AI Agent Allowlist
Home Page-Types Database Agent Guardrails 2026 Incidents API Docs Pricing
Resources
Use Cases (15) Industries & Buyers (12) Learn: Core Concepts (12) Implementation Guides (15) Comparisons (8) Schema & Data Reference (6) FAQ Glossary
Why It Matters
2026 Agent Incidents Category Targeting Database Refreshes Contact Customer Login
Download Free Sample
identity teams meet AI agents

Non-Human Identity Vendors and AI Agent Identity

Service accounts, API keys and tokens now outnumber people in most companies. AI agents are the fastest-growing kind.

This page groups the NHI vendors by approach and shows what identity can and cannot control. Identity answers "who is this agent". An AI agent allow list answers "where may it go".

5Vendor approaches
20+Vendors named
2Questions: who and where
40M+Domains mapped for "where"
What NHI means

The non-human identities in a company

A non-human identity is anything that logs in or holds access without being a person.

Service accountsIn directories and cloud IAM
API keysFor SaaS and internal APIs
OAuth tokensApps acting for users
CertificatesMachines and workloads
WorkloadsContainers, functions, pipelines
AI agentsUse all of the above, and decide on their own

Most companies already manage some of these. Agents are different from other NHIs in one way. A service account does the same thing every time. An agent chooses what to do next.

Why NHI became urgent once agents arrived

More identities, faster

Every new agent brings keys, tokens and service accounts, often created by the agent's builder in minutes.

Wider reach per identity

One agent may touch a CRM, a file store, email and the public web in a single task.

Decisions without a person

Nobody reviews each step, so access mistakes show up only in logs.

Identities made elsewhere

Agents can create accounts on outside sites, which no internal directory will list.

The market

NHI vendors, grouped by approach

Vendors are listed as examples, based on how they describe their products. Many cover more than one approach.

NHI discovery and governance

Find every machine identity across SaaS and cloud, then score and clean up.

  • Inventory of keys, tokens and service accounts
  • Owner assignment and offboarding
  • Risk scoring per identity
Examples: Astrix Security, Oasis Security, Clutch Security, Entro Security, Token Security

Workload and agent access

Replace static secrets with short-lived, policy-based access.

  • Identity for workloads and agents
  • Just-in-time credentials
  • Access policy per target service
Examples: Aembit, Keycard, Natoma

Identity platforms extending to agents

Large identity providers adding agent identities to their directories.

  • Agents registered like users or apps
  • Single sign-on and consent flows
  • Central policy and audit
Examples: Okta, Microsoft Entra (Agent ID), Ping Identity

Privileged access and secrets

Vaults and privileged access tools that store and rotate secrets.

  • Secret storage and rotation
  • Privileged session control
  • Machine identity certificates
Examples: CyberArk, HashiCorp Vault, Akeyless, Delinea

Identity security and governance

Access reviews and entitlement analysis across people and machines.

  • Who can access what, and why
  • Certification campaigns
  • Agent identity security features
Examples: SailPoint, Veza, Silverfort, Saviynt

Secrets detection

Find leaked keys in code, tickets and chat before attackers do.

  • Scanning repositories and logs
  • Leak alerts and remediation
  • NHI inventory from findings
Examples: GitGuardian, and scanning features in developer security platforms

Most large companies end up with two or three of these approaches working together, not one.

The market is consolidating. Palo Alto Networks announced a deal to acquire CyberArk in 2025, and more identity deals are likely.

Two questions

Identity answers "who". Agents also need "where".

QUESTION 1: WHO

Is this agent allowed to act as itself?

  • Which identity does it hold?
  • Which systems may that identity reach?
  • How long do its credentials last?
  • Who owns it, and when is it retired?

Answered by NHI and identity platforms.

QUESTION 2: WHERE

Which web pages may this agent open?

  • Is this URL a login page?
  • Is it a signup, checkout or upload page?
  • Is the host on a high-risk list?
  • Is the destination classified at all?

Answered by page-type data, checked before each request.

An agent with a perfectly scoped identity can still open a stranger's signup page and create an account. Identity never saw that request, because it was not using the agent's credentials.

