Tap any grade for its evidence.
Coding agents & IDEs
Claude Code
OpenAI Codex CLI
GitHub Copilot
Lovable
Replit
Devin AI
Kiro
Cursor
Devin Desktopformerly Windsurf · Cognition
Gemini Code Assist
Enterprise chat & knowledge
Claude Cowork
Claude (Team & Enterprise)Anthropic
ChatGPT Enterprise
Glean
Google Gemini (chat app)
Microsoft 365 Copilot
Microsoft 365 Copilot CoworkGA Jun 2026
Notion AI
Slack AI
Atlassian Rovoexcludes Rovo Dev
Perplexity Enterprise
Agent platforms
Salesforce Agentforce
Copilot Studio
Microsoft Foundry
Amazon Bedrock AgentCore
Gemini Enterprise Agent Platform
Databricks Unity AI Gateway
ServiceNow AI Agentsgraded at Prime tier
Snowflake Cortex Agents
| Product | Model routing | Tools & connectors | Guardrails | Agent-to-agent | Live logs | Log contents | Containment | Data boundary | Agent identity |
|---|---|---|---|---|---|---|---|---|---|
| Coding agents & IDEs | |||||||||
| Claude Code | |||||||||
| OpenAI Codex CLI | |||||||||
| GitHub Copilot | |||||||||
| Lovable | |||||||||
| Replit | |||||||||
| Devin AI | |||||||||
| Kiro | |||||||||
| Cursor | |||||||||
| Devin Desktopformerly Windsurf · Cognition | |||||||||
| Gemini Code Assist | |||||||||
| Enterprise chat & knowledge | |||||||||
| Claude Cowork | |||||||||
| Claude (Team & Enterprise)Anthropic | |||||||||
| ChatGPT Enterprise | |||||||||
| Glean | |||||||||
| Google Gemini (chat app) | |||||||||
| Microsoft 365 Copilot | |||||||||
| Microsoft 365 Copilot CoworkGA Jun 2026 | |||||||||
| Notion AI | |||||||||
| Slack AI | |||||||||
| Atlassian Rovoexcludes Rovo Dev | |||||||||
| Perplexity Enterprise | |||||||||
| Agent platforms | |||||||||
| Salesforce Agentforce | |||||||||
| Copilot Studio | |||||||||
| Microsoft Foundry | |||||||||
| Amazon Bedrock AgentCore | |||||||||
| Gemini Enterprise Agent Platform | |||||||||
| Databricks Unity AI Gateway | |||||||||
| ServiceNow AI Agentsgraded at Prime tier | |||||||||
| Snowflake Cortex Agents | |||||||||
How to read this
- You own it
- Enforcement runs on infrastructure you control: your identity provider, your gateway, your cloud account, your endpoint fleet, your network.
- The vendor owns it
- A real control exists, but it runs in their console and they enforce it for you.
- Nobody owns it
- No control on this surface, or none you can reach.
- Security gap
- No control surface exists at all. Different from the row below: this one is a finding.
- Does not apply
- The surface is not part of how this product is built, so there is nothing to govern. Not a gap.
Tap any grade for the reasoning and the vendor documentation behind it. Every receipt carries its tier, when we last checked the page, when the document was published, and the sentence the grade rests on.
A small dot on a grade means the control is not necessarily switched on. The grade answers “if you turn this on, whose infrastructure enforces it?” The dot answers “is it on?”, which is a property of your deployment and something this map cannot see.
The full rubric for each column, the evidence-tier policy and the absence protocol are in the methodology. Every grade that has ever moved is in the changelog.
One agent. 3 of 7 domains in its containment path.
9 of 29 products sit at this depth. 11 run deeper.
In every product
- Human identity (IdP)29 of 29
- Product admin plane29 of 29
The other 5. None in more than 13 of 29.
- Network13 of 29
- Gateway credential9 of 29
- Endpoint / EDR9 of 29
- Cloud control plane5 of 29
- Data platform2 of 29
Check another product. Fewest domains to most.
Two domains are not optional: the identity provider, and the vendor’s own admin console. Every one of the 29 products runs through both. After that there is no pattern. The next most common domain appears in 13 of 29, so which other team you need is a property of the product, not of your programme. 20 of 29 products reach past those two.