“ I use Sagetap to explore initiatives for SaaS sprawl, and it surfaced vendors I hadn’t seen on sites like Gartner or Forrester. These were teams solving the problem in newer, more flexible ways. "

August 24, 2026
Developers were the first to make AI agents part of their everyday workflow. Security hasn’t made that same transition yet.
Major security platforms, until recently, generally did not offer official MCP servers. And when I randomly sample security practitioners I work with or know in the industry, relatively few seem to be working primarily through agents.
That surprises me because it has completely changed how I work, and I’ve started bringing that way of working into my own teams.
Imagine my world of application security. We might start with a static analysis finding. From there, an agent can pivot into our cloud environment to understand where the application is running and whether the vulnerable component is actually exposed. Then it can move into GitHub to inspect the code and configuration, understand how the application is deployed, and verify whether the finding is real and exploitable.
From there, it can pivot again and create a highly personalized Jira ticket for the development team, with the relevant code context, exposure information, evidence, and remediation guidance already included.
That kind of investigation traditionally meant opening several tools, gathering context from each one, and stitching the evidence together yourself. Something that could easily consume an hour can increasingly happen in minutes.
Once you start working this way, it changes what you look for in security products.
For years, vendors have invested heavily in making their products easier for humans to use: better interfaces, cleaner workflows, and experiences designed to make security tools more accessible. That work still matters. But I increasingly think the more important question is whether the product is easy for an agent to use.
I want every security provider to be API-first, MCP-first, and agent-first. APIs give us the building blocks, MCP makes those capabilities immediately accessible to agents, and an agent-first product assumes from the beginning that software, not just humans, will be one of its primary users.
We’re still early, but I think this is where security operations are heading. The security stack has always been fragmented. Agents finally give us an interface that can make that fragmentation feel much less visible.
Tool and strategies modern teams need to help their companies grow.
Join over 4,000+ startups already growing with Sagetap.