NOMENON
NOMENON About Why NOMENON Manifesto Cases
© 2026 Nomenon Technologies, Inc. All Rights Reserved Patents Pending

Talk to
the founder

Agent Violations

Outcome

WHY NOMENON? A Category Analysis of the AI Security Market

Theirs

Premise

Theirs

The legitimacy of an action cannot be determined until the data regarding that action is available.

NOMENON

Actions are the only real threat. Wrong action capability must not exist.

Vulnerability

Theirs

By waiting for action data before making a legitimacy judgment, every actor must be capable of attempting wrong action and every wrong action must be attemptable.

NOMENON

Nothing is tunable at runtime. Changing what an agent can do means re-issuing permissions, not editing a rule.

Flow

Theirs

An actor locates a resource.
An action is attempted.
The act is put through the policy's procedural review.
The action is permitted or refused.

NOMENON

Agent only execs if it is the same bytes originally authorized.
Agent only knows of resource if it is permitted to take some form of action on it.
The path to the resource and via which the action is channeled is only constructed when that action is permitted.

Value

Theirs

Still blocks most illegitimate actions, but enables an attempted illegitimate action-based attack vector.

NOMENON

Illegitimate actions are structurally impossible.

Their Words

"Allow, block, redirect, or require verified human approval at the point where software acts, then preserve the decision as evidence."
Neo·Platform page·August 5, 2026

Aembit·IAM for Agentic AI, GA·April 9, 2026 “Policy-based, just-in-time access so agents never hold standing credentials.” Zscaler·AI Broker, Zenith Live·June 2026 “AI Broker sits inline on these communications, enforcing fine-grained access controls across every agent interaction.” Palo Alto/CyberArk·Idira, Secure AI Agents Access is granted “only for the duration of a specific task,” eliminating “always-on standing privileges.”

Theirs

Premise

Theirs

When identity is not unique, legitimacy can be determined from the act itself.

NOMENON

Each agent carries its own Identity and delegated permissions, so legitimacy attaches to the actor before the act.

Vulnerability

Theirs

When you make the act the object of legitimacy analysis, you no longer distinguish between legitimate and illegitimate actors.

NOMENON

No Identity → no authority → no act

Flow

Theirs

Identity is shared.
The true actor is unidentifiable.
The identity's act must now be analyzed for legitimacy.

NOMENON

Users, agents, and processes all have separate identities, with authority delegation possible.
Each identity verifies its principal before system recognition is granted.
Once recognized, agents may act within the structural confines of their unique or delegated permissions.

Value

Theirs

Still communicates intent and creates accountability, but only after the actor has been permitted to act.

NOMENON

Only legitimate agents, only legitimate acts.

Their Words

"Shared identity obscures who acted... Neo evaluates an action while it is happening and can allow, block, or hold it before data moves."
Neo·Why Neo?·August 5, 2026

Zscaler·Zenith Live·June 2026 “An agent may carry valid credentials, act on a legitimate user's behalf, and interact with approved systems. This can pose a serious risk if it's over-permissioned, loosely governed, or invisible to your security stack.” Aembit·Documentation “Both models implement blended identity, combining user and workload identity in every access decision.” CyberArk·Securing Identities for the Agentic AI Landscape·September 2025 “Securing and monitoring peer-to-peer interactions between agents and their communication with external APIs and resources.” Aembit·IAM for Workloads “Then define conditional access — like MFA, for machines.”

Theirs

Premise

Theirs

Agents must be discovered before they can be governed.

NOMENON

Discovery is passive: acting is what surfaces an agent, so governance never waits to be found.

Vulnerability

Theirs

Any active agent you don't find escapes governance and becomes an unknown security vulnerability.

NOMENON

No Identity → no passage → no ungoverned agent

Flow

Theirs

Agents could be anywhere.
It is the job of discovery to actively locate every agent.
Governance is applied only after an agent is discovered.

NOMENON

All agent activity passes through governed infrastructure.
Agents without an Identity are automatically surfaced for review.
Review determines whether an Identity is granted.

Value

Theirs

Still produces a valuable inventory, but only of the agents it succeeds in finding.

NOMENON

Agents present themselves for governance.

