Cisco Just Spent $400M on Your AI Agent Identity Problem
Cisco's $400M Astrix Security acquisition signals that non-human identity governance is the next battleground — and no-code builders deploying AI agents need to pay attention now.
Table of Contents
TL;DR: Cisco spent about $400 million on Astrix Security, a startup that secures non-human identities — API keys, service accounts, OAuth tokens. The same credentials your AI agents use to do anything. Combined with Microsoft giving every agent a proper Entra identity via Agent 365, an agent identity layer is forming. No-code builders deploying agents across Zapier, n8n, and Make should care about who controls those credentials. Platforms with identity built into the architecture, not added on after the fact, are about to look very smart.
When Cisco writes a $400 million cheque for something, the rest of us should probably pay attention.
That cheque landed on Astrix Security's desk in May 2026. Astrix, founded in 2021 by two veterans of Israel's Unit 8200, had spent five years building a platform to do one thing: discover, govern and secure non-human identities. NHIs to their friends. API keys. Service accounts. OAuth tokens. The invisible plumbing that modern software runs on.
These are not glamorous things to build a company around. They are the cybersecurity equivalent of being the person who cares deeply about plumbing standards at a party where everyone is talking about AI. But here is what Cisco understood that your average CIO is still sleeping on: every AI agent you deploy is a non-human identity. And right now, most of them are running around your systems with the digital equivalent of a master key and no one watching.
Why should no-code builders care about a cybersecurity acquisition?
I will tell you why.
A no-code builder who deploys five automations across Zapier, three workflows in n8n, and a couple of AI agents in Make has probably created somewhere between 15 and 40 individual non-human identities. Each one has an API key. Each one has permissions. Each one could, if misused, become a very quiet entry point into whatever systems those automations touch. The question is not whether you have NHIs. You do. The question is whether anyone in your organisation knows what they are, what they can access, and whether they still need to exist.
I have been in rooms where a marketing ops person admits they set up a Slack-to-HubSpot integration two years ago using a personal API key from someone who left the company. Nobody rotated it. Nobody audited it. It still works. That is not a hypothetical — that is the default state of most mid-market companies I have seen.
Now multiply that by AI agents, which are being spun up at a pace that makes traditional SaaS adoption look glacial. According to Cisco's own AI Readiness Index, only 24% of organisations can control agent actions with proper guardrails and live monitoring. Just 31% feel fully capable of securing their agent AI systems. That is a confidence gap the size of a canyon.
What Astrix actually does
Astrix built a platform that gives security teams a real-time inventory of every non-human identity in their environment. It does not just list them — it maps what they are connected to, what permissions they have, and whether those permissions are excessive. It detects when an agent suddenly calls an API it has never touched before. It spots when credentials have not been rotated in years. It can auto-revoke access when something looks wrong.
This sounds like basic hygiene. It is. And almost nobody was doing it until recently, because the tooling did not exist in a usable form. Astrix built it. Cisco bought it. The NHI category — which barely existed as a named thing three years ago — now has a $400 million valuation anchor.
Cisco's plan is to integrate Astrix across its security platform: Identity Intelligence, Secure Access, Duo, Splunk. The pitch from Peter Bailey, who runs Cisco's security business, is that Cisco's position across identity, network, application and infrastructure layers means they do not just know what an agent is — they understand how it behaves. It is a good pitch. Whether they execute on it is another question — Cisco's acquisition integration track record is mixed. But the strategic bet is correct. Agent identity is becoming a first-class security concern, and someone needs to own it.
Microsoft is building the same thing from the other direction
While Cisco is acquiring its way into agent identity, Microsoft is building it natively. In May 2026, Microsoft Agent 365 went GA, and with it came Microsoft Entra Agent ID.
This is where it gets interesting for the no-code world. Entra Agent ID gives every AI agent a proper, first-class identity. Agents get blueprints that define their permissions, credentials and security policies. Those blueprints can be applied across dozens or hundreds of agent instances. Conditional Access policies — the same thing that stops your employees accessing SharePoint from an unmanaged device — now apply to agents too. Agents get lifecycle management: onboarding, access reviews, decommissioning.
Microsoft is treating agents like employees. Which, in a very real operational sense, is what they are becoming. Here is the subtle but important thing: Microsoft can do this because identity is architectural in their platform. Entra is not a feature they added to support agents. It is the foundation Agent 365 sits on. Identity came first. Agents came second.
The two paths for no-code builders
This is where the story splits, and I think the split matters more than most builders realise.
If you are building AI agent workflows on general-purpose automation platforms — stitching Zapier, Make, n8n and a handful of API calls together — you are operating in what I would call the ungoverned agent model. Each connection creates a credential. Each credential is a potential risk. The governance is on you: you need to track what is connected to what, rotate keys, audit permissions, and hope nothing slips through.
Most people do not do this. They cannot. The tools do not make it easy, and the people deploying agents are often not the people who understand credential hygiene. A marketing manager setting up a Claude-powered email workflow in Make is not going to audit OAuth token scopes. Nor should they have to.
The alternative is the governed platform approach. Platforms where identity, authentication and permissioning are not things you configure per-agent — they are things the platform provides as infrastructure. Where every user, every agent and every data source sits inside a coherent permission model that was designed before the first agent was ever deployed.
Stacker is in this second camp. So is Microsoft's Power Platform, certain ServiceNow configurations, and a handful of other platforms that treat identity as the substrate, not the afterthought. The advantage is not theoretical. When every agent action is traceable to a specific authenticated identity, when permissions are inherited from a role rather than copy-pasted from a sticky note, when access can be revoked centrally rather than tracked down across seventeen different automation platforms — you have something that looks like actual governance.
What the $400M signal actually means
Cisco's acquisition of Astrix and Microsoft's GA of Agent 365 are not coordinated. But they are responding to the same reality: the agent identity layer is becoming the new battleground.
For no-code builders, the practical takeaway is this: the way you handle agent identity today is probably not going to cut it in eighteen months. Either because a security audit will catch it, or because an incident will expose it, or because an insurance underwriter will start asking questions you cannot answer.
The smart money is on moving toward platforms where identity governance is structural. Where you do not have to be a security professional to have a secure deployment. Where the platform's architecture enforces what a hardworking ops person would have to enforce manually otherwise.
Cisco just spent $400 million telling the market that non-human identity is a problem worth solving at enterprise scale. Microsoft is telling the market that every agent deserves a proper identity.
If you are a no-code builder who plans to deploy AI agents in any serious way, the gap between these two approaches — governed and ungoverned — is about to become the most important architectural decision you make. Pick the one where identity is not something you have to remember to get right.
Want to read
more articles
like these?
Become a NoCode Member and get access to our community, discounts and - of course - our latest articles delivered straight to your inbox twice a month!



