Broad enforcement, and the directory it sits beside.
Onyx is the most capable product in this comparison set, and the scored table says so: seven ties out of sixteen and two rows they win outright. The distinction worth a buyer's time is not whether they enforce, and it is not whether they know who acted. It is what that knowledge is anchored to, and which agents are inside the scope at all.
Five modules, one plane
Onyx presents as five modules on one platform: observability, security, governance, orchestration and a return-on-investment view. Observability is the entry point and the strongest of them — discovery combines directory scanning, native platform APIs and behavioural signature learning for browser-based AI across SaaS, cloud, endpoints and code, and most environments produce a working AI inventory inside a day.
Orchestration adds a managed gateway that routes across models for failover, latency and cost, and can either sit on top of an existing gateway to add inline policy inspection or handle routing itself. Deployment is cloud, hybrid or self-hosted. For a team that cannot route agent traffic through a vendor, that last property matters, and it is why the deployment row comes out level.
Enforcement is real, and the vocabulary is wide
This is where a comparison against a discovery-first product usually finds its argument, and here it does not. Onyx inspects every prompt, tool call and model response inline, and intervenes at the moment an action would execute: an unauthorised step is blocked, masked or redirected rather than logged after the fact. The verdict set is alert, block, mask, steer and ask — the last of those routing to a person for a decision.
That is a wide vocabulary, wider than most of this category manages, and it includes one verdict we do not have an equivalent for: steer, which redirects an agent's decision-making rather than stopping it. Policy is written in natural language and scopes over prompts, responses, agent actions and which tools and MCP servers are trusted. Four of the rows in this group come out level or near it, and the enforcement row is a clean tie.
Who the record names, and where that name lives
This is the row that decides the page, and it is closer than the category usually is. Onyx does resolve people. Each governed agent carries an owner alongside its permissions and lifecycle stage, and every session records the invoking user, the agent owner, and the identity used on each individual tool and MCP call. Called against most of this market, that is a strong answer.
The distinction is where that identity lives. Onyx describes each governed agent as carrying its own Onyx-attributed identity, distinct from the user who invoked it — a deliberate design, and their own phrasing for it. The agent is a first-class object inside Onyx, and the accountability line is one Onyx maintains rather than one the enterprise directory already holds.
Two consequences follow, and both are visible in the table rather than argued for. There is no step-up challenge among the five verdicts, because a step-up is a live challenge against an identity provider and no identity-provider integration is described. And the record is an account of what happened rather than a credential the action was permitted under, so it cannot be carried into a delegated request downstream.
Agen starts from the other end. The agent is a first-class identity in the same fabric as the humans and machines already in the directory, carrying a named accountable owner before it does anything. Every individual action is attributed to that person and judged in context in under 30ms, and because the identity is the enterprise's own, the same action can be escalated to a step-up challenge or delegated on someone's behalf without leaving the plane it was judged on.
Whose agents are in scope
The second boundary is scope, and it is the one most likely to decide a shortlist. Onyx's framing is consistent everywhere it appears: every company is becoming an agent operator, AI agents are now within reach of every employee, discovery runs across the enterprise. The product governs the AI an organisation's own people use.
- Internal coverage is genuinely broad.Browser AI, coding assistants, desktop agents, cloud workloads and MCP servers, with discovery reaching SaaS, cloud, endpoints and code. On the internal side this is as wide as anyone's, and several of those rows are ties.
- The browser is theirs.Browser AI leads their inline enforcement list, and discovery adds behavioural signature learning for it. Our own browser coverage is in early access, so this row goes to them and is published that way.
- Customer-facing agents are outside it.No customer-facing, external, multi-tenant or product-embedded agent governance appears in any public material. A company that ships an agent to its own customers is governing something the product was not scoped for.
None of this is a shortcoming in what Onyx built. It is the shape of a product that chose the enterprise's own environment and covers it thoroughly. The question for a buyer is whether the agents they are accountable for are all inside that shape — and for anyone whose product has an agent in it, some are not.
What it costs to run
Onyx publishes no pricing page — the commercial path is a demo request. Nothing about that is unusual for an enterprise security platform, and it is scored as a capable-but-not-comparable answer rather than a failing. It does mean a buyer cannot model the cost of governing a growing agent estate before a sales conversation, which is the thing the pricing-unit row exists to measure.
Where Onyx is strongest
- Browser enforcement, and the row they win.Browser AI is first in their inline enforcement list and carries dedicated behavioural signature learning in discovery. Our BrowserShield is in early access and scored as such on every comparison we publish, so this row goes to Onyx.
- Ecosystem breadth, and the second row they win.Over a hundred pre-built integrations spanning the major clouds and model providers, named integrations for the large agent platforms, and a fully-managed open-source AI gateway. We are a focused platform rather than a marketplace, and this is the row where that shows.
- Discovery, scored level.Directory scanning, native platform APIs and behavioural signatures combining into a working inventory of an environment inside 24 hours. On the row the rubric names as this archetype's real strength, we score level.
- Inline enforcement and human approval, scored level.Five verdict types applied at the moment an action would execute, including routing to a person for a decision. On the surfaces they cover, the enforcement is as deep as ours.
- Session replay in the audit record.Their per-action logging carries full session replay for forensics — a genuinely useful capability we do not offer in that form, on a row that scores level.