ASAI Security ResearchIndependent public-source research
Public reviewread only

Solution approach

Agent identity and permissions

Register agents, assign accountable owners, control delegated permissions, and support access review and revocation.

Research scopeVendorsPublicly documented vendor profiles
Evaluation guideRequirementsSecurity requirements buyers can verify
Evidence basisSourcesPublic claims linked to their original sources
Unresolved itemsQuestionsMissing support is labeled instead of assumed
View research coverageThese counts describe available public research, not product quality or suitability.Expand
Vendor profiles
13 shown in this view
Security requirements
3 to review
Strong public support
21 requirement records
Limited public support
11 requirement records
Open research
7 with no supporting claim · 0 incomplete

Evaluation guide

What buyers should verify

Foundational security requirement

AI agent identity and permissions

Register AI agents as accountable identities, bind them to owners and delegating users, authorize task- and tool-level access, issue short-lived credentials, review access, and revoke or suspend agent authority.

Questions to test
  1. A test agent is registered with a unique identity, accountable owner, purpose, and permitted resources.
  2. A delegated or task-level policy issues or denies scoped access to a tool, application programming interface (API), application, or another agent.
  3. Suspension, revocation, or lifecycle action immediately changes the agent's ability to obtain or use access.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Foundational security requirement

Agent-to-agent communication security

Authorize, log, and control agent-to-agent, agent-to-tool, Model Context Protocol (MCP), connector, and tool-chain handoffs.

Questions to test
  1. An agent, tool, connector, or Model Context Protocol (MCP) handoff logs source identity, destination, and authorization decision.
  2. An allowed or denied access attempt produces an audit event with agent or tool identity.
  3. Rapid or anomalous inter-agent communication can be filtered, investigated, or alerted on.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Foundational security requirement

Non-human identity and service-account security

Inventory, least privilege, credential hygiene, monitoring, and lifecycle management for non-human identities, workloads, service accounts, application programming interface (API) keys, and machine credentials.

Questions to test
  1. A test service account, agent identity, or non-human identity appears in inventory with owner and privileges.
  2. A credential, secret, rotation, or hygiene issue is detected for the test identity.
  3. A least-privilege or lifecycle control changes the status of the test identity.
Related frameworks

NIST AI RMF Playbook · NIST Cybersecurity Framework 2.0 · CIS Critical Security Controls · ISO/IEC 42001 · OWASP GenAI Security Solutions Landscape

Vendor research

Vendors with public research for this approach

Choose vendors to compare →

Vendors are grouped by whether this approach is a core product focus or related coverage, then ordered by documented support across the requirements shown. This organizes public research coverage; it is not a product ranking or recommendation.

Evidence labelsStrong public supportLimited public supportNo supporting claim foundResearch incomplete
VendorAgent identityAgent/tool trustNon-human identity securitySourcesAction
Core product focusThis approach is central to how these vendors present the product · 7 vendors
AembitEmergingSupport found for 3 of 3 requirementsStrong public supportStrong public supportStrong public support2Profile →
CyberArk Secure AI AgentsEstablishedSupport found for 3 of 3 requirementsStrong public supportStrong public supportStrong public support3Profile →
Okta for AI AgentsEstablishedSupport found for 3 of 3 requirementsStrong public supportStrong public supportStrong public support1Profile →
Cequence AI GatewayScaledSupport found for 3 of 3 requirementsStrong public supportStrong public supportLimited public support1Profile →
KeycardGrowth stageSupport found for 3 of 3 requirementsStrong public supportLimited public supportStrong public support1Profile →
Speakeasy AI Control PlaneGrowth stageSupport found for 2 of 3 requirementsLimited public supportLimited public supportNo supporting claim found2Profile →
RunlayerGrowth stageSupport found for 1 of 3 requirementsLimited public supportNo supporting claim foundNo supporting claim found1Profile →
Related coverageThese vendors address the requirements through another core product focus · 6 vendors
Cloudflare AI Security SuiteEstablishedSupport found for 3 of 3 requirementsStrong public supportLimited public supportStrong public support1Profile →
CrowdStrike AI SecurityEstablishedSupport found for 3 of 3 requirementsLimited public supportStrong public supportStrong public support3Profile →
Obsidian AI SecurityGrowth stageSupport found for 2 of 3 requirementsStrong public supportNo supporting claim foundStrong public support1Profile →
Holistic AIEmergingSupport found for 2 of 3 requirementsLimited public supportStrong public supportNo supporting claim found2Profile →
Kong AI GatewayScaledSupport found for 2 of 3 requirementsLimited public supportStrong public supportNo supporting claim found2Profile →
Enkrypt AIEmergingSupport found for 2 of 3 requirementsLimited public supportLimited public supportNo supporting claim found2Profile →

Company maturity remains a filter and profile attribute; it does not affect the research-coverage order.