Product1 distinct publisher3 min readPublished
The new Agentic IdP registers every agent Falcon Guardian finds, issues it a cryptographic identity and brokers short-lived tokens instead of credentials, which quietly makes your discovery coverage the thing that decides the rollout.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
Read the order of operations before the feature list. Guardian has to see an agent before Agentic IdP can register it, and an agent without a registered identity is not eligible for authorization at all [6][7]. In practice that means one of two outcomes on Monday: a workflow halts and someone has to track down who owns it, or an exception ticket reinstates the standing credential that token brokering was supposed to eliminate [8].
Most agents in production today run on a service account, an API key or a workload identity set up by whoever was closest to the problem at the time, carrying whatever permissions that person happened to have, even though teams often describe them as running under managed identities [5]. CrowdStrike's own framing is that none of those were designed for software that acts on a person's behalf and hands work to sub-agents [5]. Accept that and the bill lands on engineering rather than security: an agent written to read a key out of an environment variable has to learn to ask for a scoped, short-lived token instead [8], and every action it takes now carries the name of a human or workload that answers for it [9].
The SOC half is a throughput claim. Charlotte AI now runs agents against endpoint, identity, SaaS, cloud and network at the same time on a single investigation, rather than one agent per alert worked in sequence, which CrowdStrike argues returns a fragment from one domain instead of a verdict [11][12]. The part that makes parallel work coherent is the shared context layer on Enterprise Graph, described as persistent memory across agents, investigations and tenants, so what one agent establishes the others can use without a handoff [13]. CrowdStrike puts platform volume at close to 4 trillion events a day across those five domains [14], which works out to roughly 46 million events a second (4,000,000,000,000 divided by 86,400) [16]. Michael Sentonas calls single-agent SOC tooling "table stakes" and cross-domain agents "the new standard" [17]; the hours-into-minutes figure attached to the rebuild is the company's own [11]. More useful for the person evaluating it: investigations now cover prompt injection, model abuse and exfiltration through AI assistants, and the agents return reasoning with the verdict rather than a bare conclusion [15].
The forcing function for next week is a two-column list of every agent you run in production. Column one, can you name the human or workload it acts for. Column two, does anything break if you revoke its standing credential tomorrow. If there's a named owner and nothing breaks, you can register the agent and move on. If there's a named owner and something breaks, that's scoped engineering work with a cost you can estimate. If there's no named owner and something breaks, that agent belongs to the group this whole model was built to handle, a group that typically goes uncounted. If that list comes out shorter than your actual agent count, the discovery product matters more to you right now than the identity product does.
Ranked by verification strength, evidence, and original report placement.
CrowdStrike Holdings Inc. announced three additions to its Falcon platform: an identity provider built for AI agents, a rebuilt investigation layer that runs multiple Charlotte AI agents across security domains at once, and a feature that blocks malicious open-source packages on the endpoint before their embedded code can run.
All three additions were detailed at CrowdStrike's Fal.Con 2026 conference in Las Vegas.
The CrowdStrike Agentic Identity Provider, or Agentic IdP, fills a gap in Continuous Identity, the real-time authorization model CrowdStrike detailed at Identiverse in June and built on technology from its $740 million acquisition of SGNL Inc.
Continuous Identity decides whether an agent should be allowed to do something at a given moment; Agentic IdP handles the step before that, establishing what the agent is in the first place.
Companies currently stand in for agent identity using service accounts, API keys and workload identities, none of which were designed for software that takes autonomous action on a person's behalf and delegates work to sub-agents.
Registration runs through Falcon Guardian, the agent discovery and enforcement product CrowdStrike launched earlier at the conference; Guardian finds agents across the enterprise and Agentic IdP registers each one as it comes online, under a single directory.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 2, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
The number in the Palo Alto-NTT DATA deal is not $1 billion. It is 80 machine accounts per human2 distinct publishers
leadership
CrowdStrike buys SGNL, and standing privilege becomes a line item you have to defend1 distinct publisher
build
Pandex hooked a Fortune 500 agent four minutes after claiming a package name from llms.txt1 distinct publisher
build
AWS's one-minute test for agent access is really a test of where the answer lives1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One stage, one reporter
Trace any specific in this story and it ends in the same place: CrowdStrike's Fal.Con keynote, relayed by SiliconANGLE. The $740 million SGNL figure, the near-4-trillion daily event count, the assertion that an agent's identity cannot be spoofed or shared — all company-stated, none tested. The mechanical claims are internally consistent and unusually concrete, which is why this is not a floor score; but there is no second publisher, no customer, and no specification to check the cryptography against.
Announced, not yet observed anywhere
Three products introduced in one keynote week, and that is the entire adoption record. No named customer, no general-availability date, no pricing, no pilot. The only quantity offered — telemetry volume across the platform — describes what Falcon already ingests, not anyone running Agentic IdP. For a product whose whole premise is registering agents you have discovered, the number that would matter is how many agents anyone has actually registered.
Architecture detailed, results asserted
Two registers are running at once here. The plumbing is described soberly and checkably — registration through Guardian, brokered tokens, delegation binding, five domains in parallel. The persuasion is carried by numbers nobody has measured: hours becoming minutes, up to half off storage, identities that cannot be spoofed, and a president declaring cross-domain agents 'the new standard' the week his company shipped them. Strip the unverified figures and a solid product story remains, which is why the gap is moderate rather than severe.
A $740 million bet needs a category
CrowdStrike bought SGNL for $740 million, launched Continuous Identity on that technology in June, and now needs enterprises to accept that agent identity is a distinct thing you buy an identity provider for. Guardian discovers, Agentic IdP registers, Continuous Identity authorizes — a sequence that only works if you buy all three, which is the definition of a platform pitch. Fal.Con is CrowdStrike's own stage, and coverage of a keynote is closer to distribution than to scrutiny, however precise the reporting.
Sure what was said, unsure what ships
We can be firm about the shape of the announcement: SiliconANGLE names the products, the executives, the domains, the package managers and the acquisition price, and none of it is internally contradictory. What we cannot stand behind is behaviour — whether registration actually catches the agents Guardian misses, whether the identities resist spoofing, whether investigations really collapse from hours to minutes. That split is why this sits mid-range rather than high.