Key takeaways

Answer auditor questions about agent access: Use Resource Access Certifications for AI Agents to produce audit-ready campaign reports proving who approved an AI agent’s resource access, what scopes were approved, and when access was last reviewed.

Reduce your agent attack surface: Every unnecessary connection represents a potential attack vector. Use Resource Access Certifications for AI Agents to rapidly revoke access across your agent catalog.

Respond as fast as agent threats evolve: Automatically trigger resource access certification campaigns when Okta detects an agent security event, transforming a routine compliance task into an integral part of your overall security response.

Two AI agent governance challenges: security and compliance

Agents pose new security and compliance challenges, and most organizations are unprepared to address them.

More than 60% of survey respondents in Okta’s AI at Work 2025 report cited security as their primary AI concern, and 69% mentioned governing the non-human identity (NHI) lifecycle, including account creation and deactivation, as a key concern. This is not surprising considering only 10% report having a well-developed strategy to manage NHIs, and only 32% consistently apply the same governance standards to agents as they do to human employees. These statistics show two distinct challenges organizations face when deploying agents: a security problem and a compliance problem.

What is Resource Access Certifications for AI Agents?

Okta for AI Agents already helps you discover agents across your enterprise and govern who can access them. That's the foundation: knowing your agents exist and controlling who can reach them. 

Resource Access Certifications for AI Agents is a new identity governance capability within Okta for AI Agents that enforces least-privilege access across non-human AI agent workflows. It provides visibility into agent-to-resource connections, enables event-driven access reviews, and executes immediate revocation of AI agent connections to close compliance gaps and eliminate over-privileged attack vectors. This capability is central to answering one of the foundational questions from the blueprint for the secure agentic enterprise: What can they do?

The security problem: Agent connections accumulate unchecked permissions and excess privileges

Non-human identities tend to have broad, persistent access with less oversight than human accounts, making them valuable targets for attackers. Even when organizations apply the same security standards to agents as they do to human accounts, a key remaining challenge is the accumulation of privilege. As agents are deployed and modified over time, they accumulate an increasing number of connections and privileges that are rarely revisited. These unmanaged connections create an increasingly large surface area for attackers to exploit. If an agent is compromised, the attack's blast radius is determined by all of these connections. Auditing and removing unnecessary connections can reduce the scope of any attack.

The compliance problem: Traditional access certifications fail for AI agents

From a compliance perspective, access certification programs have served as a foundational control for years. Quarterly access certifications were designed to help ensure user access to resources adheres to least privilege. This model could be extended to cover service accounts because the same structure for certifying an account’s access to a resource continued to work.

Agents upend this model. Many users can connect to a given agent, and each agent also has connections to multiple downstream resources. In addition, the periodic nature of these reviews created gaps between certification cycles. These gaps might have been acceptable before but are not nearly adaptive enough to the continuously changing, ephemeral nature of agents.

The result is a compliance program that looks complete on paper but has a growing blind spot: agents that have access to your most sensitive systems, with no means to review this access. Auditors are already scrutinizing agent access with the same rigor they apply to human users, and it's the question compliance teams are currently not well equipped to answer. Enterprises will need to justify who authorized an agent’s access and show evidence that this access has been reviewed, yet most cannot generate those records today.

The agent access certification gap shows up differently across teams:

  • Engineering teams struggle to bring agents to production because of the lack of a security and compliance framework to govern them
  • Security teams cannot produce a record of which agents are connecting to sensitive systems
  • Internal audit and compliance teams run access certification programs that cover users and service accounts, but leave agent access entirely unreviewed

Access certifications built for AI agents

Okta Resource Access Certifications for AI Agents extends identity governance to cover AI agent resource connections directly:

  • Agent connection visibility and ownership mapping: Automatically discovers agent connections and ensures resource owners are assigned before running a campaign. 
  • Granular review workflows: Reviews surface the exact resource connections and permission scopes and route them directly to agent owners (or another user or group) through email and Slack.
  • Immediate automated remediation: Revoked resource connections are instantly stripped from an agent without creating manual IT help desk tickets, ensuring enforcement of least privilege for agents.
  • Audit-ready logging: Logs reviewer identity, decision timestamp, and decision context (including specific permission scopes) into exportable access certification reports ready to be presented to auditors.
  • Event-driven security response: Targeted access reviews can be launched when potential threats are detected, making access certification part of the incident response process.