NHI terms in plain words

Workload identityAn identity given to running software, proven by where and how it runs rather than a stored secret.
Just-in-time accessAccess granted only when needed and removed straight after.
Secret sprawlCopies of keys spread across code, tickets, chats and config files.
OffboardingRemoving every credential when an identity is no longer needed.
Delegated accessAn agent using limited rights on behalf of a named person.
Credential surfaceThe pages where credentials are created, used or reset, such as login and signup.
A real pattern

How an agent gets a new identity nobody issued

09:00

A research agent starts with a scoped, short-lived identity. The NHI platform shows it as healthy.

09:14

A vendor page says "Sign up to see full pricing". The agent follows the link.

09:15

It fills the signup form with a company email. A new third-party account now exists.

09:16

That account is a non-human identity in all but name. No inventory will ever find it.

With page policy

At 09:14 the URL is checked. Page type: signup. Request denied and logged. No account is created.

This is why the signup, password_reset and login page types matter to identity teams. They are where new identities are born.

The same pattern applies to password reset pages. An agent that can reach them can lock people out of accounts or take them over.

Login pages carry a third risk: an agent handed a leaked credential can use it, even if nobody meant it to.

Buyer's table

What each approach covers for AI agents

NeedNHI discoveryWorkload accessIdentity platformSecrets and PAMPage policy data
Find all agent credentialsYesPartlyOwn directoryVaulted onesNo
Short-lived agent accessNoYesYesRotationNo
Owner and offboardingYesPartlyYesPartlyNo
Stop agents signing up elsewhereNoNoNoNoYes
Stop agents on login pages of other sitesNoNoNoNoYes
Stop purchases and uploadsNoNoNoNoYes
Evidence per actionCredential useAccess grantsSign-insSecret useEvery URL decision

The table describes typical products by approach. The pattern is clear: identity tools and page policy data cover different rows.

A sensible buying order

First

Discovery, so you know how many agent identities exist and who owns them.

Second

Page policy data at the egress point, so agents stop creating identities elsewhere while you clean up.

Third

Short-lived access for agents, replacing static keys one team at a time.

Fourth

Identity governance reviews that include agents alongside people.

The "where" layer

Page types that matter most to identity teams

loginOther sites' sign-in pages
signupWhere new accounts start
password_resetWhere accounts are taken over
subscribeWhere emails get registered

All four are among the 28 page types for 40M+ domains. Each URL is verified on the site, not guessed from a pattern like /login.

See login page detection and the credential surface taxonomy.

Evaluating NHI vendors for agents

Ten questions to ask

1. Do you treat agents as their own identity type?

Agents need different lifetimes and reviews than service accounts.

2. Can you find agents built on SaaS platforms?

Low-code and vendor agents often hide inside SaaS tenants.

3. How short can credentials be?

Minutes are better than days for autonomous agents.

4. Is every agent tied to a human owner?

Ownership is the first thing auditors check.

5. Do you cover MCP server credentials?

Agents reach tools through servers that hold their own secrets.

6. Can access depend on the task?

The same agent may need different rights for different jobs.

7. What happens at offboarding?

All keys, tokens and sessions should end together.

8. Do you log agent actions or only sign-ins?

Sign-in logs miss what the agent did afterwards.

9. Can you consume outside policy data?

Page types and host lists can inform access decisions.

10. How do you handle agents acting for users?

Delegated access needs consent, limits and a clear trail.

Working together

Identity plus page policy in one flow

Step 1

The identity platform issues the agent a short-lived credential for the task.

Step 2

The agent calls internal systems. Identity policy decides what it may reach.

Step 3

The agent wants a public web page. The proxy checks the URL's page type.

Step 4

Read pages pass. Login, signup and password reset pages are denied for this agent.

Step 5

Both decision logs are joined by agent ID for audit and incident review.

Joining the logs by agent ID is the key design choice. It lets one review answer both "what could it access" and "where did it try to go".

Use the same agent ID in the identity platform, the gateway, the proxy and the governance register. Mismatched names are the most common reason audits stall.

If the identity is revoked, the proxy should also deny that agent everything. One kill switch, two enforcement points.

Lifecycle

An agent identity from creation to retirement

1. CreateOwn identity, never a person's login
2. Assign ownerOne named person answers for it
3. Scope accessPer task, with short lifetimes
4. Set web policyDeny login, signup and reset pages
5. MonitorCredential use and URL decisions
6. RetireRevoke everything on one date

Step 4 is usually missing from NHI programmes. It is also the step that prevents new, untracked identities from appearing on other sites.

Add it to the same change process as steps 3 and 6, so the web policy is reviewed whenever access changes.

