Bot and Agent Trust Management Software: The 2026 Landscape

Table of Contents

1. Frame

In June 2026 Forrester renamed a market category. "Bot Management" – ten years of blocking scrapers and credential-stuffing bots – became "Bot and Agent Trust Management" (Carielli 2026). The rename is not cosmetic. It marks the point at which the traffic a website receives stopped splitting cleanly into humans and attackers, and started including a third class: automated clients acting with authority, on someone's behalf, that the origin server needs to admit rather than block.

This note surveys the software built for that third class in 2026: what shipped, who bought whom, which protocols reached v1.0, and which pieces of the stack – discovery, signing, registration, revocation – still have no agreed answer. It is a product survey. Where this site already has framework-level work on the same territory, this note links out rather than repeating it: identity/attestation theory lives in Agent Identity and Attestation, this site's own bot-compliance contract lives in the Walsh-Research spec, and the open mathematical problem of typing a trust boundary lives in Trust Boundaries as a Typed Category.

2. The category gets a name

Forrester's Q2 2026 Wave evaluates vendors on Current Offering, Strategy, and Customer Feedback, and it frames the market shift explicitly: "the market is evolving from a security-first mindset to a trust-first model," moving away from "block bots" toward "enable trusted automated traffic" (Carielli 2026). DataDome and HUMAN Security are named Leaders; DataDome takes the highest published Current Offering score, 4.12 out of 5. Arkose Labs is named a Strong Performer.

:CUSTOM_ID: forrester-wave-q2-2026-rename :VERIFIED_AT: 2026-09-27T20:00:00Z :VERIFIED_BY: claude-research-agent :VERDICT: attributed :FINDING: Forrester's own blog (fetched directly) confirms the category rename and June 15, 2026 publication date, authored by Sandy Carielli. Vendor scores (DataDome 4.12/5 Current Offering) and Leader/Strong-Performer placements are attributed from DataDome's and HUMAN Security's own press summaries of the report, since the report itself sits behind Forrester's paywall (direct fetch returned 403). The full vendor list – who else is a Contender – was not independently confirmed.

The vendors named are worth reading against each other, not just as a list. DataDome and HUMAN Security both sell request-level bot detection – JavaScript fingerprinting, behavioral signals, network-layer reputation – and both have shipped an agent-specific product line in 2026 (DataDome Agent Trust, HUMAN AgenticTrust). Cloudflare and Akamai, the two largest CDN-layer bot-management incumbents, are not confirmed Leaders in this particular report from the sources checked, but both shipped agent-trust features on their own timeline in 2026 – see below.

3. Traffic layer: detecting and admitting agents, not just blocking bots

3.1. Cloudflare: Web Bot Auth and Verified AI Agents

Cloudflare's approach is cryptographic signing at the HTTP layer rather than behavioral fingerprinting. Web Bot Auth has an agent sign every outbound request with a private key; the public half sits at a well-known URL; the edge verifies the signature per RFC 9421 (HTTP Message Signatures) (Cloudflare 2026). On June 2, 2026, Cloudflare shipped a "Verified AI Agent" bot-management category built on this mechanism. Nineteen agents were verified at launch – ChatGPT Atlas, Claude in Chrome, Perplexity Browser, Gemini Agent Mode, Brave Leo, Arc Browse for Me among them – covering an estimated 84% of identified AI-browser traffic by Cloudflare's own measurement (Cloudflare 2026).

The harder problem Web Bot Auth exposed is key discovery: an origin can verify a signature only if it can find the signer's public key. Cloudflare's answer, an open registry format published October 30, 2025, predates the Verified AI Agent launch by seven months and solves exactly this – a "Signature-Agent" header points to a metadata card (contact, logo, crawl rate, keys), structurally similar to how robots.txt names a crawler (Cloudflare 2025). Amazon Bedrock AgentCore adopted the registry for its own key-signing; Vercel, Shopify, and Visa are named early Web Bot Auth implementers (Cloudflare 2025).

:CUSTOM_ID: cloudflare-webbotauth-registry-dates :VERIFIED_AT: 2026-09-27T20:00:00Z :VERIFIED_BY: claude-research-agent :VERDICT: corrected :FINDING: An initial search summary dated the Cloudflare registry format to "February 2026 in collaboration with Amazon Bedrock AgentCore." Direct fetch of the primary source (blog.cloudflare.com/agent-registry/) gives the actual publication date as 2026-10-30 – which is 2025, not 2026, and precedes the Verified AI Agent launch rather than following it. Corrected in the text above; treat any secondhand summary of vendor timelines in this space as needing a primary-source check, not just a second search.

