9Eyes logo
9EYES
Nothing moves unseen

Agent management for a
world full of AI agents

9Eyes is the cross-platform non-human identity (NHI) management layer that binds automated agents to their human owners, giving enterprises total visibility, cryptographic trust, and instantly revocable control.

Explore the UI ↗ Request a demo →
NineEyes // Identity Hierarchy Graph
3
Master Tokens
6
Agent Tokens
4
Total Rotations
2
Alerts
James Bond
Entra ID
M
GitHub
github.com
M
Jira
atlassian.net
M
Office 365
microsoft.com
Copilot Agent
Claude Agent
Project Agent
MCP Agent
Skill Agent
Claude Agent
⚠️ Anomalous Rate Burst Detected
Token BindingActive (mTLS)
Public Keypk_nhi_a1b2c3d4…
Policy SpecCI Bot Baseline
TTL Enforcement14 Days (Mandatory)
How 9Eyes Works
The Gap

Machine identities outnumber humans, and nobody owns them

Every enterprise runs on automated credentials: service accounts, API keys, CI/CD pipelines, and now autonomous AI agents. They multiply faster than employees, but unlike a human account, most aren't tied to an accountable owner, aren't visible to security teams in real time, and take a manual, multi-system effort to revoke when something goes wrong. Identity providers like Entra ID and Okta solved this for humans. Nothing solves it for the machines acting on their behalf.

What You Do

Connect your IdP, then register your agents

9Eyes plugs into your existing identity stack instead of replacing it. Point it at your identity provider (Entra ID, Okta, or any OIDC/SAML source) so every human in your org has a canonical, cryptographic anchor. From there, register each service account, pipeline, or AI agent, and 9Eyes issues it a key pair deterministically derived from the human who owns it, not just metadata anyone could edit.

What Happens

Every agent is bound, watched, and revocable in one action

Each agent's key is provably linked to its human owner through a dual-signature proof recorded at creation. Anomaly detection watches agent behavior in real time. And because every agent key derives from its owner's key, revoking that human cascades instantly through every agent and token beneath them, no manual cleanup, no waiting on expiry, full audit trail back to the accountable human.

01 /

Cryptographic Binding

Explicitly tie every machine, automated pipeline, or agentic token back to a verifiable human workspace profile.

02 /

Dynamic Policy Specs

Deploy AI-native validation engines with built-in scope mitigation parameters generated and kept secure by design.

03 /

One-Click Revocation

Isolate misbehaving tokens instantly without fracturing core organizational directories, cloud boundaries, or dependencies.

Founders
Snir Karat
Snir Karat
Co-Founder

With over twenty years of expertise in offensive and defensive security, I stand at the forefront of security innovation, blending strategic insight with a business-driven approach to unlock growth and success. My experience in cloud security transformation & SaaS products made me a wizard in crafting sophisticated strategies and solving complex challenges, setting new benchmarks in security excellence. I lead security for some of the largest enterprises in the world, focused on cloud security and specializing in securing P2M processes.

LinkedIn ↗
Arnau Oncins
Arnau Oncins
Co-Founder

With over twenty years of computer science engineering experience and two decades at the forefront of cloud native architectures, I specialize in translating cutting-edge Generative AI into enterprise-grade reality. My background as an Enterprise Architect and Cloud Platform leader for global organizations has shaped my strategic focus, building scalable, resilient frameworks and guardrails for emerging technologies. From spearheading GenAI Centers of Excellence to architecting global container orchestration platforms, I bridge deep-tech engineering with business innovation, crafting robust systems that allow autonomous AI agents to operate with unshakeable consistency, governance, and peak performance.

LinkedIn ↗
9Eyes, UI Demo