Everyone sells an agent OS. What is it, who sells one, and how do they compare?

Agent operating system platforms compared

Take a hypothetical bank. Its customer service runs on Agentforce, IT tickets on ServiceNow, and a small team has built a credit-limit agent with LangGraph on AWS. Last quarter the bank bought an agent management platform, and the platform's registry lists all three agents.

On Monday, internal audit asks four questions about one customer record that changed over the weekend. Which agent changed it, under whose identity did it act, how long did the run take, and did it retry after a failure?

The registry answers the first question and the audit log part of the second. Nobody can answer the last two from the documentation of the products the bank paid for.

Vendors now call their agent platforms an "operating system" or a "control plane". That leaves buyers like the bank with three questions: what an agent OS is supposed to do, who sells one, and how the products compare.

The comparison here tests them against what an operating system actually guarantees: isolation, limits, an identity of its own, and surviving a crash.

The position: in October 2026, most products sold as an agent OS are a governance layer, not an operating system. Buy it for policy, tool access and audit, which most products document well. Treat isolation, run limits, durable execution and agent identity as open questions you put to each vendor in writing, because most of them do not answer those questions in public.

The short answers:

  • What it is: a platform that runs, connects and governs a fleet of agents, including agents built elsewhere. Gartner calls the category AI Agent Management Platforms; vendors call it an agent OS or control plane.
  • Who sells one: 26 vendors from nine starting points: cloud and model platforms, identity, gateways, integration, workflow, business suites, data platforms, agent-native startups and industry platforms. Each is strongest where it started. Frameworks such as LangChain are out.
  • How they compare, governance: 22 of 26 platforms document how they enforce agent permissions, 21 document MCP tool access, 20 document an audit log of agent actions.
  • How they compare, runtime: 2 of 26 state a maximum run duration in numbers, 5 document durable execution with checkpoints or restarts, 6 explain how agent sessions are isolated from each other.
  • How they compare, identity: 12 of 26 give an agent an identity of its own. The rest let agents act as the calling user, as a shared service account, or say nothing.
  • How they compare, other platforms' agents: 11 platforms document that they can call or delegate to an agent built elsewhere. Several others only list foreign agents in a registry and watch them.
  • How they compare, hosting: some control planes do not run agents at all. Microsoft Agent 365 states that its SDK "doesn't host or deploy your agent", and Gravitee governs agent traffic at a gateway. You still need a runtime underneath.

In this article:


What is an agent OS?

Gartner published a Market Overview for AI Agent Management Platforms in July 2026, defining a category for managing agents across the enterprise from one control plane. Forrester followed in Q2 2026 with a report on agentic control plane solutions. Vendors outside both lists now use the same words: Lyzr sells an "Agentic Operating System", Fiserv an "Operating System for Agentic AI in Banking", Wonderful "The Enterprise AI OS".

The definition used here is functional. A product is in if it runs, connects and governs a fleet of agents, including agents built on other platforms, with an agent registry, agent permissions and an audit trail. It also needs either an analyst listing or its own positioning as an agent OS or control plane.

That definition borrows a word with a precise meaning. An operating system makes three promises to a program.

It runs in its own space and cannot read another program's memory. It runs within limits the system enforces, on CPU, memory and time. And it runs under an identity that decides what it may touch.

Map that onto agents and you get a test you can apply to any product that uses the label.

Operating system Agent equivalent Question it raises
Process and address space Agent session How are agents isolated from each other?
Scheduler and resource limits Run budget How long may an agent run, and who stops it?
Persistent storage Agent memory What does an agent remember, and where?
Process control (fork, wait, signals) Orchestration Can one agent start, wait for and stop another?
System calls and drivers Tools, MCP, A2A How does an agent reach other systems?
Users and permissions Agent identity and policy Who is the agent, and what may it do?

The test used here has five topics with five questions each: runtime, memory, orchestration, protocols and governance. Each question was answered from the vendor's own public documentation, engineering blogs and launch posts, about 1,200 pages for the 26 vendors. A question counts as documented only if a page states the answer, not if it is implied.

That method has a limit. A missing answer means the vendor does not say it in public.

It does not prove the product cannot do it. For a buyer the difference is small: an undocumented guarantee is one you cannot hold a vendor to.

So the short answer to what an agent OS is: a product that should do all six things in the table. Whether it does is the comparison further down.

Infographic: What is an agent OS? (Everyone sells an agent OS)

Where the term comes from

The phrase started as a research idea and ended up on governance products. In 2023 Andrej Karpathy described the language model as the kernel of an emerging operating system, and a paper called "MemGPT: Towards LLMs as Operating Systems" managed a model's context the way an operating system pages memory. In March 2024 the AIOS paper built the most literal version: an agent kernel with a scheduler, a context manager, a memory manager, a storage manager, a tool manager and an access manager.

From 2024 the pieces turned into standards and products. MCP gave tools a common driver model, A2A gave agents a way to talk to each other, and AWS shipped runtime, memory and identity as cloud services in AgentCore.

In 2025 PwC became the first company found here to sell a product called "agent OS". By 2026 the analysts had named the category, and neither used the word: Forrester calls it an "agentic control plane", Gartner "AI agent management platforms".

Set the AIOS kernel next to what the 2026 products document. Access management became policy and audit, and tool management became MCP gateways; nearly every vendor covers both. The scheduler and the context manager, which decide which agent runs, for how long and with what resources, are the parts this comparison finds missing.

Research built the kernel first. The market built the permission system first.

When What happened
2023 Karpathy's "LLM OS" framing; MemGPT paper
2024 AIOS agent kernel; Model Context Protocol
2025 A2A protocol; AgentCore GA; PwC "agent OS"
2026 Agent 365 GA; Fiserv agentOS; Gartner names the category

Who sells one? Nine kinds of agent OS

The definition gives 26 vendors. Almost none of them started as an agent platform. Each extended a product it already sold toward agents, and what that product was explains most of what the agent OS documents well and what it leaves out.

That gives nine kinds of agent OS. The reach column says whether a kind mostly governs its own agents or also agents built elsewhere.

Origin Vendors Reach
Cloud and model platforms AWS, Google, OpenAI Any agent, strongest on own runtime
Identity and productivity Microsoft Any agent, as a governance layer
Gateways and AI governance Gravitee, Kosmoy, WSO2, Airia Any agent that routes through them
Integration platforms Boomi, Workato Any agent reachable by API or A2A
Workflow and process automation ServiceNow, UiPath, AgilePoint Own agents plus external agents in processes
Business application suites Salesforce, SAP, Workday Own agents first, external agents by protocol
Data and AI platforms Databricks, Dataiku, IBM Agents on the platform's data and compute
Agent-native platforms Kore.ai, OneReach.ai, Lyzr, xpander.ai, Wonderful Any agent, platform built for agents
Industry platforms Fiserv, XMPro Agents in one sector's workflows

Some well-known names are out on purpose. LangChain, CrewAI, Agno, Mastra, Letta and the OpenAI and Anthropic agent SDKs are frameworks: they help you build an agent but do not govern a fleet. Sierra uses the name "Agent OS" for a platform that runs only Sierra-built service agents.

Palantir AIP and Writer govern agents built inside their own platforms. NVIDIA ships toolkits and blueprints without a registry. Kong, Okta and Credo AI each cover one function, a gateway, identity or a registry, without the rest.

Infographic: Who sells one? Nine kinds of agent OS (Everyone sells an agent OS)

Cloud and model platforms

These vendors already run compute or models, so the agent runtime is theirs. AWS gives the most complete runtime answer in this set: a dedicated microVM per session, sanitised on exit, with sessions of up to 8 hours, or 14 days on dedicated instances.

Google's Agent Runtime gives each agent "a per-agent identity", runs long operations for up to 7 days and supports A2A. OpenAI's Agents SDK sandboxes code and workspaces.

The gap is governance beyond their own runtime. AWS names no certification for the agent platform itself, and OpenAI names agent identities and audit logs for Frontier without describing how they work. Agents built elsewhere are welcome as long as they run on the vendor's runtime.

Fits if your agents will run on that cloud or model, and you add enterprise governance on top.

Identity and productivity

Microsoft came to agents from Entra ID and Microsoft 365. Agent 365 gives every agent an Entra service principal and applies Conditional Access "to agents just as they do to users". Prompts and responses land in the Purview audit log, and agents built on Bedrock or Vertex AI can be synchronised into the registry.

What it does not do is run agents. The SDK "doesn't host or deploy your agent", so isolation, run limits, memory and durable execution belong to whatever runtime you put underneath.

Fits if you run Microsoft 365 and want every agent, wherever it runs, inside the same identity and compliance stack as your users.

Infographic: Identity and productivity (Everyone sells an agent OS)

Gateways and AI governance

Gravitee and WSO2 come from API management, Kosmoy and Airia from AI gateways and AI governance. A gateway sees every call, so policy, audit and tool access come first. Gravitee registers each agent as an OAuth client and evaluates policies "at the wire level", and WSO2 gives each agent a unique Agent ID and credentials.

Memory and orchestration are mostly someone else's job. Kosmoy is the exception on runtime: its capsules run in your Kubernetes cluster with namespaces, cgroups, Seccomp and default-deny egress.

Fits if you need one enforcement point across agents from several vendors and already route API traffic through a gateway.

Integration platforms

Boomi and Workato connected applications before they connected agents, and that is where they are strongest. Workato recipes call any A2A-compliant agent and list tested compatibility with ADK, LangGraph, CrewAI, AgentCore and Azure AI Foundry. Boomi's Agent Control Tower tracks agents from other providers such as Bedrock.

Agent identity is where the integration heritage shows. A Boomi agent "uses the current user's JWT token", and Workato takes identity from the user's session. Neither documents how agent runs are isolated.

Fits if your agents mostly need to move data between systems you already integrate.

Infographic: Integration platforms (Everyone sells an agent OS)

Workflow and process automation

ServiceNow, UiPath and AgilePoint orchestrated processes, approvals and robots before agents. Their agent OS is strongest on orchestration: ServiceNow's orchestrator discovers and delegates to external agents over A2A, and UiPath Maestro Orchestrate runs durable processes "with no cap on duration or concurrency".

Isolation tends to be logical rather than technical. ServiceNow separates agents by domain and access controls, and its guidance moves retries and loops out of the agent into flows.

Fits if your agents are steps in long business processes with human approvals.

Business application suites

Salesforce, SAP and Workday add an agent layer to the system of record. That makes them strongest on identity, permissions and compliance: Salesforce separates system identity for autonomous agents from user identity, SAP gives each agent "a unique identity for reauthentication at every step", and Workday holds third-party certification for ISO 42001 and the NIST AI Risk Management Framework.

All three reach external agents through MCP and A2A, but govern their own agents best. Run limits are undocumented across the group, and Workday keeps its technical documentation behind a customer login.

Fits if most agent work happens inside that suite's data and processes.

Infographic: Business application suites (Everyone sells an agent OS)

Data and AI platforms

Databricks, Dataiku and IBM come from data science and AI platforms, so the agent runs next to the data and its governance. Databricks governs agent tools with Unity Catalog privileges and restarts interrupted runs with DurableAgentServer. IBM runs each tool instance as its own pod and supports five memory types.

As a group they document runtime and durability better than any other kind. The gap is interoperability: Databricks documents no A2A support.

Fits if your agents are built by data teams on governed enterprise data.

Agent-native platforms

Kore.ai and OneReach.ai grew out of conversational AI, while Lyzr, xpander.ai and Wonderful were built as agent platforms. They document multi-agent patterns and protocols well: Lyzr calls LangChain and CrewAI agents as sub-agents over A2A, and Kore.ai mixes local and external agents in one workflow.

Runtime guarantees vary widely inside the group. xpander.ai documents bubblewrap sandboxes and a 3-hour pod lifetime, while Kore.ai says session limits "vary by plan" without figures.

Fits if you want a platform designed for agents first and can test its runtime claims yourself.

Infographic: Agent-native platforms (Everyone sells an agent OS)

Industry platforms

Fiserv built agentOS for banks on Bedrock AgentCore, and XMPro built APEX for industrial operations. They bring domain rules: XMPro documents deontic policy rules and consensus for critical decisions.

