Comparison · agent governance · Onyx Security

Onyx Security, measured.

Onyx discovers the AI running across an enterprise and enforces policy inline on what it finds — blocking, masking, steering or escalating an action at the moment it would execute. This page scores that architecture across 16 capabilities against the same capabilities in Agen.co, with the sources, the scoring ladder, the seven rows that come out level, and the two rows Onyx wins.

The short answer

  • Onyx enforces. Five verdict types — alert, block, mask, steer and ask a human — applied inline at the moment an action would execute. This is not a comparison about whether they can stop something.
  • Coverage is broad: browser AI, coding assistants, desktop agents, cloud workloads and MCP servers, with a working inventory of an environment inside 24 hours.
  • Onyx issues each governed agent its own identity, in their words distinct from the user who invoked it, and records the invoking user and the agent owner on every tool call.
  • That identity sits outside the enterprise directory. It is why there is no step-up challenge among the verdicts, and why accountability stops at an Onyx-side record rather than a directory-backed name.
  • The scope is an enterprise's own workforce AI. Agents a company builds into its product and exposes to its customers are outside it.
  • Seven of the sixteen scored rows come out level, including inline enforcement, human approval, endpoint coverage and shadow discovery. Onyx wins browser enforcement and ecosystem breadth.
The long read

Broad enforcement, and the directory it sits beside.

Onyx is the most capable product in this comparison set, and the scored table says so: seven ties out of sixteen and two rows they win outright. The distinction worth a buyer's time is not whether they enforce, and it is not whether they know who acted. It is what that knowledge is anchored to, and which agents are inside the scope at all.


Five modules, one plane

Onyx presents as five modules on one platform: observability, security, governance, orchestration and a return-on-investment view. Observability is the entry point and the strongest of them — discovery combines directory scanning, native platform APIs and behavioural signature learning for browser-based AI across SaaS, cloud, endpoints and code, and most environments produce a working AI inventory inside a day.

Orchestration adds a managed gateway that routes across models for failover, latency and cost, and can either sit on top of an existing gateway to add inline policy inspection or handle routing itself. Deployment is cloud, hybrid or self-hosted. For a team that cannot route agent traffic through a vendor, that last property matters, and it is why the deployment row comes out level.

Enforcement is real, and the vocabulary is wide

This is where a comparison against a discovery-first product usually finds its argument, and here it does not. Onyx inspects every prompt, tool call and model response inline, and intervenes at the moment an action would execute: an unauthorised step is blocked, masked or redirected rather than logged after the fact. The verdict set is alert, block, mask, steer and ask — the last of those routing to a person for a decision.

That is a wide vocabulary, wider than most of this category manages, and it includes one verdict we do not have an equivalent for: steer, which redirects an agent's decision-making rather than stopping it. Policy is written in natural language and scopes over prompts, responses, agent actions and which tools and MCP servers are trusted. Four of the rows in this group come out level or near it, and the enforcement row is a clean tie.

Who the record names, and where that name lives

This is the row that decides the page, and it is closer than the category usually is. Onyx does resolve people. Each governed agent carries an owner alongside its permissions and lifecycle stage, and every session records the invoking user, the agent owner, and the identity used on each individual tool and MCP call. Called against most of this market, that is a strong answer.

The distinction is where that identity lives. Onyx describes each governed agent as carrying its own Onyx-attributed identity, distinct from the user who invoked it — a deliberate design, and their own phrasing for it. The agent is a first-class object inside Onyx, and the accountability line is one Onyx maintains rather than one the enterprise directory already holds.

Two consequences follow, and both are visible in the table rather than argued for. There is no step-up challenge among the five verdicts, because a step-up is a live challenge against an identity provider and no identity-provider integration is described. And the record is an account of what happened rather than a credential the action was permitted under, so it cannot be carried into a delegated request downstream.

