Launch Week Roundup: The Agentic Control Plane C1, a cybersecurity company, launched four products last week to help organizations secure AI agents: Shadow AI Discovery, Agentic Vault, Agent Runtime Governance, and a fourth unnamed product. The launches form an 'agentic control plane' that discovers AI tools, secures credentials, governs runtime actions, and responds to risk. Shadow AI Discovery scans for unsanctioned AI tools and credentials, Agentic Vault provides short-lived credentials with post-quantum readiness, and Agent Runtime Governance routes agent tool calls through an identity-aware AI gateway with risk scoring. Last week C1 shipped four launches that introduce the building blocks organizations need to adopt and secure AI agents. Each launch covered another step: discovering the AI already in environments, securing the credentials it carries, putting up guardrails to govern at runtime, and responding to risk once it's under management. Together, they offer a practical path to adopting AI fearlessly. Each one stands on its own. Together they form the agentic control plane: a unified control plane to secure the agentic enterprise. In case you missed it, here's what we announced. Day 1: Shadow AI discovery day-1-shadow-ai-discovery You cannot govern what you cannot see, and AI adoption moved faster than anyone's ability to see it. Shadow AI discovery finds the unsanctioned AI tools, agents, MCP servers, and exposed credentials across your cloud and your endpoints, then assigns ownership and brings them under governance. It works on two surfaces. On developer endpoints, it scans for AI tools installed locally, the MCP servers each tool declares normalized across a dozen config dialects , and credential files left behind, recorded by type and location. In the cloud, connectors enumerate the AI agents running in platforms like Agentforce and Bedrock AgentCore, alongside the service principals, managed identities, app registrations, and service accounts spread across Entra, Okta, GCP, GitHub, Snowflake, and Active Directory. Every discovered item becomes an access item on the same control plane as your employees. You assign an owner, route it through request and approval, certify it in a review, and deprovision it when it is done. Discovery stops being a one-time scan and becomes governance you can act on. Want to learn more? Check out the Shadow AI Discovery post → /blog/introducing-shadow-ai-discovery Day 2: Agentic Vault day-2-agentic-vault Discovery surfaces the exposed credentials. Agentic Vault secures them. It is a secrets vault built into identity governance, so every secret moves through the same request, approval, and audit process as any other access. Today's vaults were not built for agent speed. Legacy vaults were built for a person checking out a password now and then. At agent scale you either hand out broad access and accept the blast radius, or spin up a vault per credential and drown in sprawl. Neither is least privilege. Agentic Vault gives agents short-lived, scoped credentials instead of underlying keys. An agent authenticates as a workload identity, and a workload with a matching signed identity can exchange it for a short-lived credential issued by C1. The underlying key stays sealed in the vault. You can restrict the credential to an IP range or require proof of possession, and engineers get the same through just-in-time credentials from the desktop app or CLI. Two more things set it apart. The vault is post-quantum ready from the start. So organizations are protected against "harvest-now, decrypt-later" attacks. And decoy credentials, seeded in .env files, CI variables, and secrets managers, turn any misuse into a high-confidence alert the moment a decoy is used. Want to learn more? Check out the Agentic Vault post → /blog/introducing-agentic-vault Day 3: Agent runtime governance day-3-agent-runtime-governance Knowing what an agent is and securing its keys still leaves the hardest question open: what is the agent allowed to do ? An agent's power is its tools, and one over-permissioned agent can turn a single hidden instruction into a breach with a wide blast radius. Identity checks stop once access is granted. Prompt filters only read words. Agent runtime governance brings governance to the tool call itself. Every call an agent makes routes through C1's identity-aware AI gateway, and each agent is scoped to only the tools its job requires. A support agent gets support tools. A data agent gets read and query tools. Neither gets destructive ones. Each call is risk-scored in real time against three conditions: whether private data is in reach, whether untrusted content entered the session, and whether the call opens a path to send data out. When those line up, policy can block the call, hold it for human approval before it runs, or redact sensitive fields from the result. Want to learn more? Check out the Agent Runtime Governance post → /blog/introducing-agent-runtime-governance Day 4: Agentic security and intelligence day-4-agentic-security-and-intelligence Agentic security and intelligence detects and remediates the machine identity risk that is left: an agent or service account with no owner, an account misclassified as human, a name shadowing a real account, a connector with anomaly detection switched off. Each risky condition becomes a finding that names the affected identity, explains the flag, and shows the severity. C1 combines those findings with an intelligence graph of the identity's reach across apps, accounts, and entitlements, so you can see the blast radius before you act. Remediation runs through the same request, approval, and audit path you already use, and findings resolve themselves once C1 confirms the gap is closed. When a finding belongs in your team's tools, routing rules and webhooks open tickets in ServiceNow, Jira, or PagerDuty. You can also ingest findings from other security tools through the API into the same queue. Want to learn more? Check out the Agentic Security & Intelligence post → /blog/introducing-agentic-security-and-intelligence See the whole thing live at C1 Transform see-the-whole-thing-live-at-c1-transform Four releases, one control plane. C1 now discovers unsanctioned AI, secures agent credentials, governs tool calls at runtime, and remediates the identity risk that remains. We are walking through all of it, in depth and in person, at C1 Transform 2026 on October 6 in San Francisco . It is the identity conference built for the people setting AI strategy, sign up today.