Discover shadow agents, govern agent access, and stop enterprise rogue agents at runtime with the Agent Kill Switch
Key takeaways
- Agent Identity Security adds new controls to discover, govern, and stop enterprise rogue agents. Discovery covers shadow and sanctioned agents, custom agents, and the AI Skills available to and used by agents, all captured in an expanded AI Bill of Materials (AIBOM).
- A new centralized MCP Gateway provides a control point for agent-to-MCP communication, with granular access and bidirectional security policies. Teams can monitor model and token usage, trends, and costs, with threshold policies to manage spend.
- New framework support lets organizations assess and demonstrate alignment of their agent deployments with the OWASP Top 10 for Agentic Applications, NIST AI RMF, EU AI Act, and other key frameworks.
- New runtime controls combine intent-based policies, cryptographically rooted JIT access, and the Agent Kill Switch to limit agent access to specific tasks or approved periods and stop out-of-scope activity. The Kill Switch covers sanctioned and shadow agents.
- AppViewX now also issues quantum-resilient agent identities that chain to the customer’s AppViewX-managed PKI, so trust in every agent holds as cryptography evolves.
These capabilities address a broader challenge: even routine, authorized agent tasks can have unintended consequences. The Claude Code incident shows how quickly that can happen.
A developer asked a Claude Code agent to build a mirror of a project, a routine job the agent was authorized to do. The mirror couldn’t be refreshed, so the agent wrote its own Python script to clear out an older copy. That copy contained Windows directory junctions pointing back to the live project. The script followed those links and reportedly deleted 48,218 files in the live project in 103 seconds, including the Git object store, leaving Git unable to restore anything.
It was an authorized agent whose actions during a legitimate task caused serious damage. Unfortunately, agents acting outside of their intended scope are no longer an edge case. OWASP names Rogue Agents (ASI10) in its Top 10 for Agentic Applications. In an April 2026 Cloud Security Alliance (CSA) survey, 65% of organizations reported an AI agent-related security incident in the past 12 months.
When we introduced Agent Identity Security in June, we laid the foundation: agent inventory, policy-based governance, and runtime security. This release builds on that foundation with new capabilities to discover shadow and sanctioned agents, govern their risk and access, and stop rogue agents at runtime with the new Agent Kill Switch.
What’s New in Agent Identity Security
Discover Every Agent Across the Enterprise
Shadow agents pose a significant risk to an organization. In the same CSA survey, 82% reported discovery of at least one unknown AI agent running in their infrastructure. It’s impossible to govern what you can’t see.
Agent Identity Security now discovers browser-based and short-lived script-based agents, whether shadow or sanctioned. Organizations can discover these agents through API integrations with existing EDR solutions, SaaS and cloud platforms, and AppViewX’s new lightweight endpoint Guardian Agent. Unlike alternatives that rely on a single detection method, this combination helps ensure no shadow agent goes undetected. AppViewX discovers these agents in minutes, providing a faster view of what is running across the organization.
For custom agents, the AppViewX SDK lets developers integrate internally developed agents for discovery, governance, and runtime security, bringing them into the same visibility and policy framework as commercial agents.
Agent Identity Security also discovers the AI Skills available to and used by agents, building an inventory that helps teams understand what those Skills enable, assess their security posture, and identify potentially unsafe or vulnerable capabilities.
For every managed and unmanaged agent, Agent Identity Security builds a complete AI Bill of Materials (AIBOM) covering its users, credentials, endpoints, Skills, MCP servers, models, and packages, along with activity such as DNS calls, terminal commands, API calls, and file access. A live access graph shows how each agent connects to its users, credentials, Skills, models, and resources.
Key benefits
- See agents deployed outside approved processes in minutes
- Extend the same visibility and controls to internally developed agents as commercial agents.
- Discover the AI Skills agents use and assess their risk
- Track LLM and token usage
- Get a complete AIBOM and live access graph showing how every agent connects to users, credentials, Skills, models, and resources
Govern Agents, Skills, and Usage Through a Centralized MCP Gateway
Discovery is the starting point. Agent Identity Security helps teams bring discovered AI Skills into their governance processes, assess risk, and apply appropriate controls to the capabilities available to agents. Visibility into model and token consumption, usage trends, and associated costs, combined with token and spend threshold policies, helps teams identify unexpected or excessive consumption and apply guardrails before autonomous tasks, repeated actions, or loops drive up usage.
To help teams keep pace with emerging AI regulations, Agent Identity Security now helps organizations assess and demonstrate alignment of their agent deployments with support for additional frameworks including the OWASP Top 10 for Agentic Applications and Agentic Skills, MITRE ATLAS, NIST AI RMF, NIST SP 800-53 Rev. 5, ISO 27001/42001, the EU AI Act, GDPR, HIPAA, SOC 2, and SEC Cyber Disclosure. Audit-ready activity logs for every agent support those efforts.
Organizations also need to govern the resources agents reach through MCP. MCP gives agents access to enterprise data and applications, and their permissions can be broader than needed. Sensitive information can flow in both directions during MCP communication. In an agent-to-MCP request, an agent may send confidential information, PII, or secrets to an MCP server. In an MCP-to-agent response, the server may return sensitive enterprise information to the agent.
