C1

C1

AI-native identity security platform

Overview

C1 provides an AI-native identity security platform unifying IGA, IAM, and PAM into one system. It manages human, non-human, and AI identities by automating access requests, provisioning, and reviews with dynamic and just-in-time controls and AI recommendations. The platform offers real-time visibility into permissions and integrates with many cloud apps and infrastructure through AI agents that automate identity operations. Its goal is to reduce identity sprawl, speed access decisions, and automate identity workflows so AI identities can outnumber human users while maintaining security.

About C1

Simplify's Rating
Why C1 is rated
B-
Rated B on Competitive Edge
Rated B on Growth Potential
Rated C on Differentiation

Industries

Enterprise Software

Cybersecurity

AI & Machine Learning

Company Size

51-200

Company Stage

N/A

Total Funding

N/A

Headquarters

San Francisco, California

Founded

N/A

Get referred to C1

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • June 15, 2026 Autonomous Worker automates reviews, revocations, and audit evidence immediately.
  • April 28, 2026 Wiz integration converts cloud findings into real-time entitlement revocations.
  • March 10, 2026 survey showed 95% of enterprises already run AI agents autonomously.

What critics are saying

  • Identity rivals like Okta, SailPoint, and Microsoft can copy agent governance fast.
  • C1's rebrand from ConductorOne risks brand confusion during enterprise buying cycles in 2026.
  • If agent identity standards fragment, C1's MCP and XAA bet loses relevance by 2027.

What makes C1 unique

  • June 18, 2026 EMA support gives C1 day-one control for Anthropic Claude agents.
  • May 6, 2026 Headless Identity Infrastructure unifies governance, vaulting, credentials, and authorization.
  • C1 models agents as governed identities, not side tools, across one policy engine.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Company Equity

Company News

MSSP Alert
Jul 21st, 2026
"Stop asking whether AI works and start asking what it can reach": C1 CISO on AI agent security.