Agen starts from the other end. The agent is a first-class identity in the same fabric as the humans and machines already in the directory, carrying a named accountable owner before it does anything. Every individual action is attributed to that person and judged in context in under 30ms, and because the identity is the enterprise's own, the same action can be escalated to a step-up challenge or delegated on someone's behalf without leaving the plane it was judged on.

Whose agents are in scope

The second boundary is scope, and it is the one most likely to decide a shortlist. Onyx's framing is consistent everywhere it appears: every company is becoming an agent operator, AI agents are now within reach of every employee, discovery runs across the enterprise. The product governs the AI an organisation's own people use.

  • Internal coverage is genuinely broad.Browser AI, coding assistants, desktop agents, cloud workloads and MCP servers, with discovery reaching SaaS, cloud, endpoints and code. On the internal side this is as wide as anyone's, and several of those rows are ties.
  • The browser is theirs.Browser AI leads their inline enforcement list, and discovery adds behavioural signature learning for it. Our own browser coverage is in early access, so this row goes to them and is published that way.
  • Customer-facing agents are outside it.No customer-facing, external, multi-tenant or product-embedded agent governance appears in any public material. A company that ships an agent to its own customers is governing something the product was not scoped for.

None of this is a shortcoming in what Onyx built. It is the shape of a product that chose the enterprise's own environment and covers it thoroughly. The question for a buyer is whether the agents they are accountable for are all inside that shape — and for anyone whose product has an agent in it, some are not.

What it costs to run

Onyx publishes no pricing page — the commercial path is a demo request. Nothing about that is unusual for an enterprise security platform, and it is scored as a capable-but-not-comparable answer rather than a failing. It does mean a buyer cannot model the cost of governing a growing agent estate before a sales conversation, which is the thing the pricing-unit row exists to measure.

Where Onyx is strongest

  • Browser enforcement, and the row they win.Browser AI is first in their inline enforcement list and carries dedicated behavioural signature learning in discovery. Our BrowserShield is in early access and scored as such on every comparison we publish, so this row goes to Onyx.
  • Ecosystem breadth, and the second row they win.Over a hundred pre-built integrations spanning the major clouds and model providers, named integrations for the large agent platforms, and a fully-managed open-source AI gateway. We are a focused platform rather than a marketplace, and this is the row where that shows.
  • Discovery, scored level.Directory scanning, native platform APIs and behavioural signatures combining into a working inventory of an environment inside 24 hours. On the row the rubric names as this archetype's real strength, we score level.
  • Inline enforcement and human approval, scored level.Five verdict types applied at the moment an action would execute, including routing to a person for a decision. On the surfaces they cover, the enforcement is as deep as ours.
  • Session replay in the audit record.Their per-action logging carries full session replay for forensics — a genuinely useful capability we do not offer in that form, on a row that scores level.
The scored comparison

Sixteen capabilities, scored side by side.

Runtime enforcement, identity and accountability, coverage, and what it costs to operate — each scored 0–5 on capability depth against vendor documentation, including the seven rows that come out level and the two rows Onyx wins.