This site's own bot-attestation work already named the shape of this problem before Web Bot Auth's registry shipped: the four-tier attestation model in the Walsh-Research spec puts "UA + policy URL" at tier 2 and cryptographic signing at tier 4, and the wal.sh access-log study underlying that spec found tier-2 conventions covering roughly 95% of observed bot traffic by volume, with tier 4 nearly unobserved in the wild as of May 2026. Web Bot Auth's registry is the missing piece that makes tier 4 operationally reachable at scale: a discovery layer for the keys, not just the signing mechanism itself.

3.2. DataDome and HUMAN Security

DataDome's 2026 State of Bot and Agent Security report claims 7.9 billion AI agent requests observed in early 2026 across its customer base, feeding a detection engine it describes as processing five trillion signals daily. HUMAN Security, which absorbed the bot-management vendor PerimeterX in 2022, ships AgenticTrust as its 2026 agent-specific product line, leaning on JavaScript-side behavioral signals (mouse movement, scroll pattern, keystroke dynamics) where Akamai leans harder on network-layer signals (TLS fingerprint, ASN history, request timing).

:CUSTOM_ID: datadome-human-akamai-figures :VERIFIED_AT: 2026-09-27T20:00:00Z :VERIFIED_BY: claude-research-agent :VERDICT: needs-citation :FINDING: The 7.9B-request and 5-trillion-signals-daily figures come from DataDome's own marketing/press page, which returned HTTP 403 on direct fetch; they are relayed here via a search-engine summary of that page, not independently verified against the primary document. Treat as vendor-claimed, not audited.

3.3. Akamai

Akamai's public framing for 2026, "Bot Management for the Agentic Era," argues for keeping agent traffic in the same detection pipeline as adversarial bot traffic rather than building a parallel agent-only product, on the grounds that an agent acting on stolen credentials looks identical to a credential-stuffing bot at the network layer. This is the one vendor position among the four Forrester-adjacent incumbents that treats "agent" as a traffic pattern rather than a new identity primitive.

4. Identity layer: enterprise IAM extends to agents

Bot management answers "is this request automated, and by whom." Identity and access management answers a different question: "does this agent hold a credential this system should honor." 2026 is the year the two questions collided inside the same enterprise stack.

4.1. Okta Agent SSO and Cross App Access

Okta's Agent SSO reached general availability on August 24, 2026, built on Cross App Access (XAA), a protocol built as an OAuth extension and subsequently incorporated as an MCP authorization extension (Okta 2026). The mechanism: register an agent as a first-class identity in Okta's Universal Directory, and issue it short-lived, governed tokens in place of the static API keys agents have historically carried. XAA supports native integrations across more than 25 cloud, developer, and enterprise SaaS platforms as of the GA date. Auth0, under the same corporate umbrella, ships a parallel developer-facing surface: Auth for MCP, "Agent as Principal," On-Behalf-Of token exchange, and a Token Vault, aimed at LangChain/LlamaIndex/Vercel-AI-SDK-style application code rather than workforce SSO.

:CUSTOM_ID: okta-agent-sso-ga-date :VERIFIED_AT: 2026-09-27T20:00:00Z :VERIFIED_BY: claude-research-agent :VERDICT: corrected :FINDING: An initial search pass returned "April 30, 2026" for Agent SSO's GA date, sourced from a secondary blog summarizing Okta's own newsroom page. A second, independent search of Okta's press coverage converged on August 24, 2026 across four independent outlets (startwithidentity.com, techjacksolutions.com, quasa.io, Okta support docs). Used the later, corroborated date.

4.2. MCP's own authorization spec catches up

The Model Context Protocol – the interface this note's own subject matter increasingly runs over – shipped its largest authorization revision to date on July 28, 2026 (Model Context Protocol 2026). MCP servers are now formally OAuth 2.1 resource servers. Three hardening measures matter for a trust-management reading of the spec: servers must implement OAuth 2.0 Protected Resource Metadata (RFC 9728) so a client can discover the right authorization server automatically; clients must implement Resource Indicators (RFC 8707), naming which MCP server a token is scoped to, closing the class of attack where a malicious server captures a token meant for a different server; and authorization servers must return an iss claim (RFC 9207) that the client validates before redeeming a code, closing an authorization-server mix-up hole. Dynamic Client Registration – the mechanism by which an MCP client previously obtained an OAuth client ID without a human registering it by hand – is deprecated in favor of Client ID Metadata Documents (CIMD).

