Agent Identity & Access

Identities, scoped access, and access reviews for AI agents as non-human principals.

Agents need their own identities, least-privilege access, owners, and access reviews — the same controls people get. Compare identity-provider, governance, and privileged-access vendors on how they register, authorise, and audit agents.

In dataset
10
Filter tools by type
Filter tools by cloud support
10 matching tools
More filters

Major vendor tools

Tools from the major platform vendors are listed first; independent and open-source options follow below.

Vendor

SPIFFE-based cryptographic identity for agents on Gemini Enterprise Agent Platform, usable as an IAM principal with auto-rotated certs.

GCP
Proprietary
SaaSSOC 2License medium

Filtered open source and third-party tools

8 matching non-vendor tools in this filtered view.

Policy-based, just-in-time access for AI agents via an MCP Authorization Server and MCP Identity Gateway with credential injection.

Proprietary
SaaSHybridSOC 2License medium
Commercial

Developer identity for AI agents: user login, Token Vault for third-party APIs, CIBA human approvals and fine-grained authorization for RAG.

Proprietary
SaaSSOC 2License medium

Idira Secure AI Agents

Palo Alto Networks (Idira)

Commercial

Discovers AI agents across SaaS, cloud and dev environments and brokers their MCP tool access with just-in-time privilege and audit.

Proprietary
SaaSLicense medium
Commercial

Discovers, registers and governs AI agents in Okta Universal Directory with scoped tokens, vaulted secrets and access reviews.

Proprietary
SaaSSOC 2License medium
Commercial

Runtime identity for AI agents: Agent IAM Core, an Agent Gateway enforcing fine-grained authorization, and agent detection.

Proprietary
SaaSSOC 2License medium
Commercial

Saviynt's AI identity security platform: discovers agents, MCP servers and NHIs, maps access paths and governs agent lifecycle.

Proprietary
SOC 2License medium

Important notes

Warning

Descope Agentic Identity Hub: Gateways feature in early access as of 2026-09-30.

Warning

Idira Secure AI Agents: CyberArk's platform was rebranded as Idira by Palo Alto Networks in May 2026.
2026-08-24
Okta for AI Agents
Okta for AI Agents

Okta made Agent SSO generally available, built on the Cross App Access standard and included in core Okta SSO.

Source
2026-07-28
Saviynt Zuma
Saviynt Zuma

Saviynt launched Zuma, an AI identity security platform with agent discovery, runtime intent-aware access, and governance for AI agents and non-human identities.

Source

Frequently asked questions

  • Why do AI agents need their own identities?

    An agent that reuses a person's credentials or a shared API key cannot be scoped, reviewed, or revoked on its own, and its actions cannot be told apart from the human's in audit logs. A dedicated agent identity with a named human owner makes least privilege, access reviews, and kill switches possible.

  • What standards matter for agent authorization?

    OAuth 2.x remains the base. The Model Context Protocol's authorization spec builds on OAuth 2.1 for agent-to-tool access, and its enterprise-managed authorization extension lets an identity provider decide which agents can reach which MCP servers. The OpenID Foundation's AuthZEN work covers fine-grained authorization decisions.

  • Who usually owns this purchase?

    The identity and access management team or the CISO, not the AI platform team — which is why it is tracked separately from agent control planes. Most vendors here extend an existing identity provider, governance, or privileged-access product to agents.

Explore adjacent hubs

Compare the active category against the platform foundation layer, the cross-category updates feed, and the sourcing/contribution guide.