Executive summary:

Okta Identity Security Posture Management now includes AI agent discovery across all existing ISPM customer subscriptions. This capability identifies shadow AI agents, unmanaged OAuth grants, and MCP servers across endpoint detection platforms, browser plugins, and builder environments such as Salesforce Agentforce and Microsoft Copilot Studio to reduce attack surfaces.

Every organization needs to answer three questions about its AI agents: Where are my agents, what can they connect to, and what can they do? Okta for AI Agents already answers all three,  end-to-end.

Starting today, we're bringing that first question—Where are my agents?—to all Identity Security Posture Management (ISPM) customers. They can now discover AI agents across their organizations through their existing ISPM subscriptions.

Security teams have spent years building visibility into who and what touches their systems: employees, service accounts, API keys, and more. Today, AI agents are quietly growing faster than any of these, and until now, they've remained largely invisible.

Employees are deploying AI agents on their own, often without IT's knowledge. They grant them access to sensitive data, connect them to internal tools, and let them act semi-autonomously across critical systems. Security teams often lack an inventory of these agents and a way to assess the risk they pose. Traditional identity tracking tools simply miss them.

Expanding AI agent discovery to every ISPM customer

With this update, human and non-human identities, including AI agents, will appear together in a single posture view.

ISPM AI agent discovery features

  • Inventory of endpoint agents and MCP servers available through the CrowdStrike integration, currently in Early Access. Okta Verify is the next source we are planning to bring online, so endpoint discovery does not depend on any particular endpoint detection and response (EDR) platform. We plan to support additional EDR platforms after that.
  • Inventory of homegrown agents from builder platforms you already use, such as Salesforce Agentforce, Microsoft Copilot Studio, Amazon Bedrock, and Agentcore.
  • Inventory of OAuth grants and shadow AI apps that the Okta Browser Plugin picks up on managed browsers.
  • A new AI agent risk category that surfaces agent-related misconfigurations alongside every other identity risk.
  • A count of AI agents right on your ISPM Dashboard.

New tenants get all of this from day one. Existing customers will see it activate automatically, with a short guided introduction.

Digital interface showing an Okta ISPM dashboard and an AI agent workflow screen. The Okta ISPM Dashboard displays agent risk and an AI agent graph mapping owners to their connected tools.

Why AI agent discovery is critical for enterprise security posture

A complete identity security posture depends on seeing everything that touches your systems, not just some of it. Extending visibility to AI agents provides two key advantages:

  1. Complete attack surface visibility: Eliminates blind spots and gives you a clear, complete view of your organization’s identity security posture, from human to non-human identities
  2. Proactive risk mitigation: Minimizes the blast radius from an unmanaged agent before an issue becomes an incident

Okta for AI Agents goes beyond discovery to lifecycle governance

Discovery answers the first of three questions every organization needs to ask about its AI agents: Where are my agents? It's a good first step, but it’s really just the start. From there, you need to take these shadow agents and ask: What can they connect to, and what can they do?

We built Okta for AI Agents to answer those exact questions. Okta for AI Agents builds on ISPM discovery through three governance mechanisms:

  • Resource mapping: Tracks every resource an agent can reach, from MCP servers and SaaS apps to other agents, so you can see and control its blast radius before it becomes compromised.
  • Runtime least-privileged access: Enforces real-time access controls and offers an instant kill switch to revoke access if an agent strays outside its defined scope.
  • Audit trails: Maintains centralized audit logs, mapping every action back to the originating user and agent identity.

That's how teams go from knowing their agents exist to actually managing them, adopting AI as fast as they want without security trailing behind. Read the blueprint for the secure agentic enterprise for the full picture.

Get started

Already an ISPM customer? Check out our ISPM documentation to get started with agent discovery. 

Just getting started with securing your AI agents? Learn more about how Okta for AI Agents can help. 

These materials are intended for general informational purposes only and are not intended to be legal, privacy, security, compliance, or business advice. Any features or services that are on the roadmap or available in beta, early access or similar non-generally available release status may not be developed, released or made generally available, or may have different features, functionalities, technologies, configurations, and/or documentation at the time of release, if any. © 2026 Okta, Inc. and/or its affiliates.

Continue your identity journey