"Stop asking whether AI works and start asking what it can reach": C1 CISO on AI agent security. July 21, 2026 AI agents are already inside the enterprise, often with access to business systems, data, and security tools. The problem is that many companies still do not have a clear view of where those agents are running, what they can reach, or who is responsible for their access. This is becoming an identity issue. Security teams have spent years managing access for employees, contractors, and applications. Now they have to account for agents that can act on their own, move between systems, and make decisions much faster than a person could. C1 CISO Kevin Paige says most CISOs understand the risk, but what they are missing is visibility. Many organizations know they have a growing number of non-human identities, but they cannot confidently say how many exist, what permissions they hold, or whether those permissions are still necessary. C1 is trying to address that gap by bringing people, workloads, and AI agents into an identity governance model. The company has also launched Autonomous Worker, an agent that handles some identity governance tasks itself. In this conversation with MSSP Alert, Paige talks about how companies should think about access for AI agents, where current identity programs are falling short, and how MSSPs and other partners can build services around discovery, access reviews, governance, and ongoing monitoring. MSSP Alert: What does C1 actually do, and why is identity suddenly such a big part of the AI agent conversation? Kevin Paige: C1 is an AI-native identity security platform. In plain terms, we govern access. Who can get into your most important systems, what they can do once they are in, and whether that access should still exist tomorrow. For years, that meant two populations, people and applications. Now there is a third one in the building, the AI agent, and it is the fastest-growing of the three. Identity moved to the center of the AI conversation for a simple reason. An agent is only as safe as what it is allowed to do. It does not matter how capable the model is if it is holding a standing credential in finance, IT, and customer data, and nobody is watching what it touches. The old question was who has access. The new question is what this agent can do, on whose behalf, and whether it is staying inside those lines. Agents act, decide, and move between systems at machine speed, so the cost of getting access wrong is far larger than it was when identities were just people and apps. C1 brings all three populations, people, workloads, and agents, into one place where you can see them and govern them. MSSP Alert: When you talk to CISOs, are they worried about AI agents having too much access, or are they still trying to figure out where these agents even exist? Kevin Paige: Both, but not in equal measure, and not in the order you would hope. The worry about too much access is real. Our 2026 Future of Identity Report found that 87% of security leaders now rate non-human identity risk as urgent, so the concern is there. The problem is that they cannot see the agents well enough to act on it. Only 22% say they have full visibility into their non-human identities. Agents are getting spun up by developers, by business teams, by SaaS tools that quietly shipped an AI feature last quarter, and almost none of it runs through a central identity process. So the honest state for most security leaders is that they know it matters, and they still cannot find all of it. You cannot govern what you cannot inventory, and right now, the inventory is the gap. The access problem sits downstream of a visibility problem, and the visibility problem is bigger than most teams think. MSSP Alert: C1 just launched Autonomous Worker, an AI agent doing identity governance work. If AI agents are creating new identity risk, how do you make sure the agent fixing identity problems does not become another identity problem itself? Kevin Paige: The honest answer is that the agent doing the governance has to live under the same rules as every other identity, and we built it that way on purpose. Our governance agents are modeled as regular users inside the platform. They get their own roles, their own permissions, their own entitlements, and they are subject to the same policies they enforce. The watcher is not above the system. It is an identity inside it. Underneath that, the controls are concrete. Each agent gets a finite, predefined set of tools, and if a task is not in its toolkit, it simply cannot do it. The core instructions are immutable, so an agent cannot be talked out of its own guardrails by clever input, which is how we defend against prompt injection. We separate the agents that can take action from the ones that read untrusted input, so the piece that can approve access never touches raw user text. Every action an agent takes is logged in detail and tagged as agent activity, and a human can be inserted at any point in the flow. The way we put it internally is that their work can be approved by humans, but humans no longer have to do the work itself. If our own governance agent could not be governed, we would have disproven our own product. So it is the most tightly scoped worker on the network, not the least. MSSP Alert: Your 2026 identity report says 95% of enterprises are already running AI agents autonomously. Are CISOs treating this like a real identity problem yet, or is it still sitting in the AI experimentation bucket? Kevin Paige: That number is the whole story, because it means the experiment is already over. When 95% of organizations are running agents that autonomously perform IT or security tasks, this is not a lab project. It is production, touching real systems and real data right now. And to your question, the awareness is actually there. In the same research, 87% of leaders called non-human identity risk urgent, and nearly half already run more non-human identities than human ones. So most CISOs are past denial. What they are missing is not belief, it is capability. They know it is real, they rate it urgent, and they still do not have the visibility or the controls to do much about it yet. That gap between knowing and doing is where the risk actually lives. The reframe I push is simple. Stop asking whether the AI works and start asking what it can reach. MSSP Alert: For partners, where does C1 fit in? Is this mainly a security sale, an identity governance sale, or a bigger services conversation around helping customers find and control non-human workers? Kevin Paige: It opens as a security conversation, because fear is what gets the meeting, but it lands as identity governance, and for partners the real prize is the services layer on top. Finding and controlling non-human workers is not a one-time project. Agents get created and retired constantly, their access drifts, and the population never stops moving. That is not something you install and walk away from. It is an ongoing discipline, and ongoing disciplines are exactly what partners are built to deliver. We frame it for partners as governing access across humans, workloads, and agents, and helping customers adopt AI securely and at speed. Whether a partner resells or refers, the durable framing is the same. You are the team that helps a customer find every non-human worker they did not know they had, decide what each one should be allowed to touch, and keep that true as the population changes week over week. The product underneath can be C1. The relationship on top belongs to the partner, and it renews. MSSP Alert: Where is the revenue opportunity for partners? Can they turn this into assessments, access reviews, governance projects, managed monitoring, or ongoing services? Kevin Paige: All of it, and the smart way to see it is a ladder, not a menu. The entry rung is the assessment. Every customer needs someone to walk in and answer a question they cannot answer themselves. How many non-human identities and agents do we actually have, and what can they reach? That discovery work is billable on day one, and it draws the map for everything that follows. From there it climbs. The map becomes access reviews and cleanup, which become standing governance projects, which become the real recurring revenue, ongoing identity security for the non-human population. And that annuity is bigger than the human side, because nearly half of enterprises already run more non-human identities than human ones, and agents churn far faster than employees, so the review-and-recertify cycle never ends. A partner who owns identity security for a customer's agents owns an engagement that grows every time that customer adds another one. That is the opportunity. Not a license resale. A permanent seat as the team that keeps the customer's non-human workforce under control. Suparna is the Senior Managing Editor for CyberRisk Alliance's Channel Brands, including MSSP Alert and ChannelE2E. She manages content development, sharpens editorial workflows, and ensures storytelling is tightly aligned with audience needs. With a background in technology, media, and education, she combines strategic insight with creative execution.

