AI Governance · Non-Human Identity
Every agent gets a name. Almost none get their own key.
Three real breaches in the last thirteen months, three different industries, the same root cause: one long-lived credential wired into everything an agent touches. A deep dive into how AI agents actually get authenticated, the market now selling against this exact failure, and the guardrails that would have changed each outcome.
THE EVIDENCE · THREE INCIDENTS, ONE PATTERN
This didn't start as a theory
Three documented breaches from the last thirteen months, at three different scales, all tracing back to the same design choice.
Aug 2025 · Salesloft Drift OAuth breach. A set of long-lived, broadly-trusted OAuth tokens, once compromised by the group tracked as UNC6395, gave attackers a path into 700+ downstream organizations' Salesforce environments — including Cloudflare, Google, PagerDuty, Palo Alto Networks, Proofpoint and Zscaler. The tokens were revoked only after the fact, on August 20.
— per Google Threat Intelligence and multiple vendor disclosures
2026 · Klue / Salesforce credential cascade. A four-year-old Salesforce credential, never rotated, was used to breach Klue and cascade into roughly 200 companies, including LastPass, Jamf and HackerOne.
— as reported via Tech Insider
PowerSchool breach. Attackers used a single unprotected maintenance credential — with no MFA in front of it — to access the data of 62 million students and nearly 10 million teachers.
— per public breach disclosures
Three incidents, three industries, one identical root cause: a credential built to be shared, not scoped — issued once, trusted everywhere, and never re-evaluated per connection.
— the pattern across all three
THE MARKET RESPONSE
A category getting absorbed as fast as it formed
A wave of purpose-built vendors emerged to discover, govern and secure non-human identities — and in 2026, the biggest identity and security platforms started buying their way in rather than building it themselves.
Astrix Security
Discovers NHIs across SaaS, cloud and code; flags over-privileged or untrusted connections.
Oasis Security
Full lifecycle coverage — discovery, posture, rotation and decommissioning in one place.
Entro Security
Secrets-centric view: traces where a secret lives, how it's used, and which NHI owns it.
Aembit
Runtime access and policy-based enforcement for workload-to-workload authentication.
Akeyless
SaaS-native secrets management using distributed key-fragment encryption instead of a single master key.
GitGuardian
Secrets-sprawl detection across source code and CI/CD pipelines, at public-repo scale.
This category is consolidating fast. In 2026 alone: Cisco announced its intent to acquire Astrix (May), SailPoint closed its acquisition of Entro (June), and Cyera signed a letter of intent for Oasis (July, at roughly $1B). Non-human identity management is being absorbed into core identity platforms rather than staying a standalone product line — a strong signal that credential sharing has moved from "edge case" to "board-level line item" in about eighteen months.