News alert: Orchid Security brings Zero-Trust to AI Agent identities, earns Gartner recognition
嗯,用户让我用中文总结一下这篇文章,控制在100字以内,而且不需要以“文章内容总结”或“这篇文章”这样的开头,直接写描述。好的,首先我需要通读整篇文章,抓住主要信息。 文章主要讲的是Orchid Security被Gartner评为Guardian Agents市场的代表供应商。他们专注于管理AI代理的身份和访问权限,采用零信任策略和治理。Gartner指出AI代理带来了新的风险,企业准备不足。Orchid认为这需要五个核心原则来确保安全采用AI代理。 接下来,我需要提取关键点:Orchid被认可、管理AI代理的身份、零信任策略、Gartner的市场指南、以及Orchid的五个原则。然后把这些信息浓缩到100字以内。 可能的结构是:Orchid被Gartner评为代表供应商,专注于管理AI代理的身份和访问权限,采用零信任策略。Gartner指出AI带来的风险和企业准备不足的问题。Orchid提出了五个核心原则来确保安全使用AI代理。 现在检查字数是否在限制内,并且语言要简洁明了。 </think> Orchid Security被Gartner评为Guardian Agents市场的代表供应商,专注于管理AI代理的身份和访问权限,采用零信任策略和治理。Gartner指出AI代理引入了超出人工审查的新风险,而大多数企业由于组织结构分散和发现挑战而准备不足。Orchid认为这需要五个核心原则来确保安全采用AI代理。 2026-3-18 04:15:21 Author: securityboulevard.com(查看原文) 阅读量:5 收藏

NEW YORK, Mar. 17, 2026, CyberNewswireOrchid Security, the company bringing clarity and control to the complexity of enterprise identity, today announced it has been recognized as a Representative Vendor in Gartner’s Market Guide for Guardian Agents, as a vendor “managing the identities/access for AI agents with zero-trust policies and governance.”

In this inaugural market guide, Gartner asserts that:

“AI agents introduce new risks that outpace human review, yet most enterprises are unprepared to manage them due to fragmented organizational structures and ongoing challenges with discovery.”

Orchid Security concurs with this assessment. The company finds that the growing use of AI agents exponentially expands the amount of identity dark matter—the invisible and unmanaged layer of identity—within organizations. AI agents may also exploit the dark matter that already exists in order to achieve their prompted purposes as efficiently as possible by design.

Katmor

“For all the exciting business transformation promise of agentic AI, its growing adoption poses very real cyber, compliance and operational risks to be managed,” said Roy Katmor, co-founder and CEO of Orchid Security.

In reviewing Gartner’s research, Orchid notes several key requirements for properly managing AI agents that are shaping the guardian agent market:

Human operator attribution

Although AI agents are assumed to act on behalf of individuals, they have their own identities independent of users. Organizations must identify all agents and map their activity to the relevant human owner for accountability, compliance, and governance.

Activity audit

Organizations must see, log, monitor, and report on agent activity and output to ensure accountability, demonstrate compliance, and enable incident response in the event of unauthorized modifications or incidents.

Posture management

Secure use of each AI agent requires proper identity and access management hygiene, including centrally managed identities, strong authentication, time- and purpose-bound access, and least-privilege authorization.

Runtime inspection, enforcement

Agentic actions and outputs must remain aligned with intentions, goals, and governance policies to maintain appropriate use.

Secure AI agent adoption

Orchid believes these requirements align closely with its view of secure AI-agent adoption within comprehensive identity and access management, guided by five core principles:

Human-to-agent attribution

Identify and classify every AI agent—whether embedded in self-hosted applications, delivered via SaaS platforms, or operating through third-party solutions—and explicitly correlate it to a responsible human owner (and, where relevant, a system/service owner). This ensures organizations know exactly who triggered an agent run, who approved the tool use, and who is ultimately responsible for the outcome.

Comprehensive activity audit

For every agentic entity, capture the full operational context: the agent identity, assigned role, intent behind the action, approvals, and the complete chain of custody from Agent ? Tool/API ? Action ? Target. This enables accountability, compliance reporting, and rapid incident response.

Dynamic, context-aware guardrails

Ensure every AI agent’s access is continuously evaluated and enforced based on real-time context, human owner entitlements, environment, time, purpose, sensitivity of the target, and risk signals—avoiding broad, standing privileges regardless of how the agent is implemented or integrated.

Least privilege

Require properly scoped permissions and Just-in-Time (JIT) elevation for agent actions, replacing persistent “god-mode” access with purpose-bound, time-bound authorization aligned to the minimum required access.

Remediation responses

Detect unauthorized or risky agent activity—such as attempts to bypass controls, use static secrets, exceed intended scope, or access sensitive targets—and orchestrate remediation by blocking the action, stepping up approval, enforcing re-authentication, or rotating credentials via Vault/PAM integrations.

“AI agents will not be adopted safely on top of yesterday’s identity stack,” Katmor summarized.

“Orchid delivers the identity infrastructure for every identity, human and non-human—including agentic AI—with attribution, audit, and least-privilege guardrails built in. That’s how enterprises unlock the full power of AI without expanding their attack surface or compromising compliance.”

Enterprise leaders responsible for cybersecurity, identity and access management, and AI agent governance register for select access to the Gartner Market Guide for Guardian Agents, compliments of Orchid Security.

Additional resources

•Forbes: The New Perimeter is Identity—and It’s Moving Faster Than We Are

•The Hacker News: AI Agents: The Next Wave of Identity Dark Matter

•Orchid Security: When “Lazy” LLMs Meet Identity Dark Matter

Gartner’s Market Guide for Guardian Agents, 25 February 2026

Gartner Disclaimer: Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose. GARTNER is a trademark of Gartner, Inc. and its affiliates.

About Orchid Security: Orchid Security sees straight into application binaries to deliver the industry’s first Identity Control Plane, transforming IAM complexity into clarity, compliance, and control. Its Identity-First Security Orchestration platform continuously discovers enterprise applications, analyzes their native authentication and authorization flows, and accelerates onboarding into governance systems—cutting months of manual work into a single click. The platform also observes all identity activity—managed and unmanaged—at the application level, providing a full audit of use and identifying orphan, dormant, local, and over-permissioned accounts. By exposing and remediating the “identity dark matter” hidden across modern environments, Orchid helps enterprises reduce risk, lower operational costs, and achieve compliance at scale.

Backed by Intel Capital and Team8, Orchid leverages observability, automation, and large language models to unify fragmented identity operations. Global organizations rely on Orchid to modernize identity governance, accelerate IGA adoption, and secure the next generation of applications and AI agents.

Media contact: Chloe Amante, Montner Tech PR, [email protected]

Editor’s note: This press release was provided by CyberNewswire as part of its press release syndication service. The views and claims expressed belong to the issuing organization.

March 17th, 2026 | News Alerts | Top Stories


文章来源: https://securityboulevard.com/2026/03/news-alert-orchid-security-brings-zero-trust-to-ai-agent-identities-earns-gartner-recognition/
如有侵权请联系:admin#unsafe.sh