Salt Security has expanded its integration with CrowdStrike to give security teams greater visibility into how AI agents connect to enterprise systems, use APIs and exercise their permissions. The expanded partnership brings together Salt’s Agentic API platform with CrowdStrike Falcon Foundry, Falcon Next-Gen SIEM and Falcon Firewall Management. According to the companies, the integration is designed to help joint customers discover AI agents operating across their environments and track the infrastructure and permissions that allow them to act.
The move comes as enterprises shift from experimenting with generative AI towards deploying agents capable of performing tasks autonomously. These agents can hold credentials, connect to internal systems through Model Context Protocol (MCP) servers and tools, invoke APIs and take actions on behalf of employees.
This creates a new visibility challenge for security teams, particularly when agents connect to tools, APIs or MCP servers that have not been formally reviewed or are granted broader permissions than necessary. Through Salt’s certified application on CrowdStrike Falcon Foundry, customers can deploy Salt using their existing Falcon sensor without introducing additional gateways or proxies.
The integration can then identify AI agents, the MCP servers and tools they connect to, the APIs those connections invoke and the permissions associated with them. This includes identifying publicly exposed MCP servers and integrations that may have been introduced without going through an organisation’s normal security review process.
Salt’s findings can also be fed into Falcon Next-Gen SIEM and correlated with endpoint, identity and cloud telemetry already collected through CrowdStrike.
Where agent behaviour deviates from an established baseline, organisations can use Falcon Firewall Management to trigger an automated response.
The companies say this should allow security teams to answer three increasingly important questions: which AI agents are operating within the business, what systems and data they are able to access, and whether their actual behaviour remains consistent with those permissions.
“Most enterprises can tell you which AI agents they have approved. Far fewer can follow the full path those agents take once they begin acting across the business,” said Roey Eliyahu, co-founder and CEO at Salt Security. “An agent may start with a legitimate prompt, but risk can emerge later through an over-permissioned tool, an MCP connection, or an API call. By combining Salt’s Agentic API capabilities with the power of the AI-native Falcon platform, we’re giving joint customers deeper visibility and control over agent activity across the enterprise.”
The announcement builds on an existing relationship between the two cybersecurity companies. CrowdStrike’s Falcon Fund invested in Salt Security in 2022, with the companies subsequently launching a certified Salt application on Falcon Foundry and an integration with Falcon Next-Gen SIEM.
The latest expansion extends that partnership specifically into the security of AI agents as organisations begin giving autonomous systems greater access to business applications, data and workflows.





