ASAI Security ResearchIndependent public-source research
Public reviewread only

Public-source research

Vendor evidence

Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.

Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6

Showing 41–60 of 67 evidence records

Clear all filters
AurascapeAI agent identity and permissionsSource checkedLimited public support for this requirement

Aurascape claims context-aware tool policy based on user identity, account type, agent intent, entitlement, data sensitivity, OAuth roles and scopes, and approved-call signatures.

Context-aware policy on identity, intent, entitlement, and data sensitivity.
Varonis AI SecurityAI agent identity and permissionsSource checkedLimited public support for this requirement

Varonis Atlas claims visibility into identities and intent interacting with AI, agent permissions and data access, policy verification for every action and Model Context Protocol (MCP) call, and continuous enforcement of least-privilege outcomes.

The identities and their intent interacting with AI systems.
Operant AIAI agent identity and permissionsSource checkedStrong public support for this requirement

Operant claims AI non-human identity detection, agent identity and access control, fine-grained identity-aware Model Context Protocol (MCP) enforcement, least privilege, authorization validation, trust scores, and per-agent tool restrictions.

Detect and block unauthenticated and unauthorized AI agent behavior in real time.
Apex Security / TenableAI agent identity and permissionsSource checkedLimited public support for this requirement

Tenable claims agent ownership and access inventory, identity and entitlement correlation, least-privilege remediation, risky permission detection, and agent isolation or access-level changes.

View agent owner, access level, tools, knowledge, and isolate the agent from the agent details panel.
KnosticAI agent identity and permissionsSource checkedLimited public support for this requirement

Knostic claims OAuth-based agent authentication, agent-role to privilege mapping, least-privilege and need-to-know boundaries, and policy enforcement across software as a service (SaaS), in-house, and Model Context Protocol (MCP) agents.

Map agent roles to privileges and enforce need-to-know boundaries.
Onyx AIAI agent identity and permissionsSource checkedLimited public support for this requirement

Onyx AI claims organization and group-based agent sharing plus configurable knowledge and action permissions for enterprise agents.

Publish your Agent to your entire organization or share it with specific users or groups.
AIM Security / Cato NetworksAI agent identity and permissionsSource checkedLimited public support for this requirement

Cato AI Security claims visibility into agent configurations, licenses, data and tool access, plus corporate policy enforcement and blocking of unauthorized access or unsafe actions across managed and local agents.

Reduce the risk of unauthorized access, sensitive data exposure, and unsafe agent actions.
JetStream SecurityAI agent identity and permissionsSource checkedStrong public support for this requirement

JetStream claims an accountable identity fabric binding humans, agents, service accounts, and models with short-lived identity-scoped keys, ownership attribution, permission monitoring, and runtime enforcement.

Bind every AI action to an accountable identity using short-lived, identity-scoped keys.
Singulr AIAI agent identity and permissionsSource checkedLimited public support for this requirement

Singulr claims agent discovery, ownership and intent, topology and permission mapping, enforceable boundaries based on agent type, data sensitivity, tool access, and scope, plus runtime restriction of unauthorized system access.

Define enforceable policies based on agent type, data sensitivity, tool access, and scope.
Grip SecurityAI agent identity and permissionsSource checkedLimited public support for this requirement

Grip claims discovery and posture analysis for AI agents as non-human identities, including permissions, authentication, OAuth grants, application programming interface (API) keys, service accounts, access scopes, machine identities, and connected applications.

Security teams need visibility into AI agents, permissions, OAuth grants, and machine identities operating across SaaS environments.
RecoAI agent identity and permissionsSource checkedLimited public support for this requirement

Reco claims mapping of each AI agent to authorizing users, connected applications, OAuth grants, application programming interface (API) identities, permissions, data access, ownership, and policy status with least-privilege controls.

For each agent, Reco maps which SaaS applications it connects to, what permissions it holds, who authorized it, and what data it can access.
ZenityAI agent identity and permissionsSource checkedLimited public support for this requirement

Zenity claims ownership, identity relationship, permission, tool-access, and execution-path mapping with policy enforcement against over-privileged agents, unauthorized application programming interface (API) calls, restricted-data access, and privilege escalation.

Know which agents exist, who owns them, what they can access, and how they behave across your environment.
Token SecurityAI agent identity and permissionsSource checkedStrong public support for this requirement

Token Security claims discovery and lifecycle control for agent identities, owners, intent, credentials, tokens, roles, permissions, access paths, behavioral baselines, access reviews, least-privilege enforcement, remediation, and deprovisioning.

Token Security helps teams manage the full AI agent identity lifecycle.
Iterate.ai AgentWatchAI agent identity and permissionsSource checkedLimited public support for this requirement

AgentWatch claims JWT authentication, role-based access control, organization and team hierarchies, encrypted application programming interface (API)-key management, user and device attribution, correlated request logs, and policy status across business and coding agents.

Built-In Enterprise Security: encrypted API keys at rest, JWT authentication and role-based access control, comprehensive audit logging for every operation.
Credo AIAI agent identity and permissionsSource checkedLimited public support for this requirement

Credo AI claims agent cards containing purpose, tools, data sources, and guardrails, with ownership and accountability in the Agent Registry.

Agent Registry with agent cards (purpose, tools, data sources, guardrails)
Holistic AIAI agent identity and permissionsSource checkedLimited public support for this requirement

Holistic AI claims tracking of agent identity, reasoning chains, and tool calls with runtime access controls.

Track every agent's identity, reasoning chain, and tool calls
MindgardAI agent identity and permissionsNo supporting claim found

Mindgard materials reviewed did not provide a public claim for agent registration, delegated authorization, short-lived credential issuance, or agent identity lifecycle controls.

No quoted source text is recorded for this claim.
Enkrypt AIAI agent identity and permissionsSource checkedLimited public support for this requirement

Enkrypt AI claims role- and tenant-aware rules using SSO, identity and access management (IAM), and identity claims to constrain tools, data sources, and actions.

Role/tenant-based rules
AktoAI agent identity and permissionsSource checkedLimited public support for this requirement

Akto claims access governance by user, team, and tool plus actor-aware monitoring for agent and Model Context Protocol (MCP) actions.

AI access governance by user, team and tool
Okta for AI AgentsAI agent identity and permissionsSource checkedStrong public support for this requirement

Okta claims unique agent registration, human ownership, short-lived credentials, runtime policies, governance, audit, and retirement.

temporary, short-lived credentials