Silverfort Featured in the SACR ARISE Report
Runtime means something different to every vendor. SACR explains why doing it right matters more than ever in the agentic era
Everyone says ‘runtime.’ Few mean the same thing. Some mean a log review after the session ends. Some mean scanning a prompt before it reaches a model. Analyst firm Software Analyst Cyber Research (SACR) built a new category, Agentic Runtime Identity Security Enforcement (ARISE), to draw a hard line between those and the real thing: enforcement that acts inside the decision path, before an action completes.
In its inaugural ARISE vendor landscape report, SACR gives Silverfort direct alignment across all three ARISE core layers
This report gives security and identity teams a rigorous way to tell genuine runtime enforcement apart from AI gateways and prompt-filtering tools that only observe agent activity after the fact.
Use this report to see how the ARISE framework defines agentic runtime identity security, and where Silverfort’s Runtime Access Protection (RAP) architecture fits across the three core layers.
Here’s what you’ll learn:
- What ARISE is, and why SACR built a new framework to cut through the market’s competing definitions of “runtime”
- How Silverfort aligns with runtime enforcement, agentic context, and MCP/tool governance within the ARISE framework
- The three layers that separate enforcement that stops an action before it happens from after-the-fact detection wearing the same label
- How Silverfort steps in before authentication completes, not after something’s already gone wrong
- Where AI agents and non-human identities fit into the picture, and why they can’t be governed like a normal user account
SACR Agentic Runtime Identity Security Enforcement Report

Download here
FAQs
What is Agentic Runtime Identity Security Enforcement (ARISE)?
Agentic Runtime Identity Security Enforcement (ARISE) is a framework from analyst firm SACR for evaluating how identity security vendors govern AI agents and non-human identities at runtime, rather than only monitoring or logging their activity after the fact.
What are the three core layers of the ARISE framework?
The ARISE framework evaluates vendors across three core layers: deterministic governance, which maps and enforces policy on agent identities and actions; behavioral and intent analysis, which compares what an agent intended to do against what it actually did; and dynamic runtime governance, which acts in real time to allow, deny, step up, or route actions to human review before they complete.
How did Silverfort rate in the SACR ARISE report?
Silverfort ranked extremely high across all three ARISE core layers, including runtime enforcement, agentic organizational context, AI-powered policy engines, tool and MCP governance, and behavioral and intent analysis.
What is Runtime Identity Security?
Runtime Identity Security refers to enforcing identity access controls at the moment an action happens, such as during authentication or a tool call, rather than detecting and responding to it afterward. Silverfort calls its architecture for this Runtime Access Protection (RAP): a checkpoint inside the identity provider that can allow, deny, step up with MFA, grant just-in-time access, or send a request to human review before authentication completes.
What is AI Agent Security?
AI Agent Security is the practice of discovering, monitoring, and enforcing what AI agents can access and do, including the non-human identities (NHIs), credentials, and tools they use. Silverfort’s AI Agent Security extends its identity graph and Runtime Access Protection (RAP) to AI agents, mapping agent owners, consumers, connected tools, and NHIs, and enforcing access controls, such as blocking a specific delete operation without blocking an entire application.
What is MCP governance?
MCP governance means controlling what actions AI agents and coding tools, such as Cursor or Claude, can take when they call external tools through the Model Context Protocol (MCP). Silverfort routes MCP tool calls through a gateway that applies identity policy at the action level, so a specific operation can be blocked without cutting off the entire tool.
How is agentic identity security different from an AI gateway?
An AI gateway typically focuses on prompt filtering, redaction, or model routing. Agentic identity security, as defined by frameworks like ARISE, focuses on governing what identities, including AI agents and non-human identities (NHIs), can actually do across enterprise systems, and enforcing that policy inline before an action completes.
Learn more
AI Agent Security — Discover, monitor, and protect your AI agents.
Securing AI Agents — Enforce identity controls the moment an AI agent acts.
Stop AI-powered Attacks — Get ahead of AI-speed attacks.
Runtime Access Protection — The architecture behind Silverfort’s inline enforcement.
