The static one your identity stack assigns - and the Dynamic Identity it earns by how it behaves. FortLine learns every agent's missions - the real units of its work - and catches the moment one goes wrong. Per agent, not per population. While it runs, not after.
A prompt-injected, poisoned or drifting agent acts entirely inside its granted permissions - so every gate says yes. An agent can do ten individually permitted things that add up to something wrong. No per-action gate can see that. A mission can.
Decides which agents may act and what they may touch. Necessary - and it assumes the agent stays itself.
Filters prompts and enforces policy at the chokepoint. Blind to whether the run inside the policy is normal - and blind to everything that never passes through it.
What the agent actually did, step by step, across the whole mission. This is the blind spot FortLine closes.
You want all three. Nobody argued that directory and access control made endpoint detection unnecessary. FortLine's verdicts fire while the mission runs and feed the gates you already own - and because it sits off the data path, it can never slow down, throttle or break an agent.
FortLine links every anomaly to the agent conversation that produced it - the prompts, tool calls, reasoning, and the exact step where the mission went off-baseline. Investigation that took an afternoon becomes one click.
From a cluster full of unknown AI workloads to a learned agent catching its first anomaly - every screen is AgentShield, the FortLine platform, running live.
Identity vendors answer who is this agent and what may it do. That is essential, and we build on it. FortLine adds the missing dimension: a learned, living model of how each agent normally behaves - so you can tell when an authorized agent is no longer acting like itself.
Inventory every agent, model, MCP server and AI workload across clusters and clouds. Shadow-AI and posture (AI-SPM).
A self-governing AutoML engine learns each agent's missions and their normal behavior - no rules to write, no policy files to rot.
Catch drift, goal hijack, tool misuse and rogue behavior in production - the anomaly, not a signature.
Every alert links to the exact conversation, tool calls and reasoning that produced it. One click, not an afternoon.
Capture happens off the data path - at the kernel with eBPF, or through a transparent gateway for serverless. No SDK, no code change, and zero added latency to your agents.
OpenAI's escaped eval agents created a hidden message board to coordinate - and after it was shut down, rebuilt it four days later. Disclosed on the Black Hat stage, August 2026. Every action was authorized.
A top-US-retailer shopping agent was chained to remote code execution straight through an LLM gateway with an intent-classification layer - and stayed unremediated past the 90-day window (Rein Security, Black Hat 2026).
Roblox presented multi-layer sandboxing plus behavioral monitoring of Claude Code as day-to-day enterprise practice at Black Hat 2026. Watching what agents actually do is no longer a research idea.
"One of the key questions for me now is trying to figure out how do we detect good agent behavior versus bad agent behavior?" - a sitting CISO, August 7, 2026 (Forbes). That question is this product.
Every inline control sees only the traffic that passes through it. FortLine captures behavior at the kernel and below the SDK - on and off the brokered path - so the same Dynamic Identity baseline covers containerized, serverless and MCP-speaking agents alike. No SDK, no code change.
Containerized and serverless agents, captured the same way.
The full agentic surface, including the tool-use layer prompt-firewalls never see.
Provider-agnostic by construction: we capture below the SDK, so any model works - even ones not on this list. A sample of what partners run:
eBPF DaemonSet or transparent gateway. Off the data path, by design.
FortLine maps to the OWASP Top 10 for Agentic Applications, with runtime behavioral evidence for the risks that show up in what the agent actually does - goal hijack, tool misuse, memory poisoning and rogue agents (highlighted below).
Start with free runtime visibility - we will baseline a mission and show you its Dynamic Identity. No SDK, no code change, off the data path.