Agent gateways, registries and identity controls arrive as a product category
Cequence shipped AI Discovery, an API Registry, an LLM Registry and a Skill Registry, plus Agent Personas binding an agent's job description to its model, tools and guardrails. Snowflake announced Cortex AI Gateway with MCP governance and agent identity at Black Hat.
When two vendors ship the same abstraction in the same week, the abstraction is usually correct. The shared idea here is that an agent needs an identity, a scope and an audit trail — the things every other principal in an enterprise system already has and agents were deployed without.
The most useful primitive is the credential-free call. Cequence's API Registry lets an agent invoke approved APIs without ever holding a raw credential, which changes the blast radius of a compromised or misdirected agent from "everything that key could reach" to "the specific calls the registry allows". That is the difference between a bad afternoon and a breach notification.
Discovery is the unglamorous half and probably the more immediately valuable one. Surfacing every agent, AI provider and MCP server already running by mining existing security logs is an admission that these things arrived without being inventoried — which is exactly what happened, and you cannot govern what nobody has enumerated.
Agent Personas — binding a job description to a specific model, tool set and guardrails — is the piece that will be argued about, because it makes the scope decision explicit and therefore auditable. That is progress, and it is also a document somebody now has to own. Nothing here is exotic; it is IAM arriving for a new kind of principal, roughly two years late.
Snowflake — Enterprise AI Security: Agentic Controls and MCP Governance → · The Agentics — The Enterprise MCP Guide 2026 →