More on the topic...
Generating detailed summary...
Failed to generate summary. Please try again.
Enterprises building AI agents still lean heavily on no-code workflow tools that mix predefined actions with LLM-driven steps. But these platforms rarely deliver truly self-governing agents—they require users to map out flows in advance and plug in code where needed. In this second annual report, Andrew Green zeroes in on what makes an “enterprise-grade agent” secure and auditable. He separates authentication for human users (SSO, MFA via the company’s identity provider) from agent-level auth (API keys, JWTs, mTLS). Only Google, Langflow, Workato, CrewAI, Sim.ai and Gumloop provide full credential-passing when agents call third-party systems. Fewer still—about half—offer any sandbox for running untrusted, LLM-generated code, and most of those outsource sandboxing to third-party services like E2B.
Lineage—tracing every agent action back to a real person—and robust secrets management barely exist across the market. Only Google, Workato and Gumloop earned any lineage scores; Google, Sim.ai and Gumloop scored highest on secrets handling. A handful of vendors (notably Google and Gumloop) bundle proxy-based filtering, policy definitions, attribute-based tool access, auth, lineage and secrets management into a coherent package. Others tack on LLM-based “evaluations” to flag PII or factual errors, then route flagged content through secondary agents or regex-style handlers. Those approaches blur the line between rule-driven security and probabilistic LLM checks.
On integration and extensibility, most platforms implement both host/client MCP (multi-agent communication protocol) roles, though Google’s proprietary agent-to-agent protocol shows up only at Google, CrewAI, Retool and Sim.ai. Citizen-developer pitch aside, real users write code. Yet no single vendor excels at both executing human-written scripts and safely running LLM-generated code. This year’s additions—filesystem-access metrics and an explicit sandbox requirement—highlight emerging gaps. Finally, the report notes that whether a tool was born AI-native or pivoted from workflow automation no longer dictates its security posture; feature sets matter more than pedigree.
Questions about this article
No questions yet.