AppViewX’s centralized MCP Gateway discovers sanctioned and shadow MCP servers, continuously assesses their risk and posture, and provides a control point for MCP communication. It applies granular runtime access policies to MCP servers and tools based on available agent and identity context, governing which resources agents can reach and under what conditions. The Gateway also inspects MCP communication and applies data security policies to protect sensitive information across both directions of MCP communication. Sensitive data is redacted using built-in controls or by integrating with existing data security tools such as Microsoft Purview.
Agent Identity Security can also incorporate existing enterprise DLP classifications , helping prevent agents from exposing, uploading, or improperly handling data the organization has identified as sensitive.
Key benefits
- Assess Skill risk and govern the capabilities available to agents.
- Set thresholds to manage AI usage and spend.
- Assess and demonstrate alignment with frameworks such as OWASP, NIST AI RMF, and the EU AI Act, with audit-ready activity logs.
- Discover shadow and sanctioned MCP servers
- Keep agent access to MCP servers and tools within the limits set by identity and context.
- Protect confidential information, PII, and secrets in MCP communications
Stop Enterprise Rogue Agents at Runtime with the Agent Kill Switch
Permissions can’t tell you whether an agent should take an action given the job it was assigned. Regulators see the same gap. FINRA’s 2026 Regulatory Oversight Report lists agents acting beyond their intended scope and authority among the risks firms need to supervise.
Agent Identity Security introduces cryptographically rooted just-in-time access to MCP servers and tools. Access is determined dynamically using applicable agent and user context, granted only when needed for a specific task or approved period, and removed when that task or period ends. This helps reduce standing privileges and limits the resources available if an agent is compromised, manipulated, or behaves unexpectedly.
Intent-based access policies assess whether an agent’s actions remain aligned with its assigned objective. Traditional permissions establish whether an agent is allowed to use a tool or access a resource, but intent-based policies identify when an otherwise permitted action falls outside the agent’s task. When an agent’s activity does not meet the defined policy conditions, Agent Identity Security can automatically terminate the agent and its active sessions through the Agent Kill Switch.
Termination can be triggered in several ways: by runtime policies based on resource type, the agent itself, and its intent; by event-driven workflows that respond to changes AppViewX detects, such as configuration changes; by signals from third-party security tools through the Shared Signals Framework (SSF); or on demand from the console to contain risky activity. Unlike alternative approaches, the Agent Kill Switch covers both sanctioned and shadow agents and does not depend on an MCP gateway.
Key benefits
- Reduce standing access with task-based, time-limited permissions.
- Stop actions outside an agent’s assigned objective.
- Contain risky activity with the Agent Kill Switch, terminating agents and sessions automatically, through event-driven workflows, runtime policies or on demand.
Bringing agent security together
The Claude Code incident shows how an agent can cause serious damage when its actions move beyond its assigned task. AI agents have been treated as trusted automation, without the identity and access controls expected of other privileged system actors. AppViewX Agent Identity Security helps reduce the risk of similar incidents by enabling organizations to discover agents, govern their access, and stop actions outside their intended scope, so every agent is known, governed, and controlled and teams can deploy AI agents with confidence.
Agent Identity Security is available today. Learn more about Agent Identity Security or schedule a call with an expert
Frequently Asked Questions.
How is Agent Identity Security deployed?
Agent Identity Security is available as a SaaS or on-premises deployment. It discovers agents through API integrations with EDR and identity tools (such as CrowdStrike, SentinelOne, Okta, and Ping Identity), SaaS platforms (such as Copilot Studio, ServiceNow, and Salesforce), and cloud platforms (such as AWS Bedrock, Azure AI Foundry, and Google Gemini). The AppViewX endpoint Guardian Agent is a lightweight process that can detect agent activity at the endpoint and within the browser. It is deployable through MDM tools such as Microsoft Intune, and we also offer an SDK for custom agents.
What kinds of shadow agents can Agent Identity Security discover?
Agent Identity Security continuously discovers and monitors shadow agents across coding agents, enterprise productivity agents, custom agents, and SaaS agents. Each agent is shown with its activity and associated risk.
What does AppViewX’s centralized MCP Gateway control?
It governs communication between agents and MCP servers. Based on agent and identity context, it controls which MCP servers and tools agents can access. It also applies data-security policies to requests sent to MCP servers and responses returned to agents.
Agent Identity Security also provides cryptographically rooted just-in-time access to MCP servers and tools. Access is determined dynamically using applicable agent and user context, granted only when needed for a specific task or approved period, and removed when that task or period ends.
How are intent-based access policies different from permissions?
Permissions define what an agent is allowed to do, such as access a resource or use a tool. Intent-based policies also check whether the agent’s actions align with its assigned objective. An agent may be allowed to use a tool but take an action with it that falls outside its stated task. In that case, AppViewX can stop the action at runtime. When defined policy conditions are met, AppViewX can also terminate the agent and its active sessions. The Agent Kill Switch is available to stop an agent on demand, and it covers both sanctioned and shadow agents without depending on an MCP gateway.
Can Agent Identity Security govern AI agents my team builds in-house?
Yes. The AppViewX SDK lets developers integrate custom, internally developed agents with Agent Identity Security for discovery, governance, and runtime security.