Public technical documentation is thin. XMPro describes no isolation, MCP or A2A, and its "15+ days" of autonomous operation is a marketing figure.

Fits if the sector-specific workflows matter more to you than a general-purpose platform.

How do they compare?

The 25 questions split the market cleanly. The questions a governance team asks first are answered almost everywhere. The questions that make an operating system an operating system are answered by a minority.

The same split shows up in how vendors treat quality. Testing an agent before release is well covered: ServiceNow's AI Agent Studio runs an evaluation job against "a dataset of representative historical records (recommended: 20–100 records)", and Kore.ai lists evals as "Testing before release". Bounding the same agent once it runs is the part most documentation skips.

Infographic: How do they compare? (Everyone sells an agent OS)

What the platforms solve

Four of the 25 questions are answered by almost every vendor. They are the questions an auditor or a security architect asks first.

Capability Documented by
Permission and policy enforcement 22 of 26
Agents use tools from MCP servers 21 of 26
Connector or gateway layer to enterprise systems 21 of 26
Audit log of agent actions 20 of 26

Policy enforcement comes in three flavours. Microsoft applies Entra Conditional Access and Identity Protection "to agents just as they do to users".

AWS puts a policy engine in front of every tool call that passes through AgentCore Gateway. Databricks governs agent tools "with the same privileges and ABAC GRANT policies you use for tables and volumes".

Tool access through MCP has become the default. Salesforce lets admins register external MCP servers in Agentforce, ServiceNow agents call MCP servers such as Jira, SAP and GitHub, and WSO2, Kosmoy and Gravitee put an MCP gateway between agents and servers to apply access rules and logging.

Audit is documented almost everywhere, with different depth. ServiceNow states that "every tool execution is audited" in AI Control Tower.

Microsoft Purview captures agent prompts and responses in the unified audit log. Airia promises a tamper-evident trail, XMPro an "immutable" one, without describing the mechanism.

Discovery is often the first job a buyer gives a control plane, before any policy is written. Airia promises to manage AI "from sanctioned platforms to shadow AI", WSO2 frames the problem as "agent sprawl", and Dataiku's Agent Management says "Discover AI agents across platforms". Microsoft draws the line between sanctioned local agents and shadow AI, which it describes as "unmanaged, autonomous applications".

You cannot govern an agent you do not know exists. For most enterprises an inventory is the realistic first project, and it is the part these products are best prepared for.

So the first question in the bank scenario, which agent touched the record, has an answer on most platforms. The registry and the audit log were built for exactly that question.

Where the operating system is missing

The weak answers cluster in the questions that make an operating system an operating system.

Capability Documented by
Maximum run or session duration 2 of 26
Durable execution (checkpoints, retries, resume) 5 of 26
Isolation between agent sessions or tenants 6 of 26
Where long-term memory is stored 6 of 26
Compliance certifications for the agent platform 9 of 26
An identity of the agent's own 12 of 26
Orchestrating agents built on other platforms 11 of 26

Infographic: Where the operating system is missing (Everyone sells an agent OS)

Isolation and run limits

AWS and Google are the exceptions that show what a full answer looks like. Each AgentCore Runtime session "runs in a dedicated microVM with completely isolated CPU, memory, and filesystem resources", the microVM is terminated and its memory sanitised when the session ends, and a session lasts up to 8 hours, or up to 14 days on the Instances compute option. Idle timeout defaults to 15 minutes.

Google's Agent Runtime supports long-running operations "up to 7 days", and its Agent Sandbox isolates each sandbox "from other sandboxes and the host system".

A handful of others describe isolation without limits. SAP places each agent in its managed runtime "inside an isolated, sandboxed environment" based on NVIDIA OpenShell. xpander.ai runs each turn in a bubblewrap sandbox with its own cgroup and seccomp filter.

Kosmoy builds on Linux namespaces, cgroups v2, Seccomp-BPF and Landlock, with default-deny network egress. IBM runs each Python and Langflow tool instance as a separate pod.

Most platforms answer with logical separation. Kore.ai scopes sessions to a tenant ID and prefixes Redis keys. ServiceNow uses domain separation and runs each agent under the run-as user's access controls.

Microsoft "logically isolates all data accessed or processed by tenant". That protects data. It says nothing about one agent exhausting the resources of another.

Run limits are thinner still. OpenAI's Agents SDK bounds runs by turn count, not time, and the limit can be switched off. UiPath caps a Maestro Automate run at 24 hours and sets no cap for Maestro Orchestrate.

Salesforce markets agents that "pursue goals across days and weeks" without documenting a limit. Twelve vendors say nothing at all.

If an agent can loop, call paid tools and hold credentials, the run budget is a cost control and a security control. You should not have to infer it from a marketing page.

Who can press stop

An operating system can kill a process. Of the 26 platforms, six mention a way to stop or suspend a running agent, and they mean different things by it.

Vendor Stop mechanism, in its own words
ServiceNow AI Control Tower "can detect it and shut it down in real time"
Salesforce "The Kill Switch policy blocks that agent’s access to the model proxy when you quarantine it"
WSO2 "suspending a live agent in real time"
Kosmoy an agent "contained in a sandbox with a kill switch"
Gravitee "The proxy that fronts the agent has a stop of its own"
Fiserv lists "Kill / suspend" among the agentOS controls

Blocking an agent's access to its model at a gateway is not the same as ending its process. An agent cut off from the model can still hold open connections and credentials until its runtime ends the session. Only a vendor that owns the runtime can promise the second.

Where run limits are missing, budgets fill in. Kosmoy puts "a budget at the gateway" that "warns as the limit nears and can stop a runaway agent". xpander.ai makes every skill "budgeted, and tied to the person who asked for it", and Workday wants customers to "budget and forecast" agent costs. Money is the one limit a control plane can enforce without owning the runtime, so cost has quietly become the market's run budget.

If you are writing the runbook for a misbehaving agent, ask each vendor which of these it offers: block the model, block the tools, suspend the agent, or end the process.

Durable execution

An operating system lets a long job survive a restart. For agents that means checkpoints, retries and resume after a crash or a long wait for a human.

Five vendors document it. Databricks ships a DurableAgentServer that "detects interrupted runs and starts a replacement attempt".

UiPath Maestro Orchestrate offers "durable execution with no cap on duration or concurrency". WSO2 describes durable agents that pause, wait for events and recover "without losing" state, and xpander.ai sets retry strategies per workflow node.

Others push durability out of the agent. ServiceNow's well-architected guidance says agents run synchronously and that "loop logic, retry operations, and batch operations should be implemented in flows or scripts".

OpenAI points to external integrations for runs that "may span long waits, retries, or process restarts". Microsoft documents no durable workflow for Agent 365 at all.

That matters for the bank scenario's last question. Without a documented resume model, a retry after a failure is whatever the agent's own code happened to do.

Agent identity

12 of the 26 platforms give an agent an identity of its own. The mechanisms differ, and the difference decides what an audit log can prove.

Model Example What the log shows
Directory identity for the agent Microsoft: an Entra service principal per agent; Google: "a per-agent identity" tied to the agent's lifecycle; WSO2: unique Agent ID and credentials The agent, as itself
Workload or service identity AWS: agent identities "implemented as workload identities"; Databricks: the service principal of the app The deployment, not always the agent
Platform user for the agent ServiceNow: an "AI User" sys_user with fixed roles; Salesforce: autonomous agents use a system identity A technical user per agent or class
The calling user Boomi: the agent "uses the current user's JWT token"; Workato: identity from the authenticated session The human, not the agent

SAP and Workday state the strongest intent. SAP gives each agent "a unique identity for reauthentication at every step", and Workday says each agent is issued "a unique identity, scoped permissions, a complete audit trail, and continuous attestation". IBM's Agent Identity, "separate from the identity of its creator, owner, or end user", is in preview.

Acting as the calling user is not wrong. It keeps an agent inside the user's permissions. But in the bank scenario it means the audit log records a clerk's name for a change no clerk made.

Microsoft describes the choice most directly. In Microsoft 365, an agent works in one of three modes: "acting on behalf of a user", "acting as an application", or "acting with its own user identity". Whichever mode a vendor defaults to decides what your audit log can later prove.

Other platforms' agents

Every cross-vendor control plane claims to cover "any agent". The documentation shows two different things behind that claim.

Orchestration means the platform can call another vendor's agent and hand it work. ServiceNow's orchestrator "discovers an external agent, retrieves that agent's capabilities, then executes and delegates the task to it" over A2A.

SAP's Joule "orchestrates external agents built with any A2A-compliant framework". Salesforce built MuleSoft Agent Fabric to "orchestrate with other third-party agents", and Workato recipes "can communicate with any A2A-compliant AI agent server".

Governance only means the platform lists and watches the foreign agent. Microsoft lets you synchronise agents built on Bedrock or Vertex AI into the Agent 365 registry "for centralized visibility and governance", and states that Agent 365 "wraps agents with governance but doesn't control internal behavior".

Boomi's Agent Control Tower tracks agents from providers such as Bedrock. Airia discovers AI across clouds and SaaS.

Both are useful, but they answer different procurement questions. If you need one agent to delegate to another across vendors, look for A2A support: 13 of 26 document it, and Microsoft, OpenAI, Databricks, Boomi, Airia, Wonderful, AgilePoint, XMPro and Fiserv do not.

Memory

Session state is well covered: 18 of 26 explain how an agent keeps context during a conversation. Long-term memory is not. Only 8 vendors name their memory types, and 6 say where memory is stored.

The ones that do are specific. AWS AgentCore Memory extracts knowledge through semantic, summarisation, user preference and episodic strategies.

IBM's SDK supports "preference, fact, procedural, episodic, and semantic" memory. UiPath offers episodic and escalation memory, xpander.ai session, user and agent memories.

An agent's long-term memory holds customer facts and past decisions. Where it lives, and who can read it, is a data-protection question before it is an AI question.

Why the gaps sit where they do

The nine origins explain the pattern. Gateways, identity stacks, integration platforms and suites came to agents through governance, and governance is what they document.

Isolation, run limits and durability are documented mainly by the vendors that host agents: AWS, Google, Databricks, UiPath, SAP, IBM, xpander.ai and Kosmoy. A control plane on top of someone else's runtime cannot promise what that runtime does not.

Documentation adds its own bias. Feature pages describe what a product can do; limits and failure modes are what it promises not to break, and those sit in contracts and security reviews. So the "OS" in agent OS is usually two products, a control plane that governs and a runtime that executes, and your architecture needs both.

Infographic: Why the gaps sit where they do (Everyone sells an agent OS)

Where this is going

The last two weeks

Recent announcements fit the pattern in this comparison. Glean made Agent Identity generally available on 1 October, IBM previewed its own Agent Identity a day later, and RSA launched Agent ID with a named owner and risk tier per agent. Oracle's Fusion Claw, a governed agent runtime that writes an audit "receipt" for every action, shows a suite vendor moving into the runtime itself.

What comes next

OpenAI said in February that Frontier would open beyond its first customers "over the next few months", and Salesforce plans to roll out its AI Control Plane from early FY28, which begins in February 2027.

Five shifts sit underneath those dates.

Agent identity becomes a directory object. Microsoft's Entra agent identities, AWS workload identities, Gravitee's OAuth clients and WSO2's Agent IDs all move the agent into the identity system that already governs users. Expect identity providers, not agent platforms, to become the place where an agent's permissions are decided.

Control planes start governing each other. Microsoft synchronises Bedrock and Vertex AI agents into its registry, Gravitee syncs agents from Azure AI Foundry and Gemini Enterprise, and Kore.ai's management platform governs LangGraph, AgentCore, Foundry and Agentforce agents. A large enterprise will run several control planes, and the registry of registries becomes the next contested layer.

A2A turns "any agent" into delegation. 13 of 26 platforms already document A2A. As it spreads, "governs third-party agents" will have to mean "can hand them work", and the governance-only products will be measured against that.

Observability already has its standard, control does not. 17 of the 26 vendors' documentation mentions OpenTelemetry. Databricks stores "OpenTelemetry traces in Unity Catalog", and AWS documents OpenTelemetry instrumentation for LangGraph agents.

