What the verdict is derived from.
This is not a comparison between a product that enforces and a product that watches. Oasis enforces, in real time, and the table prints four level rows saying so. The distinction sits one step earlier, in what the policy engine is handed before it decides: a purpose inferred from the text of a request, or a principal whose entitlement can be looked up.
The enforcement is real, and it reads intent
It is worth settling this before anything else on the page, because the category name invites the wrong assumption. A non-human identity platform is usually an inventory with a remediation queue attached. This one ships an inline product: a request is evaluated deterministically against policy in real time, a risky action is stopped before it reaches data, and a privilege boundary that gets crossed escalates to a person rather than failing silently.
The step that makes it distinctive comes before the policy check. A language model reads the prompt, the tool call or the action plan and turns it into a structured intent — which resource, which operation, which scope, and for what purpose — so a rule can be written about why an agent wants something rather than only about what it is touching. That is a real idea and it is not a common one. Four published rows come out level at the top of the scale as a result: human-in-the-loop approval, the agent identity object, the audit record per action, and agentless discovery.
Where Oasis Security is strongest
Three of the sixteen rows go to them outright, plus the four level ones above. They follow from the same decision: treat the credential as the thing you manage, and manage all of it rather than part of it.
- Rotation that actually runssecrets rotate automatically at a defined interval through the customer's own vault, configured once as policy and then executed by the platform without a person driving it. Anyone who has run a rotation programme knows the hard part is not deciding to rotate — it is rotating without taking down the workload that depended on the old value, which is why so many organisations have a rotation policy and a set of keys that are four years old. Agen does not rotate credentials and does not claim to; that row scores a 1 in our column and it is printed rather than left out.
- The whole lifecycle, not a slice of itprovisioning, ownership assignment, vaulting, posture, rotation and decommission are named stages of one workflow, and stale identities are identified and retired rather than accumulating. Ownership is resolved with CMDB data and heuristics that suggest an owner, then closed out through certification campaigns. We govern what an agent does; the birth-to-death administration of the credential it carries is their row and they win it.
- Where it plugs inthe integration story runs in both directions — a listing in the Okta Integration Network, and a Wiz integration that pulls posture findings into Oasis and enriches each one with identity and usage context. That marketplace breadth is a row we score ourselves a 2 on. We are a focused platform rather than an ecosystem, which is a deliberate choice with a real cost, and the table prints the cost.
- Level, not lostfour more rows finish even, and they are not consolation rows. Escalating a risky action to a human for approval, giving every agent a first-class identity object, writing an audit record for each action, and discovering identities across the estate through APIs with nothing to install — on all four, both products are doing the same thing to the same depth.
An inferred purpose is not an authenticated principal
Here is the boundary the table is built around. Their policy engine is handed a structured intent produced by a language model reading a request. That inference can be very good, and it answers a question worth asking: what is this agent trying to do, and does the estate permit that kind of thing? What it cannot answer is a different question entirely — is this specific person, on whose behalf this agent is running, entitled to this specific resource at this moment?
The published accountability chain runs prompt, intent, policy, session, action, and it captures who invoked the agent. For an interactive agent that is a genuine attribution and the table scores it as one. The gap opens on the agents that matter most in production: the scheduled job, the workflow triggered by a webhook, the agent that runs overnight with nobody in the room. There is no invoking user for the chain to record, and the accountable party becomes the system that started it.
Agen runs humans, machines and agents as primitives on one fabric, on a customer identity foundation that has been in production for seven years. Because the human is in the same fabric as the agent, entitlement at the moment of the action is a lookup rather than an inference — and an autonomous agent still carries a named person who answers for it, because the ownership is a property of the identity rather than a record of who happened to type something.
The session is the unit of access
Just-in-time session identities are the mechanism that replaces standing secrets, and on their own terms they work: an ephemeral, least-privilege credential is provisioned for a window measured in seconds to minutes, used, and gone. Against the alternative — a long-lived key in an environment variable that nobody has rotated since it was created — this is a straightforward improvement, and the row about the identity object publishes level because of it.
The scoring turns on tense. A credential issued for a window is a decision made at the start of that window about everything the agent will do inside it. Narrow the window and you narrow the blast radius, which is the entire point and it is well made. You do not change what the decision was about. The row scores a 3 rather than a 5 for exactly that reason: the check is per session, and a session is many actions.
The verdict runs where the host agrees to ask
The published integration pattern is a hook fired by the agent's host application. Their own worked example uses an editor's pre-execution hook, which posts the tool name, the input, the model and the user to an endpoint and acts on what comes back — allow, warn, step up, or deny. That is a clean design and it produces a real inline verdict, which is why the runtime row scores a 3 and not lower.
The property to check against your own estate is that the host has to make the call. An agent running in a host without that hook, a script hitting an API directly, a person working in a browser tab — none of those fire a callout, and none of them meet a decision point. Endpoint coverage in the published material is visibility rather than enforcement, and no browser enforcement point appears at all, which is where those two rows land. Both products then depend on very different things: theirs on the host cooperating, ours on being present where the agent acts.
What is not published
Two absences shape the table. There is no latency figure anywhere in the public material, which matters more here than it usually would, because a language model inference sits on the decision path before policy is evaluated — so the row scores on the absence rather than assuming either a good number or a bad one. And the pricing page publishes no unit, tier or rate; it routes to a demo request. That is a normal enterprise motion, but it means the cost of governing a hundred agents cannot be modelled before a sales conversation. The total-cost row was dropped rather than scored a second time off the same absence.
Three more rows were held. Agent-to-agent authority chaining is not documented either way, so it was dropped rather than guessed in our favour. The new-integration commitment is unpublished on their side. And our own audit-first rollout row stays held pending internal confirmation, which is the seventh comparison in a row it has sat out.