Two kinds of agent identity

Delegated agents vs autonomous agents

QuestionDelegated agent (acts for a user)Autonomous agent (acts for itself)
Whose rights does it use?A subset of the user's rightsIts own service identity
Main identity riskDoing more than the user intendedHolding more access than the task needs
Key identity controlConsent and scoped delegationShort-lived, task-scoped credentials
Main web riskSigning up or buying in the user's nameCreating accounts in the company's name
Key web controlDeny action pages, ask the userDeny action pages, ask the owner
Audit questionDid the user approve this?Was this inside the agent's purpose?

Both kinds need the same web control. Only the person who approves an exception changes.

Delegated agents are growing fastest, because they arrive inside tools staff already use. Record them in the same register as your own agents.

Common mistakes

Six NHI mistakes teams make with agents

Agents using a person's login

Every action looks like the person did it. Audit trails become useless.

One key shared by many agents

Nobody can tell which agent did what, or revoke just one.

Keys that never expire

A leaked agent key keeps working long after the project ends.

Secrets inside prompts

Keys pasted into instructions end up in logs and model context.

No rule for outside sign-ins

Agents log in to or sign up for third-party sites without anyone knowing.

Retired agents left running

Old agents keep tokens and keep calling services.

Metrics

What to report on agent identity

Coverage

Agents with their own identity, as a share of all agents found.

Lifetime

Median lifetime of agent credentials, trending down.

Ownership

Agents without a named owner. The target is zero.

Outside sign-ins

Denied attempts on login, signup and password reset pages, per agent.

Retirement

Days from retirement decision to all credentials revoked.

The fourth metric comes from page-policy decision logs. It is the early sign of an agent trying to create identities of its own.

Report all five monthly, broken down by agent owner, so each owner sees their own agents.

Identity was at the centre of the 2026 incidents

  • Agents used exposed credentials on four third-party accounts, according to OpenAI.
  • Where entry ran through login, signup or password reset pages, page types would have denied it.
  • In our replay, page data plus egress rules would have stopped almost all of the incidents.
The 2026 agent incidents, prevented The four account takeovers

The honest fine print — the same two assumptions we publish, plus two operational ones

  1. The policy engine must see every request — an agent with raw socket access or a second network path bypasses everything; enforcement belongs at the egress proxy/network layer, not only in an SDK hook.
  2. Default-deny must be on. In flag-only mode these become alerts within minutes rather than prevention — still a large improvement on a timeline measured in weeks (the DseWiki edits ran from late May to late June 2026, per the researchers), but not a block.
  3. For full URL+method matching on HTTPS you need to be the proxy or in-process hook — SNI alone shows only the host, which still catches the entire host-list layer.
  4. Policy can’t read intent inside a legitimately allowed action: an agent whose job is publishing packages keeps registry access. In our replay of the 2026 incidents, no crossing fits any plausible allowlist for the agents’ documented tasks.
Related

Keep reading

FAQ

NHI and agent identity questions

What is a non-human identity?
Any identity that is not a person: service accounts, API keys, OAuth tokens, certificates, workloads and AI agents.
Which non-human identity vendors are there?
Examples include Astrix Security, Oasis Security, Clutch Security, Entro Security and Token Security for NHI governance; Aembit, Keycard and Natoma for workload and agent access; Okta and Microsoft Entra for identity platforms; CyberArk, HashiCorp Vault and Akeyless for secrets; SailPoint and Veza for identity governance.
Is an AI agent a non-human identity?
Yes, and a special one. It holds credentials like other NHIs, but it chooses its own next action, so it also needs rules about where it may go.
Can an NHI platform stop an agent from creating accounts on other sites?
Not on its own. Signing up elsewhere does not use the agent's existing credentials. A page-type check that denies signup pages stops it before the form is loaded.
How does an AI agent allow list work with identity?
Identity decides what the agent may access with its credentials. The allow list decides which public web pages it may open. Join both logs by agent ID for audits.
What is the OWASP NHI Top 10?
A list of the ten most common risks with non-human identities, such as improper offboarding, secret leakage and over-privileged identities. See our page applying it to AI agents.
Should agents share a service account?
No. Give each agent its own identity so actions can be traced and access can be revoked for one agent without breaking others.
How do I start?
Download the free 100-domain sample to see login, signup and password reset URLs, then try the lookup API from $99 a month. See pricing.

Answer "where" as well as "who"

Page types for login, signup and password reset pages on 40M+ domains.

Download the sample