The industry map
The main NHI products and services on the market, grouped by what part of the question they answer — because most answer part, and a mature programme combines a discovery-and-posture layer, a secrets layer and a workload-identity layer under one policy. Each provider has a profile page compiled from published materials; nothing here is a hands-on assessment (those live under Options, with the scenario and the columns).
Grouping and vendor claims are drawn from the Aembit vendor guide and the 2026 NHI tools survey, plus vendor materials. Date verified: 18 August 2026 — this market moves monthly; corrections via comms. Vendors are mapped as complementary layers, not ranked: the cited guidance is that most enterprises use several parts of this stack.
Open standards & reference implementations
| Name | What it is | Profile |
|---|---|---|
| SPIFFE / SPIRE | The open, vendor-neutral workload identity standard: attested, short-lived cryptographic identities without long-lived secrets. The mature answer for agents you run — and the clearest illustration of the thesis, since it requires infrastructure you control. | Concept page, with diagrams → |
NHI discovery, posture & governance
Who exists, what can each reach, who owns it, when does it die. The layer the CSA survey found most organisations missing.
| Provider | Focus | Profile |
|---|---|---|
| Astrix Security (Cisco) | Shadow-agent and NHI discovery, privilege analysis, lifecycle governance; Agent Control Plane | Profile → |
| Entro Security | Secrets-centric: agent-to-credential mapping, ownership, exposure, detection & response | Profile → |
| Oasis Security | One programme for service accounts, machine identities and agents; intent-aware access | Profile → |
| Token Security | Machine-first identity security across hybrid environments | Profile → |
| Veza (ServiceNow) | The authorization graph: effective permissions, excessive access, least privilege | Profile → |
| SailPoint | Identity governance extended to agents: ownership, certification, lifecycle | Profile → |
Workload IAM & runtime access
Authenticate the workload, evaluate policy, deliver credentials just-in-time — no standing secrets.
| Provider | Focus | Profile |
|---|---|---|
| Aembit | Secretless, policy-based runtime access for workloads and agents; MCP Identity Gateway | Profile → |
Secrets management & detection
Where credentials live, how they rotate — and how you find the ones that leaked.
| Provider | Focus | Profile |
|---|---|---|
| HashiCorp Vault (IBM) | The reference secrets manager; dynamic credentials; now issues SPIFFE identities natively | Profile → |
| CyberArk (Palo Alto Networks) | PAM + Conjur secrets + the Venafi machine-identity line; agent discovery, MCP identity broker | Profile → |
| Akeyless | SaaS-delivered secrets and key management, multi-cloud | Profile → |
| GitGuardian | Secrets detection in code and pipelines — the leaked-credential compensating control | Profile → |
Machine identity & certificates
Certificate lifecycle at machine scale — the layer an agent-key registry would sit beside.
| Provider | Focus | Profile |
|---|---|---|
| Keyfactor | PKI automation, short-lived certificates, crypto-agility | Profile → |
| Venafi (CyberArk) | TLS and code-signing certificate lifecycle automation | Covered in the CyberArk profile → |
Human IAM platforms extending to agents
Agents managed through the same identity provider as the workforce — the platform-native answers.
| Provider | Focus | Profile |
|---|---|---|
| Microsoft Entra (Agent ID) | Agents as first-class identities inside the Microsoft ecosystem | Profile → |
| Okta (+ Auth0) | Agent discovery, registration and governance through the workforce IdP | Profile → |
How to read this map against the thesis
Every group above serves the population that runs its own workloads, or governs the credentials the other population hands over. That is not a criticism — it is the thesis, observable in a market map: attestation-based identity requires infrastructure you control; discovery, governance, secrets and detection make the do-nothing baseline more survivable without changing its nature; and the platform IdPs offer per-agent identity exactly as far as their platform boundary. The shared-drives research is the same observation at scenario level, and the PKI section is the design for the missing piece.