Product1 publisher3 min readPublished
Rig Security raises $12 million to tell AI agents apart from the employees whose logins they use
Rig Security launched with $12 million to separate the actions of AI agents from those of the employees whose accounts they run under. Its early customers use it to learn whether a person or an agent took an action logged under an employee's name.
The Product Desk · Product desk

What happened
- Coding assistants and autonomous agents seldom sign in under an identity of their own, so their actions are recorded against the developer or service account that launched them.
- Rig's Identity Correlation Engine uses machine learning to match one identity across identity providers, cloud and on-premises systems, and Rig says the matching is better than 96% accurate.
- A lightweight endpoint sensor separates an agent's session from the employee's and can stop a risky action before it leaves the machine.
- The 20-person company says Fortune 200 firms in financial services, insurance and health care already run its software in production.
- Ten Eleven Ventures and Brightmind Partners co-led the seed round, with CrowdStrike joining as a strategic investor.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- constraint As Kozliner describes it, halting a risky agent today means blocking the engineer it runs under, so every containment call also takes a person off their work.
- capability A live map of which people, service accounts and agents can reach which systems gives security teams an inventory of agents to write access policy against.
- decision Because the core platform installs no software, a team can map its agents first and decide later which developer machines need sensors.
Rig's own example is a production database wiped by an agent. In the audit log, that looks like the engineer's own work [3].
An audit log is useful to the extent that the name on each line belongs to whoever acted. Developers start agents under their own accounts and let them run [2]. Guy Kozliner, Rig's founder and chief executive, said AI agents are now the most active identities in an enterprise "and they are acting under human names." [10]
A customer describes the same gap from the inside. Bill Harper is assistant vice president of digital identity at New American Funding, a mortgage lender that uses Rig. He said agents write code and investigate issues across the company, and that traditional identity tools cannot reliably tell their activity apart from the employee's [11].
The attribution half of the product rests on the matching figure. Taken at face value, better than 96% leaves up to 4 in every 100 identity matches that could still be wrong [1]. Rig did not disclose pricing or how it measured that figure.
The endpoint sensor does the stopping, and it covers only the machines where it is installed [7]. For a team whose engineers run agents with write access to production from their laptops, I think the sensor is worth buying. It also puts software on every developer machine. Harper said Rig gives the lender control over its agents "without getting in the employee's way." [12]
Rig says its software analyzes hundreds of millions of identity events and access signals a month [13]. It sells through both the AWS Marketplace and the CrowdStrike Marketplace [15]. Mark Hatfield, co-founder and partner at Ten Eleven Ventures, said most identity tools only point out what is wrong. Rig connects findings to enforcement in real time, he said, so security teams "can actually act on identity risk, including risk created by AI agents." [16] The demand on show here belongs to one 20-person company [9]. Agent attribution would need more buyers and more vendors than one seed round can show before it became a separate budget category.
Two questions put to a team's own logs show whether it has the problem Rig describes. First, take a recent sensitive action by an engineer's account and establish whether the engineer or an agent took it. Second, name what would have to be switched off to stop that agent now. If the answers are "we can't tell" and "the engineer's account," the gap matches Kozliner's account [4], and where the agents run decides what to buy. Agents launched from laptops with production access call for the endpoint sensor [7]. Agents running under service accounts need the identity map first [6]. A buyer with those agents should ask Rig how it stops them, because the enforcement it describes happens on the endpoint [7].
What to watch
- Whether CrowdStrike, an investor that also lists Rig in its marketplace, builds agent attribution into its own products.
- Whether other identity vendors ship their own separation of agent sessions from human ones, a test of whether buyers treat this as a category.
- Whether more of the Fortune 200 customers Rig cites go on the record the way New American Funding has.