Standing is not the same thing as the action.
Astrix built the most complete picture of the agent and machine-identity estate that anyone in this category publishes, and it arrives in an afternoon with nothing installed. It is worth being precise about what that picture is for, because it is worth a great deal — and about the one step it stops short of.
What the product actually is
Worth stating plainly, because the category name attracts products that do much less than this one. Astrix is three things that fit together, and the first of them is the reason the other two exist.
- Discoverconnect over APIs — agentless, non-proxy, metadata only, minimal permissions — and within hours hold a real-time inventory of AI agents that are custom, third-party or home-grown, managed and shadow, plus MCP servers, service accounts, OAuth apps, API keys, SSH keys, IAM roles and secrets inside and outside the vaults. An identity graph maps each one to the platforms and the specific resources it can reach, and to a responsible human owner.
- Securerisk-score everything in that inventory, then fix it. Excessive permissions removed, weak configurations corrected, shadow agents onboarded and unused ones offboarded, owners assigned. Machine-learning baselines flag unusual access patterns and out-of-scope activity, and access policy — allow, flag and block, scoped by user, department, platform and resource type — is evaluated before an action executes.
- Deploytheir Agent Control Plane applies policy at creation. An administrator defines least-privilege permission profiles, a developer launches an agent against a pre-approved one, and the agent runs on short-lived, precisely scoped, auto-expiring tokens with an audit trail per agent and drift detection on top.
- And now, Ciscothe acquisition has completed, and the capabilities are moving into Identity Intelligence, Secure Access, Duo and Splunk. For a buyer weighing whether a young vendor will still be here in three years, that is a real answer, and it is why one row of the sixteen goes to them.
Where Astrix is strongest
One of the sixteen rows below goes to Astrix and four more are level. They follow from a real difference in where each product places itself: theirs is beside the environment, reading it completely; ours is on the path of the action.
- Discovery, level at the top twiceagentless discovery and shadow-agent discovery are both even, and they are even at 5. Nothing installs, nothing self-registers, nothing has to be filed first, and the correlation across vaults, CI/CD and ephemeral sessions finds the agents that were never anybody's project. This is the capability the category is bought for and they are as good at it as anyone.
- A named owner on every agent, levelassigned automatically, from the graph, rather than requested in a spreadsheet nobody fills in. Most products we score cannot answer who is responsible for an agent at all; this one answers it for the whole estate on the first day. Even, and printed as even.
- Time to a first governed agent, levelfive minutes to connect and an inventory within hours is the fastest start we have scored. We govern in days rather than minutes because our first action is a verdict rather than a read, and both of those are honest ways to reach a first governed agent — so the row ties.
- Ecosystem breadththis row goes to them and it is earned. Remediation already runs through the buyer's own ITSM, SIEM and SOAR tooling, and the platform now carries Cisco's distribution and its security portfolio behind it. We are a focused platform rather than a marketplace presence, and that row is a 2 for us on every comparison we publish.
A policy about standing, and a policy about the action
Their access policy is real and the table scores it as real. Rules are evaluated before an action executes, and they can be written about the user, the department, the platform and the resource type. Every one of those is a property of the agent's standing: who it belongs to, what it is entitled to reach, which class of thing it may touch.
The platform is non-proxy by its own description, which is a deliberate design choice and the reason onboarding takes five minutes instead of a quarter. The consequence is that it is not in the request path. A rule can decide that this agent may reach this platform and this class of resource; the individual write, export or delete then happens between the agent and the system, and comes back to Astrix as activity to score rather than as a request to adjudicate.
That is why the remediation verbs are the ones they are — rotate the secret, cut the permission, revoke the access, offboard the identity, open the ticket. All of them change what the agent will be able to do next. None of them is available while the action is in flight, which is where masking a response, stepping up authentication or holding a write for a named person have to happen if they are going to happen at all.
An owner answers for the agent; someone else answers for the write
Automatic owner assignment across a whole estate is a hard problem solved well, and it ties at the top of the scale for that reason. It is worth separating from the question next to it, because the two get used interchangeably and they are not the same.
An owner is who answers for the agent existing: who created it, who maintains it, who is called when it misbehaves. That is a property of the agent, and it holds still. Attribution is who a particular action was taken for, and it changes with every call. Their own policy scope names departments, which is the tell — an agent serving a department has one owner and many people it acts on behalf of, and the audit trail is kept per agent.
It matters at the two moments this is usually bought for. In an investigation, the owner tells you who to ring and the per-action record tells you what happened and for whom; only one of those closes the question. In an approval, a verdict that has to reach a person in seconds needs to know which person this specific write concerns, not who filed the agent.
What the acquisition changes, and what it does not
It settles the vendor-risk question, which for a security buyer is not a small thing, and it is scored where it belongs rather than used as an argument. The capabilities are stated as moving into an identity intelligence product, a secure access product, an access management product and a data platform. For customers already in that estate, that is compounding value.
For everyone else it is a consideration on the operating row. Remediation already runs through the buyer's own service management, SIEM and orchestration tools by design, and an integration path into four more products is a surface count that grows rather than shrinks. Neither of those is a criticism of the architecture; both are things to ask about on the call.
What is not published
Three things were dropped rather than guessed. There is no pricing or packaging page, so the pricing unit is scored on that absence once and total platform cost is not scored at all. There is no published decision latency, so that row is not on the page. And agent-to-agent authority chaining and delegated on-behalf-of access do not appear in the product material in either direction, so neither is scored — an absence from a marketing site is not evidence of an absence from a product.