Ask a market map what agent security still lacks and it will name three things: an agent behavioral baseline, cross-layer correlation, and agent-to-agent trust. What is interesting is not the list; it is that every incumbent addresses all three from the wrong side of the loop.

A baseline that is derived, not learned

“Normal” for a human developer was never learnable either, which is why anomaly detection in security has a tuning knob and a false-positive curve. For an agent, there is a better answer: normal is decidable.

The repository a developer works in already commits its own definition of normal: the lockfiles, the remotes, the scripts in package.json and the Makefile. An agent acting on a host outside those origins, a package the manifest does not name, or a command the toolchain does not imply, is outside normal. Not by a probability, but by membership. There is no training data, no score to tune, no baseline to drift.

Correlation as a byproduct, not a product

The “SIEM for agents” gap exists because identity, gateway, runtime and governance telemetry live in four different systems at four different vendors. Correlating them is a product that has to be built and maintained.

It is a product only if the observation points are separate. When the enforcement point is the observation point (the same hook that decides the action is the thing that records the session), one identifier already spans identity, the tool definition, the runtime and the proof. Correlation falls out of where the decision happens, instead of being bolted on afterwards.

Agent-to-agent trust, verified

Multi-agent systems today have no verification that one agent’s message to another is what it claims to be. The primitive is well understood: sign inter-agent messages and verify them against an allowlist of peer keys. And it is cheap to build. The reason it is rare is that it needs a place to live: someone has to verify, at the boundary between two agents, before the message is acted on.

Why placement is the whole argument

A detector reads transcripts after the agent has acted. An identity graph maps who holds what after the fact. A server-side sandbox contains an agent that is still running somewhere else. Each of these is useful, and none of them is positioned to answer the three gaps structurally, because all three gaps are properties of the moment before an action runs.

The one point positioned to answer all three is the in-loop decision, monotonically, on the developer’s machine, before the tool executes. And because that point is also where the action is observed and where the proof is signed, it produces the one thing the rest of the market is consolidating to buy: a complete, signed record of what an agent was authorized to do, what it did, what it touched, and where the result went.

That is not a claim that this is finished. It is a claim about where the work should live.


The three gaps are attributed to the AgentMarketCap market map (2026-04-05), a secondary source, and are treated here as dated positioning hypotheses, not facts. Contrasts with competitors are sourced in the security page’s market landscape and concede what those competitors do well.