MCP & Agent Identity

Related: AI Security, Identity, Security for AI, AI for Offense.

On May 4, 2026, Cisco announced its intent to acquire Astrix Security — a non-human-identity (NHI) startup — for a reported ~$400M (Cisco blog; Calcalist), its third cybersecurity acquisition of 2026 after Galileo and ahead of WideField Security (Jun 18 2026). Astrix had raised ~$85M total (including a $45M Series B in Dec 2024 from CRV and Menlo Ventures), so the reported price is a substantial strategic premium for a company most enterprise buyers had not yet deployed at scale. (Reported intent, subject to closing.) The rationale reflects a structural shift AI is forcing on the identity market: every AI agent is a new identity that must be authenticated, scoped, monitored, and revoked — and there are about to be far more of them than there are humans. This shift, and the protocol layer (Model Context Protocol) that makes it urgent, are the subject below. The broader identity market sits on 03a; the new AI attack surface is 03l.

What a non-human identity is

A non-human identity is any credentialed actor that is not a person: a service account, an API key, an OAuth token, a machine certificate, a CI/CD secret, a service-mesh workload — and now, an AI agent. NHIs already vastly outnumber human identities in the enterprise; the commonly cited ratio is on the order of 45–50 non-human identities for every human (estimate; figures vary 40:1 to 100:1 by source and environment). They are also the worse-governed half of the identity estate: secrets get hard-coded, tokens never expire, service accounts accrete permissions no one revokes, and most never appear in the joiner-mover-leaver lifecycle that governs human accounts. NHIs were already the leading breach vector in cloud environments before agents arrived.

AI agents make the problem categorically worse along three axes:

  1. Volume. An agentic workflow can spawn many short-lived agent and sub-agent identities, each needing credentials to call tools, APIs, and data stores. The NHI population stops being a stock and becomes a flow.
  2. Autonomy. A human's actions are bounded by what a human can do per hour. An agent acts at machine speed and can chain tool calls — so an over-permissioned agent identity is a far larger blast radius than an over-permissioned human.
  3. Delegation ambiguity. When an agent acts "on behalf of" a user, whose authority is it exercising, and within what scope? Traditional IAM has no clean answer. This is the agent-identity problem proper.

The agentic identity lifecycle

Every AI agent runs the same identity gauntlet — and platforms want to own it The five-stage non-human / agent identity lifecycle; the discipline humans get, agents mostly don't 1 · Discover find every NHI & agent; map ownership 2 · Authenticate verify identity; secretless / attestation 3 · Authorize least-privilege scope; delegation on-behalf-of 4 · Monitor detect drift, anomalous agent behavior 5 · Revoke rotate / offboard; kill switch Stage 3 (Authorize) is where agents break the model Human IAM answers "who are you?"; agentic IAM must answer "whose authority, for which task, for how long?" — scoped, time-boxed, on-behalf-of delegation that today's tokens don't natively carry. Schematic. Reflects NHI/agent-identity vendor architectures (Astrix, Oasis, Aembit, Token, Entro). Exhibit: The Business of Cyber Security.
Humans get a disciplined joiner-mover-leaver lifecycle; non-human and agent identities mostly don't. The vendor that owns all five stages owns the agentic identity control plane — which is why identity platforms (Cisco→Astrix, SailPoint→Entro, and the [PANW–CyberArk](03a-identity.md) combination) are buying into it rather than building. Stage 3 is the unsolved frontier.

MCP — the protocol layer

Model Context Protocol (MCP), the open standard Anthropic introduced in late 2024, is the USB-C of agentic AI: a uniform way for an AI agent to connect to tools, data sources, and external systems via "MCP servers." Adoption exploded through 2025–2026 because it solved a real integration problem — but it also created a new, poorly-secured trust boundary. An agent that can call arbitrary MCP servers can be steered by whatever those servers return. The recognized MCP attack classes now include:

MCP makes the agent-identity problem concrete: each MCP connection is a delegation decision, and most early deployments grant agents standing, over-broad credentials with no scoping, expiry, or audit. Securing MCP is securing agent identity plus the data/tool boundary.

Agent-mediated bypass of existing controls

The delegation problem described above has a demonstrated attack pattern. At DEF CON 2026 in Las Vegas on August 9, 2026, researchers from Tenet Security presented a technique they call Ghostjacking, positioned as the next stage of the earlier Agentjacking class, in which an AI coding agent is induced to execute arbitrary code on a developer's machine. Ghostjacking's distinguishing property is that it requires no new privilege. The attacker plants content that an agent will later read as ordinary operational data; the agent then acts on that content using access it has already been granted. No control fails and nothing anomalous appears at the credential layer, because at that layer nothing anomalous occurs.

Three platforms were used to demonstrate the pattern, none of them a security product:

The platforms named were Cloudflare, Datadog and Sentry; the researchers disclosed to all three in June 2026 and characterized the three cases as one shape rather than three separate flaws — wherever an AI reads outside data it trusts and can also act on that data, the boundary is open. Other pairings named as carrying the same shape include a log-analytics platform with a build system and an APM platform with a container orchestrator.