Real-world scenario: Automated agent containment in action

Let’s look at a real-world example in action:

  • Agent: Kota Ticket is an IT support agent. 
  • Trigger event: Okta detects a risky configuration on Kota Ticket and triggers an automated security response, notifying the security incident response team and launching an access certification campaign assigned to Bob, Kota Ticket’s owner. 
  • Review and remediation: Bob receives an email and Slack notification that a campaign has been assigned to him.  When he opens the reviewer table, he evaluates the following:
    • Kota Ticket’s ServiceNow access (read and write access): Bob approves it. Kota Ticket creates tickets daily, so both read and write permissions are appropriate and have been in place for months.
    • Kota Ticket’s Jira access (write access): Bob revokes it. That connection was created for an earlier pilot program in a test environment, not production. There is no business reason for Kota Ticket to retain write access to Jira in production.
  • Outcome: The Jira connection is removed immediately. From a security standpoint, an attacker who might exploit the Kota Ticket agent is blocked from writing to Jira, minimizing potential damage. From a compliance standpoint, Bob’s decisions are logged, and the campaign report shows what was certified, by whom, and when.

Contrast this with the alternative: Without an access certification tool that covers agent access, Kota Ticket retains write access to Jira indefinitely. This unmanaged access increases the agent’s attack surface. If Kota Ticket were compromised, the attacker would have immediate write access to a production system. In the next quarter, when the auditor asks who certified the Kota Ticket agent’s connections, the compliance team is left without a record showing that the access was ever reviewed.

One platform for every identity, including your agents

All of these activities use the same unified governance platform Okta administrators already use to govern human and other non-human identities. Administrators get a familiar setup, reviewers get a familiar interface, and agents are governed without requiring a separate tool or workflow.

Resource Access Certifications for AI Agents fills a key gap in the Okta for AI Agents lifecycle, ensuring you maintain visibility and control over what your agents can access. Together with the ability to discover, onboard, protect, and govern agents, Okta for AI Agents provides the comprehensive foundation you need to greenlight AI agent deployments with confidence, knowing that your agent connections adhere to least privilege and integrate directly into your existing identity governance processes and framework.

Take control of your agent access today

Resource Access Certifications for AI Agents is now Generally Available for all Okta for AI Agents customers. Follow these steps to deploy AI agent identity campaigns and certify AI agent resource connections in your Okta Admin Console:

  1. Prepare your agent list: Identify the AI agents you want to audit and ensure each agent has a designated owner configured to receive review assignments.
  2. Configure notifications: As an optional step, integrate Slack with your org to route review notifications directly to agent owners alongside email alerts.
  3. Create an identity campaign: In the Admin Console, go to Identity Governance > Access Certifications, select “Create campaign,” and choose “Identity campaign.”
  4. Target your AI agents: Select “AI Agents” as the identity type and “Resource owners” as the reviewer type. Okta will create a campaign containing all associated resource connections for the selected AI agents, and route the reviews directly to each AI agent owner.

Not an Okta for AI Agents customer yet? Learn more about how Resource Access Certifications for AI Agents in Okta for AI Agents reduces blind spots, protects sensitive downstream systems, and provides complete audit trails across your entire agent catalog.

These materials are intended for general informational purposes only and are not intended to be legal, privacy, security, compliance, or business advice. You are responsible for obtaining security, privacy, compliance, or business advice from your own professional advisors. Any mention of future products, features, functionalities, or certifications in this blog is for informational purposes only. These items are not commitments to deliver and should not be relied upon to make purchasing decisions. © Okta, Inc. and/or its affiliates 2026.

Continue your Identity journey