Enterprise identity security is expanding beyond employee passwords as companies contend with machine credentials, privileged accounts and increasingly autonomous AI agents. Keeper Security has received top-tier evaluations from GigaOm and Information Services Group (ISG) in the same week, putting its password management and identity security technology into a broader conversation about how enterprises should govern human and non-human identities.
The password manager is becoming a very different piece of enterprise security infrastructure.
As organizations add cloud workloads, service accounts, applications and AI agents, the number of identities requiring authentication and authorization is growing well beyond employees. That is pushing identity and access management (IAM) vendors to expand from traditional user access into privileged access, secrets management and non-human identity governance.
Keeper Security is positioning itself squarely in that transition.
The company said this week that GigaOm named it a Leader in the Enduring Innovators quadrant of its Enterprise Password Management Radar, while ISG classified Keeper as an Exemplary Provider in its 2026 Buyers Guide for Identity and Access Management Platforms.
The two evaluations examine different parts of the identity market, making the combined recognition notable. GigaOm focused on enterprise password management, while ISG assessed broader IAM capabilities across authentication, authorization, identity lifecycle management and access governance.
ISG evaluated 31 IAM providers, with Microsoft, AWS and Oracle ranked as the top three overall leaders. Keeper was among the providers classified as Exemplary, alongside major vendors including AWS, CyberArk, Google Cloud, IBM, Microsoft, Okta, Oracle, SailPoint and SAP.
That competitive context matters. Keeper is not competing only against password-management specialists. Its expansion into identity security puts it against established IAM, privileged access management and cybersecurity vendors with much larger enterprise footprints.
The company’s strategy is to bring several identity-security functions into a unified architecture.
At the foundation is Keeper Password Manager, which provides a zero-knowledge credential vault for passwords, passkeys and secrets. Keeper’s broader identity security platform extends into privileged access management and endpoint privilege management, while KeeperAI adds AI-assisted threat detection around privileged sessions.
GigaOm’s assessment highlighted Keeper’s secrets management capabilities, its Model Context Protocol (MCP) server and its approach to agentic and non-human identity governance. The report’s broader finding reflects an important shift in enterprise security: organizations increasingly need to manage credentials belonging not only to people but also to software, workloads and autonomous systems.
That trend is being reinforced by the rise of AI agents.
An AI agent that can access databases, cloud infrastructure or business applications effectively becomes another identity inside the enterprise. Giving such an agent credentials without appropriate lifecycle controls, permissions and monitoring creates a new attack surface.
ISG’s separate 2026 research on non-human identity management makes the issue explicit. It describes machine identity management as an emerging cybersecurity discipline because applications, services, workloads, devices and AI agents are creating identities at increasing scale. Traditional IAM and PAM approaches are not necessarily designed for their dynamic lifecycles and autonomous behavior.
That changes the role of identity security.
Historically, IAM systems focused on questions such as who an employee is, how they authenticate and which applications they can access. The emerging model has to answer additional questions: What software is acting? What credentials does it possess? What infrastructure can it reach? How long should access remain active? And what happens when an AI agent begins making decisions or requests access on behalf of a human?
Keeper’s emphasis on both human and non-human identities is designed to address that convergence.
The company’s two analyst recognitions also illustrate how the identity market is fragmenting—and then beginning to recombine.
Organizations often assemble security stacks from separate password managers, IAM platforms, privileged access management systems, secrets-management products and endpoint privilege tools. That can create operational complexity and gaps between systems.
Keeper cites research showing that 40% of organizations operate four or more disconnected identity products or platforms. Its own research claims 96% of cybersecurity decision-makers believe disconnected tools create exploitable gaps. Those figures should be viewed as vendor-sponsored research rather than independent market measurements, but the underlying problem is consistent with the direction of analyst research.
ISG recommends that enterprises evaluate IAM platforms on unified identity lifecycle management, strong authentication, consistent access governance, adaptive controls, integration, auditability and scalability. It also recommends examining AI-enabled risk analysis and lifecycle automation.
The implication for IT and security teams is straightforward: buying another point product may solve an immediate problem while making the overall identity architecture harder to manage.
But consolidation is not automatically better.
