BeyondTrust boosts AI agent oversight with new security controls
BeyondTrust has announced the introduction of new AI security controls within its Identity Security Insights platform, offering customers increased visibility and oversight into AI agents operating within their IT environments.
The new features include three specific capabilities: AI Agent Insights, secure Model Context Protocol (MCP) orchestration, and an embedded AI decision-support layer.
These additions are available now to both Identity Security Insights and Pathfinder Platform customers.
Responding to emerging AI risk
Marc Maiffret, Chief Technology Officer at BeyondTrust, highlighted the urgency around securing AI identities. He commented,
"The rise of AI agents is creating a new and urgent identity security challenge. Agentic AI is not an isolated problem; it's a subset of the broader non-human identity landscape. To secure it effectively, organisations must think holistically about their entire identity ecosystem, not just one type of identity in a silo. Often built on low-code and no-code platforms, AI agents can be deployed in minutes with privileges that rival human admins. BeyondTrust uniquely connects visibility with proactive control across all identities so customers can rein in this new frontier of risk and turn AI into a safe force multiplier that also meets compliance requirements."
With these updates, BeyondTrust aims to give organisations more control over the increasing deployment of AI agents, particularly those created quickly using low-code or no-code platforms - often without thorough oversight or risk assessment.
Identity governance for AI agents
The new AI Agent Insights module expands identity discovery, classification, and risk-scoring beyond human or traditional machine identities to include AI agents.
This enables customers to identify agents operating within their cloud or software-as-a-service (SaaS) platforms, such as Salesforce Agentforce and ServiceNow.
It also introduces mechanisms for uncovering so-called shadow AI - AI agents operating without full visibility - and allows companies to enforce Zero Standing Privilege (ZSP) and Just-In-Time (JIT) access policies for enhanced governance.
Secure Model Context Protocol (MCP) orchestration is introduced via a lightweight server, serving as a controlled interface for AI agents to interact with other BeyondTrust security products. This facilitates workflows such as Just-In-Time API requests with Entitle, credential management with Password Safe, and anticipated integration with both BeyondTrust AI copilots and customer-deployed large language models (LLMs).
Real-time AI guidance
The newly released omnipresent AI decision-support layer is embedded directly within the Pathfinder Platform, enabling users to interact with their identity security data through a ChatGPT-like assistant.
This layer provides real-time analytical insights, guidance, and suggested remediation steps, and is underpinned by research from BeyondTrust Phantom Labs.
According to BeyondTrust, this integration is designed to support security teams in making more informed decisions without requiring them to leave their existing operational workflows.
Unified visibility across identities
The new integration means customers can view and control human, non-human (including machine and service accounts), secrets, and now AI identities from a single platform.
The goal is to deliver consolidated governance and enforcement, reducing risks related to privilege escalation or access abuse by unknown or unregulated AI agents.
BeyondTrust stated that the enhancements are intended to support businesses aiming to move forward with AI deployments without sacrificing security or regulatory compliance. The platform's unified architecture is designed to help organisations automate risk remediation steps and streamline overall identity security operations.
Wider risk assessment
The company also revealed that it has expanded its Identity Security Risk Assessment programme to include the detection and assessment of shadow agentic AI. This service is offered to provide organisations with early visibility and an opportunity to address risks before any activity by attackers or compliance auditors.
The release builds on features introduced earlier, such as Secrets Insights, which helps organisations discover and manage risks tied to secrets and non-human identities, now extended to cover the growing use of AI agents within enterprise environments.