Alphabetical, not ranked. Membership includes primary and secondary research categories. These products have different scopes; inspect the evidence profile before comparing capabilities.
Primary category
A developer kit layered on 1Password vaults and SDKs that gives a software agent a verifiable identity tied to a workload, issues short-lived agent tokens instead of shared API keys, scopes what the agent may access and links agent actions to audit trails. It sits within the broader 1Password Unified Access platform.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show an agent receiving a short-lived credential tied to its workload identity, using an approved secret without exposing it, and the audit trail linking the action to a user.
Read sources and limitations →
Primary category
A workload identity and access platform that attests the client environment of a workload or AI agent, evaluates a policy at request time, then injects short-lived credentials into the outbound API call so the workload never stores a secret. Discovery and inventory of existing non-human identities is not evidenced.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate an AI agent obtaining a 15-minute credential through client attestation and policy evaluation, and show the access log for a denied request outside business hours.
Read sources and limitations →
Primary category
Apache-2.0 project from the Linux Foundation-hosted AGNTCY effort that issues and verifies identities for AI agents, MCP servers and multi-agent systems using verifiable credentials and badges, and can onboard existing identities from providers, A2A agent cards or W3C DIDs. Deployment and adoption maturity are unproven.
open_source · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate issuing a verifiable badge to an MCP server and having a relying agent verify it, including how revocation and key storage work.
Read sources and limitations →
Primary category
Akeyless brokers AI agent connections through its Gateway so agents reach databases, SaaS, cloud services and legacy systems without receiving passwords, API keys or certificates; access is created on demand, scoped by policy, revoked afterwards and recorded in a central audit trail. Requires routing agent traffic through the Gateway.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate an MCP-based agent querying a production database through the Akeyless Gateway with no credential ever entering the agent's context, plus the audit record.
Read sources and limitations →
Also covers this layer
AWS's set of composable services for running agents built with any framework, covering serverless execution with isolated sessions, persistent memory, a gateway that turns APIs into MCP tools, identity and credential management, and built-in observability. Documented governance is strongest on identity and authorization rather than approvals.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me an AgentCore Gateway exposing two Lambda tools where the agent's inbound and outbound authorization is verified per request through AgentCore Identity.
Read sources and limitations →
Also covers this layer
Capability of AppOmni's SaaS security platform that surfaces AI agents running inside connected SaaS tenants - such as Salesforce Agentforce, ServiceNow Now Assist and Microsoft 365 Copilot - including agents enabled without security review, with their declared tools, identities, permissions and over-privilege findings. Discovery depends on AppOmni's SaaS API connections.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate listing every Agentforce and Now Assist agent in our tenants, flagging which ones were enabled without approval and which hold write or destructive permissions.
Read sources and limitations →
Also covers this layer
Actions runtime that brokers agent tool calls to SaaS systems, handling OAuth and user token storage and applying per-action authorization so an agent acts within both the user's and its own scope. Pre- and post-tool-call hooks allow blocking or redaction, though the hosted tool catalogue is vendor-maintained.
hybrid · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me an agent calling a Gmail tool through Arcade where the user consents via OAuth, a pre-tool-call hook blocks a send action, and the audit log records the decision.
Read sources and limitations →
Primary category
Astrix discovers AI agents, MCP servers, service accounts, OAuth apps, API keys and other non-human identities across cloud, SaaS, CI/CD and vaults, maps each to a human owner in an identity graph, and applies agent policies plus onboarding and offboarding actions. Enforcement depth outside integrated platforms is unclear.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me the identity graph for one shadow agent — its NHIs, credentials, reachable resources and owner — then apply a policy that blocks it and offboard it.
Read sources and limitations →
Primary category
Developer-facing authorization service from Auth0 that lets an AI agent call first-party and third-party APIs on behalf of an authenticated user using OAuth scopes, with Token Vault obtaining, storing and refreshing external API tokens. It governs user-delegated agent access, not enterprise-wide agent inventory.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate an agent obtaining a Google and Slack token from Token Vault after user consent, and show what happens when the agent requests a scope the user never granted.
Read sources and limitations →
Primary category
Britive registers each AI agent as its own identity with a human owner and permitted access profiles, authenticates it via SPIFFE SVID, OIDC federation or API tokens on every request, and grants just-in-time privileges that are created and destroyed per task so no standing credential remains. Cloud-target coverage varies.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Register an agent with an owner and job function, then show a just-in-time credential created for one task and destroyed at task end, with the access record.
Read sources and limitations →
Also covers this layer
Identity-aware proxy positioned in front of MCP servers and APIs so that users and agents authenticate through an existing IdP before any tool call proceeds. Product material describes filtering tools/list discovery and gating tools/call invocation by policy; the fetched documentation site provides only high-level confirmation of that scope.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me Datawiza filtering the tools/list response for a low-privilege group and denying a tools/call write action after validating the Entra ID token claims.