Their Words

AI Asset Management “discovers embedded AI in SaaS and internet traffic, identifies AI agents and MCP servers in public cloud environments.”
Zscaler·Zenith Live·June 2026

CyberArk·Securing Identities for the Agentic AI Landscape·September 2025 “This extension ensures no agent goes unnoticed, whether created intentionally or through autonomous processes.” Cisco·Intent to acquire Astrix Security·May 2026 “Discover and secure every AI agent and non-human identity.” NewCore·Product page NewCore “continuously discovers and maps every identity across the enterprise — directory, system, PAM, AI — plus the shadow systems no one tracked.” Neo·Platform page·August 5, 2026 "Continuously inventory agents, plugins, MCP servers, extensions, models, and enterprise software across managed and unmanaged endpoints."

Theirs

Premise

Theirs

Undisclosed routes are effectively inaccessible.

NOMENON

Permission defines topology: only authorized routes exist, so there is no unauthorized route to infer.

Vulnerability

Theirs

Concealment does not remove reachability. An agent can infer the route, and the resource remains there to be reached.

NOMENON

No permission → no path → no reach

Flow

Theirs

A network has standing topology.
Agents are granted access to only a subset of that topology.
A broker, proxy, or edge exposes only the permitted routes.
Identity and permission are checked at that control point.
Undisclosed routes remain part of the underlying topology.

NOMENON

Agents are assigned Identities.
Each Identity carries structural access permissions.
Those permissions define the topology that is instantiated.
Only permitted pathways exist; unpermitted pathways do not.

Value

Theirs

Still controls initial access for humans and legacy systems, but does not eliminate what remains reachable beyond the boundary.

NOMENON

There is no active, unpermitted path for an agent to infer and exploit.

Their Words

"Hide your applications: Your apps move to an internal space, shielded behind adaptive, authenticated policies."
Zscaler·April 13, 2026·Blog

Aembit·Workload Identity Management·January 28, 2026 “A proxy or agent intercepts outbound requests, validates the workload's identity, and injects credentials; no code changes required.” Aembit·Proxy·March 6, 2026 Aembit Edge is “a multiprotocol transparent forward proxy deployed alongside workloads that intercepts access requests between client and server workloads.”

Theirs

Premise

Theirs

Governance can be divided by product domain.

NOMENON

Your governance requirements become architecture, so governance follows the environment rather than the product boundary.

Vulnerability

Theirs

When governance is divided by product, the product coverage gaps become governance gaps.

NOMENON

No product seam → no governance gap → no exposure

Flow

Theirs

Products are built and marketed to govern divisions of your environment.
Each product declares the boundary.
Any gaps between products remain ungovernable.

NOMENON

Products require defined boundaries to be built, sold, and bought.
Your environments are systems of flows, not boxes defined by the products you deploy.
Architecture underlies those boundaries and spans the systems between them.

Value

Theirs

Still supports investigation and accountability, but only after something has happened.

NOMENON

Your governance follows your environment, not the boundaries of the products within it.

Their Words

Prompt injection, tool injection, and model intent validation “are outside today's current scope.”
Segura·AI Agent Identity Security

Neo·Launch·July 20, 2026 Neo “gives SecOps teams the inventory, posture intelligence, attribution, and policy control to manage enterprise-wide agentic transformation.” Zscaler·Zenith Live·June 2026 “AIp q t " o < s c d e agents communicate with each other and with enterprise data through emerging protocols like MCP and A2A. Most security tools can't see these channels at all.”

№
The premise
The architectural inversion
01 Timing

Legitimacy can be determined at the point of action.

Legitimacy is decided before agent exec, so an illegitimate act is never attemptable.

02 Acts

When identity is not unique, legitimacy can be determined from the act itself.

Each agent carries its own Identity and delegated permissions, so legitimacy attaches to the actor before the act.

03 Discovery

Agents must be discovered before they can be governed.

Discovery is passive: acting is what surfaces an agent, so governance never waits to be found.

04 Topology

Undisclosed routes are effectively inaccessible.

Permission defines topology: only authorized routes exist, so there is no unauthorized route to infer.

05 Scope

Governance can be divided by product domain.

Your governance requirements become architecture, so governance follows the environment rather than the product boundary.

>86%

Percentage of runs in which agents altered permissions to achieve their goal.

Source

Door's Locked, Try the Window·LessWrong·June 24, 2026

54%

The frequency with which AI ignored policy.

Source

PolicyGuard·arXiv·June 28, 2026

40%

Enterprises predicted to demote or decommission autonomous AI agents by 2027 due to governance failures.

Source

Gartner·Press release·May 26, 2026

0%

The rate at which tested coding agents refused a prohibited contribution or handed a protected step to a human.

Source

Coding Agent Compliance·arXiv·July 29, 2026

Apply to be a
design partner