Traces from different platforms can already land in one place. Identity, run limits and stop commands have no shared standard yet, and A2A covers delegation, not control.

Runtime guarantees become the differentiator. Once policy, MCP and audit are table stakes, the questions left are the ones in the bank scenario: isolation, run limits, retries, identity. The vendors that publish those numbers today are the ones that own a runtime, and that is where the next round of competition sits.

Infographic: What comes next (Everyone sells an agent OS)

What researchers are working on

The gaps in the products are open research questions, and the studies point in one direction: decide outside the model, and keep the record out of the agent's reach. Defences that rely on the model to police itself rarely survive attackers who adapt; twelve published defences were bypassed mostly above 90%. Deterministic checks outside the model blocked over 90% of unsafe executions at 1 to 3 milliseconds each in AgentSpec.

Least privilege is harder than it looks. Asked to infer the scopes an agent needs, LLMs over-grant in up to 34.7% of cases (MiniScope). The stop button has a measured price too: ending a task on any violation stopped attacks but left 0% task success, while halting only the offending call kept most of the work (VeriGuard).

The agent's own record is weak evidence. All ten models in one 2026 study tampered with their own traces under reward pressure, and in 64 of 64 memory-poisoning failures, log-based attribution blamed the model instead of the poisoned input. Human approvers are no backstop by default: in a live study, 52.8% of failures had been waved through by an earlier "approve similar" decision.

The runtime side is moving too, mostly in systems research. Schedulers now treat a whole agent run as the unit of work instead of a single model call: Autellix reports 4 to 15 times the throughput of vLLM. Sandbox checkpointing makes durable execution cheap, with 14 ms checkpoints and 5 ms rollbacks in DeltaBox, and Crab raises correct recovery from 8% to 100% compared with replaying chat history.

Run limits and stop commands are the gap here as well. Hard budgets and interruptibility for agents have almost no academic work yet, which leaves the market's budget caps and kill switches untested.


Vendor by vendor

The 26 vendors below are grouped by the same nine origins. The table is the short version: where each one comes from, who it fits and the one thing that stands out. The profiles that follow describe each platform's components, strengths, use cases, deployment, pricing metric and ideal customer, drawn from the vendor's own documentation.

Vendor Origin Best for Standout
AWS Bedrock AgentCore Cloud AWS shops with several agent teams and frameworks microVM per session, up to 8 hours or 14 days
Google Gemini Enterprise Agent Platform Cloud Google Cloud customers building agents in ADK Per-agent identity, 7-day runs
OpenAI Frontier Model Enterprises standardised on OpenAI models Shared semantic layer over business systems
Microsoft Agent 365 Identity Microsoft 365, Entra and Purview estates Every agent an Entra identity with a human sponsor
WSO2 Agent Manager Gateway Open-source-first, data-sovereignty rules Per-agent identity, 40+ guardrails, Apache 2.0
Gravitee Gateway Teams that already run API gateways Human approval held at the gateway
Kosmoy Gateway Regulated firms with Kubernetes, no vendor cloud Linux-sandboxed capsules, per-run credentials
Airia AI governance Security teams governing agents built by many groups Policy as code at the execution layer
Workato Integration Companies already automating on Workato recipes Skills built once, exposed to genies and MCP
Boomi Integration Enterprises with Boomi integrations Regional runtime clouds in four countries
ServiceNow Workflow Large Now platform customers AI User identities, A2A both ways
UiPath Maestro Automation UiPath robot estates in banks and insurers Durable workflows with no duration cap
AgilePoint NX Workflow Process-heavy, regulated enterprises AI proposes, governance checks, systems execute
Salesforce Agentforce Suite Salesforce and MuleSoft customers Delegated user identity from Okta or Entra
SAP Business AI Suite S/4HANA and Ariba estates Effective permission = user ∩ agent
Workday ASOR Suite Workday HCM and Financials customers Per-agent identity with continuous attestation
IBM watsonx Orchestrate Data and AI Multi-platform, partly on-premises estates Agent identity separate from its creator
Databricks Agent Bricks Data and AI Data estates on Unity Catalog Durable agent server, per-user data masks
Dataiku Data and AI Several AI teams on different platforms Neutral inventory of other vendors' agents
xpander.ai Agent-native Engineering teams using Claude Code or Codex Structural control: only the skills it was given
Lyzr Agent-native Banks and insurers with mixed frameworks Agent releases with security checks and rollback
Kore.ai Agent-native Enterprises with agents on several stacks Typed agent language with deterministic flows
OneReach.ai GSX Agent-native Multi-channel contact operations One session across voice, chat and email
Wonderful Agent-native Banks, telcos, insurers outside English-first markets Build permissions and integrations once, reuse them
XMPro Industry Asset-intensive operators Replayable decision trace per action
Fiserv agentOS Industry Banks and credit unions on Fiserv Agents next to the banking core

Infographic: Vendor by vendor (Everyone sells an agent OS)

Cloud and model platforms

Amazon Bedrock AgentCore

What it is. Amazon Bedrock AgentCore is AWS's managed platform for running, connecting and governing agents, whatever framework or model built them. It comes from the company that sells cloud building blocks, so it is a set of separate services you combine rather than one packaged product.

Components. Runtime hosts the agent code, Memory keeps session and long-term state, and Gateway turns APIs and Lambda functions into tools. Identity and Policy handle who an agent is and what it may call, while Observability, Evaluations and Registry cover tracing, quality tests and the catalogue. Code Interpreter and Browser Tool are built-in tools that sit beside them.

Strengths. Every Runtime session gets its own microVM with isolated CPU, memory and filesystem, and the memory is sanitized when the session ends. Policy intercepts every tool call that passes through a Gateway and evaluates it against Cedar rules, with default-deny and forbid-wins semantics. Memory goes beyond chat history: an episodic strategy turns important moments into compact records and then writes reflections across episodes.

Use cases. AWS names customer support, workflow automation, data analysis and coding assistance as the workloads to deploy. The second pattern it documents is the internal platform team that gives developers "a paved path" to build and deploy agents with approved tools, shared memory stores and governed access to enterprise services. Long jobs fit too, since sessions run up to 8 hours on microVMs and up to 14 days on the Instances compute type.

Deployment. The default is a serverless runtime that AWS operates. The Instances option runs the agent on EC2 managed instances inside your own AWS account, and Runtime and the built-in tools can attach to your VPC. Registry can catalogue agents and tools that live on AWS, on-premises or in another cloud.

Pricing metric. The microVM Runtime is charged per vCPU-hour and per GB-hour, and the Instances option per instance-hour. Gateway is charged per 1,000 invocations. Memory, Identity, Policy and Registry each have their own metered units, so the bill is consumption based.

Protocols and integrations. Runtime works with CrewAI, LangGraph, LlamaIndex, Google ADK, OpenAI Agents SDK and Strands Agents, and the Claude Agent SDK is also supported. Gateway attaches external MCP servers and combines all its MCP targets into one virtual MCP server. A2A is a supported Runtime protocol, and models from Bedrock, OpenAI and Google Gemini can be used through LiteLLM.

Ideal customer. A large enterprise that already runs on AWS and has several teams building agents in different frameworks. The buyer is usually the cloud or platform engineering group that wants one runtime, one tool gateway and one policy layer for all of them. Teams that already use IAM, CloudWatch and CloudTrail get the most from it.

Ask about. Ask how Policy rules and Registry approvals map onto your existing IAM roles and CloudTrail audit pipeline.

Docs. What is bedrock agentcore; Gateway core concepts; Runtime instances how it works.

Google Gemini Enterprise Agent Platform

What it is. Gemini Enterprise Agent Platform is Google Cloud's agent platform and the successor to Vertex AI Agent Engine. Google launched it in April 2026, and Agent Gateway, Agent Registry and Agent Observability reached general availability on 18 June 2026. It comes from Google Cloud and brings Gemini models, Model Garden and the open-source Agent Development Kit under one roof.

Components. The build side has Agent Studio for low-code work, the code-first ADK and Agent Garden templates. The scale side has Agent Runtime, Agent Sandbox, Sessions and Memory Bank. The govern side has Agent Identity, Agent Registry and Agent Gateway, and the optimize side has Simulation, Evaluation, Observability and an Optimizer.

Strengths. Each agent gets its own identity in a SPIFFE-style format, and the logs show both the agent and the user when it acts on a user's behalf. Agent Gateway is the network entry and exit point for all agentic traffic, and Model Armor scans prompts and tool responses in real time. ADK documents eight multi-agent patterns, from sequential pipelines to human-in-the-loop, and has SDKs for Python, TypeScript, Go, Java and Kotlin, some of them experimental.

Use cases. Google's launch material describes a virtual cancer clinic that checks screening eligibility and books appointments, and a telecom assistant that troubleshoots with several cooperating agents. It also shows a financial controller agent that shortens expense submission, and a restaurant discovery app that uses Memory Bank to recall user preferences. Agent Runtime supports multi-day work, with long-running operations of up to 7 days.

Industries. The documented examples span healthcare, telecom, fintech, construction and engineering, consumer goods, transportation and hospitality. HIPAA, VPC Service Controls, customer-managed encryption keys and data residency are listed for Agent Runtime, Sessions and Memory Bank. The service is in scope for ISO 27001, SOC 1, SOC 2, SOC 3 and PCI DSS.

Deployment. Agent Runtime is a fully managed Google service that runs any agent you can containerize. Sandboxes hold execution state for up to 14 days.

Pricing metric. Google consolidated billing for Runtime, Sandbox, Sessions and Memory Bank into three units: compute per vCPU-hour, memory per GiB-hour and storage per GiB-month.

Protocols and integrations. Google exposes its own services as managed remote MCP servers, and ADK agents can use them. Agent Registry supports A2A version 1.0, and Agent Gateway handles MCP and A2A traffic. Runtime hosts ADK, LangChain, LangGraph, AG2 and LlamaIndex agents, and Model Garden offers more than 200 models including Claude.

Ideal customer. An enterprise that already runs data and applications on Google Cloud and wants to build, host and govern agents in one place. It suits teams with software engineers who will write ADK code, as well as business teams that start in Agent Studio. The buyer is typically the cloud or AI platform group, with security teams as the main governance users.

Ask about. Ask which Registry access policies and Gateway controls apply to agents that run outside Agent Runtime.

Docs. Introducing Gemini Enterprise Agent Platform, powering the next wave of agents; Agent Development Kit (ADK); Release notes.

OpenAI Frontier and Agents SDK

What it is. OpenAI Frontier is an enterprise platform for building, deploying and managing agents that OpenAI calls AI coworkers. It launched on 5 February 2026 to a limited set of customers, with broader availability promised over the following months. OpenAI comes from the model side, and Frontier is its move into the layer where companies run agents across their business software, including agents from Google, Microsoft and Anthropic.

Components. Frontier has a Business Context layer that links data warehouses, CRM, ticketing tools and internal applications, plus an agent execution environment for files, code and tools. Identity and permissions, evaluation and optimization loops, memory built from past interactions and detailed logs complete the platform. Forward Deployed Engineers work inside the customer. For developers, the open-source Agents SDK covers agents, handoffs, guardrails, sessions, tracing and sandbox agents.

Strengths. The semantic layer means every agent starts from the same picture of how your systems relate. Runtime can be local, in your cloud or OpenAI-hosted, so you choose where the work happens. In the SDK, a run that needs approval pauses with pending interruptions, and you resume it from saved state after calling approve or reject.

Use cases. The SDK documents a manager agent that calls specialists as tools, and a triage agent that hands a conversation to the right specialist. It also shows an evaluator loop in which one agent produces work and another critiques it. For long waits and restarts, it lists Temporal, Dapr, Restate and DBOS integrations.

Industries. OpenAI describes Frontier as having built-in security and governance for regulated industries. No sector focus is otherwise documented.

Deployment. Frontier agents can run on your own servers, in your cloud or on OpenAI-hosted infrastructure. In the SDK, the agent loop runs in your own process, hosted tools run on OpenAI servers, and shell can run locally or in an OpenAI-managed container. Sandbox agents can use local Unix, Docker or hosted sandbox clients.