Every product in the "MCP gateway" category that follows – Kong AI Gateway, Amazon Bedrock AgentCore Gateway, Microsoft MCP Gateway, Docker MCP Gateway, IBM ContextForge, and smaller entrants like NeuralTrust TrustGate and MintMCP – exists to sit in front of this spec and centralize what it otherwise leaves to each client's config: authentication, per-tool scoping, and audit logging across every MCP server an organization runs.

5. Non-human-identity consolidation

A parallel product category, "non-human identity" (NHI) security – discovering and governing the API keys, service accounts, and OAuth tokens that let software rather than people authenticate – absorbed three acquisitions in the two months from May to June 2026, each folding a standalone NHI vendor into a larger security platform:

Date Acquirer Target Deal size
2026-05-04 Cisco Astrix Security ~$400M
2026-06-29 SailPoint Entro (closed) ~$129.9M
2026 (announced) Cyera Oasis Security ~$1B

:CUSTOM_ID: nhi-consolidation-2026 :VERIFIED_AT: 2026-09-27T20:00:00Z :VERIFIED_BY: claude-research-agent :VERDICT: attributed :FINDING: Cisco/Astrix date and figure from Calcalistech and Industrial Cyber press coverage. SailPoint/Entro closing date and cash+stock breakdown ($122.6M cash + $7.3M restricted stock = $129.9M) from SailPoint's own SEC Form 10-Q filing (sail-20260731.htm). Cyera/Oasis from SecurityWeek; as of the most recent search, this deal was reported as an agreement/LOI rather than a closed transaction – treat the $1B figure as the announced deal size, not a confirmed final price.

The pattern is consistent with the identity layer above: none of these three built an AI-agent product from scratch. Astrix, Entro, and Oasis were all NHI-discovery vendors from before the agent wave (their original problem was API keys and service accounts sprawling across SaaS and cloud). All three extended into "agent identity" discovery and policy as AI agents became the fastest-growing class of non-human identity, and all three were acquired by platforms (Cisco, SailPoint, Cyera) that wanted that capability rather than building it. This is the standard pattern for a category maturing under pressure: point-solution vendors prove the wedge, platform vendors buy the wedge.

6. Agent registries and catalogs

A registry answers "what agents, tools, and MCP servers exist in this organization, who owns each, and is it approved." Four enterprise platforms shipped one in 2026:

Platform Vehicle Status as of 2026-Q3
AWS Agent Registry (Bedrock AgentCore) Public preview, 2026-04-13 (Amazon Web Services 2026)
Google Cloud Agent Registry + Agent Gateway (Gemini Enterprise) GA 2026-04-22 (Google Cloud 2026)
Microsoft Agent 365 Registry (Entra/Defender/Intune) GA 2026-05-01 (Microsoft 2026)
Salesforce MuleSoft Agent Registry + Trusted Agent Identity GA components through 2026-06 (Salesforce 2026)

All four converge on the same shape: a searchable catalog (keyword or semantic), an approval workflow (draft to pending to approved), and an audit trail. AWS's registry is itself queryable as an MCP server, so any MCP-compatible client can search it directly. Microsoft's recognizes more than twenty kinds of local agent, including coding agents and MCP servers themselves, and feeds discovered-but-unmanaged agents into Defender, Conditional Access, and Purview as first-class identities via Entra Agent ID. None of the four interoperates with the others: an agent registered in AWS's registry is not visible in Google's, and vice versa. The registries solve organizational sprawl; they do not solve cross-organization discovery – that problem is what the protocol layer below is trying to answer.

7. Cross-agent trust protocols: A2A, AP2, and the discovery problem

Registries govern what one organization knows about its own agents. A2A (Agent2Agent), the protocol Google open-sourced in April 2025 and handed to Linux Foundation governance two months later, governs what one organization's agent can prove to a different organization's agent it has never talked to before. Version 1.0, shipped March 12, 2026, formalizes Signed Agent Cards: a cryptographic signature (JWS, RFC 7515, with JCS canonicalization, RFC 8785) over the Agent Card, so a receiving agent can verify the card was actually issued by the domain it claims (Linux Foundation / A2A Project 2026). More than 150 organizations, including Microsoft, AWS, Cisco, Salesforce, SAP, and ServiceNow, are named as A2A supporters by mid-2026.