Read sources and limitations →
Primary category
An identity provider for AI agents and MCP servers that registers OAuth clients (including dynamic client registration), records agentic identities created by user consent or tenant grants, and issues short-lived scoped credentials with policy-based access to protected APIs and MCP resources. Aimed at application builders rather than workforce IT.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me an autonomous agent registering via DCR, receiving a short-lived scoped token, and being denied an MCP tool call by an access policy — with the audit record.
Read sources and limitations →
Primary category
Entro inventories non-human identities, secrets and agentic AI deployments across cloud, code, CI/CD, on-prem and SaaS, links each agent to the NHIs, entitlements and secrets it uses and to a human owner, and monitors agent behaviour for anomalies through its NHIDR detection engine. Credential issuance is not part of the evidenced scope.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me an agent's NHI lineage — creator, secrets used, entitlements, resources touched — and a live NHIDR alert for anomalous agent behaviour.
Read sources and limitations →
Primary category
GitGuardian's module for non-human identity secrets: the ggscout collector inventories secrets and metadata from secrets managers, CI and infrastructure, tracks consumers, rotation dates and permissions, and flags stale or over-privileged credentials. It governs credentials used by machines and agents rather than issuing agent identities.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me every secret outside our vaults, who consumes it, when it was last rotated, and the semi-automated rotation workflow for an over-privileged NHI secret.
Read sources and limitations →
Also covers this layer
Centralized catalog in Gemini Enterprise Agent Platform for registering and governing AI agents, MCP servers, skills and endpoints. Agents can be registered automatically from supported runtimes or manually for custom deployments, and consumers can search the catalog and authenticate to registered tools. It governs registered assets; unregistered agents are out of scope.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me an ADK agent auto-registered from its runtime, then demonstrate searching the registry and binding it to an authenticated endpoint.
Read sources and limitations →
Primary category
The agentic module of Idira, Palo Alto Networks' identity security platform built on acquired CyberArk technology. It scans SaaS, cloud and developer environments for active agents, enriches them with ownership and permission context, brokers task-scoped access through an agent identity broker and logs agent actions for audit.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me agents discovered across our SaaS and cloud estate with owner and permission context, then a task-scoped grant issued and revoked by the agent identity broker.
Read sources and limitations →
Also covers this layer
Data access governance platform that centralizes classification, policy authoring and query-time enforcement across warehouses and lakehouses, and can onboard RAG indexes and storage platforms as governed data sources. Its AI-specific evidence is limited to that onboarding capability; retrieval-time enforcement inside AI applications is not documented.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate onboarding a RAG index as an Immuta data source and enforcing a row-level policy so the AI application cannot retrieve restricted records.
Read sources and limitations →
Also covers this layer
Israeli vendor whose platform maps enterprise content into a policy-aware knowledge graph, tests what enterprise LLM assistants will reveal, and adjusts access so answers respect need-to-know. Evidence comes from vendor product pages rather than technical documentation, and enforcement examples centre on Microsoft 365 Copilot content.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate how Knostic detects that a Copilot answer exposed salary data to a user without need-to-know, and show the control change it applies.
Read sources and limitations →
Primary category
Microsoft's extension of Entra ID that creates dedicated directory identities for AI agents, built from reusable agent identity blueprints, so agents authenticate with their own credentials and are governed by Conditional Access, lifecycle and cleanup workflows. Evidence covers Microsoft-centric estates; cross-vendor agent coverage is not established.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me how you create an agent identity from a blueprint, bind it to a sponsor and owner, and enforce Conditional Access on that agent's token request.
Read sources and limitations →
Also covers this layer
Managed Microsoft platform for building, deploying and scaling agents, offering prompt agents configured in a portal, hosted container agents from frameworks such as Agent Framework and LangGraph, and direct Responses API use. Each hosted agent receives a dedicated Microsoft Entra identity plus managed endpoint, scaling and observability.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me a hosted agent deployed from a container that receives its own Entra identity, and the end-to-end trace of one of its runs.
Read sources and limitations →
Also covers this layer
Managed MCP gateway for enterprises that curates which MCP servers and tools each role may reach, issues per-agent credentials, and logs every tool call. An agent monitor captures file reads, command execution and tool calls so teams can write rules that block risky behaviour. Self-hosting requires vendor contact.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me two role-based MintMCP endpoints where a destructive tool is switched off for one role, plus the agent monitor rule that blocks a risky command.
Read sources and limitations →
Also covers this layer
Research-preview capability of Nudge Security that inventories AI agents employees create on platforms such as Copilot Studio, Agentforce, Gemini, OpenAI, n8n, ServiceNow, Databricks, Workato and Tines, surfacing creator, permissions, connected data and MCP connections. Nudge's discovery approach centres on corporate email signals and OAuth grants.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate discovering an n8n or Copilot Studio agent an employee built last week, showing the creator, its OAuth grants, and any unauthenticated MCP connection.
