
Rig Security Raises $12M to Track AI Agents Using Employee Accounts
Published by AINave Editorial • Reviewed by Ramit
Rig Security’s launch targets a problem that makes ordinary audit trails hard to interpret: when an AI agent uses an employee’s or service account’s credentials, its actions can appear to belong to that account holder. The Israeli startup launched with $12 million in funding to help enterprises identify those agents and control their activity.
The attribution problem comes before enforcement
A coding assistant or autonomous agent may operate under the identity of the developer or service account that started it. If an agent wipes a production database, the log may show the engineer’s account, leaving security teams unable to tell whether the person or the software acted. Blocking that identity could also stop the employee.
Rig’s Identity Correlation Engine uses machine-learning models to match identities across identity providers, cloud infrastructure and on-premises systems. The company says its matching is more than 96% accurate; the launch coverage does not give a validation method, so that figure is a vendor claim rather than an independently assessed benchmark.
Rig feeds the matches into a live graph showing which people, service accounts and agents have access to what. The platform also includes posture management and threat detection. The useful distinction is that Rig is trying to connect identity visibility to action: knowing an agent used an account matters more when a security team can respond without disabling the employee’s access altogether.
A sensor separates the agent’s session
Rig says a lightweight endpoint sensor separates an agent’s session from the user’s own and can stop a risky action before it leaves the machine. The company says the rest of the platform needs no installed software, while sensors can be rolled out after the platform is running. That makes the sensor the enforcement component, not a detail to overlook when assessing deployment.
Rig reports that Fortune 200 companies in financial services, insurance and health care run its software in production, and that it analyzes hundreds of millions of identity events and access signals each month. New American Funding is a named customer. Its assistant vice president of digital identity said the platform shows which agents are running and whose access they use, with control over agents that does not get in the employee’s way. These deployment and usage figures come from the company’s account of its product.
Funding and availability
Ten Eleven Ventures and Brightmind Partners co-led the seed round, with CrowdStrike participating as a strategic investor alongside cybersecurity founders and executives. Rig is available through the AWS Marketplace and CrowdStrike Marketplace.
The product’s central promise is narrower and more operational than simply discovering AI use: separate the agent’s actions from the human identity that authorized them, then intervene at the endpoint. How reliably that separation works in varied customer environments remains the key question behind Rig’s reported accuracy and production deployments.



