Protocols and integrations. OpenAI says Frontier is built on open standards, so teams can plug in their own agents. The SDK connects to hosted MCP servers, Streamable HTTP and SSE servers, and OpenAI connectors. It is provider-agnostic and supports 100+ other LLMs.

Ideal customer. A large enterprise that already standardizes on OpenAI models and has business data spread across CRM, ERP and ticketing systems. The high-touch Forward Deployed Engineer model points to buyers who want hands-on help, usually an AI or digital leader backed by business-unit sponsors. Developer teams can start on the SDK alone.

Ask about. Ask which systems Business Context connects to today and whether agents from other vendors fall under the same identity and permission model.

Docs. Sessions; Running agents; Tools.

Identity and productivity

Microsoft Agent 365 and Foundry Agent Service

What it is. Microsoft Agent 365 is a control plane for agents: a registry, identity, policy and observability layer that does not host or run the agents. Foundry Agent Service is the matching place where agents run, in Foundry hosted agents. Microsoft comes from the identity and productivity side, so the control plane is built on Entra, Defender, Purview and the Microsoft 365 admin center.

Components. Agent 365 combines the registry and lifecycle controls in the Microsoft 365 admin center, Entra Agent ID, Defender, Purview and a Tooling Gateway. An SDK for Python, JavaScript and .NET adds identity, tooling and notifications to an existing agent. Foundry hosted agents and Copilot Studio agents plug into it.

Strengths. Each agent is an Entra service principal, credentials sit on a blueprint rather than the identity, and every agent needs at least one human sponsor. Conditional Access and Identity Protection apply to agents just as they do to users. Purview audits agent-to-human, human-to-agent, agent-to-tools and agent-to-agent interactions, and new agent instances are audited automatically.

Use cases. Microsoft describes autopilots: you create a blueprint from a Foundry hosted agent, an administrator approves it, and people hire instances in Teams and other Microsoft 365 surfaces. A second scenario is a mixed fleet, where agents built on Amazon Bedrock, Google Vertex AI, Salesforce Agentforce or Anthropic Claude managed agents sync into one registry. Admins can also allow or block individual tools inside an MCP server.

Industries. Microsoft points to regulated industries, with agents handling financial data, health information or intellectual property under the same Purview rules as the rest of the tenant. As of 1 October 2026, Agent 365 meets all FedRAMP High controls its independent assessor reviewed. Authorization is pending.

Deployment. Agent 365 is a Microsoft 365 service, and the agent itself can run on Azure, AWS, Google Cloud or on-premises. Foundry hosted agents are created, stored and run inside the Foundry platform. Data is logically isolated per tenant, and agent identities are single-tenant.

Pricing metric. Agent 365 is licensed per user, and it is also included in Microsoft 365 E7. One license covers the agents a person owns, sponsors, manages or interacts with. Foundry hosted agents are billed per vCPU-hour and per GiB-hour of memory, with model tokens billed separately.

Protocols and integrations. Agents invoke governed MCP servers, including Work IQ servers for Mail, Calendar, SharePoint and Teams. You can connect an AI Gateway or Azure API Management instance to discover and govern MCP servers. The SDK covers the Microsoft 365 Agents SDK, Microsoft Agent Framework, OpenAI Agents SDK, LangChain, CrewAI and LlamaIndex, with telemetry in OpenTelemetry.

Ideal customer. A large enterprise that already runs Microsoft 365, Entra and Purview and wants agent governance in the tools its admins and security team use daily. The buyers are IT and security leaders, and the people who act on it hold the AI Administrator role. It fits best where most agents are built in Copilot Studio or Foundry.

Ask about. Ask which of your non-Microsoft agents authenticate through Entra, because runtime policy enforcement depends on it.

Docs. Agent 365 sdk; Microsoft Learn overview; Identity.

Gateways and AI governance

WSO2 Agent Manager

What it is. WSO2 Agent Manager is an Apache 2.0 control plane for AI agents from WSO2, a vendor founded in 2005 that also sells integration, API and identity products. It pulls every agent, "whether it runs natively in the platform or in an external framework", into one inventory with a named owner and a defined access scope. General availability is documented for both self-hosted and managed SaaS use.

Components. The product page names four parts: agent identity, guardrails and gateways, monitoring and evaluations, and lifecycle management. Around them sit an MCP Gateway with a searchable MCP Hub catalogue and Identity Server 7.2 for agent IDs. WSO2 Integrator is the build side, with a low-code and VS Code experience for writing agents.

Strengths. Identity is set per agent and per environment, with "instant revocation". Guardrails, 40+ of them, are enforced at the agent, MCP and LLM levels. Swapping a model provider "doesn't touch the agent's identity, credentials, or trace history", so a model change does not break your audit trail.

Use cases. ScheduleMe is a documented calendar assistant where a supervisor agent extracts intent and delegates subtasks to specialised agents, with several supervisors running in parallel. A global entertainment company's virtual team member uses an orchestrator, conversation memory in Azure SQL and Azure AI Search across four indexes. A customer-support troubleshooting agent calls backend REST APIs exposed as tools through an MCP server.

Industries. WSO2 frames its regulated conversations as running "from banks preparing for the Digital Operational Resilience Act (DORA) to governments writing open-source-first procurement rules". It also publishes a banking whitepaper on a core abstraction layer for AI agents.

Deployment. You can self-host it or use managed SaaS. In your own data center or private cloud, "agent identity, policy enforcement, and trace data stay inside your environment". The agents it manages can run across cloud, on-premises and hybrid environments.

Protocols and integrations. Agent Manager is "Built on open standards including OpenTelemetry, OpenAPI, and MCP" and manages agents in "any Python or Ballerina framework that supports OpenTelemetry", such as LangChain, CrewAI, Amazon Bedrock Strands or Microsoft Agent Framework. The MCP Gateway can generate MCP servers from existing APIs and proxy existing ones. AI Workspace ships provider templates for OpenAI, Azure OpenAI, Azure AI Foundry, Anthropic, Google Gemini, Mistral AI and AWS Bedrock.

Ideal customer. It suits an enterprise with data-sovereignty or open-source-first rules and an agent estate spread over several frameworks. The teams that already run identity, APIs and integration are the natural owners. Regulated buyers such as banks and government bodies are the audience WSO2 writes for.

Ask about. Durable agent capabilities arrive with WSO2 Integrator 5.1 in October 2026, so ask which recovery and approval-pause features are in the release you would deploy first.

Docs. WSO2 Agent Manager Brings Sovereign AI Governance to Enterprise Agent Sprawl; Why Every Enterprise Deploying AI Agents Needs a Control Plane; Beyond Autonomy: Why the Agentic Enterprise Needs Durable Agents.

Gravitee AI Agent Management

What it is. Gravitee AI Agent Management is the agent product line of an API management vendor that calls itself "The AI Agent Management Platform". The docs describe "a unified control plane and runtime" for LLM calls, MCP tool invocations and agent-to-agent delegations. Gravitee governs agents at the gateway instead of hosting them, so they can run "on multiple platforms".

Components. Three proxy types sit at the AI Gateway: an LLM Proxy, an MCP Proxy that can compose tools into a "governed Composite MCP Server", and an A2A Proxy. A Catalog holds imported agents, MCP resources and knowledge sources, and each agent gets an OAuth identity in Gravitee Access Management. Authorization Management supplies the policies, with a human-approval inbox and activity logs on the governance side.

Strengths. Human approval needs no change to the agent, which just "perceives a slow tool call" while the gateway holds matching MCP calls for a person to approve, edit or reject. The default decision window is 900 seconds, at most 30 days. Policies are "evaluated at microsecond latency with no network hop", and API tools inherit the security plans of the source API, such as API Key, JWT, OAuth2 or mTLS.

Use cases. The docs cover guardrails, PII filtering and rate limiting on model traffic. Existing REST APIs become MCP tools from an OpenAPI spec, and Kafka APIs can become tools too. Agents imported from Azure AI Foundry or Gemini Enterprise Agent Platform can be routed through an A2A Proxy, and each carries a risk classification from Negligible to High.

Industries. Gravitee's site lists use cases by industry for financial services and fintech, insurance, government, travel and hospitality, software and healthcare.

Deployment. Gravitee does not host agents. The Gravitee side runs as "A self-hosted or hybrid Gamma installation", and your agents stay on their own platforms.

Pricing metric. Agent Management is sold as a module that you add to a platform tier. The pricing page lists the LLM, MCP and A2A proxy capability as available "With Agent Management module".

Protocols and integrations. Agents reach upstream MCP servers such as HubSpot, GitHub, Salesforce and Jira through the MCP Proxy. The A2A Proxy supports agent-card discovery at /.well-known/agent-card.json, per-plan client authentication and SSE streaming. The LLM Proxy accepts OpenAI, Anthropic and Gemini request formats and routes to OpenAI, Anthropic, Gemini, Bedrock and Vertex AI.

Ideal customer. It fits an organisation that already runs API gateways and wants one policy point over LLM, MCP and A2A traffic from agents built elsewhere. Workloads that combine REST, Kafka and agent traffic benefit most. The API platform or security team is the natural buyer.

Ask about. Ask which of your agents' calls will actually pass through the AI Gateway, since Gravitee governs traffic and does not host the agent.

Docs. AI Agent Management; Agent management overview; Require human approval for MCP tool calls.

Kosmoy AI Agent Management

What it is. Kosmoy is an AI management platform headquartered in Milan, described on its site as an "AI Gateway, LLM Gateway & AI Governance Platform for the Enterprise". Its Agents Master Registry keeps "one record shape for every agent, wherever it was built". It covers agents from hyperscaler agent services, SaaS builders and internal runtimes.

Components. The platform has four layers: AI Inventory, AI Monitoring, AI Governance with the gateway, and AI Action Control. The gateway covers LLM, MCP and A2A traffic, with a Key Vault, guardrails and a no-code Agent Builder alongside. Action Control is the Action Capsule, a Kubernetes-native sandbox with "execution leases, JIT credentials and kill switch".

Strengths. A Capsule isolates one runtime with standard Linux primitives (namespaces, cgroups v2, Seccomp-BPF, Landlock, AppArmor or SELinux), default-deny egress and a paired gateway as the only exit. Every run is admitted first and gets a run-scoped lease, and its just-in-time credentials are revoked at the end. The trajectory view records "every step with its model invocation, tool call, failure and cost".

Use cases. Kosmoy's homepage frames two jobs: "Manage the AI you already have" and govern the agents you are about to deploy. Its docs say the runtime needs containment once agents start writing to systems of record. The registry reconciles discovered agents against approved use cases to flag shadow AI, and an onboarding template for accounts, welcome emails, tickets and calendar invites is "bounded by human approval cards".

Industries. Kosmoy says it is "Built for regulated enterprises". Its homepage describes customers as an Italian central bank and banking regulator, and Europe's largest defense and aerospace company.

Deployment. Self-hosted is the only model. It installs by Helm into your own Kubernetes cluster on EKS, AKS, GKE, OpenShift or on-prem, is single-tenant by default and supports air-gap.

Pricing metric. Pricing is proposal-based and scoped around the platform layers, AI workloads, deployment boundary, integrations and support the enterprise requires.

Protocols and integrations. The A2A Agents Gateway applies "No anonymous A2A" and gives each agent an allow-list of approved peers. The MCP Gateway restricts which tools each caller can invoke on each server. One OpenAI-compatible endpoint fronts providers including OpenAI, Anthropic, Google, Mistral, Azure, Bedrock and vLLM or Ollama on-prem, and the gateway reaches Azure AI Foundry, Bedrock and any A2A-compliant agent.

Ideal customer. A regulated enterprise, such as a bank or a defence group, with a Kubernetes platform team and a rule that nothing runs in a vendor cloud. The homepage addresses CIOs directly. Kosmoy says it "is not an iPaaS", so it sits beside an integration layer.

Ask about. Calls that bypass the Kosmoy route are outside its enforcement boundary, so ask how bypass is detected and what the registry does with agents it can only inventory.

Docs. Platform; The Action Capsule.; Manage every AI agent like production software..

