AI agents are multiplying faster than traditional access controls can handle, creating a new identity challenge for security teams. AppViewX has expanded its Agent Identity Security platform to address this, adding capabilities for discovering shadow agents, governing MCP servers, and stopping agents at runtime.

The updated platform discovers sanctioned and unsanctioned agents, including browser-based and short-lived script-based agents, and compiles them into an AI Bill of Materials that now includes the skills agents can access. A new MCP Gateway provides just-in-time access to MCP servers and tools, while an Agent Kill Switch can terminate an agent and its active sessions automatically, through runtime policies, or on demand. The kill switch works for both sanctioned and shadow agents and does not rely on an MCP gateway.

AppViewX also issues quantum-resilient agent identities through its PKI and certificate lifecycle management platform, giving security teams a single trusted root and audit trail. New cost and compliance controls track token usage and spending, and help organizations align agent deployments with frameworks such as OWASP Top 10 for Agentic Applications, MITRE ATLAS, GDPR, HIPAA, ISO 27001/42001, NIST SP 800-53 Rev. 5, the EU AI Act, and SOC 2.

The vendor cites customers who see the platform as a way to scale AI without losing control. "Governance becomes much harder to introduce after agents and their access have already spread," said Venkat Chivukula, VP of Enterprise Applications and AI at ZoomInfo. Sadeq Zabihi, Senior Director of Platform and Services at Docusign, said the platform brings discovery, governance, security, detection and response together so his team can see where agents are operating and detect risky behavior.