Capability depthNoneCompleteOnyx SecurityAgen.co
01 · Runtime enforcement
Verdict rendered at the moment of actionOnyx SecurityInline, five surfacesComplete5/5Agen.coPer-action verdicts, <30msComplete5/5
Decision latency, published and measuredOnyx SecurityNo enforcement latency publishedPartial2/5Agen.co<30ms, published, no samplingComplete5/5
Step-up authentication on a risky actionOnyx SecurityNot among the five verdictsBasic1/5Agen.coStep-up, built inComplete5/5
Human-in-the-loop approval on a risky actionOnyx SecurityA native verdict typeComplete5/5Agen.coHuman-in-the-loop, built inComplete5/5
02 · Identity & accountability
Agent has a first-class identity objectOnyx SecurityIssued in its own namespaceStrong4/5Agen.coFirst-class agent identityComplete5/5
Agent identity unified with human and machine identityOnyx SecuritySeparate from directory identityPartial2/5Agen.coOne fabric: humans, machines, agentsComplete5/5
Each individual action attributed to that humanOnyx SecurityInvoking user and owner, per callStrong4/5Agen.coAttributed per actionComplete5/5
Audit record per actionOnyx SecurityPer-action log, session replayComplete5/5Agen.coA record per actionComplete5/5
03 · Coverage
Endpoint enforcementOnyx SecurityDesktop agents, coding assistantsComplete5/5Agen.coAgenShield on the deviceComplete5/5
Browser enforcementOnyx SecurityInline on browser AIComplete5/5Agen.coBrowserShield, early accessCapable3/5
Network-layer enforcementOnyx SecurityNot their layer eitherPartial2/5Agen.coNot our layer — works alongsidePartial2/5
Shadow-agent discoveryOnyx SecurityInventory inside 24 hoursComplete5/5Agen.coShadow AI surfacedComplete5/5
External customer-facing agentsOnyx SecurityEnterprise workforce AIPartial2/5Agen.coCustomer-facing agents, same planeComplete5/5
04 · Operate & buy
Pricing unit — what you are billed perOnyx SecurityNot published, sales-quotedCapable3/5Agen.coPer governed agentComplete5/5
Deployment model and data residencyOnyx SecurityCloud, hybrid, or self-hostedComplete5/5Agen.coSaaS, hybrid, or on-premComplete5/5
Ecosystem and marketplace breadthOnyx Security100+ integrations, managed gatewayCapable3/5Agen.coFocused platform, not a marketplacePartial2/5
7 rows Agen.co leads7 tied2 rows Onyx leads
Levels reflect capability depth and supporting evidence. Capability descriptions based on vendor public documentation, August 2026.
What the scores mean

Two boundaries, and neither one is enforcement.

Onyx blocks, masks, steers and escalates at the moment an action would execute, across five surfaces, and it records who invoked the agent and who owns it. Seven rows come out level and two go to them. This comparison does not turn on whether they can stop an action, and it does not turn on whether they know who acted.

It turns on where that identity lives and whose agents are in scope. The accountable identity is issued alongside the enterprise directory rather than inside it, which is why the verdict set stops short of a step-up challenge and why the record cannot be carried into a delegated request. And the estate it governs is an organisation's own workforce AI — the agents a company builds into its product and puts in front of its customers sit outside it. Agen governs both on one plane, with a named person answerable for every action.

The findings

Four groups, four conclusions.

The same argument the table makes, read as findings rather than scores.

01

Enforcement is real, and the vocabulary is wide

Alert, block, mask, steer and ask a human, applied inline at the moment an action would execute across five surfaces. Inline enforcement and human approval both score level. The set stops short of a step-up challenge, which follows from the identity sitting outside the directory rather than from a gap in the enforcement layer, and no enforcement decision latency is published.

step-up challengenone
02

An owner on the record, issued in its own namespace

Each governed agent carries an owner, and every session records the invoking user and the identity used on each tool call. That identity is described as distinct from the user who invoked it and lives alongside the enterprise directory rather than inside it, so the accountability line is one the platform maintains rather than one the organisation already holds.

identity sourcevendor-issued
03

Broad inside the enterprise, bounded at its edge

Browser AI, coding assistants, desktop agents, cloud workloads and MCP servers, with discovery producing an inventory inside 24 hours. Browser enforcement goes to them outright and shadow discovery scores level. The scope is an organisation's own workforce AI — the agents it builds into its product and exposes to its customers are outside it.

customer-facing agentsout of scope
04

Fast to stand up, and strong on the ecosystem

Cloud, hybrid or self-hosted, with a working inventory of an environment inside a day and deployment scored level. Over a hundred pre-built integrations and a fully-managed open-source gateway win the ecosystem row outright. No pricing page is published, so the cost of governing a growing agent estate cannot be modelled before a sales conversation.

published pricingnone
Watch it happen

Every action resolved to the human who answers for it.

