask for a demonstration
Show me an OpenFGA model where an agent receives a task-scoped grant to two MCP tools with a turn limit, then revoke the agent without touching the user's permissions.

Read sources and limitations →

Also covers this layer

Permit MCP Gateway

Enforcement proxy placed between MCP clients such as Cursor or Claude Desktop and upstream MCP servers. It authenticates the human behind an agent, checks each tool call against fine-grained policy, records allow and deny decisions, and requires no change to existing MCP servers. Policy authoring depends on Permit's control plane.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me a Cursor session where a write-capable MCP tool is denied by policy while a read tool succeeds, then show the audit entry naming the agent and the authorizing human.

Read sources and limitations →

Primary category

SailPoint Agent Identity Security

Part of SailPoint Identity Security Cloud, this module aggregates AI agents from AWS, Azure, GCP, Salesforce and Copilot Studio, onboards each as a registered identity with business and access context, and surfaces shadow AI usage. It complements SailPoint's separate machine identity module for service accounts, bots and RPAs.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me every AI agent aggregated from Copilot Studio and Salesforce, each registered with an owner and access context, plus the shadow AI usage report.

Read sources and limitations →

Primary category

SPIRE (SPIFFE Runtime Environment)

A CNCF graduated open-source toolchain that attests running workloads and issues them short-lived SPIFFE identities (X.509 and JWT SVIDs) through the Workload API, enabling mutual TLS and authentication to secret stores, databases and cloud services. It provides identity plumbing, not agent inventory or governance workflows.

open_source · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate a Kubernetes workload attesting to SPIRE, receiving a rotating X.509 SVID, and using it for mTLS to another service across a federated trust domain.

Read sources and limitations →

Primary category

Teleport Machine & Workload Identity

Teleport issues short-lived certificates, JWTs and SPIFFE-compatible identities to bots, CI jobs, workloads and AI agents via its tbot agent, then enforces role-based access and records every command an agent runs against SSH hosts, Kubernetes clusters, databases and MCP servers. Agent use cases are positioned around design partnerships.

hybrid · Research snapshot 2026-09-06

Ask for a demonstration
Show an AI agent issued its own Teleport identity, restricted to read-only Kubernetes access by RBAC, with the full session recording of its commands.

Read sources and limitations →

Primary category

Token Security NHI & AI Agent Security Platform

Token Security continuously discovers AI agents and non-human identities across on-prem, hybrid and cloud estates, correlates agents, humans, secrets, permissions and data in an identity graph, enforces ownership and governs agents from creation through retirement, decommissioning orphaned identities. Credential issuance is not evidenced.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me a custom GPT agent discovered in our tenant, its owner and blast radius in the identity graph, and the workflow that decommissions it when the owner leaves.

Read sources and limitations →

Also covers this layer

Valence SaaS and AI Discovery

Part of Valence's SaaS security platform: it inventories sanctioned and unsanctioned SaaS and AI applications, and continuously identifies OAuth tokens, API keys, connected apps and service accounts linking business SaaS tenants to third-party AI tools. Detection is API-based against connected SaaS tenants, so unconnected apps stay invisible.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate how you surface an OAuth grant that connects an employee's unsanctioned AI tool to our Google Workspace tenant, including the scopes granted and the granting identity.

Read sources and limitations →

Primary category

Veza AI Agent Security

Veza's access graph labels non-human accounts across its integrations, shows their effective permissions, supports right-sizing and periodic review, and its agent-focused release maps unmanaged AI agents and service accounts to human owners and enumerates the tools an agent may invoke. Agent capabilities were described as early access.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me every tool and action an AI agent is authorized to invoke in a connected app, with the suggested human owner and a review campaign to revoke unused entitlements.

Read sources and limitations →

About this guide

The evaluation questions and fictional scenario are DutyGraph's editorial guidance. Product listings use the supplied source-linked research snapshot. We have not independently tested these offerings. Listing is not an endorsement, certification or working integration.

Read the directory methodology · Suggest a correction