New Okta for AI agents innovations increase visibility into agent behavior, secure connections at runtime, and enforce continuous agent governance

New capabilities let businesses deploy AI agents fast, with enterprise-grade security and control built in.

Über Okta

Okta

Okta, Inc. is The World’s Identity Company™. We secure AI, machine, and human identity so everyone is free to safely use any technology. Our customer and workforce solutions empower businesses and developers to protect their AI agents, users, employees, and partners while driving security, efficiencies, and innovation. Learn why the world’s leading brands trust Okta for authentication, authorization, and more at okta.com.

22 September 2026 Lesezeit: ~

Today, Okta is launching a series of new Okta for AI Agents capabilities to help organizations manage risk across the agent lifecycle, providing sufficient access to drive business outcomes while maintaining visibility and control. By extending shadow AI discovery to endpoints, enabling visual configuration of agent connections, and expanding the Kill Switch to revoke active tokens at the Agent Gateway, Okta is delivering real-time visibility, runtime security, and continuous lifecycle governance for agentic AI.

"Moving fast with AI agents should not mean sacrificing control. Okta for AI Agents gives us the governance to deploy across the enterprise, accelerating innovation while eliminating security blind spots," said Ryan Barnes, Director of IT at MJS Packaging.

Proven Identity Solutions Extended to AI Agents

Across B2B, B2C, and ecosystem partners, the blueprint for the secure agentic enterprise helps separate the risks of AI from its rewards by giving organizations a clear way to answer four questions: Where are my agents? What can they do? What are they doing? and How do I respond? Okta for AI Agents and all associated innovations announced today provide customers with an on-ramp to the blueprint.

Consider what this looks like in practice: An employee links an AI assistant to everyday tools to move faster, unintentionally giving it unapproved access to sensitive systems. Worse, when that employee leaves, the orphaned agent keeps running in the background - ungoverned and unknown. With Okta for AI Agents, organizations gain centralized governance over their agents – delivering end-to-end lifecycle management, runtime policy enforcement, and an instant kill switch to revoke access the moment something goes wrong.

“The challenge businesses face is the same access that makes agents powerful also makes them dangerous,” said Ric Smith, President of Products and Technology, Okta. “For over a decade, Okta has continuously modernized how the workforce authenticates and connects to every app they use. That same discipline extends to AI agents. Our goal is to give enterprises the visibility and runtime assurance they need to turn AI agents from an unmanaged security risk into a massive competitive advantage.”

Where Are My Agents?

Across the enterprise, employees are spinning up agents on their own — developers, marketers, designers, and anyone with a laptop. Meanwhile, brands are embedding autonomous agents directly into customer-facing digital experiences. 

Okta already brings agents into Universal Directory as a single source of truth: known agents can be registered directly or imported from platforms like AWS Bedrock or Salesforce Agentforce. Shadow agents interacting through the browser can be discovered and registered, too. Now, Okta is extending shadow agent discovery to the endpoint itself:

  • Okta for AI Agents: Shadow AI Agent Discovery for Endpoints — surfaces unmanaged agents running on employee devices before they become blind spots.

Image

What Can They Do?

Agents connect to apps, MCP servers, and other agents, and if those connections can't be inspected or controlled, it can quickly open the door to a breach. Okta already governs the connections an agent makes through Resource Connections, controlling both what data it can access and how it gets there. Based on what the agent needs to access, admins can configure several resource connection types: authorization servers, vaulted credentials, service accounts, SaaS applications, or MCP servers. Okta now extends how connections are governed to: 

  • Agent SSO — brings Cross App Access to all SSO customers, allowing them to swap non-expiring keys for short-lived, identity-governed tokens that decrease user consent fatigue. 

  • Okta for AI Agents: Agent-to-Agent Connections — sets rules for which agents can call other agents, what each agent can access, and captures the handoff in an auditable chain.

  • Okta for AI Agents: Configuration Designer — visually maps agent-to-resource connections so the handoff is governed, scoped, and auditable.

  • Resource Access Certifications — reviews agent connections over time to help prevent standing and excessive permissions.

Image

What Are They Doing?

Most organizations running AI agents today can't say, in real time, what those agents are actually doing — and one bad prompt can expose far more than it should. Okta already provides a durable audit trail by capturing agent events in System Log and streaming them directly to SIEMs. Today, Okta builds on that foundation by extending visibility directly into the execution path with real-time runtime enforcement:

  • Okta for AI Agents: Agent Gateway — sits in the execution path between agent and tool call, enforcing policy and logging every interaction at runtime.

Image

How Do I Respond?

Even a well-managed agent can be compromised, and when that happens, teams need to be able to cut off rogue agent access instantly. Okta already gives administrators a manual off switch: deactivating an agent through the admin console immediately blocks new sessions. 

  • Okta is now planning to expand kill switch capabilities to Okta’s Agent Gateway. For agents connected to the Agent Gateway, every agent action already passes through it — making it an ideal enforcement point to cut access off the moment something goes wrong. When an agent is deactivated at the gateway, you can revoke every active token held by a compromised agent and shut down every session in flight.

Image

Every workflow in your enterprise now involves AI, whether it's in the codebase or at a customer touchpoint. As AI agents take on more of the work inside organizations, identity can no longer just guard the perimeter. It has to govern how every agent connects, acts, and gets shut down when something goes wrong. Okta gives organizations one identity foundation across all the agents they run, so they can innovate fast without losing control. 

Blueprint for the Secure Agentic Enterprise

Okta today also announced the Blueprint Alliance, a cross-industry coalition formed to help organizations operate their agentic stack as a unified, governed system. Founding Alliance members have aligned toward a shared set of principles for securing AI agents — treating every agent as a first-class identity, scoping access to the task rather than granting standing access, keeping delegation traceable, monitoring runtime behavior continuously, enabling containment that is instant and reversible, and helping ensure governance adapts at the speed AI moves.

 

Image

Okta for AI Agents and all associated innovations announced today represent Okta’s contribution to the blueprint.

To learn more about Okta’s AI identity solutions and explore the Blueprint Alliance framework, visit okta.com/ai.

Availability:

  • Agent SSO, Agent-to-Agent Connections, and Resource Access Certifications are generally available today.

  • Agent Gateway and Shadow AI Agent Discovery for Endpoints are planned to be generally available in Q3.

  • Configuration Designer and expanded Kill Switch capabilities to the runtime layer are planned to be generally available in Q4.

Any mention in this article of solutions, features, functionalities, certifications, authorizations, or attestations that are not currently generally available or have not yet been obtained may not be delivered or obtained on time or at all. We assume no obligation to deliver on such items, and you should not rely on them to make your purchase decisions.

 

Über Okta

Okta

Okta, Inc. is The World’s Identity Company™. We secure AI, machine, and human identity so everyone is free to safely use any technology. Our customer and workforce solutions empower businesses and developers to protect their AI agents, users, employees, and partners while driving security, efficiencies, and innovation. Learn why the world’s leading brands trust Okta for authentication, authorization, and more at okta.com.

Get our Identity newsletter

Access Granted Newsletter