Scale is what makes the finding a market fact rather than only a technical one. Tenet's estimate is that half of the Fortune 500 are exposed. The footprints behind that estimate are large and overlapping: the edge provider is reported to run in about 42% of the Fortune 500 and to carry a fifth of all internet traffic, the APM vendor in about 48%, and the error-tracking tool to be used by about four million developers — figures that describe the same enterprises repeatedly and therefore cannot be added. Organizations running the exposed configuration were not identified and were described only by type.

Two consequences follow for the market covered on this page. The first is demand formation. The recommended mitigations — deny outbound network access by default, require human approval for any command an agent executes, prevent data an agent reads from becoming an instruction it runs, and treat every reachable token as at risk while inventorying every tool an agent connects to — correspond to stages 3 and 4 of the lifecycle above, and they are architectural rather than model-level, which is the portion of the problem that agent-identity and agent-runtime vendors sell against. The second is buyer identification. The systems carrying the exposure belong to observability, error-tracking and edge-delivery vendors (42a, 42e), which hold both the deployment footprint and the telemetry needed to add the control themselves, and which therefore belong alongside the identity and data-security platforms in the buyer universe for this category (11b).

Sources: Tenet Security — Ghostjacking and the agentic kill chain · Infosecurity Magazine — "Ghostjacking" Exploits AI Agents' Trusted Access to Evade Firewall Controls (Aug 10, 2026)

The named landscape

Actor What it does How it makes money M&A status / relevance
Astrix Security NHI + AI-agent discovery, governance, lifecycle, secrets SaaS platform subscription Cisco intent to acquire ~$400M (announced May 4 2026; subject to closing) — the category's marquee exit
Oasis Security NHI lifecycle management & posture for agents SaaS subscription Acquired by Cyera for ~$1B (announced Jul 28 2026; completed Sep 3 2026; ~$700M cash + Cyera stock) — the largest NHI/agent-identity exit to date; had raised ~$195M ($120M Series B Mar 19 2026), the largest pure NHI round, so the price is ~5.1x capital raised on a gross, pre-dilution basis. Now operates as Cyera Identity. A data-security platform absorbing agent identity
Aembit Secretless workload IAM; cryptographic attestation via an Edge sidecar Workload-IAM subscription Independent; differentiates on no secrets — verify, don't store
Token Security NHI + machine/agent identity security SaaS subscription Well-funded independent; agent-identity positioning
Entro Security NHI & secrets security (acquired) Acquired by SailPoint — identity-governance leader bolting on NHI (03a)
Clutch Security · GitGuardian · Natoma · Britive NHI discovery, secrets detection, just-in-time NHI access SaaS / consumption The independent field; consolidation candidates
CyberArk (now PANW) Secrets management + machine identity at platform scale Platform The incumbent control point — agent identity folds into the PANW–CyberArk platform

The falsifiable bear case

Three ways the "agent identity is a durable standalone market" thesis could disappoint. First, it is a feature, not a market: NHI/agent identity may be absorbed wholesale into the identity and data-security platforms (Okta, Microsoft Entra, PANW-CyberArk, SailPoint, Cyera) the moment they ship native agent governance — Cisco buying Astrix, SailPoint buying Entro, Cyera buying Oasis (~$1B, Jul 2026), and Okta buying Permiso (ITDR across human, machine and agent identities, Jul 30 2026) are evidence for this absorption, not against it, and they leave little room for standalone scale. Okta's move also extends the pattern from identity issuance into identity detection: the platforms are absorbing both the credentials the agents carry and the runtime monitoring of how those credentials behave. Keyfactor buying Cofide (Jul 27 2026, SPIFFE-based workload/agent identity) is the issuance counterpart — a machine-identity/PKI incumbent absorbing the layer that hands each agent a short-lived verified identity. Second, the protocol layer standardizes the problem away: if MCP, OAuth working groups, and the model providers bake scoped, delegatable, expiring agent credentials into the protocol and the platforms themselves, the third-party "agent IAM" layer thins out. Third, agent adoption underdelivers: if enterprise agentic deployment stays in pilot (as much of the 04c autonomous-SOC market still is), the NHI explosion is slower than the funding implies, and 2026's valuations look early. The falsification data: watch whether the remaining independents (Aembit, Token) reach durable eight-figure ARR before the platforms ship credible native agent governance — Oasis, the most-funded pure NHI vendor, exited to Cyera before that question was settled.

→ & angle

Sources: Cisco — intent to acquire Astrix Security (blog, May 4 2026); Cisco to acquire Astrix for ~$400M — Calcalist/Ctech; Astrix $45M Series B — GovInfoSecurity (Dec 2024); Oasis Security $120M Series B — Bloomberg, Mar 19 2026; Oasis $120M — GovInfoSecurity; NHI platform comparison 2026 — GitGuardian; RSAC 2026 NHI report — Cremit.


Updated 2026-10-04 19:34 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.