Agent Payments Protocol (AP2), announced by Google in late 2025 as an extension of A2A and MCP, addresses the narrower and higher-stakes case of an agent initiating a payment on a human's behalf, with more than 60 partners including Mastercard, PayPal, American Express, and Coinbase (Google Cloud 2025). Security research on AP2 published mid-2026 identifies a specific failure mode worth naming precisely: a "whisper attack," in which the transaction an agent signs and the decision a human approved diverge, because the signature binds the transaction payload but not the natural-language decision context that produced it. The proposed defense binds the two cryptographically rather than relying on the checkout screen showing the same numbers twice.

:CUSTOM_ID: a2a-v1-date-discrepancy :VERIFIED_AT: 2026-09-27T20:00:00Z :VERIFIED_BY: claude-research-agent :VERDICT: disputed :FINDING: Secondary sources disagree on the A2A v1.0 date: one search summary cited April 9, 2026 under Linux Foundation governance; the protocol's own site (a2a-protocol.org/latest/announcing-1.0/) redirects to a URL slug dated 2026-03-12. Used the primary-source-adjacent date (the project's own URL) over the secondary summary, but flagging as disputed rather than resolved – did not find a dated changelog or git tag to break the tie definitively.

At the protocol layer, three separate mechanisms now claim a piece of "how does an agent prove who it is to a stranger": A2A's Signed Agent Cards (domain-bound, JWS), Web Bot Auth's Signature Agent Cards (per-request-signed, registry-discoverable), and – as of the next section – DNS records themselves. None of the three specifications reference each other's card format as of this writing.

8. DNS as the identity substrate

The Linux Foundation took a fourth position on discovery entirely: use DNS, which already exists, rather than inventing a new registry. On June 23, 2026 it announced intent to launch the Agent Name Service (ANS), a federated, DNS-anchored identity and discovery layer for agents, backed by GoDaddy, Cloudflare, Cisco, Salesforce, and Infoblox among others (Linux Foundation 2026b). Alongside it, the Linux Foundation launched DNS-AID as an open-source project (originated at Infoblox): publish an SVCB record for an agent in a domain's DNS zone, sign the zone with DNSSEC, and any resolver – not a proprietary registry – can discover and verify it (Linux Foundation 2026a). The pitch is explicit about the alternative it is rejecting: "no proprietary namespace and no gatekeeper," a direct contrast with a per-vendor agent registry (AWS's, Google's, Microsoft's) that only that vendor's tooling can query.

DNS-as-identity has an existing failure-mode literature to draw on before adopting it uncritically. The Cloud Security Alliance published a security analysis of the closely related Agent Name Service concept (a distinct, earlier proposal under the same acronym, IETF draft draft-narajala-ans-00) flagging DNS cache poisoning, DNSSEC misconfiguration, and registrar-level takeover as inherited risks – the identity layer becomes only as trustworthy as DNS's own decades-old threat model, which was not designed for machine-to-machine authorization.

9. Verifiable credentials and the "agent passport" metaphor

A smaller and more speculative line of work applies W3C Decentralized Identifier (DID) and Verifiable Credential (VC) standards directly to agents: a credential, cryptographically signed by an issuer, that an agent presents to a verifier without a centralized identity provider in the loop. Indicio's ProvenAI is the concrete 2026 example, issuing VCs that carry an agent's capabilities, authorizations, and provenance, framed by the vendor as a "digital passport for AI agents" (Indicio 2026).

:CUSTOM_ID: agent-passport-metaphor-caution :VERIFIED_AT: 2026-09-27T20:00:00Z :VERIFIED_BY: claude-research-agent :VERDICT: speculative :FINDING: "Agent passport" is marketing language for the direction of the work, not the name of a ratified standard – multiple independent sources converge on exactly this caveat (Popular AI's coverage states it outright). No production deployment at meaningful scale was found beyond Indicio's own travel-industry pilot messaging; basis for including it here is that it is the clearest concrete instance of W3C VC applied specifically to agent identity, not that it is production-proven.

