A new group of security vendors is moving to treat AI agents as governed enterprise identities, with controls for ownership, access, runtime authorization, and audit trails.

Andromeda Security, Omada, and P0 Security all announced or showcased agent-focused security products around Identiverse, the identity industry conference taking place in Las Vegas. The announcements differ in scope, but they point in the same direction: enterprises are starting to ask how AI agents should be discovered, assigned to owners, granted access, monitored, and stopped when they take actions inside business systems.

Andromeda expanded its platform to cover human users, AI agents, and non-human identities in one system. The company said the update includes real-time, resource-level enforcement for agents, human-in-the-loop approval for high-risk actions, lifecycle governance, and an MCP Gateway designed to act as an inline policy enforcement point. The goal is to let companies define what an agent can do at the level of tools, repositories, databases, and other resources, rather than treating the agent as a generic application integration.

Omada launched Agent Governance, extending its identity governance and administration platform to AI agents and other non-human identities. The product is designed to discover agents, assign accountable human owners, review access, compare permissions with actual usage, and generate audit evidence for governance programs. Omada framed the launch around compliance with emerging AI and security frameworks, including the EU AI Act, NIST AI Risk Management Framework, ISO 42001, OWASP, and MITRE ATLAS.

P0 Security is using Identiverse to showcase agentic runtime access control. Its product focuses on the moment an agent tries to act, combining the identity of the invoking user, the agent, the tool, and the target resource into an authorization decision. The company said the system can discover shadow agents, enforce zero standing privilege across agents and infrastructure, audit authorization decisions, and revoke access after a task is complete.

The launches build on a broader agent identity thread already visible in the standards world. FIDO, the OpenID Foundation, the Linux Foundation’s Agent2Agent project, and the Model Context Protocol community have all been working toward ways to authenticate agents and describe what they are allowed to do. Newer entrants such as VeryAI’s AG9 have also pushed the idea that agents may need distinct credentials, attestations, or trust signals before they can operate across enterprise systems.

The commercial market is now moving from that standards discussion into product packaging. The common claim across the new launches is that agents should not simply inherit permissions from the users, service accounts, or applications that invoke them. They should be governed as identifiable actors with owners, policies, access boundaries, and logs.

Sources: Andromeda Security, Omada, P0 Security


By the Control Plane Editorial Team