Airia

What it is. Airia is an AI platform that brings "orchestration, security, and governance into a single execution layer". Its pitch is "One control plane across your entire AI stack." It discovers AI across cloud infrastructure, SaaS platforms, development environments and network traffic, shadow tools included.

Components. You get an agent builder (drag-and-drop, no-code, low-code or pro-code), a routing engine for models, and an MCP Gateway. Governance sits in AI Inventory Management, Agent Constraints, guardrails and a model lifecycle registry. Compliance reporting is built on the same execution logs.

Strengths. Constraints "run as code at the execution layer", so every agent "inherits the same controls, regardless of who built it or where it's deployed". The Human Approval node pauses "only the decisions that need review" while the rest of the workflow continues. Every agent decision lands in a tamper-evident audit trail.

Use cases. The site lists exposing shadow AI and unapproved tools, stopping unauthorized agent actions before the tool call fires, applying the same controls to agents whether purpose-built, commercially adopted or never approved, and producing compliance documentation. High-impact actions can be routed to human review by risk classification, data sensitivity or action type. Reports are generated automatically against GDPR, HIPAA, ISO 42001, NIST RMF and EU AI Act requirements.

Industries. AWS GovCloud and Azure Government deployment is offered for US government customers.

Deployment. Managed SaaS runs on AWS, Azure or Google Cloud with SOC 2 Type II certified operations. Private cloud runs in your own AWS, Azure, GCP or OCI account, and on-premises runs on VMware, Kubernetes or bare metal, air-gapped if needed. In a hybrid setup the control plane and execution can sit in different environments.

Pricing metric. Licence tiers meter "Agent Executions Per Second" and a document ingestion limit in GB.

Protocols and integrations. The MCP Gateway offers "over 1,000 pre-configured integrations" and also governs custom MCP servers and internal tools. Native integrations include Microsoft 365, Salesforce, Confluence, SharePoint, Snowflake and Databricks. Models from OpenAI, Anthropic, Mistral and Meta can be approved, versioned, retired and routed in one place.

Ideal customer. Airia says it is used by security and AI transformation teams. The fit is a team that needs one policy layer over agents built by many groups. It fits regulated organisations that need air-gapped or sovereign options, US government clouds, or HIPAA and ISO 42001 evidence. Business units can build in the same tool, which suits a central team that wants builders on a governed path.

Ask about. The documentation covers constraints and audit trails but does not describe a per-agent identity or credential, so ask how each agent is identified.

Docs. Flexible Deployment Options; Deploy AI at Enterprise Scale with Confidence; Ai platform agent builder.

Integration platforms

Workato AI Control Plane and Agent Studio

What it is. Workato comes from integration automation and now describes itself as "the control & execution platform to govern AI, connect apps and data, and orchestrate workflows and agents". Its agents are called genies, and they are "hosted and managed by Workato". The AI Control Plane governs "every model, agent, workflow, API, and MCP interaction".

Components. In Agent Studio you write a job description, attach skills (Workato recipes) and add knowledge bases and data tables for memory. Four gateways sit under the control plane: Model, MCP, Agent and API. A hosted MCP Runtime operates your MCP servers, and the execution plane reaches "17,000+ apps".

Strengths. Skills are recipes, and the docs say "Build skills once, then deploy them to genies or expose them through MCP to external AI clients". Verified user access runs a skill "using the identity and permissions of the individual user". Content safety guardrails are "automatically active for all genies and can't be disabled".

Use cases. In the docs, a primary genie hands subtasks to specialist genies for classification, routing, validation and chained processing, and line items run as concurrent genie runs. Business approvals send access provisioning to a designated approver before the write executes.

Deployment. Genies and MCP servers run on Workato-hosted infrastructure, on multi-tenant or Virtual Private Workato hosting in regional data centers. The on-prem agent is installed in your network only to reach on-prem apps, databases and folders "without having to open ports in the corporate firewall".

Pricing metric. Workato "uses a usage-based billing model".

Protocols and integrations. The A2A connector lets recipes and genies call any A2A-compliant agent, with documented examples for Google ADK, LangGraph, CrewAI, Bedrock AgentCore and Azure AI Foundry. Genies consume Workato-hosted and external MCP servers, and Workato hosts MCP servers that expose skills as tools. Genies use Claude by default, and you can switch to OpenAI GPT, Azure OpenAI or AWS Bedrock.

Ideal customer. A company that already automates on Workato recipes, where IT, operations or business-systems teams want agents to act through the same governed connectors. Teams that need agents to run with each employee's own permissions benefit most.

Ask about. The documentation establishes identity through the authenticated user session rather than a service principal for the genie, so ask whether a dedicated per-agent identity is planned.

Docs. Agentic {: #agentic :}; Agentic - FAQ {: #faq :}; MCP Gateway {: #mcp-gateway :}.

Boomi Agentstudio

What it is. Boomi Agentstudio comes from Boomi, an iPaaS vendor that Gartner has named a consecutive Magic Quadrant leader for integration platforms as a service. Agent Control Tower tracks agents "built internally using the Boomi Agentstudio or sourced from third party providers like Amazon Bedrock".

Components. Agent Designer is the low-code builder, and Agent Garden runs deployed agents on regional runtime clouds with Execute APIs for invoking sessions. Agent Control Tower is the registry and monitor, and API Control Plane turns API endpoints into agent tools. Meta Hub glossaries and Knowledge Hub knowledge bases ground agents in company data.

Strengths. Boomi manages "four runtime clouds: US, UK, Japan, and Australia", and each environment links to one, which fixes where the agent runs. A business glossary "is not pre-loaded into the context window", and the model fetches only the relevant parts on demand. Agents call tools with the current user's JWT, so access is "limited by the user's Boomi Platform permissions".

Use cases. The site shows a SaaS vendor that automated order-to-cash and a pharmaceutical firm that built a self-healing integration architecture with Agentstudio. An Agent Step lets an integration process call an Agent Designer agent. A multi-unit deployment pattern uses a one-line embed code to put a chat widget on each site, and a tool can be flagged to ask the user before a permanent write.

Industries. The Boomi homepage customer stories cover healthcare, industrial software, SaaS and energy.

Deployment. Agentstudio agents run on the Boomi-managed regional runtime clouds, and a North America platform sees all four while a European platform sees the UK cloud. Regional deployment "keeps data within your region's boundaries for regulatory compliance purposes". The wider Boomi platform offers on-premises, cloud and hybrid options.

Protocols and integrations. Agent Designer is an MCP client for remote servers over SSE and Streamable HTTP, with OAuth 2.0 and 2.1 among the auth options. API Control Plane exposes API products to agents through an MCP bridge. Control Tower accepts metrics from agents built in CrewAI, LangChain, LangGraph, LlamaIndex, OpenAI Agents SDK, Microsoft AutoGen, Semantic Kernel, PydanticAI, SmolAgents, Strands Agents and Mastra.

Ideal customer. An enterprise that already runs Boomi integrations and wants agents built next to them. The integration team is the likely owner, and healthcare, energy and software firms match the customer stories on the site. Teams that need regional data residency for agent execution benefit from the four runtime clouds.

Ask about. The documented audit trail covers registry changes and session logs, so ask how you can get a dedicated log of runtime tool calls and approvals.

Docs. Building AI agents; Connecting to an MCP server; Agentstudio token limits.

Workflow and process automation

ServiceNow AI Control Tower and AI Agent Fabric

What it is. AI Control Tower is ServiceNow's console to discover, observe, govern, secure and measure AI across the enterprise, including assets on systems beyond ServiceNow. It sits on the Now platform, where ITSM, HRSD and CRM already ship out-of-box agents. AI Agent Fabric and Action Fabric connect those agents to third-party agents over MCP and A2A.

Components. Agents are built in AI Agent Studio, and an orchestrator meta-agent decides which one handles each subtask. AI Gateway governs MCP traffic in both directions, MCP Server Console publishes ServiceNow capabilities as MCP tools, and Control Tower adds discovery, risk assessment and cost tracking on top. Traceloop supplies runtime observability and Veza supplies access governance.

Strengths. Identity is the clearest strength. An agent can run as an AI User with fixed roles, or as a Dynamic User that inherits the invoker's permissions, and role masking caps the roles it can hold. Control Tower can also shut down an agent that operates beyond its permissions in real time. Memory is practical too: short-term memory is shared by agents inside one conversation, and long-term memory is stored per user and per category.

Use cases. An incident agent reaches external documentation through an MCP client without leaving the incident workflow. An Incident Auto-Resolver diagnoses and remediates common IT incidents, and a Project Portfolio Policy Agent checks projects against governance rules. AI Agent Advisor reads your incident and case tables and matches the patterns it finds to out-of-the-box agents.

Industries. The documentation organises agents by function (ITSM, HRSD, CRM), not by industry. Compliance content packs cover the EU AI Act, California AI Act and Colorado AI Act, which matters most to regulated sectors.

Deployment. It is a SaaS platform. The default orchestration model, Azure OpenAI GPT-5.5, runs on ServiceNow-managed Azure servers. GCC and self-hosted instances are supported with NowLLM only, and bring-your-own-key routes requests through your own provider account.

Pricing metric. ServiceNow charges by the assist, which it calls its unit of AI consumption. An assist is triggered each time a Now Assist skill or agentic workflow runs, and different capabilities consume different amounts.

Protocols and integrations. ServiceNow is both an MCP client and an MCP server. It speaks A2A v0.3 as either the primary or the secondary agent, and it can delegate to agents built on Google ADK, LangGraph or AWS. Discovery adds 30 enterprise integrations across AWS, Google Cloud, Azure, SAP, Oracle and Workday.

Ideal customer. A large enterprise that already runs IT, HR or customer workflows on the Now platform, and wants one control plane for ServiceNow and third-party agents. The buyer is usually the platform or IT operations team, with risk and compliance as co-sponsors.

Ask about. How many assists does one run of your busiest agent consume, and which agent traffic, such as A2A calls, sits outside AI Gateway control?

Docs. Ta p 3557794; Ta p 3200454; Ta p 3339826.

UiPath Maestro

What it is. Maestro is the orchestration layer of UiPath's agentic automation platform. UiPath comes from RPA, so Maestro is built to coordinate agents, RPA robots, APIs and people inside one end-to-end process. It does not try to replace the process, it runs around it.

Components. Maestro Orchestrate offers three canvases on one runtime: Case, Flow and BPMN. Agents come as low-code agents from Agent Builder or as coded agents in Python, and Action Center handles human tasks. Memory spaces, an AI Trust Layer and Automation Ops policies cover learning and control.

Strengths. Durability is the standout. A Maestro Orchestrate workflow has no cap on duration and can wait days, and operators can pause, resume, retry or migrate a live instance while its state is kept. Agent memory is unusual too. Escalation memory stores how humans resolved past escalations, and the agent checks it before it raises a new one.

Use cases. Documented scenarios are order-to-cash, claims processing, employee and customer onboarding, procure-to-pay, product recall, and KYC and compliance case handling. A loan origination walkthrough shows a process growing from a simple diagram into an agent-driven, fully orchestrated flow. Existing RPA stays in place as the workers, with Maestro orchestrating around them.

Industries. UiPath documents banking and financial services (loans, KYC), insurance (claims) and procurement-heavy operations. The process examples are mostly regulated, document-heavy and case-driven work.

Deployment. Agents run on serverless infrastructure in Automation Cloud. Agents are also available on Automation Suite on EKS, AKS and OpenShift for on-premises deployments, which suits data sovereignty needs. The advanced agent harness is Cloud only and in preview.

Pricing metric. Consumption is metered per run and per LLM call. Customers draw from Agent Units on the Flex plan or Platform Units on Unified Pricing, and a monthly allowance of runs is included depending on plan and tier.

Protocols and integrations. Agents use MCP servers as tools, and UiPath can host MCP servers that expose RPA workflows, agents and processes. Coded agents can be built with LangGraph, LlamaIndex or OpenAI Agents. Integration Service connectors turn downstream systems into agent tools.

Ideal customer. A large enterprise that already runs UiPath robots and wants to put agents into those processes under one governed runtime. The buyer is typically the automation or process excellence team in a bank, insurer or shared-services organisation.

Ask about. Which of our processes need the full Orchestrate runtime, and how many Agent Units or Platform Units does one LLM call at our chosen model tier draw?

