The Business of Cyber Security

MCP & Agent Identity

Related: AI Security, Identity, Security for AI, AI for Offense.

On May 4, 2026, Cisco announced its intent to acquire Astrix Security — a non-human-identity (NHI) startup — for a reported ~$400M (Cisco blog; Calcalist), its third cybersecurity acquisition of 2026 after Galileo and ahead of WideField Security (Jun 18 2026). Astrix had raised ~$85M total (including a $45M Series B in Dec 2024 from CRV and Menlo Ventures), so the reported price is a substantial strategic premium for a company most enterprise buyers had not yet deployed at scale. (Reported intent, subject to closing.) The rationale reflects a structural shift AI is forcing on the identity market: every AI agent is a new identity that must be authenticated, scoped, monitored, and revoked — and there are about to be far more of them than there are humans. This shift, and the protocol layer (Model Context Protocol) that makes it urgent, are the subject below. The broader identity market sits on 03a; the new AI attack surface is 03l.

What a non-human identity is

A non-human identity is any credentialed actor that is not a person: a service account, an API key, an OAuth token, a machine certificate, a CI/CD secret, a service-mesh workload — and now, an AI agent. NHIs already vastly outnumber human identities in the enterprise; the commonly cited ratio is on the order of 45–50 non-human identities for every human (estimate; figures vary 40:1 to 100:1 by source and environment). They are also the worse-governed half of the identity estate: secrets get hard-coded, tokens never expire, service accounts accrete permissions no one revokes, and most never appear in the joiner-mover-leaver lifecycle that governs human accounts. NHIs were already the leading breach vector in cloud environments before agents arrived.

AI agents make the problem categorically worse along three axes:

  1. Volume. An agentic workflow can spawn many short-lived agent and sub-agent identities, each needing credentials to call tools, APIs, and data stores. The NHI population stops being a stock and becomes a flow.
  2. Autonomy. A human's actions are bounded by what a human can do per hour. An agent acts at machine speed and can chain tool calls — so an over-permissioned agent identity is a far larger blast radius than an over-permissioned human.
  3. Delegation ambiguity. When an agent acts "on behalf of" a user, whose authority is it exercising, and within what scope? Traditional IAM has no clean answer. This is the agent-identity problem proper.

The agentic identity lifecycle

Every AI agent runs the same identity gauntlet — and platforms want to own it The five-stage non-human / agent identity lifecycle; the discipline humans get, agents mostly don't 1 · Discover find every NHI & agent; map ownership 2 · Authenticate verify identity; secretless / attestation 3 · Authorize least-privilege scope; delegation on-behalf-of 4 · Monitor detect drift, anomalous agent behavior 5 · Revoke rotate / offboard; kill switch Stage 3 (Authorize) is where agents break the model Human IAM answers "who are you?"; agentic IAM must answer "whose authority, for which task, for how long?" — scoped, time-boxed, on-behalf-of delegation that today's tokens don't natively carry. Schematic. Reflects NHI/agent-identity vendor architectures (Astrix, Oasis, Aembit, Token, Entro). Exhibit: The Business of Cyber Security.
Humans get a disciplined joiner-mover-leaver lifecycle; non-human and agent identities mostly don't. The vendor that owns all five stages owns the agentic identity control plane — which is why identity platforms (Cisco→Astrix, SailPoint→Entro, and the [PANW–CyberArk](03a-identity.md) combination) are buying into it rather than building. Stage 3 is the unsolved frontier.

MCP — the protocol layer

Model Context Protocol (MCP), the open standard Anthropic introduced in late 2024, is the USB-C of agentic AI: a uniform way for an AI agent to connect to tools, data sources, and external systems via "MCP servers." Adoption exploded through 2025–2026 because it solved a real integration problem — but it also created a new, poorly-secured trust boundary. An agent that can call arbitrary MCP servers can be steered by whatever those servers return. The recognized MCP attack classes now include:

MCP makes the agent-identity problem concrete: each MCP connection is a delegation decision, and most early deployments grant agents standing, over-broad credentials with no scoping, expiry, or audit. Securing MCP is securing agent identity plus the data/tool boundary.

The named landscape

Actor What it does How it makes money M&A status / relevance
Astrix Security NHI + AI-agent discovery, governance, lifecycle, secrets SaaS platform subscription Cisco intent to acquire ~$400M (announced May 4 2026; subject to closing) — the category's marquee exit
Oasis Security NHI lifecycle management & posture for agents SaaS subscription Cyera agreement ~$1B (announced Jul 28 2026; ~$700M cash + Cyera stock) — the largest NHI/agent-identity exit to date; had raised ~$195M ($120M Series B Mar 19 2026), the largest pure NHI round. A data-security platform absorbing agent identity
Aembit Secretless workload IAM; cryptographic attestation via an Edge sidecar Workload-IAM subscription Independent; differentiates on no secrets — verify, don't store
Token Security NHI + machine/agent identity security SaaS subscription Well-funded independent; agent-identity positioning
Entro Security NHI & secrets security (acquired) Acquired by SailPoint — identity-governance leader bolting on NHI (03a)
Clutch Security · GitGuardian · Natoma · Britive NHI discovery, secrets detection, just-in-time NHI access SaaS / consumption The independent field; consolidation candidates
CyberArk (now PANW) Secrets management + machine identity at platform scale Platform The incumbent control point — agent identity folds into the PANW–CyberArk platform

The falsifiable bear case

Three ways the "agent identity is a durable standalone market" thesis could disappoint. First, it is a feature, not a market: NHI/agent identity may be absorbed wholesale into the identity and data-security platforms (Okta, Microsoft Entra, PANW-CyberArk, SailPoint, Cyera) the moment they ship native agent governance — Cisco buying Astrix, SailPoint buying Entro, Cyera buying Oasis (~$1B, Jul 2026), and Okta buying Permiso (ITDR across human, machine and agent identities, Jul 30 2026) are evidence for this absorption, not against it, and they leave little room for standalone scale. Okta's move also extends the pattern from identity issuance into identity detection: the platforms are absorbing both the credentials the agents carry and the runtime monitoring of how those credentials behave. Keyfactor buying Cofide (Jul 27 2026, SPIFFE-based workload/agent identity) is the issuance counterpart — a machine-identity/PKI incumbent absorbing the layer that hands each agent a short-lived verified identity. Second, the protocol layer standardizes the problem away: if MCP, OAuth working groups, and the model providers bake scoped, delegatable, expiring agent credentials into the protocol and the platforms themselves, the third-party "agent IAM" layer thins out. Third, agent adoption underdelivers: if enterprise agentic deployment stays in pilot (as much of the 04c autonomous-SOC market still is), the NHI explosion is slower than the funding implies, and 2026's valuations look early. The falsification data: watch whether the remaining independents (Aembit, Token) reach durable eight-figure ARR before the platforms ship credible native agent governance — Oasis, the most-funded pure NHI vendor, exited to Cyera before that question was settled.

→ & angle

Sources: Cisco — intent to acquire Astrix Security (blog, May 4 2026); Cisco to acquire Astrix for ~$400M — Calcalist/Ctech; Astrix $45M Series B — GovInfoSecurity (Dec 2024); Oasis Security $120M Series B — Bloomberg, Mar 19 2026; Oasis $120M — GovInfoSecurity; NHI platform comparison 2026 — GitGuardian; RSAC 2026 NHI report — Cremit.


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.