nhi.sgit.ai / industry

The industry map

The main NHI products and services on the market, grouped by what part of the question they answer — because most answer part, and a mature programme combines a discovery-and-posture layer, a secrets layer and a workload-identity layer under one policy. Each provider has a profile page compiled from published materials; nothing here is a hands-on assessment (those live under Options, with the scenario and the columns).

Map status

Grouping and vendor claims are drawn from the Aembit vendor guide and the 2026 NHI tools survey, plus vendor materials. Date verified: 18 August 2026 — this market moves monthly; corrections via comms. Vendors are mapped as complementary layers, not ranked: the cited guidance is that most enterprises use several parts of this stack.

Open standards & reference implementations

NameWhat it isProfile
SPIFFE / SPIREThe open, vendor-neutral workload identity standard: attested, short-lived cryptographic identities without long-lived secrets. The mature answer for agents you run — and the clearest illustration of the thesis, since it requires infrastructure you control.Concept page, with diagrams →

NHI discovery, posture & governance

Who exists, what can each reach, who owns it, when does it die. The layer the CSA survey found most organisations missing.

ProviderFocusProfile
Astrix Security (Cisco)Shadow-agent and NHI discovery, privilege analysis, lifecycle governance; Agent Control PlaneProfile →
Entro SecuritySecrets-centric: agent-to-credential mapping, ownership, exposure, detection & responseProfile →
Oasis SecurityOne programme for service accounts, machine identities and agents; intent-aware accessProfile →
Token SecurityMachine-first identity security across hybrid environmentsProfile →
Veza (ServiceNow)The authorization graph: effective permissions, excessive access, least privilegeProfile →
SailPointIdentity governance extended to agents: ownership, certification, lifecycleProfile →

Workload IAM & runtime access

Authenticate the workload, evaluate policy, deliver credentials just-in-time — no standing secrets.

ProviderFocusProfile
AembitSecretless, policy-based runtime access for workloads and agents; MCP Identity GatewayProfile →

Secrets management & detection

Where credentials live, how they rotate — and how you find the ones that leaked.

ProviderFocusProfile
HashiCorp Vault (IBM)The reference secrets manager; dynamic credentials; now issues SPIFFE identities nativelyProfile →
CyberArk (Palo Alto Networks)PAM + Conjur secrets + the Venafi machine-identity line; agent discovery, MCP identity brokerProfile →
AkeylessSaaS-delivered secrets and key management, multi-cloudProfile →
GitGuardianSecrets detection in code and pipelines — the leaked-credential compensating controlProfile →

Machine identity & certificates

Certificate lifecycle at machine scale — the layer an agent-key registry would sit beside.

ProviderFocusProfile
KeyfactorPKI automation, short-lived certificates, crypto-agilityProfile →
Venafi (CyberArk)TLS and code-signing certificate lifecycle automationCovered in the CyberArk profile →

Human IAM platforms extending to agents

Agents managed through the same identity provider as the workforce — the platform-native answers.

ProviderFocusProfile
Microsoft Entra (Agent ID)Agents as first-class identities inside the Microsoft ecosystemProfile →
Okta (+ Auth0)Agent discovery, registration and governance through the workforce IdPProfile →

How to read this map against the thesis

Every group above serves the population that runs its own workloads, or governs the credentials the other population hands over. That is not a criticism — it is the thesis, observable in a market map: attestation-based identity requires infrastructure you control; discovery, governance, secrets and detection make the do-nothing baseline more survivable without changing its nature; and the platform IdPs offer per-agent identity exactly as far as their platform boundary. The shared-drives research is the same observation at scenario level, and the PKI section is the design for the missing piece.