Not a record kept beside your directory but an identity inside it — a named accountable owner carried on every agent, and every individual action attributed back to them, judged in context before it runs.

agent ownership · live product scene
What closes the gap

Keep the coverage. Anchor it to the directory you already run.

Your discovery and inline enforcement keep working exactly as they do today. Agen governs on top: every agent a first-class identity in the same fabric as your people and your machines, carrying a named accountable owner, with every action judged against your policy in under 30ms — escalated to a step-up challenge where it needs one, and covering the agents your customers touch as well as the ones your staff run.

Select a capability

Continuous discovery across your IdP, gateway, devices, cloud, and registries. Nothing has to self-register: agents are found, risk-scored, and resolved to a named human before they act.

  • Agentless and API-based across five surfaces
  • First-party, custom, and third-party agents alike
  • Every agent mapped to an owner, approver, and escalation
Agen Discover AI agent discovery flow: any identity provider, productivity suites and assistants, cloud, gateway, endpoints, and MCP server registries all feed one agent registry where every AI agent is inventoried, risk-scored on arrival, given a named human owner, and shadow AI is surfaced.
Discovery pulls from five surfaces into a single agent registry — no SDK self-registration required.
ClosesWhich agents are running that nobody registered?
no SDK required5 surfacesowner-mapped
Discover in depth →

Methodology

How these scores were reached.

Forty-two capabilities were scored against the ladder in our internal rubric; sixteen are published here. Five were dropped and are not published on any page, in every case because the only finding was an absence in public documentation — weaker evidence than a documented limit, and not something we will score a competitor down for. One further capability is held back because our own column could not be verified against the rubric baseline: audit-first rollout, where this vendor's alert verdict is a documented monitor mode and the row would likely not go to us. This is the most level table we publish. Seven of the sixteen published rows are ties and two go to Onyx; all nine are printed rather than filtered.

Sources8 primary
Evidence ledger
  1. Onyx Security — AI SecurityTier AInspects every prompt, tool call and model response inline across browser AI, coding assistants, desktop AI agents, cloud workloads and MCP servers. Five enforcement actions: alert, block, mask, steer and ask (human in-the-loop). Intervention happens at the moment an action would execute — an unauthorised step is blocked, masked or redirected instead of just logged.
  2. Onyx Security — PlatformTier AFive modules: AI Observability, AI Security, AI Governance, AI Orchestration and AI ROI. Cloud, hybrid or self-hosted deployment. Over 100 pre-built integrations including AWS, GCP, Azure, OpenAI and Anthropic. A fully-managed open-source AI gateway. Full session replay and audit trail for compliance and forensics.
  3. Onyx Security — AI GovernanceTier AEach governed agent carries its own Onyx-attributed identity, distinct from the user who invoked it, giving one line of accountability. Policy is authored in natural language across prompts, responses, agent actions and tool and MCP server access, and applied at execution time.
  4. Onyx Security — AI ObservabilityTier ADiscovery combines directory scanning, native platform APIs and behavioural signature learning for browser-based AI across SaaS, cloud, endpoints and code. Most environments produce a working AI inventory within 24 hours. Per agent: owner, permissions and lifecycle stage. Per session: the invoking user and the agent owner, and the identity used on each tool and MCP call.
  5. Onyx Security — AI OrchestrationTier AThe AI Gateway routes across models to automate failover, minimise latency and load-balance on task complexity and cost. It layers on top of an existing gateway to add inline policy inspection, or handles routing directly, with tool-call enforcement for MCP servers using the same five enforcement modes.
  6. Onyx Security — product siteTier APublished performance figures appear under production LLM gateway performance metrics: 4,218 requests per second, 94ms P95 latency and a 0.07% error rate. These measure gateway routing throughput; no enforcement decision latency is published.
  7. Onyx Security — Introducing Onyx SecurityTier AScope is the enterprise's own environment and workforce: every company is becoming an agent operator, and AI agents are now within reach of every employee. The platform continuously discovers every AI asset across the enterprise. No customer-facing, external or multi-tenant agent governance is described, and no step-up authentication, identity-provider integration or on-behalf-of delegation is mentioned.
  8. Onyx Security — published sitemapTier ANo pricing or plans URL appears in the published sitemap, and both /pricing and /plans return HTTP 404. The commercial call to action across the site is a demo request.

