THEPERMISSION [LAYER]

Landscape

The AI-Agent Governance Vendor Map

Who sells what in agent identity, permissions, MCP security, and spend governance. Maintained weekly; every change ships with an evidence link in the briefing's Landscape Watch section.

PREVIEW — seeded categories; per-vendor details land after evidence verification.

Agent identity & NHI 6

Identity, authentication, and lifecycle for AI agents and non-human identities.

  • Oasis Security
  • Saviynt
  • Cyera
  • SailPoint
  • Okta
  • Microsoft Entra

MCP security & gateways 7

Gateways, allowlisting, and security tooling for Model Context Protocol deployments.

  • Runlayer
  • Helmet Security
  • Operant AI
  • Manufact
  • Kong
  • MintMCP
  • Composio

AI security platforms 5

Broader platforms securing AI applications, models, and agents.

  • Noma Security
  • WitnessAI
  • Lasso Security
  • Lakera (Check Point)
  • Protect AI (Palo Alto)

Agentic SOC 4

AI agents doing security operations work.

  • Torq
  • 7AI
  • Dropzone AI
  • Qevlar AI

Offensive & testing 2

Automated pentesting and adversarial testing of AI systems.

  • XBOW
  • RunSybil

Exposure management 3

Discovering and managing AI-related attack surface.

  • Astelia
  • Eclypsium
  • Surf AI

LLM gateways & spend 5

Model routing, observability, and cost governance.

  • TrueFoundry
  • Maxim AI
  • Concentrate AI
  • LiteLLM
  • Portkey

Agent observability 6

Tracing, logging, and evaluation — the audit trail for what agents actually did.

  • Langfuse
  • LangSmith (LangChain)
  • Arize
  • Braintrust
  • Helicone
  • W&B Weave

Data flow & AI-DLP 6

Controlling what data reaches agents, and what agents can leak back out.

  • Nightfall
  • Harmonic Security
  • Metomic
  • BigID
  • Varonis
  • Cyera

Shadow-AI discovery 5

Finding and governing the AI tools employees adopted without asking.

  • Nudge Security
  • Reco
  • Grip Security
  • Island
  • SquareX

AI governance & compliance 6

Policy, risk, and regulatory compliance for AI programs (EU AI Act, NIST RMF).

  • Credo AI
  • Holistic AI
  • OneTrust
  • IBM
  • Vanta
  • Drata

Agent sandboxing (watchlist) 2

Runtime isolation for agent code execution. Early — mostly developer infrastructure today.

  • E2B
  • Daytona

Agent payments (watchlist) 3

Wallets, virtual cards, and transaction limits for agents that spend money. Embryonic.

  • Stripe
  • Skyfire
  • Payman

Platform giants 6

Hyperscalers and incumbents shipping agent-governance features.

  • Microsoft
  • Okta
  • Google
  • AWS
  • ServiceNow
  • Palo Alto Networks

† seeded pending verification. Vendor-neutral: inclusion is editorial, never paid. Corrections: [email protected]