Identity and Access Management · AI Security, Governance and Assurance · Third-Party Risk Management

Cisco’s Astrix Deal Puts Non-Human Identity in the Platform Layer

Cisco’s planned acquisition of Astrix Security moves non-human identity into IAM, zero trust access, Duo, Secure Access, and SOC workflows—not just another identity security tuck-in.

By Tal Eliyahu · · 8 min read

Editorial technical diagram for Cisco’s Astrix Deal Puts Non-Human Identity in the Platform Layer
A clean runtime access control showing Workload, Credential Broker, Vault, Policy, and Audit Trail as connected parts of the story. CyberBiz

Cisco’s planned acquisition of Astrix Security is not just another identity security deal. It moves non-human identity closer to the places where access is already managed, enforced, monitored, and investigated: IAM, zero trust access, Duo, Secure Access, and the SOC.

Cisco announced its intent to acquire Astrix on May 4, 2026. Cisco described Astrix as focused on the credentials used by modern systems, including API keys, service accounts, OAuth tokens, secrets, and the credentials AI agents use to access enterprise systems. Cisco said Astrix capabilities cover AI-agent discovery and governance, access and lifecycle management, threat detection and response, and secrets management across vaults and cloud environments.

Cisco also said it plans to integrate Astrix into Cisco Identity Intelligence, Cisco Secure Access, and Duo IAM, with activity context feeding into Splunk or other SIEMs. Cisco did not disclose deal terms. The deal has been valued at roughly $400 million in market coverage, but the more important point is where Cisco plans to place Astrix: inside identity, access, and security operations workflows.

Astrix is not positioned only around finding forgotten service accounts. Its product messaging covers inventory for AI agents, MCP servers, service accounts, OAuth apps, API keys, SSH keys, IAM roles, secrets, owners, permissions, accessed resources, abnormal activity, and risk prioritization. That places the product at the point where discovery starts turning into access control.

That distinction matters because the NHI problem is no longer limited to secrets hygiene. A service account, OAuth app, API key, CI/CD credential, SaaS integration, workload identity, or AI agent can carry access across several systems. The question is not only whether the identity exists. It is who owns it, what it can reach, whether the access is still needed, what business process depends on it, and what should happen when behavior changes.

Cisco is not alone in moving this problem into larger platforms. CyberArk completed its Venafi acquisition in 2024 to expand machine identity security. CrowdStrike signed a definitive agreement to acquire SGNL in January 2026 to support continuous access decisions for human, non-human, and AI identities.

Enterprise

Discovery is not enough. A tool that only lists API keys, OAuth tokens, service accounts, secrets, or AI agents still leaves the main questions unanswered: who owns the identity, what access does it have, where is it being used, and how can risky access be reduced without breaking production? The product needs to connect identity, owner, privilege, data access, runtime behavior, and remediation. It also needs to work inside existing IAM, PAM, SIEM, cloud, SaaS, CI/CD, vault, and data security workflows. Otherwise, it becomes another inventory screen.

Workflow diagram for Cisco’s Astrix Deal Puts Non-Human Identity in the Platform Layer
Workflow view of the control path, market pressure, and buyer impact behind Cisco’s Astrix Deal Puts Non-Human Identity in the Platform Layer. CyberBiz

Vendors

The market is moving from visibility to enforcement. IAM, PAM, CNAPP, DSPM, SaaS security, CI/CD security, vaults, and SIEM vendors all touch part of the NHI problem. The stronger position is not “we find non-human identities.” It is “we control how software, integrations, workloads, and AI agents access business systems.”

Founders and investors

A standalone NHI company needs more than inventory. It needs clear remediation, agent governance, workflow integration, and proof that it can reduce risky access without breaking production. That is where the category gets harder, and where acquisition interest becomes easier to understand.