Docs. MCP servers compliance; Agent memory; Advanced agents (Preview).

AgilePoint NX AI Control Tower

What it is. AgilePoint NX is a process automation platform whose homepage says it has been changing running processes without an engineering cycle since 2007. Its AI Control Tower puts centralized oversight of third-party AI agents inside that process layer. The company describes itself as the missing layer for delegated execution.

Components. The Control Tower is a dedicated control tier where agents are configured and maintained, kept apart from individual workflows. AgileLLM is a native LLM in the NX OnDemand public cloud, available through process activities such as Chat Completion and Analyze Image and through eForm lookups. A central dashboard shows where agents run, what they touched and their health, and the platform connects across more than 110 systems through a unified data layer.

Strengths. The design principle is delegated execution: "AI proposes. AgilePoint governs. Your systems execute." The model output is only a proposal, a governance layer checks it against policy, risk, authority and compliance, and a deterministic enterprise system carries it out. Agents are treated as process actors with the same visibility as people and systems, and models can be replaced without disrupting workflows. The audit trail records the data given to an agent, its response and any downstream action it triggered, built on auditing that has been in the platform for decades.

Use cases. AgilePoint's own case studies cover warranty-claim fraud detection and sales lead triage. In its process model, an agent can take corrective action when automation begins to go off course. The Control Tower is also pitched at integrating operations quickly after mergers and acquisitions.

Industries. The downloaded AgilePoint pages name no target industries.

Deployment. Standard and Professional editions run on public cloud, private cloud or on-premises. The Enterprise edition is hybrid private cloud plus on-premises.

Pricing metric. AgilePoint offers four licensing units. Dynamic Concurrent Access gives utilization-based seats shared across human and agent workers. The others are named user seats, CPU core capacity licensing, and utilization-based interactions for external users.

Protocols and integrations. Documented integration is through connectors to more than 110 systems over a unified data layer. AgilePoint says it plugs AI models into processes at the system level, not inside each workflow.

Ideal customer. A regulated or process-heavy enterprise that already models work as processes and needs AI proposals gated by policy before they reach ERP, CRM or finance systems. The buyer is the process owner or enterprise architect, with the CIO or COO as sponsor.

Ask about. Does the Control Tower govern agents that run outside AgilePoint through MCP or A2A, and which of the connectors are included in the licence?

Docs. Agilepoint unveils a centralized ai control tower dashboard; Agilepoint ai control tower PCP 6235 9026; Operationalize, Democratize, and Govern Enterprise AI with AI Control Tower..

Business application suites

Salesforce Agentforce and MuleSoft Agent Fabric

What it is. Agentforce is Salesforce's agent platform, built on the CRM and on Data 360. MuleSoft Agent Fabric is the layer that "extends Agentforce to orchestrate with other third-party agents". Together they cover agents built in Salesforce and agents built anywhere else.

Components. Agentforce agents are written in Agent Script and reasoned by the Atlas Reasoning Engine, with Claude and Salesforce's own Koa model available. Agent Fabric adds an Agent Registry, Agent Broker, Agent Governance and Agent Visualizer, plus Omni Gateway as the enforcement point. Agent Scanners find agents built on Amazon Bedrock and Google Vertex AI and register them.

Strengths. Identity is the most developed part. Trusted Agent Identity delegates the user's identity from Okta or Entra ID, so every action traces back to the originating human. High-risk steps can trigger a mobile approval request through CIBA. Memory is also concrete: it lives in Data 360, persists across sessions and channels, and is injected automatically once enabled in Agent Script.

Use cases. A mortgage assistant in a banking platform routes one customer inquiry to an external credit check agent, a DocuSign agent for signatures and a homegrown compliance agent. A global retailer runs one agent on inventory, one on pricing and one on fraud, so a low-stock signal adjusts prices and triggers fraud checks. Both examples come from Salesforce's own Agent Fabric announcement.

Industries. Salesforce's published Agent Fabric scenarios are banking and retail. Its Koa model announcement also targets private clouds and air-gapped networks through a partnership aimed at secure environments.

Deployment. Agent networks and brokers deploy to CloudHub 2.0 shared or private spaces, or to a Runtime Fabric target. Guardrails can run on your own infrastructure for private cloud and on-premises workloads. Koa runs inside Salesforce's own infrastructure.

Pricing metric. Salesforce lists Flex Credits, Resolutions or per-user licensing as its Agentforce pricing options. Which unit applies depends on how and where you deploy the agent.

Protocols and integrations. Agentforce is an MCP client and offers a hosted MCP server, and MCP Bridge turns an existing API into an MCP server without custom code. A2A works inbound and outbound, and Agent Fabric supports A2A v1.0. Agent Fabric orchestrates only A2A-compliant agents, with a bridge for those that are not.

Ideal customer. A company that already runs Salesforce and MuleSoft and has agents spread across SaaS tools, homegrown builds and cloud AI services. The buyer is a CIO or integration team that owns MuleSoft, working with the Salesforce business owners.

Ask about. Which of our target Agentforce agent types support the A2A pause for approval, and how long can a task run through the bridge before the gateway timeout?

Docs. Agent Fabric Overview; Interoperability guide; How agentic memory enables durable reliable ai agents across millions of enterprise users.

SAP Business AI Platform (Joule Agents, Joule Studio, AI Agent Hub)

What it is. SAP's pitch is that agents should sit where the business process data and rules already live. Joule Agents are prebuilt agents with business process expertise that execute multistep tasks across SAP and non-SAP systems. Joule Assistants coordinate those agents by role, and the SAP AI Agent Hub is a "single, vendor-agnostic command center" for governing them.

Components. Joule Studio builds custom agents with low-code or pro-code, and the Joule Studio runtime executes them on SAP Business AI Platform. The Generative AI Hub gives access to models across providers, and SAP HANA Cloud provides long-term memory. The SAP Knowledge Graph and Business Data Cloud supply process context and data.

Strengths. Permissions are the clearest design choice. The effective permission at runtime is the intersection of user and agent permissions, all agent traffic flows through an agent gateway, and each agent gets a unique identity. Managed agents run inside an NVIDIA OpenShell sandbox. In the AI Agent Hub, only verified MCP servers can be called in production, and access is revoked when verification status changes.

Use cases. A Missed Discount Analysis Agent connects to SAP S/4HANA, pulls unmatched invoices and returns a financial impact summary. An AP invoice extension triggers an n8n workflow when matching fails. SAP also documents a Sourcing Agent for SAP Ariba, a dispute resolution agent example, and a classification agent that routes customer cases in real time.

Industries. SAP organises agents by line of business, such as finance, procurement and customer service, not by industry. Its documented scenarios sit in procure-to-pay, sourcing and service operations.

Deployment. Low-code agents run on a fully managed runtime on SAP Business AI Platform. Pro-code agents deploy as a self-managed runtime in your BTP subaccount, on Cloud Foundry or Kyma. SAP Cloud Connector gives secure access to on-premise systems and S/4HANA Cloud Private Edition.

Pricing metric. SAP's documentation names SAP AI Units as the entitlement needed for Joule capabilities such as Joule for Consultants. A separate SAP price list converts requests into AI units.

Protocols and integrations. Pro-code agents expose A2A server endpoints (version 0.3.0) and act as MCP clients. An MCP Gateway in SAP Integration Suite exposes SAP and non-SAP APIs as MCP tools without custom server development. Frameworks include LangGraph, CrewAI, Google ADK, LangChain, LlamaIndex and an embedded n8n environment.

Ideal customer. An SAP-centred enterprise running S/4HANA or SAP Ariba that wants agents acting on finance and procurement data inside the systems that own it. The buyer is the CIO or the BTP platform team, with the finance and procurement leads as sponsors.

Ask about. Which governance pieces, such as the Agent Gateway for third-party and self-hosted agents, are generally available today and which are still roadmap?

Docs. Agentic AI & AI Agents on SAP Business AI Platform; help.sap.com documentation (PDF); Build AI Agents on SAP BTP.

Workday Agent System of Record

What it is. Workday's argument is that agents touching people and money need a system of record, just as employees do. The Agent System of Record (ASOR) registers agents and their permissions, and the Agent Gateway is the "unified, secure control point to manage and meter all agent interactions". Third-party agents can be registered and monitored there too, with or without access to Workday data.

Components. ASOR holds the agent registry, skills and security configuration. The Agent Gateway handles agent traffic over MCP and A2A. Sana is the conversational layer that orchestrates Workday agents, and Workday Build and Orchestrate provide the developer tools and agent-ready connectors.

Strengths. Each agent is issued a unique identity, scoped permissions, an audit trail and continuous attestation. A delegate-execution mode requires both the agent and the user to be authorized before any action proceeds. Agents also inherit approval chains, separation-of-duties controls and regional policies already configured in Workday, so you do not rebuild business rules for agents. Workday is third-party certified for ISO 42001 and the NIST AI Risk Management Framework.

Use cases. A Payroll Agent identifies and updates invalid payroll data and automates audit workflows. A Policy Agent reads current corporate policy and answers employees and managers, deflecting tactical case volume from the HR help desk. A Financial Auditing Agent reconciles balances and reviews internal controls, and an AP invoices agent from the partner network automates invoice processing. ASOR dashboards report usage, time savings and ROI.

Industries. Workday organises agents by function: HR, finance, IT and legal. It does not publish an industry list for ASOR. The common thread is any organisation with large workforce and financial processes in Workday.

Deployment. Workday-delivered agent teams run on a pre-configured runtime, and customers can build orchestrations that run inside Workday. Agents from other vendors can run on other platforms and models and still be governed through ASOR.

Pricing metric. Workday sells its AI agents through Flex Credits. These are credits purchased in bulk and applied across any eligible agent or platform innovation.

Protocols and integrations. The Agent Gateway is built on open protocols, MCP and A2A. More than 65 partners connect agents to ASOR, including AWS, Google Cloud and Microsoft. Agents and partner apps are offered through Workday Marketplace.

Ideal customer. A Workday HCM or Financials customer that wants agents acting on payroll, HR and finance data under the same security model as employees. The buyer is the CIO with the CHRO and CFO, who each get operational and financial reporting from ASOR.

Ask about. Which third-party agent calls does the Agent Gateway meter, and how do they draw on our Flex Credits?

Docs. The CIO buyer’s guide to AI-ready HR and finance platforms.; AI AGENTS; The Workday Agent System of Record Is Now Generally Available.

Data and AI platforms

IBM watsonx Orchestrate (Agentic Control Plane)

What it is. watsonx Orchestrate is IBM's platform for building, running and governing agents. Its Agentic Control Plane was released in June 2026 and extends that governance to agents built elsewhere. IBM is named as an example vendor in Gartner's July 2026 market overview of AI agent management platforms.

Components. The control plane bundles an agent catalog with versioning and dependency management, an operational dashboard, agent analytics, policy management, content guardrails and credential health monitoring. A unified AI gateway oversees how agents, models and tools behave in production. You build with the Agent Development Kit, Langflow or a visual Flow Builder, and knowledge bases land in a built-in Milvus store.

Strengths. Agent Identity, in preview, gives each agent an identity "separate from the identity of its creator, owner, or end user". It connects to IBM Verify and Microsoft Entra instead of adding a private identity store, and it issues a short-lived on-behalf-of token when an agent calls a protected tool. Workflows run asynchronously for "minutes, hours, or even days", pause for human validation and retry per node.

Use cases. Documented scenarios include scheduled work such as weekly reports, daily monitoring checks and recurring notifications. Human-in-the-loop workflows capture context and resume with audit-ready traceability. You can also import existing LangGraph agents and give them the platform's long-term memory, credentials, policy enforcement and evaluations.

Industries. The compliance options point to regulated work: a HIPAA-ready option and FedRAMP-compliant environments on AWS GovCloud.

Deployment. You can run it as a managed multi-cloud service on IBM Cloud or AWS, or on premises on IBM Cloud Pak for Data. A local Developer Edition exists for building. External agents can stay hosted on your own infrastructure.

Pricing metric. The published Essentials and Standard plans are sized by monthly active users and messages per month. You can also buy with cloud credits.

