SecurityBrief Asia - Technology news for CISOs & cybersecurity decision-makers
Asia
Okta adds controls for AI agents amid security push

Okta adds controls for AI agents amid security push

Wed, 30th Sep 2026 (Today)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

Okta has introduced new security and governance features for AI agents aimed at giving organisations more visibility into how those agents behave.

The new measures cover how AI agents connect to software, how their actions are monitored, and how access can be cut off if something goes wrong. The package also includes a new industry coalition, the Blueprint Alliance, focused on principles for securing AI agents across organisations.

Among the new features is an extension of shadow AI discovery to endpoints, intended to help companies identify agent use beyond centrally managed systems. Okta is also adding a visual Configuration Designer that maps links between agents and the resources they access, making those handoffs easier to review and audit.

Another addition, Agent-to-Agent Connections, sets rules for which agents can call other agents and what each is allowed to access. The system records those handoffs in an auditable chain, giving security and compliance teams a clearer record of how work passes between automated systems.

Okta is also broadening the use of Agent SSO. The feature brings Cross App Access to all single sign-on customers and is designed to replace non-expiring keys with short-lived tokens governed through identity controls.

This approach can reduce the use of persistent credentials, a long-standing security concern because they can remain valid even after an account or service should no longer have access. By moving to shorter-lived tokens, companies can place tighter limits on how long an agent can use a connection.

Runtime visibility is another focus. Many organisations using AI agents still struggle to say in real time what those systems are doing, especially when a faulty or malicious prompt could trigger access to more data than intended.

Okta already logs agent events through its System Log and can stream them to security information and event management systems. It now plans to extend its Kill Switch to the Agent Gateway, which acts as a control point for agent actions that pass through it.

If an agent connected to that gateway is deactivated, administrators will be able to revoke every active token held by that agent and end sessions already under way. That would make the gateway a live enforcement point rather than only a source of records after an incident.

Alongside those controls, Okta is introducing Resource Access Certifications, a review process for agent connections over time. The feature is intended to help organisations check whether agents still need the access they have and reduce the risk of excessive or standing permissions remaining in place.

Ryan Barnes, Director of IT at MJS Packaging, said the approach addresses a common concern for companies trying to adopt AI systems while keeping oversight in place. "Moving fast with AI agents should not mean sacrificing control. Okta for AI Agents gives us the governance to deploy across the enterprise, accelerating innovation while eliminating security blind spots," Barnes said.

Alliance principles

Okta has also formed the Blueprint Alliance, which it described as a cross-industry coalition. Its founding members have aligned around a set of principles for managing AI agents as a governed system rather than a loose collection of tools.

Those principles include treating every agent as a first-class identity, limiting access to the specific task rather than granting broad standing privileges, keeping delegation traceable, monitoring runtime behaviour continuously, and enabling containment that is both immediate and reversible. Okta said its new AI agent features are its contribution to that framework.

The launch reflects a wider shift in cybersecurity as AI agents move deeper into internal workflows and customer-facing operations. As those systems take on more tasks across software development, support, and operations, companies are under pressure to show not only that agents can act autonomously, but also that their access and behaviour remain under human control.

Okta said the objective is to provide a single identity foundation across the agents an organisation runs, with controls spanning discovery, connection management, runtime monitoring, and shutdown. Every workflow in the enterprise now involves AI, whether in the codebase or at a customer touchpoint, the company said.