Ciscoβs planned acquisition of Astrix Security put more attention on non-human identity, but βNHI platformβ still describes products with different control points.
This page uses five buyer-oriented buckets to separate those control points. It is my evaluation framework, not an industry-standard taxonomy or a complete vendor ranking.
Why the Category Needs a Map
The Cloud Security Allianceβs 2024 NHI survey found that 15% of respondents felt highly confident in preventing NHI attacks, while 69% expressed concern about them.
CSA listed service-account management, discovery, auditing, privilege management, and policy enforcement among the main pain points. That breadth helps explain why products using the same NHI language may solve different problems.
| Buyer need | Primary control | Example reviewed here |
|---|---|---|
| Workload and agent access | Short-lived, policy-controlled access | Aembit |
| NHI and agent governance | Discovery, lifecycle, privilege and threat context | Astrix |
| Just-in-time privilege | Dynamic, time-bounded access | Apono |
| Secrets lifecycle | Storage, issuance, rotation and revocation | HashiCorp Vault |
| Identity threat detection | Runtime identity monitoring and response | Permiso |
These buckets can overlap. The table describes the emphasis visible in each vendorβs public product material, not a claim that the vendor offers only one capability.
1. Workload and Agent Access
Aembit presents separate IAM offerings for workloads and agentic AI. Its public material emphasizes unique workload or agent identities, policy-based access, auditing, and short-lived tokens instead of broadly distributed static credentials.
This category fits teams asking how one workload, CI job, or agent should authenticate to another service. It is different from discovering every existing OAuth grant or monitoring a stolen identity after compromise, although a product may integrate with those layers.
2. NHI and Agent Governance
Astrix describes a platform for discovering, securing, and managing AI agents, MCP servers, and other NHIs. Its published capabilities include inventory, excessive-privilege findings, lifecycle management, threat detection, and short-lived, scoped credentials through its Agent Control Plane.
On May 4, Cisco announced its intent to acquire Astrix . Cisco said it planned to integrate Astrix capabilities into Cisco Identity Intelligence, Secure Access, and Duo; the same post was later updated to record completion on June 29.
Cisco did not disclose the transaction price in that announcement. The previously cited roughly $400 million figure came from secondary reporting and has been removed from the core comparison.
3. Just-in-Time Privilege
Apono describes a cloud and hybrid access platform that creates roles, permissions, and policies dynamically at request time. Its product language focuses on just-in-time and just-enough access for humans, machines, and AI agents, with automatic revocation.
This bucket is relevant when the problem is standing privilege to cloud resources, Kubernetes, or databases. Buyers should still verify whether the same product discovers SaaS OAuth grants, manages stored secrets, or detects identity misuse in the environments they need.
4. Secrets Lifecycle
HashiCorp Vault provides identity-based access to secrets, certificates, and keys. Its public product page describes on-demand certificate and key operations, short-lived credentials, automated rotation, and policy controls for humans, machines, services, and AI agents.
A secrets platform can be a major part of an NHI program because it controls how credentials are issued and retired. That does not automatically prove coverage of every OAuth installation, package-publisher permission, or runtime agent action; those requirements need separate verification during evaluation.
5. Identity Threat Detection
Permiso markets discovery, posture management, and identity threat detection and response for human, non-human, and AI identities across cloud and on-premises environments.
This bucket asks what an identity is doing at runtime and whether that behavior indicates compromise. It complements preventive access controls, but the exact supported identity sources and response actions should be tested against the buyerβs environment.
How to Evaluate the Vendors
Start with the control gap, not the category label:
- List the non-human actors that can change code, publish packages, run CI, reach cloud resources, or access SaaS data.
- Record whether each identity is discovered, owned, scoped, rotated, monitored, and revocable.
- Map each missing control to workload access, governance, JIT privilege, secrets lifecycle, or runtime detection.
- Ask vendors to demonstrate the exact identity sources and enforcement actions you need.
- Test whether the product only inventories risk or can also reduce privilege, revoke access, or trigger a response.
Avoid fixed assumptions about product boundaries. Public feature pages change, integrations expand, and several vendors already span more than one of these buckets.
The useful output is not a single βbest NHI vendor.β It is a coverage map showing which identities and controls remain unowned after the products you already operate are included.
Which vendor or control belongs in a different bucket? Reply and tell me; Iβll update the map when the public evidence supports the change.