[DigitalToday reporter Chi-gyu Hwang (황치규)] Identity management platform Okta unveiled runtime enforcement features and an expanded kill switch to strengthen security controls for AI agents.
SiliconANGLE reported on Sept. 22 that Okta announced an update to “Okta for AI Agents” at its annual Okta event held in Las Vegas.
The newly introduced features focus on addressing problems that arise when AI agents gain broader access rights than intended. As employees connect AI assistants to work tools, sensitive system access paths can be opened, and agents can continue operating without control even after an employee leaves, the company said.
At the core is “Agent Gateway”. It applies policies in the execution path between agents and the tools they call, and records each interaction in real time. Previously, the main approach was to send agent events left in system logs to security information and event management systems for after-the-fact review.
The kill switch is also expanded. Currently, administrators can disable agents in the admin console to block only new sessions. With the update, disabling agents that pass through the gateway will cancel all active tokens and end sessions in progress.
Detection is expanded to employee laptops and desktops. Okta could already register known agents directly or bring them in from platforms such as Amazon Bedrock and Salesforce Agentforce, and it provided a feature to find shadow agents that operate through browsers. The newly introduced “Shadow AI Agent Discovery for Endpoints” feature finds unmanaged agents on those devices.
Okta also introduced the Blueprint Alliance with 11 companies, including AWS, CrowdStrike and Google Cloud, as part of expanding the agent security framework ecosystem it unveiled in March.
Databricks, Docker, Lovable Labs, Proofpoint, Salesforce, ServiceNow, Wiz and Zscaler also participate in the Blueprint Alliance. The Blueprint Alliance supports a response system that includes token revocation, session termination, network isolation and subsequent recovery procedures in the event of an agent breach.