NewCore vs Hush: Agentic SSO vs Runtime Kill Switch
Identity tickets moved from workforce SSO to machines and NHIs. The next buy asks who the agent is, who authorized it, and where access dies.
Workforce SSO was the closed ticket for a decade. Machine and non-human identity access became the next seat when service accounts and API keys outgrew the IdP story. Coding agents and autonomous workers push a third conversation into the same IAM room: who is this agent, who authorized the grant, and where is the kill switch when it goes sideways?
Between these two, NewCore productizes agentic SSO and a human-approved agent identity lifecycle inside a security-first IdP rebuilt for humans, machines, and agents. Hush Security productizes the runtime access path: enroll agents in a registry, strip standing credentials, issue scoped just-in-time permissions, log every action, and cut access from a centralized kill switch.
Shared "agent identity" language does not make them one interchangeable buy. Related NHI coverage lives under non-human identity tools; the compare index is at Compare.
| Job | Agentic SSO and first-class agent identity lifecycle for humans and AI agents | Agent and NHI registry with JIT permissions, secretless access, and kill switch |
|---|---|---|
| How risk closes | Authenticate, govern, and revoke agents as identities; human grant, review, and revoke paths | Enroll the agent, remove standing secrets, grant scoped JIT at runtime, log actions, kill switch |
| CI fail | Not a classic PR SAST gate; identity and authz control plane before agents act as principals | Not a classic PR SAST gate; runtime access and credential path while agents call tools |
| Deploy | Enterprise identity platform / IdP path; demo-gated | Access management control plane across infra and AI platforms; demo-gated |
| License/pricing | Sales quote / Request a Demo; no public dollar SKU (checked 5 Sep 2026) | Sales quote / Book a Demo; no public dollar SKU (checked 5 Sep 2026) |
| Who operates it | Identity and IAM owning agentic SSO and lifecycle | Identity and SecOps owning registry, JIT, and kill switch at runtime |
Funding marks stage and category heat rather than erase the job split. On 15 June 2026 NewCore emerged from stealth with a 66M USD seed led by Cyberstarts with Index Ventures and Evolution Equity Partners (TechCrunch coverage of that launch cited about a 300M USD valuation). On 28 July 2026 Hush announced a 30M USD Series A with Akamai joining Battery Ventures and YL Ventures, bringing total capital raised to about 41M USD.
That authorization question is why both vendors land on the same shortlist after the IAM โ machine โ agent ticket opens. The buyer still has to pick the operating surface: agentic SSO and lifecycle, or runtime JIT and kill switch.
We reviewed first-party documentation, funding notices, product pages, and live community threads. We did not test the products in paid production environments, so this is not a hands-on benchmark.
NewCore

Hush Security

Editions and pricing
Neither publishes a self-serve dollar table. Both route buyers to demo or quote. NewCore is a 2026 seed-stage identity platform with a large reported seed and a cited ~300M USD valuation at launch. Hush is a Series A access-management company at about 41M USD total after the July 2026 round with Akamai as a strategic investor. Funding is a durability signal, not proof the products compete for the same seat.
| Owner (2026) | Independent. Founded by Zohar Alon, Amihai Neiderman, and Erez Yarkoni | Independent. Founded by the Meta Networks team; Akamai as Series A strategic |
|---|---|---|
| How you buy it now | Request a Demo / Get in Touch (checked 5 Sep 2026) | Book a Demo / Contact (checked 5 Sep 2026) |
| Public units | No public self-serve dollar SKU | No public self-serve dollar SKU |
| Funding signal | 66M USD seed Jun 2026; Cyberstarts, Index, Evolution; ~300M USD valuation cited at launch | 30M USD Series A Jul 2026; Akamai + Battery + YL; about 41M USD total |
If procurement needs a published monthly number before a call, neither page ships one today. POC design should start from the job: agentic SSO and lifecycle versus runtime JIT and kill switch.
Agentic SSO and identity lifecycle
| Primary surface | Next-gen IdP: humans and AI agents as first-class identities with lifecycle, trust scoring, and revocation | Agents enroll in a central registry and map to existing permissions; not an IdP-first SSO story |
|---|---|---|
| Human approval | Mobile grant, review, and revoke for agents; Agentic Skill packages for Claude Code, Codex, and Cursor | Policies and approvals sit on the access path; human oversight is runtime governance, not SSO onboarding |
| Identity architecture | Secure Split Key for SAML/OIDC signing; VisualMFA; continuous discovery of shadow and orphaned identities | Identity-based JIT access replacing standing credentials across NHIs and agents |
| What teams argue about | Whether rebuilding the IdP for agents is required when runtime access controls already exist | Whether a registry and JIT path without agentic SSO covers coding-agent fleets that need first-class principals |
Between these two, do not buy a shared "agent identity" checkbox. Buy the operating surface: NewCore when agents must authenticate and live as governed principals inside the identity platform; Hush when the urgent gap is how agents reach systems after they exist.
Runtime JIT, secretless access, and kill switch
| Standing credentials | Agents authenticate into the enterprise trust map rather than living as disguised service accounts | Standing credentials are stripped; scoped JIT permissions are issued at runtime |
|---|---|---|
| MCP and tools | Agentic Skill integrations for coding agents; governance is identity-lifecycle first | Discovers and maps MCPs, tools, and resources agents can reach and actually use |
| Kill / revoke | Revocation path is part of first-class agent identity lifecycle and human oversight | Centralized kill switch for agent actions beside continuous logging and audit |
| What teams argue about | Whether IdP revocation alone stops a live agent mid-tool-call without a runtime fence | Whether JIT and kill switch are enough without treating agents as SSO principals |
Between these two, Hush owns the standing-secret and mid-action stop story. NewCore owns making the agent a principal you can authenticate, score, and revoke inside identity.
Where they overlap
Both sell agent identity and governance language. Both talk revocation, permissions, and AI agents that are not just another service account. Both are demo-quoted vendors riding 2025-2026 agent adoption. Overlap is category timing and shared vocabulary, not identical product breadth. Treating them as interchangeable duplicates spend without covering both jobs.
When to use both
Running both can be honest when jobs stay separate: NewCore for agentic SSO and human-approved identity lifecycle, Hush for runtime JIT, credential elimination, and kill switch across agents and NHIs. Keep ownership clear so two agent-access lanes do not fight the same ticket.
Skip Hush for this pair if the urgent buy is rebuilding workforce and agent identity in one IdP and runtime secretless access already has an owner. Skip NewCore for this pair if the buying committee standardized on runtime agent access controls and first-class agentic SSO is only a later roadmap item.
Decide the job first. If the product must deepen agentic SSO and human-approved identity lifecycle, that is NewCore. If the product must deepen runtime JIT, secretless access, and kill switch for agents and NHIs, that is Hush. Only then book the demos.
FAQs
Are NewCore and Hush the same agent identity product?
No. Both talk agent identity, but between these two NewCore leads with agentic SSO and identity lifecycle, and Hush leads with registry, JIT permissions, secretless access, and a centralized kill switch.
Do either publish list prices?
No public self-serve dollar SKUs on either first-party site as of 5 Sep 2026. Both route to demo or sales quote.
What funding should buyers note?
NewCore emerged Jun 2026 with a 66M USD seed (Cyberstarts, Index, Evolution; ~300M USD valuation cited at launch). Hush raised a 30M USD Series A in Jul 2026 with Akamai as a strategic investor, about 41M USD total. Funding is relevant for roadmap durability; it does not make the jobs identical.
Is this a scored bake-off?
No. Order is editorial.