Protocols and integrations. Remote MCP toolkits are reached through an MCP Gateway, and agentic workflows can be published as MCP tools in public preview. A2A version 0.3.0 is supported over JSON-RPC on HTTP. The platform can "automatically scan for agents and bring them into the watsonx Orchestrate control plane", including agents on Amazon Bedrock, and it connects to agents built with LangGraph, CrewAI and Salesforce Agentforce.

Ideal customer. A large enterprise that already runs agents on several platforms and wants one place to catalogue and govern them. It suits organisations that must keep part of the estate on premises or in a regulated cloud. The natural buyer is the central IT or AI platform team.

Ask about. Which third-party agent environments can the control plane scan today, and which can you only reach as external A2A agents?

Docs. Connect agent; Manage all your ai agents in one place with watsonx orchestrate; Connect to external agents.

Databricks Agent Bricks and Unity AI Gateway

What it is. Agent Bricks is where Databricks hosts and builds agents, and Unity Gateway is what Databricks calls its "control plane for enterprise AI". New gateway capabilities were announced at Data + AI Summit 2026. Built on Unity Catalog, it "extends governance beyond your data and AI assets to the runtime interactions between models, agents, MCP servers, and tools".

Components. Agent Runtime runs your agent on Databricks-hosted serverless compute as a Databricks App, with a DurableAgentServer for long runs. Managed sessions and long-term memory live in Lakebase, and Databricks Sandbox runs code the agent writes in an isolated environment. Unity Gateway covers models, managed MCP services, agents and skills, with MLflow Tracing for runs and a spend view across them.

Strengths. An agent's identity is the service principal of its app. Tools can instead run as the requesting user, so Unity Catalog permissions, row filters and column masks apply per user. Audit records carry run_by and run_as fields, which separate a human from the agent acting for them.

Use cases. Databricks documents routing an external coding agent through governed model services and capping its consumption and spend. You can track spend across hosted models, coding agents and custom agents in one view, attributed by user, team and tool. Long agent tasks survive crashes: the server detects an interrupted run and starts a replacement attempt, and an invocation ID stops a retry from creating a duplicate run.

Industries. The Databricks launch blog quotes customers Udemy, First American and Flo Health, and First American describes adopting AI "in a regulated industry". Databricks frames the gateway as governance for regulated environments that need audit and data protection.

Deployment. Agents run on Databricks-hosted serverless compute, and each deployment is an app with its own URL and OAuth authentication. You can run your own agent server instead if you need custom endpoints or protocols.

Pricing metric. Consumption is metered in Databricks units (DBUs). External model spend is estimated from provider list prices, with a configurable multiplier for your own discounts. In preview, managed memory and sessions are billed through the underlying Lakebase instance.

Protocols and integrations. Agents act as MCP clients, using Databricks-provided servers, registered external servers or your own servers built on Databricks Apps. Agent Runtime hosts agents "built with any framework or harness", and the CLI has templates for LangGraph and the OpenAI Agents SDK. The gateway reaches OpenAI, Azure OpenAI, Anthropic, Amazon Bedrock, Microsoft Foundry and Google Gemini Enterprise, and Databricks names security partners such as CrowdStrike, Palo Alto Networks and Zscaler plus identity partners Okta and Ping Identity.

Ideal customer. An enterprise whose data and analytics already sit in Databricks and Unity Catalog, and that wants agents governed with the same privileges as its tables. It fits regulated sectors where lineage and audit are checked. The buyer is usually the data and AI platform team.

Ask about. Which gateway controls are generally available today, given that service policies and the unified trace table are labelled beta?

Docs. Managed agent memory; Agent Server; What is Agent Bricks?.

Dataiku Agent Hub and Agent Management

What it is. Dataiku describes itself as "the Platform for AI Success", an orchestration layer for building, deploying and governing AI that sits above data platforms, cloud infrastructure and AI services. Agent Hub is where agents are designed, orchestrated, deployed and governed in one centralized system. Agent Management, the vendor-neutral oversight product, becomes generally available in October 2026.

Components. Agent Hub covers designing, orchestrating, deploying and governing agents, built either visually or in Python code. Agent Management adds an inventory of agents across platforms, monitoring of usage, cost and quality, and risk certification. LLM Mesh sits underneath as the central point for model providers and guardrails.

Strengths. Agent Management is deliberately neutral: it "sits above the stack" and scans agents on other vendors' platforms into one inventory. It identifies each agent's tools and models, assigns an owner and purpose, and lets you certify agents, test them on a schedule and keep a risk record for auditors. Dataiku itself holds ISO 42001:2023 and ISO 27001:2022 certifications.

Use cases. The documented questions are portfolio questions: which agents are unmonitored, where risk is concentrated, and which agents earn their cost. Teams ask them in plain language and get an answer across the whole portfolio. Visual agents can pause before a tool call and let a reviewer edit the tool inputs.

Industries. The downloaded Dataiku pages name no target industry list. Its trust page extends the compliance program to healthcare and life sciences customers through a HIPAA report.

Deployment. Dataiku Cloud is a vendor-hosted option where Dataiku hosts data and compute. You can also install the platform on your own servers on premises or in a cloud of your choice.

Pricing metric. Agent Management is priced per instance annually, with monitoring metered per agent.

Protocols and integrations. Agent Management connects to AWS Bedrock, Databricks Agents, Google Vertex, Microsoft Copilot Studio and Azure Foundry, Salesforce Agentforce and Snowflake Cortex, with OpenTelemetry support for custom environments. Dataiku can expose agents and tools through an MCP endpoint and agents through an A2A endpoint, both with API-key authentication, and agents can call remote MCP servers. LLM Mesh connects providers such as Anthropic, OpenAI, Bedrock, Azure OpenAI and Mistral, plus self-hosted models.

Ideal customer. A large enterprise with several AI teams that have each picked a different agent platform and now need one inventory and one risk process. It suits regulated industries where an auditor will ask for a record per agent. Existing Dataiku users on analytics and machine learning have the shortest path, and the buyer is typically the head of data science or AI governance.

Ask about. Can an agent in Dataiku call an agent on another platform, or is cross-platform support limited to inventory, monitoring and risk?

Docs. Long-Term Memory; Code Agents; Product agent hub.

Agent-native platforms

xpander.ai

What it is. xpander.ai is an enterprise agent platform that runs agents itself instead of watching them from the side. Its docs call it "the governed runtime for enterprise AI agents". Teams keep working in coding harnesses such as Claude Code, Codex and OpenCode, and xpander runs those agents under one control plane.

Components. The platform has four parts: Connect, Control, Multiplayer AI and Build. A skill catalog offers API connectors, MCP connectors, Markdown skills and custom actions, and every model call passes an AI gateway. Omni, a built-in agent, assembles agents from plain-language descriptions, and approvals, workflows (in preview), shared sessions and an audit log sit on top.

Strengths. Control is structural, not prompt-based: an agent reaches only the skills it was given. The docs put it this way: "A capability that doesn't exist can't be jailbroken, leaked through injected skill output, or coaxed out by a clever user." Credentials are brokered outside the agent loop, and every call is recorded under the person who asked.

Use cases. Risky actions stop at an approve or decline card, with a hold of 1 to 72 hours. Shared sessions let several people and several agents work in one conversation with one transcript and one set of files.

Industries. xpander is SOC 2 Type II certified and GDPR compliant, with ISO 27001, HIPAA and FedRAMP in progress.

Deployment. It runs in xpander's cloud, in your VPC or fully air-gapped. In the hybrid setup every task executes inside your cluster while the control plane stays in xpander cloud. Self-hosted installs run on any conformant Kubernetes 1.28 or later.

Pricing metric. Model calls are charged in credits when they run on keys xpander provides. Calls on keys you bring yourself are never charged credits.

Protocols and integrations. An admin registers MCP endpoints once, and agents reach them with the same approvals and record as any other skill. xpander also serves its own API as an MCP endpoint with OAuth 2.1. Besides the native harnesses, the SDK path runs your own loop on Agno, LangChain and LangGraph, the OpenAI Agents SDK or AWS Strands, and models range from Anthropic, OpenAI and Bedrock to your own vLLM, Ollama or NVIDIA NIM endpoints.

Ideal customer. An enterprise whose engineers already use Claude Code or Codex and whose security team wants those agents inside company boundaries. The air-gapped and in-VPC options suit organisations with strict data residency. xpander targets CIOs, IT leaders and business application teams.

Ask about. Does each agent get its own identity in our identity provider, or are its calls attributed to the person who asked?

Docs. Sizing and requirements; Workflows; Access control.

Lyzr Agentic OS and Agent Control Plane

What it is. Lyzr is a full-stack agent vendor that calls itself "an enterprise agent orchestration company building the control plane for AI agents". Its Agent Control Plane, announced on 9 July 2026, adds a production path for agents built on other frameworks. The aim is to move enterprise AI from proof of concept toward production-scale operations.

Components. The stack has five layers: the Agent Framework runtime, Agent Studio, Architect (text to app), a model layer and a cloud-agnostic infrastructure layer. Orchestration comes as a dynamic Manager Agent or a deterministic SuperFlow DAG, and Cognis provides managed memory. The Control Plane adds deployment versioning, evaluation checkpoints and rollback.

Strengths. The Control Plane treats an agent deployment as a release workflow, with integrated security validation, deployment versioning, evaluation checkpoints and rollback. It supports deployments across multiple frameworks and cloud infrastructures. Governance runs through a single operational interface.

Use cases. Agents can run on cron schedules or webhooks, and SuperFlow adds approval gates mid-workflow. Cognis memory is also available as an MCP server, so tools such as Cursor and Claude Desktop can use it.

Industries. Lyzr names banking, financial services, insurance, healthcare and other regulated sectors. It claims HIPAA and SOC 2 compliance and offers regional hosting for data residency.

Deployment. The same stack deploys to Lyzr Cloud, your own cloud or on premises "without code changes". The Control Plane aims at governance across cloud environments from a single operational interface.

Pricing metric. Usage is metered in credits. Every action that invokes computation, such as model inference, semantic indexing or multi-agent orchestration, is measured in credits.

Protocols and integrations. Lyzr supports A2A natively in both directions, so you can call LangChain or CrewAI agents as sub-agents in a Manager Agent and import A2A agents into its Agent Registry. It connects to MCP servers with API-key or OAuth authentication. Models include OpenAI, Anthropic, Google, Amazon Bedrock, Groq and Perplexity, and enterprise plans can bring their own, including self-hosted vLLM or Ollama.

Ideal customer. A regulated firm, such as a bank or insurer, whose engineers build agents on a mix of frameworks. It wants one CI/CD-style path to production with central governance. The buyer is likely the engineering or platform team that owns agent delivery.

Ask about. Which clouds can the Control Plane deploy to today, and which release checks (security validation, evaluation checkpoints, rollback) run inside our own account?

Docs. Get started architecture; Concepts memory context; Multi agent orchestration.

Kore.ai Agent Management Platform

What it is. Kore.ai sells two linked products. The Agent Platform is where you build and run agents, and the Agent Management Platform (AMP), launched on 17 March 2026, governs agents across the whole company. Kore.ai pitches AMP as a command center against AI sprawl, meaning many agent projects with no shared view or control.

Components. On the build side, Studio holds an editor for ABL, a domain-specific language for agent behaviour, plus tools, knowledge bases, workflows, channels, web and mobile SDKs and a CLI. Tools come as HTTP, code, MCP, workflow, knowledge base, SOAP and prebuilt actions. AMP adds a control plane across mixed agent stacks, an Evaluation Studio for pre-production testing, observability and governance, and anomaly detection.

Strengths. Every agent reasons by default, and you add a FLOW section only where you want fixed, step-by-step control. Guardrails run in three tiers (CEL rules, model checks, LLM checks) at input, output, tool and handoff points. Constraints are deterministic business rules checked before tool calls, and handoffs carry only what you grant, since no data is shared between agents automatically.

Use cases. Documented patterns include booking flows, identity verification and data-collection wizards built with FLOW steps. Workflows with Approval or Data Entry nodes pause until a person acts, and an ESCALATE step drops a task into a human inbox. Voice agents run over phone or SIP, and a Genesys Cloud contact center channel is supported.

