News and Press Releases

Elisity Launches Open CLI for Customer-Built AI Agents on Its Microsegmentation Platform

Written by Charlie Treadwell | Aug 5, 2026, 3:40:51 PM

SAN JOSE, Calif., Aug. 5, 2026 /PRNewswire/ -- Elisity, the identity-based microsegmentation company, today launched the Elisity CLI, an open command-line interface that lets security and network teams run their own AI agents against the Elisity platform. Teams can script discovery, manage Zero Trust least-privilege access policies, and pull posture reports, then point their own AI orchestrators at the platform to keep checking that segmentation controls still hold.

Plenty of security vendors now ship AI agents that customers can't see inside. Elisity does the reverse. Security teams point whatever agent they already run at an open interface, and built-in guardrails stop that agent from acting on a guess or making a change nobody approved. Because every action runs on identity through Elisity IdentityGraph™, an agent works from many data points Elisity has already ingested and correlated, so it can tell what a device really is instead of guessing from an IP address. Teams automate only what they want, and a person signs off before anything changes.

Elisity Intelligence reviews a clinical policy set and surfaces 425 unused allow policies across a 30-day window.

Elisity built a command-line interface rather than a Model Context Protocol server by design. An MCP server is a standing, privileged connection into the platform, and it widens what an agent can reach by default. That pattern has drawn steady scrutiny from security researchers, and it asks a security team to run one more always-on service inside the environment it is trying to protect. A CLI inverts the model. It runs only when it is called, it runs under the caller's own credentials and permissions, and every state-changing command stops for human approval. The concern is not theoretical. In July 2025, researchers disclosed CVE-2025-6514, rated 9.6 out of 10, in mcp-remote, a connector downloaded more than 437,000 times: a malicious MCP server could run operating system commands on the machine that connected to it, the first documented remote code execution against an MCP client.

Elisity built the CLI for teams that want to run the platform programmatically and stand up their own agentic workflows:

  • 466 commands covering the Elisity Cloud Control Center API, plus reporting on Zero Trust posture scores, per-site metrics, and traffic and threat vectors.
  • An operating guide and command glossary for AI agents like Claude or ChatGPT, so an agent runs a real command instead of inventing one.
  • Human approval on every state-changing command, and a separate confirmation for deletes.
  • Output in JSON, table, YAML, or CSV, with profiles for production, staging, and lab.

"Most of the industry is asking customers to trust a black-box AI agent with their network. We're doing the opposite. Our CLI hands customers the keys, so they point their own AI agents at the platform and automate exactly what they choose, with a human approving anything that changes state. And because it all runs on identity through Elisity IdentityGraph, an agent knows what a device actually is, not just a guess off an IP address. That's the difference between automation you can audit and automation you just hope works." — James Winebrenner, CEO, Elisity

"Every segmentation program eventually reaches the same question: Are these policies still enforcing the outcomes we designed them to achieve? Historically, the answer came from periodic audits and the assumption that nothing had changed. With the Elisity CLI, we can continuously validate our Zero Trust least-privilege policies against realistic adversary techniques. If a policy drifts or no longer prevents lateral movement, we know within minutes instead of discovering it during an incident. In healthcare, operational resilience matters because downtime is not just an IT problem. Automating these tests gives us continuous assurance that our controls are performing the way we expect them to. Security isn't about believing your controls still work. It's about proving they do." — Jason Elrod, Chief Information Security Officer, MultiCare Health System

Customer use of Elisity Intelligence, the platform's optional AI, has climbed steadily through 2026. The number of customer organizations using it grew 77% between April and June, and the heaviest use is in policy work, device lookups, and the overview dashboard, where the daily work happens. Nothing about it runs on its own. Administrators decide what's on, and every recommendation waits for a person to approve it before anything changes. Customers running it already include GSK, Main Line Health, and MultiCare Health System, this year's CSO Award winner.

Elisity offers the CLI to customers today. Teams that want to wire up their own agents can request access through their Elisity account team. Elisity's AI capabilities data sheet explains how Elisity Intelligence works, and you can request a demo to see the platform.

Frequently Asked Questions About the Elisity CLI

What is the Elisity CLI?

The Elisity CLI is an open command-line interface that lets security and network teams run their own AI agents against the Elisity platform: scripting discovery, managing Zero Trust least-privilege access policies, and pulling posture reports through 466 commands covering the Elisity Cloud Control Center API.

Is the Elisity CLI an MCP server?

No. Elisity built a CLI rather than a Model Context Protocol (MCP) server by design. An MCP server is a standing, privileged connection that widens what an agent can reach by default and runs as an always-on service inside the environment it's meant to protect. A CLI only runs when it's called, under the caller's own credentials and permissions, with no persistent privileged connection left open.

Does the Elisity CLI require human approval before making changes?

Yes. Every state-changing command stops for human approval, and deletes require a separate confirmation. This mirrors the human-in-the-loop design principle behind every AI capability on the Elisity platform: AI recommends, and only an administrator's explicit acceptance puts a change into effect. Nothing enforces autonomously.

How does the Elisity CLI use identity to inform AI agents?

Every action runs on identity through Elisity IdentityGraph, which unifies device attributes from more than 25 external sources, plus native network telemetry, into one authoritative identity record per device. An agent working through the CLI draws on that same correlated identity data instead of guessing from an IP address, so it can tell what a device actually is before it scripts discovery, checks policy, or pulls a posture report.

What is Elisity Intelligence, and how does it relate to the Elisity CLI?

Elisity Intelligence is the AI engine embedded across Cloud Control Center, Elisity's administrative console. It powers three built-in capabilities: the Elisity Assistant, a conversational copilot that answers questions about devices, traffic, and policy; AI Device Classification, which proposes categories for unclassified devices; and AI-Powered Insights, which recommends Policy Groups, policies, and enforcement changes. All three run on private LLMs in a single-tenant architecture, and none take effect without administrator approval. The Elisity CLI extends that same identity-driven, human-approved model outward, so a customer's own AI agents, not just Elisity's built-in ones, can work against the platform under the same guardrails.

About Elisity

Elisity (www.elisity.com) helps healthcare systems, manufacturers, and critical infrastructure operators stop lateral movement through identity-based microsegmentation. Elisity discovers every user, workload, and device, then enforces Zero Trust least-privilege access policies on existing network infrastructure, with no agents, new hardware, or network redesign. Elisity protects organizations including GSK, Main Line Health, MultiCare Health System, and Shaw Industries. For more information, visit www.elisity.com.

Media Contact:
Danielle Ostrovsky
Hi-Touch PR
Ostrovsky@Hi-TouchPR.com