Associated Press
Jun 18th, 2026
C1 launches enterprise-managed authorization support for secure AI agent access control

C1, an identity security platform, has announced support for enterprise-managed authorisation, the open MCP standard for governing AI agent access to enterprise tools. Anthropic implemented the standard in Claude, with C1 supporting it from launch. The system allows users and agents to authenticate once to C1, which then issues short-lived, scoped tokens built on the Cross-App Access standard. This eliminates the need for separate logins for each tool, functioning like single sign-on for agents. C1's control plane enforces governance by setting session length, applying fine-grained scope and enforcing re-authentication policy. For applications outside the standard, including legacy systems, C1's Access Gateway provides the same governance and fine-grained tool-call enforcement. The company serves clients including Instacart, Ramp, Zscaler and Brex.

The Mirror Democrat and Savanna Times-Journal
Jun 18th, 2026
C1 announces enterprise-managed authorization support to drive secure AI transformation for the enterprise.

C1 announces enterprise-managed authorization support to drive secure AI transformation for the enterprise. * 4 hrs ago SAN FRANCISCO, June 18, 2026 (GLOBE NEWSWIRE) - C1, the identity security platform for the agentic enterprise, today announced support for enterprise-managed authorization (EMA), the open MCP standard for governing how AI agents access enterprise tools. Anthropic shipped the first implementation in Claude today. C1 supports it on day one, issuing the short-lived, scoped tokens that govern how Claude agents reach enterprise tools. Financing for AI Requires Creativity: Morgan Stanley's Cheng With EMA, users and agents authenticate once to C1. C1 then issues short-lived, scoped tokens, built on the open Cross-App Access (XAA) standard, that grant direct access to the MCP servers they're entitled to with no separate login for each tool. The experience works like single sign-on for agents. "Putting AI in front of every employee shouldn't mean scattering credentials across thousands of laptops," said Alex Bovee, CEO and co-founder of C1. "With enterprise-managed authorization, people authenticate once to C1 and every agent stays governed. The fastest path to AI adoption should be the safest one." Governance is enforced at the C1 control plane. C1 sets session length, applies fine-grained scope, and enforces re-authentication policy before an agent touches a system. Revoke an agent's access and C1 stops issuing tokens immediately. Because the tokens are short-lived, anything in flight expires within minutes. The standard covers the apps that support it. For everything else, including apps that don't, on-premises data, and legacy systems, C1's Access Gateway enforces the same governance and adds fine-grained tool-call enforcement, regardless of protocol. Enterprises pair the two and govern every connection from one control plane, with one entitlement model and one audit trail. That coverage lets enterprises put AI in front of every employee, governed from day one. Agents enter the same access reviews as people, get certified or revoked on the same schedule, and ride the same approval workflows. Every access decision lands in one audit trail. C1's support for enterprise-managed authorization is available now. To see governed AI deployment in action, book a demo at c1.ai. C1 empowers organizations to adopt AI securely and at speed by delivering the right access and governance to every human, workload, and agent. Companies like Instacart, Ramp, Zscaler, and Brex trust C1 to accelerate AI adoption with confidence.

Associated Press
Jun 15th, 2026
C1 launches AI agent to automate enterprise identity governance tasks

C1, an AI-native identity platform, has launched C1 Autonomous Worker, a governed AI agent for enterprise identity governance. The agent can execute tasks such as revoking stale admin grants, building access reviews and pulling audit evidence without human intervention. Available now to all C1 customers through Slack, the agent operates within existing permission frameworks and logs all actions in C1's audit trail. Every action is governed by the same policy engine that controls human users, ensuring agents can only perform tasks their operators are authorised to execute. CEO Alex Bovee said the company is building towards autonomous workers running inside enterprises, with C1 serving as the identity control plane. C1's customers include Instacart, Ramp, Zscaler and Brex.

Recently Posted Jobs

Sign up to get curated job recommendations

C1 is Hiring for 13 Jobs on Simplify!

Find jobs on Simplify and start your career today

Don't see your dream role? Check out thousands of other roles on Simplify. Browse all jobs →