One in five. That is the share of organizations that can revoke an API key on request, according to the Cloud Security Alliance's most recent survey of non-human identity security. The other four in five are running fleets of software agents on credentials nobody ever handed back.

On the morning of 29 September 2026, two companies announced money for the same problem from opposite ends of the stack. Reco, the Tel Aviv vendor that maps AI agents inside enterprise networks, added $55M in a round led by AT&T Ventures, alongside Forestay Capital and Quadrille Capital, bringing total funding to $140M. Rig Security, founded in 2025 and until Monday unknown outside its own website, emerged from stealth with $12M to stop agents at the endpoint. Neither company claims the category. Both are betting that the control plane for machine identities will be worth more than the agents running on it.

Legacy identity management was built for humans who log in, and for service accounts that a human created, reviewed and eventually deleted. Agents break all three assumptions at once.

Cloud Security Alliance

20%

of organizations have a formal process for offboarding and revoking API keys

up only 1 in 5 hold the process at all

SurveyState of Non-Human Identity Security
MeasuredA documented, repeatable revocation process
ScopeMachine and application identities, agents excluded

Entro Security, cited by CSA

1 in 20

non-human identities holds full administrative privilege over production

up 5% of every machine identity fleet

SourceEntro Security research, H1 2025
CountedNon-human identities with admin-equivalent rights
Baseline5% privilege inflation against human admin counts

Reco, cumulative funding

$140M

raised in total after a $55M strategic round closed on 29 September 2026

up $55M added on 29 September 2026

RoundStrategic, extension rather than a priced stage
LeadAT&T Ventures, with Forestay Capital and Quadrille Capital
Before it$30M round closed in February 2026

The map nobody had

Reco's pitch is discovery, and the pitch starts with a number that should worry anyone running agents in production. One Fortune 100 customer deployed Reco's platform and found 21,000 agents it had never inventoried. Not 21,000 risky ones. Twenty-one thousand that no human being had named, approved or logged.

The mechanism is a graph. Reco Graph unifies network traffic, endpoint telemetry, connected applications and identity-provider records, then resolves the resulting mess into a single inventory where every node carries an owner, a permission set and a known blast radius. An agent with an entry in that inventory can be given least privilege, can be watched, can be switched off. An agent without one is indistinguishable from ordinary east-west traffic.

Reco found 21,000 of them in a single week of deployment. Nobody owned one.

The funding scale suggests investors agree the inventory problem is the entry point rather than the destination. Reco integrates with more than 280 applications, and its CEO Ofer Klein told TechCrunch the company's valuation has more than doubled since February, when it closed a $30M round, into what he called the high hundreds of millions. That is a company estimate rather than a disclosed valuation, and it is the kind of number that travels. The number worth holding is the market one: Grand View Research puts agentic AI security at $1.3B in 2025 and $17.8B by 2033, a 38.9% compound annual rate. Reco is betting the inventory layer comes first. Every vendor in this radar is betting on something adjacent to it.

The revocation gap

The CSA numbers describe the floor under all of this, and the floor is lower than most security teams assume. Entro Security's research, cited in CSA's whitepaper, found 1 in 20 non-human identities holding full administrative privilege. CSA's own survey found only 20% of organizations with a formal process for offboarding and revoking API keys.

Both studies were run against machine identities as they existed before the agent wave. Nobody measured agent credentials specifically, because there is no agreed way to count them yet. Read the two figures together and the shape of the problem becomes plain: privilege accumulates on credentials faster than any organization can write off, and the apparatus for cleanup was already missing.

Frameworks have not caught up either. CSA's assessment is that SOC 2, ISO 27001, PCI DSS, NIST 800-53 and the EU AI Act all contain provisions touching identity and access management, and none of them were written with agentic credentials in mind. An auditor can certify a control that never had a way to see the agent.

Blocking at the socket

Rig Security takes the opposite approach, and announced it on the same morning. Its platform has two named parts. RICE, the identity correlation engine, works out which actions belong to which agent. Bifrost is a lightweight sensor installed at the endpoint that separates an agent's session from the user's own and can halt the agent alone, leaving the human's session intact. The company's pitch is that this makes least privilege enforceable without a new identity system, which is a different bet from Reco's.

The funding behind it is respectable for a 2025-founded company: $12M seed, co-led by Ten Eleven Ventures and Brightmind Partners, with the CrowdStrike Falcon Fund participating. Guy Kozliner, who founded Rig Security in Tel Aviv and previously built Siemplify, told SecurityWeek the company is already in production at Fortune 200 organizations with roughly 20 employees. That is a small team claiming large deployments, and it deserves the same skepticism any such claim receives.

Two incumbents answered inside the same week. RSA introduced Agent ID, positioned around lifecycle governance for AI agents rather than endpoint enforcement. Delinea pushed continuous runtime authorization, granting and withdrawing machine access as a session runs. Both are large enough to bundle the capability into existing contracts, which is the structural disadvantage every startup in this radar faces.

Three answers, side by side

Where each answer intervenes

ApproachIntervenes atUnit of controlBlind spot
Application graph (Reco)Network and application layerAgent as a node in an account graphAgents that never generate observable traffic
Endpoint enforcement (Rig Security)Socket and endpointSession attributed to an agentCloud-native agents with no endpoint at all
Provider-native (RSA, Delinea)Identity providerToken, grant and certificateCredentials that never came from the provider

Each approach solves a different slice. The open question is whether the slice survives contact with an agent that runs entirely inside someone else's cloud.

What breaks on Monday

The practical consequence for an engineering team is narrower than the market sizing suggests. Three checks cost a sprint and cover most of the exposure.

First, count what you cannot name. Pull every credential currently attached to an agent from your identity provider and compare that list against your inventory. Reco's 21,000 figure describes the gap that appears when nobody has ever run that comparison. Most organizations cannot produce the first list at all, because agent credentials are minted by the agents themselves through delegated OAuth grants.

Second, find the delegation chains. Any agent that can call a tool which can call another agent produces an authority path that no single review captures. Ask for a graph of which agents can reach which tools, then check how many of those paths terminate in an admin scope. Entro's 1-in-20 finding describes the endpoint of exactly those paths.

Third, test revocation before you need it. Pick one non-production agent, revoke its credential, and time how long until it stops working. Most teams find the answer is never, because the agent holds a cached token or a copy of the key in an environment variable. Twenty percent of organizations have a formal process on paper. Very few can demonstrate that the process terminates a running process.

None of these three checks requires buying anything. That is the uncomfortable part of the week's funding news: the gap both startups are selling against is measurable today with the tooling most teams already own, and CSA already measured it.

What we wrote before

This is the third funding story on agent governance in three weeks, and the market is starting to look crowded rather than empty. In September we covered AIUC raising $40M to certify the very agents enterprises already deploy, and questioned then whether certification would arrive before the incidents did. The CSA figures in this radar are the first hard answer: the incidents already have a name and a measured prevalence. Certification has a market. So does revocation.

The skeptic's case

Signals to watch

Four checks over the next two quarters

  • Revocation as a purchased line item. A named non-human identity product inside a major IAM suite would confirm the category is being absorbed rather than expanded.
  • CSA tracking agent credentials separately. The next survey version, which should drop agent identities out of the machine identity bucket entirely.
  • Rig Security enterprise proof. A named reference customer with production scale, rather than a Fortune 200 count.
  • Reco's next priced stage. A conventional round after the strategic extension would convert a company estimate into a market-cleared number.

Sources