A unified platform can simplify administration and reduce the number of integrations security teams must maintain. At the same time, enterprises need to determine whether a vendor’s capabilities are deep enough in each category to replace specialist products. Identity is a foundational security layer, so migration mistakes can have consequences far beyond an ordinary software deployment.
Keeper’s challenge will therefore be proving that its breadth translates into measurable security and operational benefits.
Its competitive field includes Microsoft Entra, Okta, CyberArk, SailPoint, BeyondTrust, Delinea, AWS and Google Cloud, among others. These vendors approach identity from different starting points: workforce IAM, privileged access, identity governance, cloud infrastructure or cybersecurity.
The market is increasingly blurring those boundaries.
Microsoft, AWS and Google Cloud are embedding identity controls into broader cloud and enterprise ecosystems. CyberArk has built a major position around privileged and machine identity security. Okta remains a major workforce and customer identity provider. SailPoint focuses heavily on identity governance. Keeper’s differentiation is its attempt to connect credential management with privileged access, secrets and emerging agentic identities within one architecture.
For enterprise buyers, that makes evaluation criteria more important than vendor recognition.
Security teams should examine how platforms handle passkeys, privileged credentials, secrets, service accounts, API access, machine identities and AI agents, rather than evaluating password management as an isolated requirement.
They should also test integration with existing IAM, security information and event management (SIEM), endpoint and cloud security infrastructure.
The broader market is moving in that direction. ISG’s 2026 IAM research describes IAM as a strategic security control layer across cloud, hybrid and partner environments rather than simply a directory-management function.
Keeper’s latest analyst recognition therefore arrives at a useful moment for the industry.
The important development is not simply that a password-management vendor received strong analyst scores. It is that password management, privileged access and non-human identity governance are increasingly being treated as parts of the same enterprise security problem.
As AI agents become active participants in business workflows, the definition of “user” will continue to expand.
The identity platforms that can govern that new population without creating another collection of disconnected security tools could become increasingly important to enterprise security architecture.
Market Landscape
Enterprise IAM is undergoing a structural shift from employee authentication toward unified identity security spanning people, applications, machines and AI agents.
ISG’s 2026 IAM Buyers Guide evaluated 31 providers, with Microsoft, AWS and Oracle leading the overall rankings. Keeper was among 13 providers rated Exemplary.
At the same time, ISG’s dedicated non-human identity research evaluated 20 providers and identified Microsoft, Saviynt and CyberArk as the highest-ranked vendors overall.
That split illustrates the competitive landscape. No single category currently owns the entire identity problem.
The major market forces include:
- AI agents: Autonomous systems increasingly require credentials and permissions.
- Non-human identities: Applications, workloads, APIs and services can outnumber human users.
- Zero-trust security: Enterprises are moving toward continuous verification and least-privilege access.
- Secrets management: API keys, service credentials and application secrets require centralized governance.
- Platform consolidation: Security teams are seeking fewer disconnected tools where consolidation does not sacrifice functionality.
- Cloud identity: Hybrid and multicloud environments require identity controls that operate across infrastructure boundaries.
For HR and workforce technology teams, the implications are also growing. Employee identity is increasingly connected to onboarding, offboarding, application provisioning, privileged access and workforce automation. The identity layer is consequently becoming part of the broader digital workplace infrastructure.
Top Insights
- Keeper Security received strong GigaOm and ISG evaluations as enterprise identity management expands beyond employee passwords into secrets, privileged and machine identities.
- ISG’s 2026 IAM research places Keeper among Exemplary providers while Microsoft, AWS and Oracle lead the broader enterprise IAM category.
- AI agents are creating new non-human identities that require credentials, permissions, lifecycle management and continuous monitoring across enterprise environments.
- Keeper competes with Microsoft, Okta, CyberArk, SailPoint and cloud providers, making platform breadth and integration increasingly important enterprise buying criteria.
- Identity security is moving toward unified governance for people, machines and AI agents as organizations seek to reduce fragmented security architectures.
Join thousands of HR leaders who rely on HRTechEdge for the latest in workforce technology, AI-driven HR solutions, and strategic insights





