Category 8 of 12 · Controls: What the agent did, and how to stop it
Agent detection, response, and audit
Monitoring, detection, and response for agent behaviour: per-action audit trails, anomaly detection, and the ability to stop an agent or revoke its access quickly.
Mitigates: ASI08 Cascading Failures, ASI10 Rogue Agents
Vendors, by signal score
- #1CrowdStrikePlatform suite67
Falcon AIDR, now presented as Falcon Guardian, discovers workforce AI and endpoint agents, governs which agents may run, and ties each prompt, identity, and tool call to downstream system actions in Falcon Next-Gen SIEM. Built with the Pangea acquisition, with SGNL powering Continuous Identity for AI Agents.
- #2Zenity49
Agent security and governance platform: catalogs agents across SaaS, custom frameworks, and endpoints, correlates each agent's identities with its tools, data, and behavior, and detects and blocks prompt injection, data leakage, and unauthorized tool calls at runtime.
- #3AcuvityAcquired by Proofpoint10
AI security and governance across endpoints, browsers, MCP servers, and local AI tools: discovers AI usage, inspects interactions at runtime, and enforces policy at the MCP boundary. Acquired by Proofpoint in 2026.
Ranked within this category only. How the score works.
Also covers this category
- Geordie AI41
Agent security and governance platform that discovers agents across cloud, code, and endpoints, maps each agent's tools and permissions, keeps an auditable record of every tool invocation, and steers agent behavior through its Beam remediation engine.
- PangeaAcquired by CrowdStrike23
AI guardrails and AI detection and response: collectors capture prompts, responses, and MCP traffic, policies block or redact risky content, and every interaction is logged with user identity and sent to a SIEM. Acquired by CrowdStrike in 2025; now CrowdStrike Falcon AIDR.
- Permiso SecurityAcquired by Okta37
Identity threat detection and response across human, machine, and AI agent identities, attributing each agent run, tool call, and data access to an identity. Acquired by Okta in 2026.
Questions to ask a vendor
- Is every tool call recorded with human, agent, tool, data, and decision?
- Can responders revoke one agent's access across systems in seconds?
- Does it export to your existing SIEM and case management?
Go deeper
FAQ
- What should an agent audit log contain?
- Who the human was, which agent acted, which tool it called with what arguments, what data it touched, and whether the action was allowed, in a form your SIEM can correlate.
- What is an agent kill switch?
- A tested, fast way to revoke one agent's tokens and tool access everywhere at once, so a misbehaving agent can be stopped mid-task.