Read sources and limitations →
Primary category
Oasis places an access layer between AI agents and SaaS, cloud, on-prem and data systems: it converts each agent request into a structured intent, evaluates it against policy with optional human escalation, and provisions ephemeral least-privilege session identities with prompt-level audit trails. Enforcement depends on agents routing through Oasis.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate an agent request converted into structured intent, denied by policy, then approved with human-in-the-loop and executed under a just-in-time session identity.
Read sources and limitations →
Primary category
Okta's agent-focused offering that discovers known and shadow AI agents, registers them as identities in Universal Directory with a human owner, and brokers short-lived credentials plus secret vaulting for agent access. Discovery evidence in its posture-management documentation is limited to specific connected agent platforms.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me an unmanaged Salesforce Agentforce agent discovered via OAuth consent grants, then register it in Universal Directory with an owner and issue it a short-lived credential.
Read sources and limitations →
Also covers this layer
Apache-2.0 relationship-based authorization engine whose documentation models agents as first-class principals with narrowly scoped, revocable, optionally time-limited grants, including MCP tool-level checks and permission-filtered retrieval. It answers authorization questions but does not intercept traffic, so an application or gateway must call it.
open_source · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me an OpenFGA model where an agent receives a task-scoped grant to two MCP tools with a turn limit, then revoke the agent without touching the user's permissions.
Read sources and limitations →
Also covers this layer
Enforcement proxy placed between MCP clients such as Cursor or Claude Desktop and upstream MCP servers. It authenticates the human behind an agent, checks each tool call against fine-grained policy, records allow and deny decisions, and requires no change to existing MCP servers. Policy authoring depends on Permit's control plane.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me a Cursor session where a write-capable MCP tool is denied by policy while a read tool succeeds, then show the audit entry naming the agent and the authorizing human.
Read sources and limitations →
Primary category
Part of SailPoint Identity Security Cloud, this module aggregates AI agents from AWS, Azure, GCP, Salesforce and Copilot Studio, onboards each as a registered identity with business and access context, and surfaces shadow AI usage. It complements SailPoint's separate machine identity module for service accounts, bots and RPAs.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me every AI agent aggregated from Copilot Studio and Salesforce, each registered with an owner and access context, plus the shadow AI usage report.
Read sources and limitations →
Primary category
A CNCF graduated open-source toolchain that attests running workloads and issues them short-lived SPIFFE identities (X.509 and JWT SVIDs) through the Workload API, enabling mutual TLS and authentication to secret stores, databases and cloud services. It provides identity plumbing, not agent inventory or governance workflows.
open_source · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate a Kubernetes workload attesting to SPIRE, receiving a rotating X.509 SVID, and using it for mTLS to another service across a federated trust domain.
Read sources and limitations →
Primary category
Teleport issues short-lived certificates, JWTs and SPIFFE-compatible identities to bots, CI jobs, workloads and AI agents via its tbot agent, then enforces role-based access and records every command an agent runs against SSH hosts, Kubernetes clusters, databases and MCP servers. Agent use cases are positioned around design partnerships.
hybrid · Research snapshot 2026-09-06
- Ask for a demonstration
- Show an AI agent issued its own Teleport identity, restricted to read-only Kubernetes access by RBAC, with the full session recording of its commands.
Read sources and limitations →
Primary category
Token Security continuously discovers AI agents and non-human identities across on-prem, hybrid and cloud estates, correlates agents, humans, secrets, permissions and data in an identity graph, enforces ownership and governs agents from creation through retirement, decommissioning orphaned identities. Credential issuance is not evidenced.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me a custom GPT agent discovered in our tenant, its owner and blast radius in the identity graph, and the workflow that decommissions it when the owner leaves.
Read sources and limitations →
Also covers this layer
Part of Valence's SaaS security platform: it inventories sanctioned and unsanctioned SaaS and AI applications, and continuously identifies OAuth tokens, API keys, connected apps and service accounts linking business SaaS tenants to third-party AI tools. Detection is API-based against connected SaaS tenants, so unconnected apps stay invisible.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Demonstrate how you surface an OAuth grant that connects an employee's unsanctioned AI tool to our Google Workspace tenant, including the scopes granted and the granting identity.
Read sources and limitations →
Primary category
Veza's access graph labels non-human accounts across its integrations, shows their effective permissions, supports right-sizing and periodic review, and its agent-focused release maps unmanaged AI agents and service accounts to human owners and enumerates the tools an agent may invoke. Agent capabilities were described as early access.
commercial · Research snapshot 2026-09-06
- Ask for a demonstration
- Show me every tool and action an AI agent is authorized to invoke in a connected app, with the suggested human owner and a review campaign to revoke unused entitlements.
Read sources and limitations →