Public-source research
Vendor evidence
Review what vendors say publicly, the exact quoted source text, the security requirement each statement may support, and what still needs verification.
Research library coverageCounts describe the research workflow, not vendor quality or product effectiveness.View details
Evidence records1280
Source checked863
Needs verification0
Source captured0
No supporting claim found411
Excluded from evidence6
CyberArk claims agent discovery, contextual identity, task-scoped just-in-time permissions, zero standing privilege, audit, lifecycle, and suspension.
zero standing privileges
Related framework references (5)
BigID claims restricting genAI data access by agent and enforcing permissions over agentic data access.
Track and restrict access to genAI data by user, model, or agent
Related framework references (5)
Obsidian claims tying agent actions to owners, executors, service accounts, permissions, OAuth access, and least-privilege enforcement.
Tie actions to the real owner and the executor for each agent
Related framework references (5)
Cloudflare claims authentication of every user and agent connection with identity-scoped least-privilege permissions.
Authenticate every user and agent connection
Related framework references (5)
Orca materials reviewed did not provide a public claim for agent registration, ownership, delegated authorization, short-lived credentials, or agent lifecycle.
No quoted source text is recorded for this claim.
Related framework references (5)
Backslash claims contextual permission policy over agents, tools, models, MCPs, skills, and the human identity used on the host endpoint.
using the human user’s identity on the host machine
Related framework references (5)
HiddenLayer materials reviewed did not provide a public claim for agent registration, accountable ownership, delegated authorization, short-lived credentials, access review, or revocation.
No quoted source text is recorded for this claim.
Related framework references (5)