Vendor capabilities change. If a row is out of date or wrong, tell us and we will re-score it — corrections are published with the date they were made.

FAQ

Questions, answered.

What is Onyx Security?
It is a security and governance platform for the AI running inside an enterprise. It presents as five modules on one platform: observability, which discovers sanctioned and shadow AI across SaaS, cloud, endpoints and code; security, which inspects prompts, tool calls and model responses inline; governance, which turns natural-language policy into enforced controls over actions and over which tools and MCP servers are trusted; orchestration, a managed gateway that routes across models; and a return-on-investment view for adoption reporting.
Does Onyx Security actually block agent actions, or only observe them?
It blocks. Onyx inspects every prompt, tool call and model response inline and intervenes at the moment an action would execute, so an unauthorised step is blocked, masked or redirected rather than logged after the fact. There are five enforcement actions: alert, block, mask, steer and ask, the last of which routes to a person for a decision. On the published table, inline enforcement and human-in-the-loop approval both come out level against Agen.
What is the difference between Agen.co and Onyx Security?
Where the accountable identity lives, and whose agents are in scope. Onyx issues each governed agent its own identity, in their words distinct from the user who invoked it, and maintains the accountability record alongside the enterprise directory. Agen makes the agent a first-class identity inside that directory, in the same fabric as the humans and machines already there, which is what lets an action be escalated to a step-up challenge or delegated on someone's behalf. Onyx governs an organisation's own workforce AI; Agen governs that and the agents a company exposes to its customers, on one plane. On the sixteen published rows the two products come out level seven times, and Onyx wins two.
Can Onyx Security tell you which person is behind an agent's action?
Yes, to a real extent. Each governed agent carries an owner alongside its permissions and lifecycle stage, and every session records the invoking user, the agent owner, and the identity used on each individual tool and MCP call. The distinction scored on this page is not whether that person is known but where the identity lives — Onyx describes the agent's identity as distinct from the invoking user and maintains it in its own namespace rather than in the enterprise directory.
Does Onyx Security support step-up authentication?
Its enforcement actions are alert, block, mask, steer and ask, and step-up is not among them. A step-up challenge is a live re-authentication against an identity provider, and no identity-provider, SSO or SCIM integration appears in Onyx's public documentation. Human approval is supported through the ask verdict, which routes a decision to a person; that is a different control and it scores level against Agen on the published table.
Does Onyx Security govern customer-facing agents?
Its public material describes governing the AI inside an organisation's own environment — every company becoming an agent operator, AI agents within reach of every employee, discovery across the enterprise. No customer-facing, external, multi-tenant or product-embedded agent governance is described. The controls would apply to such an agent technically; what is absent is a per-tenant customer model for one.
Do Agen.co and Onyx Security overlap or work together?
They overlap substantially on internal coverage and differ on identity and scope. Onyx discovers and enforces across browser AI, coding assistants, desktop agents, cloud workloads and MCP servers. Agen governs the action across the endpoint, the browser, the gateway and the cloud, for internal and customer-facing agents alike, with every agent a first-class identity in the enterprise directory carrying a named accountable owner. Running broad AI discovery alongside a directory-anchored governance layer is a coherent architecture.
How were these scores produced?
Forty-two capabilities were scored 0–5 against a published ladder using vendor public documentation, and sixteen are published here. Ties and rows the competitor wins are printed rather than filtered out — this is the most level table we publish, with seven ties and two rows going to Onyx. It is scored against vendor public documentation and re-scored on a schedule we hold ourselves to.

Bring your own comparison.

Send us the rows you would score differently. We will show you the evidence behind ours, and where we are wrong we will change the page.