Ask five vendors what “runtime” means in AI Agent Security, and you’ll get five different answers. One means reviewing a log after the session already ended. Another means scanning a prompt before it ever reaches a model. Neither one is watching the moment that actually matters: the instant an agent tries to do something.
That gap is the subject of a new report from Software Analyst Cyber Research (SACR), written by analysts Paul Webber and Lawrence Pingree. SACR calls the category Agentic Runtime Identity Security Enforcement, or ARISE, and it exists to answer one question that most identity tools were never built to ask: should this agent be allowed to take this action, with this tool, this credential, and this delegated authority, right now?
Why should Identity teams care?
AI agents don’t just generate text anymore. They call tools, request credentials, query data, modify records, and trigger workflows, often through the same service accounts and standing access that security teams have spent years trying to lock down. A valid credential can still be used for an invalid action, and by the time a log shows what happened, the action is already done.
SACR frames this as the fourth era of enterprise Identity Security:
- The first era was human identity and perimeter access: authenticate the person, grant a role, review later.
- The second was cloud, SaaS, and Zero Trust, shifting decisions to per-request policy as the network perimeter dissolved.
- The third was non-human identities: service accounts, API keys, and workload identities multiplying faster than anyone could govern them by hand.
Every one of those shifts created a new control plane once the old one couldn’t keep pace. Agentic execution is the fourth, and it’s forcing the same reckoning: agents reason, plan, call tools, and modify records at machine speed, faster than any human-speed review cycle can follow.
The urgency isn’t theoretical. Software company PocketOS said they deployed AI coding agent Cursor, powered by Anthropic’s Claude Opus 4.6 model, to speed up the company’s coding, only to have it find a stray API credential and use it to delete their entire production database and backups. When asked what happened, the agent admitted it had guessed, acted without permission, and ran a destructive command without understanding it.
That’s the shape of risk ARISE is built to address: an agent with a valid credential, operating inside its permissions, taking an action nobody would have approved if they’d seen it coming.
ARISE draws the line SACR believes the market needs: tools that observe agent activity after the fact, versus tools that can actually intervene before an action completes.
SACR also gives buyers a way to measure where they stand, not just where vendors do.
Their ARISE Control Depth (ACD) scale runs six levels, from blind execution at ACD 0 to autonomous self-healing governance at ACD 5, and sets ACD 4, inline pre-completion intervention, as the production baseline for any use case touching sensitive data, credentials, or critical workflows. Below that line, SACR’s own words: an organization is “reliant on post-event remediation after a machine-speed blast radius has already been established.”

That’s worth turning into a few questions about your own environment before you evaluate any solution: Can you stop an agent action before it completes today, or only see it after the fact?Do you know which agents currently have no named owner, hold more access than their task requires, or share a non-human identity with another agent? And where’s the gap between what an agent was built to do and what it can actually reach?
Falling short of that production line isn’t free. Once an agent has already acted, what’s left is remediation and a disclosure conversation, not prevention.
Which of these criteria matter to you?
Not every organization’s exposure looks the same, and that’s worth sorting out before you prioritize anything. A team building agents that write and ship code carries a different risk profile than one running agents inside SaaS workflows like Salesforce or ServiceNow, and both differ again from a team letting agents touch regulated customer data. Start with where your own exposure actually concentrates.
What doesn’t change across any of those profiles is the security insertion point. Wherever a platform sits in that decision—at the model, gateway, or identity provider itself—determines what it can actually control. Authentication is the one checkpoint an agent can’t route around, which is why evaluating a vendor means asking not just what they can see, but where in that path they can act.
Where did Silverfort land?
In its inaugural ARISE vendor landscape report, SACR gives Silverfort direct alignment across all three ARISE core layers: deterministic governance, behavioral and intent analysis, and dynamic runtime governance. That result traces back to how Silverfort was built in the first place.
Silverfort’s patented Runtime Access Protection sits inside IAM infrastructure itself, like Active Directory, evaluating a second-opinion request before authentication completes. In that decision window, the platform can allow, deny, step up with MFA, grant just-in-time access, or send the action to human review, for human users and service accounts.
Across the five ARISE use cases SACR evaluated, that architecture earned Silverfort strongest alignment for runtime enforcement, agentic organizational context, and AI-powered policy engines and scoring, and strong alignment for tool/MCP governance and behavioral/intent analysis.
The common thread SACR points to: Silverfort doesn’t just observe an agent after the fact, it enforces policy in the decision path itself, for supported platforms, today: the Copilot Studio integration is live now, Google Agent Gateway support is expected soon, and Claude/OpenAI local-agent coverage lands in early Q4 2026.
That’s also why AI Agent Security wasn’t built as a bolt-on. It runs on the same identity graph, posture data, and access intelligence that already power Silverfort’s Identity Security platform, so an agent’s activity connects back to an owner, a credential, and a policy instead of showing up as an isolated new risk category. Our automatic inventory and risk assessment maps what agents are in use, who is responsible for each agent, the NHIs the agents use to access systems and apps—and that gives us the blast radius understanding to put runtime policies in place.
What this looks like in practice, drawn from SACR’s own evaluation
- A Salesforce delete that shouldn’t have been allowed. SACR watched the platform reason about the user’s intent versus what the agent actually did, and deny the action before it completed.
- A GitHub delete blocked at the action level while the agent keeps working. Access stays on; the one destructive operation doesn’t.
- An attacker operating through an agent on a valid credential. The same decision point catches it, arriving from the other direction.
The mechanism is the same each time: the decision happens before the action completes, not after.
We’re building quickly on this foundation, too, by extending the same runtime model into deeper behavioral baselining, broader native agent integrations, and AI-generated policy recommendations over the next year.
Next steps for Identity Security teams evaluating ARISE category vendors
Most vendor claims about “runtime” don’t hold up once you ask what actually happens in a live workflow. ARISE gives buyers a concrete way to test that: not what a platform can see, but what it can actually stop, and how far before the action completes it can step in.
SACR’s inaugural ARISE report profiles more than a dozen vendors working on this problem from different angles, and it’s worth reading in full if you’re building out an evaluation.
Get your copy of the report here.
Frequently asked questions (FAQ)
Is Silverfort a pure AI gateway vendor?
No. Silverfort is an identity runtime enforcement platform extending into AI agents and agentic access control. Buyers looking only for prompt filtering or redaction may find narrower tools; those trying to govern what human users, service accounts and AI agents can do across existing enterprise infrastructure should evaluate Silverfort more closely.
What’s the difference between an AI gateway and an ARISE-aligned identity platform?
An AI gateway typically inspects prompts and model responses. An ARISE-aligned platform evaluates the identity behind an action, the credential being used, and whether that action should be allowed to complete, before it does, across the systems an agent actually touches.
What should I ask any vendor that claims ARISE alignment?
Ask what happens in the decision window before an action completes: can the platform allow, deny, or step up (route for human review) in that moment, or does it only log and alert afterward? SACR’s report frames this as the core test of the category.
Where can I read Silverfort’s full ARISE profile?
Directly in SACR’s report: Read Silverfort’s profile in the SACR ARISE report.


