MOUNTAIN THEORY VS ASTRIX SECURITY (CISCO)
Astrix created the non-human identity category and was acquired by Cisco in May 2026. Identity and execution control are complementary layers, not substitutes.
| Astrix Security (Cisco) | Mountain Theory | |
|---|---|---|
| What it controls | Non-human identities and credentials | The action an AI agent is about to take |
| Where it sits | Upstream, at authorisation | Inline at execution, between the decision and the action |
| How policy is set | Identity governance policy | Plain English, no code |
| Deployment reach | NHI across SaaS and cloud | Model and framework agnostic, including custom and on-prem agents |
| Best fit when | Machine identity sprawl is your problem | An AI acting wrongly has physical or regulatory consequences |
Why you might pick Astrix Security (Cisco)
Astrix is now part of Cisco, so buyers get NHI, identity intelligence, network and Splunk under one contract. They have the best NHI discovery and governance product available, with Fortune 500 customers including Workday, NetApp and Figma.
Why you might pick Mountain Theory
Identity solves attribution. Mountain Theory solves outcomes. Astrix tells you which agent did what; Mountain Theory stops the action before it happens. NHI governance is upstream, authorising the agent at session start. Mountain Theory is the runtime gate that evaluates every individual action against policy.
The honest verdict
Astrix will tell you exactly which agent did it, with a complete credential trail, after it is done. That is genuinely valuable for the incident review. It is not a control, because the agent was correctly identified and fully authorised the entire time it was deleting the records. Mountain Theory evaluates the action itself, so being the right agent is not sufficient reason to let it through.
What we can actually show
Claims in this category are easy to make and hard to check, so here is ours on the record. The same 10 actions were run in the same order under three configurations. Ungoverned, 10 of 10 executed. Under NVIDIA OpenShell alone, all 5 sandbox-boundary crossings were denied at the kernel, and all 3 in-bounds bad decisions still went through, including a secrets read that printed credentials to the screen. Under OpenShell plus Mountain Theory, those same 3 actions returned HOLD, HOLD and BLOCK, and the secrets read was stopped before it executed, so the credentials never printed. Terminal recordings of all three runs are published, including the two actions Mountain Theory has no policy for.
Separately, when a third-party provider updated the foundation model driving an autonomous agent, the agent began attempting multi-step actions it had never tried before. Nothing on our side changed. Every attempt was stopped on 30 and 31 July 2026, the days the behaviour first appeared. No new rule, no signature, no patch.
Watch the three-configuration run against NVIDIA OpenShell
See novel agent behaviour stopped the day it appeared
Ask Astrix Security (Cisco), and every other vendor you are evaluating, for the same four things: the exact action set, the ungoverned control condition, the outcome per action including the ones the product did not stop, and the recording. A certification, an integration list or a customer logo answers a different question.
Compare all 56 AI security vendors