10. Standards bodies convening

Two standards bodies opened formal tracks on agent trust in 2026, on different timelines and with different scope. NIST's Center for AI Standards and Innovation (CAISI) launched an AI Agent Standards Initiative on February 17, 2026, organized around three pillars – industry-led standards, open-source protocol development, and security/identity research – with the NCCoE's concept paper proposing a demonstration project built on OAuth 2.0, SPIFFE/SPIRE, and MCP (NIST / CAISI 2026). The ITU-T's Focus Group on Trust and Identity for Humans and Agentic AI (FG-TIDA) was established by Study Group 17 in June 2026 and announced publicly on July 9, 2026 at the AI for Good summit; its scope is explicitly broader than identity alone – "whether, and under what conditions, that entity should be trusted to act" – and its first meeting is scheduled for Paris in November 2026, with a second in Geneva in January 2027 (ITU-T SG17 2026). Neither body has produced a ratified standard as of this writing; both are convening working groups, not shipping software, which is why neither appears in the product sections above.

11. Where this leaves Walsh-Research's own attestation tiers

Agent Identity and Attestation places this site's own compliance harness at tier 3 of a five-tier attestation model (0 undeclared, through 4 third-party audited), with the gap to tier 4 being independent audit rather than self-operated testing. The vendor landscape surveyed here is not directly comparable rung-for-rung – Forrester's Wave audits a vendor's product capability to classify and admit agent traffic, not a bot operator's published behavioral contract – but the axes rhyme. A bot operator publishing a Web Bot Auth signature and appearing in Cloudflare's public registry is doing, for its own outbound traffic, roughly what tier 4 asks of a compliance spec: a claim that a third party (Cloudflare, the registry) can independently verify rather than merely relay. None of the identity-layer or registry products surveyed here audit an inbound bot's stated compliance with a published contract the way the Walsh-Research spec does; they audit whether the request carries a valid credential at all. The two problems – "is this credential valid" and "is this operator's behavior what it claims" – remain separately solved.

12. What the vendor landscape doesn't cover

Trust Boundaries as a Typed Category argues that no existing formalism bounds the free-text channel an LLM emits, and that "unified control plane" claims from platform vendors are functorial on objects only – they unify what an agent is, not the leakage properties of what it says. Every product surveyed in this note is squarely on the objects side of that line: registries catalog agents, Web Bot Auth and A2A sign requests and cards, IAM products issue and scope tokens. None of them types the operating-point class (volume, request rate, per-individual versus aggregate risk, fan-out) of what an agent actually does once admitted, and none bounds what it says. A verified, signed, registry-listed agent is fully compatible with an unbounded free-text information leak on its very first authorized action. Trust management, as the 2026 product category defines it, answers "should this request be admitted," not "what happens after it is."

A second, narrower gap: How We Contain Claude: Mapping Against the Stack identifies secret-custody as the empty cell in agent sandbox architecture – vendors sell the compute boundary and leave egress and credential custody to a config the operator may never write. Everything surveyed in this note is identity and admission control, upstream of where an agent runs; none of it substitutes for the containment boundary once a credentialed, trusted agent is executing arbitrary instructions inside an environment. A well-signed Web Bot Auth request and a sandboxed execution environment answer two different questions, and 2026's product wave answers only the first.

13. Open questions

  • No reconciled discovery layer. A2A Signed Agent Cards, Web Bot Auth Signature Agent Cards, and DNS-AID/ANS SVCB records are three live, differently-shaped answers to "how does a stranger find and verify this agent's key." As of 2026-Q3 none defers to the others.
  • Registry fragmentation is the current default, and no roadmap checked here treats it as temporary. AWS, Google, Microsoft, and Salesforce each shipped an agent registry in 2026 that only its own tooling queries. Cross-platform agent discovery inside a single enterprise that runs more than one of these platforms is unsolved by any product surveyed here.
  • NHI consolidation concentrates, rather than diversifies, who audits agent identity. Three formerly-independent NHI vendors were folded into three platform vendors in eight weeks. Whether that improves or degrades independent verification of agent-identity claims is an open question this note does not attempt to answer.
  • "Agent passport" has no issuer of record. Verifiable-credential approaches to agent identity exist in vendor pilots; no body analogous to a passport authority has emerged, and the two standards bodies convening in 2026 (NIST/CAISI, ITU-T FG-TIDA) are both still in the charter-and-convene phase rather than the ratify-a-spec phase.

