What CISOs need to know about runtime identity enforcement for AI agents

New SACR research introduces ARISE as the critical enforcement layer for agents in motion.

About the Author

Lydia Chang

Product Marketing Specialist

Lydia is a Product Marketing Specialist in Analyst Relations at Okta, where she plays an integral role in communicating product strategy to industry analysts. She is focused on managing relationships and crafting messaging that highlights Okta's leadership in identity security. In her free time, you will find her at the gym, traveling, or at a concert.

17 September 2026 Time to read: ~

Not so long ago, AI was a static governance question. Today it’s a dynamic one. AI agents are operational actors—calling tools, requesting credentials, querying data, and triggering workflows across the enterprise, often faster than any human can review. That shift is the subject of a new report from Software Analyst Cyber Research (SACR), ARISE — Agentic Runtime Identity Security Enforcement

Building on earlier research on AI agent runtime security, ARISE evaluates how security vendors govern live agent actions before execution completes. 

The report identifies three layers of runtime security:

  • Deterministic governance: Agent identity, ownership, scoped credentials, allowed tools, and access policy. Necessary, but not sufficient on its own.

  • Behavioral and intent analysis: Prompt-to-action reconstruction, tool-call telemetry, and intent-drift detection-—determining whether live behavior still matches the assigned task.

  • Dynamic runtime governance: Real-time allow, block, redact, pause, escalate, or revoke decisions, made in-path before an action's consequences become irreversible.

SACR pairs this with a new six-level maturity model, the ARISE Control Depth (ACD) framework. The framework helps organizations rate their maturity from blind execution (ACD 0) to autonomous self-healing governance (ACD 5). The report sets ACD 4 (inline, pre-completion intervention) as the minimum credible production threshold for any agent touching sensitive data, credentials, or critical workflows.

Where Okta comes in

SACR recognized Okta for AI Agents among a small group of vendors with broad ARISE alignment. Okta addresses the ARISE framework from the identity control plane and extends IGA, PAM, and non-human identity lifecycle and credential controls to AI agents.

Specifically, Okta helps organizations answer three critical questions: 

  • Where are my agents? 

  • What can they connect to?

  • What can they do?

SACR credited Okta's first-class agent identity, named ownership, OAuth/OIDC policy, Cross App Access (XAA) delegation, Security Token Exchange (STS), scoped and vaulted credentials, lifecycle controls, access reviews, and Fine-Grained Authorization (FGA/ReBAC) with providing "broad baseline governance" for agents alongside human and non-human identities.

Two capabilities stood out as differentiators in SACR's assessment of Okta:

  • User-linked agent identity. An agent receives its own identity while retaining the human context under which it acts, so effective permission can be narrowed through scopes, claims, relationship-based policy, and delegated access, rather than treating the agent as a shared service account.

  • Agent-to-agent handoff governance. Per-connection policy and preserved attribution mean an inbound agent can be checked as registered and authorized before another agent accepts its work, directly addressing the trust gap around unfamiliar agents.

Across SACR's use-case scoring, Okta rated strongest in two areas:

  • Agent identity and delegation. Linking agents to human owners and delegated users with scoped credentials, entitlement review, lifecycle management, session attribution, and auditable agent-to-agent handoffs.

  • Model and third-party ecosystem support. Covering coding, browser, SaaS, local, custom, platform, and agent-to-agent actions across MCP, SaaS, APIs, and legacy resources, backed by a large integration network. 

SACR rated Okta’s tool/MCP governance as strong, citing support for MCP authorization servers, resource connections, and agent-to-agent policy. Runtime enforcement and evidence/audit/response both rated material.

SACR's practical buying case for Okta is consolidation: Existing customers can bring agent registration, ownership, delegated access, certification, and revocation into familiar identity workflows they already run for their workforce. The report notes Okta belongs on the shortlist "when attribution, delegated authority and ecosystem reach are the primary problems.” 

Arise Cohort 2026

Permiso Security’s runtime edge: Non-human identity threat protection

SACR also recognized Permiso Security among its representative vendors. Recently acquired by Okta, Permiso's focus on non-human identities (NHIs) and cloud identity threat detection and response (ITDR) directly tackles the behavioral blind spots of live execution. By reconstructing end-to-end activity sessions across distributed cloud infrastructure, Permiso detects when an agent's runtime actions deviate from authorized intent, providing SOC teams with the deep telemetry required to halt active compromise.

Two capabilities stood out as differentiators in SACR's assessment of Permiso:

  • Cross-cloud runtime session stitching. Permiso reconstructs complete execution chains and stitches together runtime activity across multi-cloud, IaaS, and SaaS environments. By correlating non-human identity actions back to originating user sessions, Permiso uncovers intent drift, credential misuse, and anomalous multi-hop handoffs across distributed architectures.

  • Non-human identity behavioral heuristics. Rather than relying solely on static rule sets, Permiso evaluates runtime execution against historical interaction baselines, detecting out-of-bounds tool calls, unauthorized API invocations, and privilege escalation in real time.

Across SACR's use-case scoring, Permiso rated strongest in two areas:

  • Behavioral and intent analysis. Continuously evaluating real-time prompt-to-action execution against organizational baselines, detecting intent drift, and flagging sequence anomalies during live multi-step task completion.

  • Identity threat detection and response. Detecting compromised machine credentials, unauthorized token usage, and out-of-context infrastructure modifications across live agent sessions, feeding real-time threat signals directly to SOC workflows.

SACR rated Permiso’s dynamic runtime enforcement as strong, citing its capability to trigger immediate containment, session termination, and automated credential invalidation upon detected drift. Ephemeral privilege brokering and audit forensics both rated material.

Together, Okta and Permiso provide full-spectrum coverage: deterministic identity governance to establish proper boundaries before execution, paired with runtime behavioral defense while execution takes place.

Top takeaways for security leaders

To put the new maturity model into practice, here’s what security leaders need to focus on when assessing their tech stack and strategy: 

Stop crediting visibility as enforcement. Discovery and inventory (ACD 1–2) are approaching table stakes across the market. The real differentiator is whether a platform can change the outcome of a live action, not just alert on it after the fact.

Demand action-level, not app-level, granularity. The report urges buyers to test whether policy can operate on individual tools, specific resources, read/write/delete distinctions, and named credentials—not just a blanket allow-or-block at the application layer.

Map your six vendor patterns before you shortlist. SACR groups the ARISE market into identity-first governance, PAM/secrets, gateway and prompt control, MCP/tool governance, runtime behavior detection, and agent lifecycle assurance. Understanding which pattern a vendor comes from explains more about fit than small feature differences.

Treat human-in-the-loop as a feature, not a gap. Fully autonomous remediation is still rare and often shouldn't be the goal. The report recommends explainable, reversible intervention—automated or human-reviewed—as the right bar, evaluated by whether it happens before completion.

Looking ahead

SACR’s ongoing research shows that agents must be treated as first-class identities and secured as runtime actors. The next test for the market is proving that identity governance can extend fully into live, in-path enforcement, not just ownership and access mapping. That's the work already underway across Okta's agent-to-agent policy engine, Global Token Revocation, and expanding gateway intervention capabilities.

To learn more about the ARISE framework, read the full SACR report.

About the Author

Lydia Chang

Product Marketing Specialist

Lydia is a Product Marketing Specialist in Analyst Relations at Okta, where she plays an integral role in communicating product strategy to industry analysts. She is focused on managing relationships and crafting messaging that highlights Okta's leadership in identity security. In her free time, you will find her at the gym, traveling, or at a concert.

Get our Identity newsletter