New Okta for AI Agents Innovations Increase Visibility Into Agent Behavior, Secure Connections at Runtime, and Enforce Continuous Agent Governance
New capabilities let businesses deploy AI agents fast, with enterprise-grade security and control built in
Okta is launching a series of new Okta for AI Agents capabilities to help organizations manage risk across the agent lifecycle, providing sufficient access to drive business outcomes while maintaining visibility and control. By extending shadow AI discovery to endpoints, enabling visual configuration of agent connections, and expanding the Kill Switch to revoke active tokens at the Agent Gateway, Okta is delivering real-time visibility, runtime security, and continuous lifecycle governance for agentic AI.
"Moving fast with AI agents should not mean sacrificing control. Okta for AI Agents gives us
the governance to deploy across the enterprise, accelerating innovation while eliminating
security blind spots," said Ryan Barnes, Director of IT at MJS Packaging.
Proven Identity Solutions Extended to AI Agents
Across B2B, B2C, and ecosystem partners, the blueprint for the secure agentic enterprise
helps separate the risks of AI from its rewards by giving organizations a clear way to answer
four questions: Where are my agents? What can they do? What are they doing? and How
do I respond? Okta for AI Agents and all associated innovations announced today provide
customers with an on-ramp to the blueprint.
Consider what this looks like in practice: An employee links an AI assistant to everyday tools
to move faster, unintentionally giving it unapproved access to sensitive systems. Worse,
when that employee leaves, the orphaned agent keeps running in the background -
ungoverned and unknown. With Okta for AI Agents, organizations gain centralized
governance over their agents – delivering end-to-end lifecycle management, runtime policy
enforcement, and an instant kill switch to revoke access the moment something goes
wrong.
“The challenge businesses face is the same access that makes agents powerful also makes
them dangerous,” said Ric Smith, President of Products and Technology, Okta. “For over a
decade, Okta has continuously modernized how the workforce authenticates and connects
to every app they use. That same discipline extends to AI agents. Our goal is to give
enterprises the visibility and runtime assurance they need to turn AI agents from an
unmanaged security risk into a massive competitive advantage.”
“For over a decade, Okta has continuously modernized how the workforce authenticates and connects to every app they use. That same discipline extends to AI agents. Our goal is to give enterprises the visibility and runtime assurance they need to turn AI agents from an unmanaged security risk into a massive competitive advantage.”
- Ric Smith, President of Products and Technology, Okta
Where Are My Agents?
Across the enterprise, employees are spinning up agents on their own — developers,
marketers, designers, and anyone with a laptop. Meanwhile, brands are embedding
autonomous agents directly into customer-facing digital experiences.
Okta already brings agents into Universal Directory as a single source of truth: known agents
can be registered directly or imported from platforms like AWS Bedrock or Salesforce
Agentforce. Shadow agents interacting through the browser can be discovered and
registered, too. Now, Okta is extending shadow agent discovery to the endpoint itself:
● Okta for AI Agents: Shadow AI Agent Discovery for Endpoints — surfaces
unmanaged agents running on employee devices before they become blind spots.
What Can They Do?
Agents connect to apps, MCP servers, and other agents, and if those connections can't be
inspected or controlled, it can quickly open the door to a breach. Okta already governs the
connections an agent makes through Resource Connections, controlling both what data it
can access and how it gets there. Based on what the agent needs to access, admins can
configure several resource connection types: authorization servers, vaulted credentials,
service accounts, SaaS applications, or MCP servers. Okta now extends how connections
are governed to:
● Agent SSO — brings Cross App Access to all SSO customers, allowing them to swap
non-expiring keys for short-lived, identity-governed tokens that decrease user
consent fatigue.
● Okta for AI Agents: Agent-to-Agent Connections — sets rules for which agents
can call other agents, what each agent can access, and captures the handoff in an
auditable chain.
● Okta for AI Agents: Configuration Designer — visually maps agent-to-resource
connections so the handoff is governed, scoped, and auditable.
● Resource Access Certifications - reviews agent connections over time to help
prevent standing and excessive permissions.
"Moving fast with AI agents should not mean sacrificing control. Okta for AI Agents gives us the governance to deploy across the enterprise, accelerating innovation while eliminating security blind spots."
- Ryan Barnes, Director of IT at MJS Packaging
What Are They Doing?
Most organizations running AI agents today can't say, in real time, what those agents are
actually doing — and one bad prompt can expose far more than it should. Okta already
provides a durable audit trail by capturing agent events in System Log and streaming them
directly to SIEMs. Today, Okta builds on that foundation by extending visibility directly into
the execution path with real-time runtime enforcement:
● Okta for AI Agents: Agent Gateway — sits in the execution path between agent and
tool call, enforcing policy and logging every interaction at runtime.
How Do I Respond?
Even a well-managed agent can be compromised, and when that happens, teams need to
be able to cut off rogue agent access instantly. Okta already gives administrators a manual
off switch: deactivating an agent through the admin console immediately blocks new
Sessions.
● Okta is now planning to expand kill switch capabilities to Okta’s Agent Gateway. For
agents connected to the Agent Gateway, every agent action already passes through
it — making it an ideal enforcement point to cut access off the moment something
goes wrong. When an agent is deactivated at the gateway, you can revoke every
active token held by a compromised agent and shut down every session in flight.
Every workflow in your enterprise now involves AI, whether it's in the codebase or at a
customer touchpoint. As AI agents take on more of the work inside organizations, identity
can no longer just guard the perimeter. It has to govern how every agent connects, acts, and
gets shut down when something goes wrong. Okta gives organizations one identity
foundation across all the agents they run, so they can innovate fast without losing control.
Blueprint for the Secure Agentic Enterprise
Okta today also announced the Blueprint Alliance, a cross-industry coalition formed to help
organizations operate their agentic stack as a unified, governed system. Founding Alliance
members have aligned toward a shared set of principles for securing AI agents — treating
every agent as a first-class identity, scoping access to the task rather than granting
standing access, keeping delegation traceable, monitoring runtime behavior continuously,
enabling containment that is instant and reversible, and helping ensure governance adapts
at the speed AI moves.
Availability:
● Agent SSO, Agent-to-Agent Connections, and Resource Access Certifications are
generally available today.
● Agent Gateway and Shadow AI Agent Discovery for Endpoints are planned to be
generally available in Q3.
● Configuration Designer and expanded Kill Switch capabilities to the runtime layer are



Editor