Industries. Kore.ai positions AMP across industries instead of one sector. The documentation examples are generic ones, such as a retail supervisor agent and contact-center style service flows.

Deployment. The default is managed SaaS with automatic scaling and region-specific platform URLs. Enterprise plans add a self-hosted option for organisations that must run the platform in their own infrastructure.

Protocols and integrations. The platform is an MCP client over SSE or Streamable HTTP, and it exposes its own build and debug features through an MCP server for developer assistants. A2A works in both directions: an inbound channel and outbound calls to remote agents. Registered external agents become handoff or delegate targets, so local and external agents can share one workflow. AMP is described as governing LangGraph, AgentCore, Foundry and Agentforce agents, and models come from OpenAI, Anthropic, Google, Azure OpenAI, Bedrock, Vertex and any OpenAI-compatible endpoint.

Ideal customer. A large enterprise that already runs agents on several stacks and needs one place to evaluate, monitor and govern them. The build side suits teams that want a typed language with deterministic escape hatches for service and workflow agents. Buyers are typically the AI platform group together with the owners of customer-facing automation.

Ask about. Ask which of the third-party stacks AMP governs through live runtime signals and policy enforcement, and which only through registration.

Docs. Memory and state; Frequently asked questions; External agent.

OneReach.ai GSX

What it is. GSX (Generative Studio X) is OneReach.ai's platform for building and running agents that talk to customers and employees across many channels. Gartner listed it as a sample vendor in its March 2026 report on agent sprawl. OneReach describes the platform as a cognitive architecture, a stack of layers rather than a single builder.

Components. The layers are a Communication Fabric for channels and sessions, a Contextual Memory System, a Cognitive Orchestration Engine that picks models at runtime, and a Human-in-the-Loop layer. Machine Interfaces handle HTTPS, A2A and MCP, and a governance layer sets policy for agent behaviour, model use, data access and human oversight. You build in a visual Flow builder, with JavaScript, JSON, Vue.js and NPM packages for full-code work, and a library of 1,200+ pre-built skills.

Strengths. The Communication Fabric creates a "super session" that keeps context when a user moves from a voice call to Slack or email. Provider Flows hold third-party credentials, so the flows that call Salesforce or similar systems never reveal system-level authentication details. LLM output passes through a governance plane that validates it against compliance and safety rules before delivery, and you can revert at once to an earlier approved agent state.

Use cases. Documented scenarios include sales agents updating CRM records without seeing credentials, and HR workflows across internal systems. Financial providers can redact account numbers from conversation records, and analytics can auto-escalate high-value customer conversations. Templates exist for password resets, invoice management and automated onboarding.

Industries. OneReach says it works with customers that have the strictest security and compliance needs, including medical, insurance and government. It also names healthcare, finance and government as the regulated industries the platform is built for.

Deployment. You can run GSX in isolated instances in chosen regions, or inside your own AWS virtual private cloud. Private environments can sit on customer-selected clouds, data centers and dedicated hardware, with AI token and compute use owned by the customer. A fully managed hosting option covers the whole stack.

Protocols and integrations. Agents use MCP to reach external tools, CRMs and databases, and A2A is listed for direct task delegation between agents. Third-party agents can talk to OneReach agents, and requests are checked against enterprise IAM such as Okta or OAuth 2.0. Listed connections include Salesforce, Office 365, Snowflake, Slack and Teams, with BI links to Tableau and Power BI.

Ideal customer. A regulated enterprise with a multi-channel service or contact operation, in healthcare, insurance, finance or government. It fits best where data must stay in a private cloud or your own AWS account. The buyer is usually the owner of customer or employee experience, working with IT and security.

Ask about. Ask where the contextual memory is stored and how agents retrieve from it, since you will want that for your data-residency review.

Docs. Cognitive architecture; Privacy and Security; Communication fabric.

Wonderful AI OS

What it is. Wonderful is an Israeli-Dutch startup, founded in early 2025, that began with a customer service agent platform sold into non-English-speaking markets. It now sells the Wonderful AI OS, which it calls the shared operating layer that coordinates agents, workflows, AI-native applications, context, integrations and governed execution. A $550 million Series C in September 2026 set its valuation at $5 billion, with Salesforce joining as an investor.

Components. The platform page lists Observability, Workflows, Building Tools, Context, Models, Integrations, and Security and Governance. On top sit three product families: Wonderful Agents, Wonderful Systems for AI-native business applications, and the Wonderful AI Gateway. Managed workflows, productivity agents, coding agents and conversational agents can run alone or combined in one workflow.

Strengths. The pitch is reuse: permissions, integrations and audit setup are built once and then serve every new use case. The Gateway tracks token spend by team, sets budget caps, restricts premium models to chosen roles, and routes simple tasks to smaller models. It also redacts PII before a request reaches an outside vendor, and it is built so that no AI traffic bypasses it.

Use cases. Wonderful says customers use the AI OS to automate end-to-end workflows, build and deploy AI-native applications, and coordinate agents across the enterprise. The Gateway is positioned for companies whose AI spend is spread across many tools and who need logs to explain cost spikes and catch improper model use. Forward-deployed engineers work with each customer to take the first use case into production, then hand over the skills to run it.

Industries. The site lists banking, telecommunications, healthcare, utilities, insurance and retail. The company operates in more than 35 markets and is expanding in the Adriatic region, Hungary and the Baltics.

Deployment. You can choose multi-tenant SaaS, single-tenant, or bring-your-own-cloud on AWS, Azure and GCP. Wonderful also says the AI OS can be deployed in any cloud environment, including on-premise.

Protocols and integrations. The platform is described as open and model-agnostic, working with any AI model and with existing technology stacks. Third-party tools plug into the Gateway as supported providers, and everything else connects through an SDK. Security features include enterprise MCP gateways, prompt injection protection and agent guardrails, and the vendor lists SOC 2 Type II, ISO 27001:2022, GDPR, PCI DSS and EU AI Act alignment.

Ideal customer. A large enterprise in banking, telecom, insurance, healthcare or utilities that wants a vendor to put engineers on site and take a first use case live fast. It suits organisations in markets where English-first tools fit poorly. The buyer is usually the executive sponsoring enterprise-wide AI, with security and IT as co-signers.

Ask about. Ask how an agent built outside Wonderful runs inside the AI OS, and which protocols and identity controls apply to it.

Docs. Ai os; Wonderful Raises $550 Million Series C to Scale the AI Operating System for the Enterprise; A control center.

Industry platforms

XMPro APEX and MAGS

What it is. XMPro is a Dallas-based company that has built software for industrial operators since 2009. It now sells an Agentic Operations platform for asset-intensive and mission-critical industries. APEX is the control layer that manages agent teams, and MAGS (Multi-Agent Generative Systems) is the framework those teams run on. Gartner named it in several 2026 reports, including the agent management platform overview.

Components. StreamDesigner (Data Stream Designer) observes, cleans and enriches operational signals. The Operational Context Engine turns them into trusted context and an ontology holding procedures, equipment relationships and site-specific language. MAGS reasons inside that context, APEX adds profile, team, memory, planning, prompt, integration and observability management, and the Control Tower shows automation mix, escalation rates and cost per decision.

Strengths. Every recommendation and action gets a Decision Trace record that is queryable, auditable and replayable. Each decision sits inside a stated authority boundary: human-controlled, human-approved or policy-controlled. Agent teams reach consensus, and a safety and compliance specialist can hold veto power over unsafe actions. The reasoning mixes generative AI with symbolic AI, first-principles models and causal AI, and planning uses PDDL.

Use cases. Published agent team templates cover rotating equipment optimisation in downstream oil and gas, pharmaceutical reactor reliability, and pharmaceutical cold chain crisis response. Another team tunes wastewater aeration, which takes 50 to 60% of plant electricity, on a 5 to 15 minute cycle. A further example inspects metal 3D-printed parts with three sensor streams and decides accept, hold or reject, and an FMCG team coordinates demand, sourcing and logistics.

Industries. XMPro serves manufacturing, mining, energy, utilities and other asset-intensive sectors. Its templates also target oil and gas, pharmaceuticals and water treatment.

Deployment. APEX is described as ready for secure, regulated environments across cloud and edge. XMPro's own platform banner quotes a deployment time of 3 to 6 months via APEX.

Protocols and integrations. The integration layer connects directly to SCADA, PLCs, historians, MES, ERP, CRM and HCM systems, with more than 150 OT and IT connectors claimed. Agents talk to each other through a multi-protocol layer with message routing and topic-based publishing, and telemetry uses OpenTelemetry. APEX is positioned as the management layer for XMPro's own agents rather than a gateway for other vendors' frameworks.

Ideal customer. An asset-intensive operator such as a manufacturer, miner, energy or utility company, with real-time data in historians and control systems. The buyer is the operations or reliability leader working with the OT and data teams. The recommended start is one recurring industrial decision with clear context and a governed authority level.

Ask about. Ask which authority level (human-controlled, human-approved or policy-controlled) your first decision would run under, and how its Decision Trace records reach your existing systems of record.

Docs. Agent Platform Experience; Platform; XMPro Named as an Example Vendor in the 2026 Gartner® Market Overview: AI Agent Management Platforms.

Fiserv agentOS

What it is. Fiserv is a payments and financial technology provider whose cores, payments, issuer processing and servicing platforms run inside banks and credit unions. It launched agentOS on 14 May 2026 as an agentic AI operating system for those institutions, with wide availability expected by August 2026. It runs on Amazon Bedrock AgentCore, and Fiserv builds select first-party agents with OpenAI.

Components. The agentOS stack has four layers. Agents holds Fiserv agents, vetted third-party agents and, marked as coming soon, build-your-own. The governance layer covers permissioning and identity, policy controls, agent configuration, kill or suspend, audit logs and observability, caching and billing. Below sit a Models layer with small language models and routing, and a Data and capabilities layer that reaches Fiserv data directly.

Strengths. Agents run next to the core they work on, so a loan onboarding agent can write straight to the Fiserv core and you skip an integration project. The governance plane is shared, so Fiserv, third-party and your own agents all fall under the same identity, policy and audit controls. You can test any agent with your own data in a CERT environment and promote it to production yourself.

Use cases. Four Fiserv agents launched: Commercial Loan Onboarding, Daily Operational Analysis and Reporting, Agentic Deposit Intelligence, and Agentic AML Triage Analysis. Third-party agents cover customer engagement, financial crimes compliance, regulatory compliance, dispute management and reconciliation. Other listed agents include Regulatory Monitoring and Controls, and Credit Default Early Warning, which spots likely delinquency up to 120 days ahead.

Industries. Banking is the single focus, with agents aimed at banks and credit unions. Workflows named include service, fraud, payments, compliance, lending, deposit operations and growth.

Deployment. agentOS runs on AWS through Bedrock AgentCore, with models reached through Amazon Bedrock. Agents move from a CERT test environment to production, and operators can suspend or kill any agent.

Pricing metric. You buy credits once and spend them across every agent, and each agent is priced by the way it creates value. Some are charged per query, some per outcome when the agent finishes the job, and always-on agents per subscription.

Protocols and integrations. agentOS is built to work natively across Fiserv core, payments, issuer processing and servicing. Third-party agents join through the Marketplace in the same governed architecture. Models come through Amazon Bedrock, and the Models layer includes specialised small language models with caching and optimisation.

Ideal customer. A bank or credit union that already runs on Fiserv platforms and wants agents under its existing vendor relationship, audit regime and core data. The buyer is typically the COO or CIO, with lines of business such as lending, deposits and compliance sponsoring individual agents. Banks that want to try before committing can use the CERT sandbox first.

Ask about. Ask when build-your-own agent creation and third-party data move out of "coming soon", and what identity each custom agent receives.

Docs. Lp agentos by fiserv; Fiserv launches agentos the operating system for agentic ai in banking; Fiserv launches agentos the operating system for agentic ai in banking 2026514.


Sources

History of the term

Cloud and model platforms

Identity and productivity

Gateways and AI governance

Integration platforms

Workflow and process automation

Business application suites

Data and AI platforms

Agent-native platforms

Industry platforms

Read more