:CUSTOM_ID: open-questions-2026-q3 :VERIFIED_AT: 2026-09-27T20:00:00Z :VERIFIED_BY: claude-research-agent :VERDICT: speculative :FINDING: This section states the author's synthesis of gaps across the sourced material above, not a claim independently verifiable against a single source. Revisit at the next major protocol release (MCP's next spec date, or A2A's next minor version) to see which of these four gaps closed first.

14. Related

Amazon Web Services. 2026. “AWS Agent Registry for Centralized Agent Discovery and Governance Is Now Available in Preview.” AWS What’s New. https://aws.amazon.com/about-aws/whats-new/2026/04/aws-agent-registry-in-agentcore-preview.
Carielli, Sandy. 2026. “The Forrester Wave: Bot and Agent Trust Management Software, Q2 2026.” Forrester Research report + blog. https://www.forrester.com/blogs/secure-the-future-of-internet-traffic-as-agents-take-over/.
Cloudflare. 2025. “Beyond IP Lists: A Registry Format for Bots and Agents.” Cloudflare blog. https://blog.cloudflare.com/agent-registry/.
———. 2026. “Verified AI Agents: Web Bot Auth in Bot Management.” Cloudflare blog / product docs. https://developers.cloudflare.com/bots/reference/bot-verification/web-bot-auth/.
Google Cloud. 2025. “Announcing Agent Payments Protocol (AP2).” Google Cloud blog. https://cloud.google.com/blog/products/ai-machine-learning/announcing-agents-to-payments-ap2-protocol.
———. 2026. “Introducing Gemini Enterprise Agent Platform.” Google Cloud blog. https://cloud.google.com/blog/products/ai-machine-learning/introducing-gemini-enterprise-agent-platform.
ITU-T SG17. 2026. “Focus Group on Trust and Identity for Humans and Agentic AI (FG-TIDA).” ITU press release / focus group charter. https://www.itu.int/en/mediacentre/Pages/PR-2026-07-09-focus-group-agentic-AI.aspx.
Indicio. 2026. “ProvenAI: Verifiable Credentials for AI Agents.” Indicio blog. https://indicio.tech/blog/digital-passport-for-ai-agents/.
Linux Foundation. 2026a. “Linux Foundation Announces DNS-AID Project to Advance Decentralized AI Agent Discovery.” Linux Foundation press release. https://www.linuxfoundation.org/press/linux-foundation-announces-dns-aid-project-to-advance-decentralized-ai-agent-discovery.
———. 2026b. “Linux Foundation Announces Intent to Launch Agent Name Service to Establish Trusted Identity Infrastructure for AI Agents.” Linux Foundation press release. https://www.linuxfoundation.org/press/linux-foundation-announces-intent-to-launch-agent-name-service-to-establish-trusted-identity-infrastructure-for-ai-agents.
Linux Foundation / A2A Project. 2026. “A2A Protocol Ships V1.0: Production-Ready Standard for Agent-to-Agent Communication.” a2a-protocol.org blog. https://a2a-protocol.org/latest/announcing-1.0/.
Microsoft. 2026. “Microsoft Agent 365, Now Generally Available, Expands Capabilities and Integrations.” Microsoft Security Blog. https://www.microsoft.com/en-us/security/blog/2026/05/01/microsoft-agent-365-now-generally-available-expands-capabilities-and-integrations/.
Model Context Protocol. 2026. “The 2026-07-28 Specification.” Model Context Protocol blog. https://blog.modelcontextprotocol.io/posts/2026-07-28/.
NIST / CAISI. 2026. “AI Agent Standards Initiative.” NIST Center for AI Standards and Innovation. https://workos.com/blog/nist-ai-agent-standards-initiative-explained.
Okta. 2026. “Okta Brings First-Class Identity to AI Agents with Agent SSO.” Okta newsroom. https://www.okta.com/newsroom/press-releases/okta-brings-first-class-identity-to-ai-agents-with-agent-sso/.
Salesforce. 2026. “Salesforce Expands MuleSoft Agent Fabric with Automated Discovery for Any AI Agent or Tool.” Salesforce newsroom. https://www.salesforce.com/news/stories/mulesoft-agent-fabric-automated-agent-discovery/.