CrowdStrike has added an identity provisioning system for AI agents to its Falcon platform, along with parallel security investigation capabilities and a feature to preemptively block malicious open-source packages.
SiliconANGLE reported on Sept. 2 that CrowdStrike unveiled the features at its annual Falcon 2026 conference in Las Vegas.
The core feature is an identity provisioning system for AI agents called Agentic IdP. It registers agents within a company in a single directory and assigns cryptographic identities that cannot be forged or shared. A Continuous Identity system then determines whether access is allowed.
Registration is carried out through the agent detection and control product Falcon Guardian. When Falcon Guardian finds agents across an enterprise, Agentic IdP registers each agent. It does not provide agents with long-term credentials, and brokers only tokens that allow the minimum privilege and minimum time for each task. All actions are tied to the person or workload for which the agent is acting.
CrowdStrike also changed how security operations centres conduct investigations. Charlotte AI deploys multiple agents at the same time across endpoints, identity, software as a service, cloud and network areas to conduct a single investigation in parallel. Targets include attacks on corporate AI systems such as model abuse, prompt injection and data leaks through AI assistants. The core of its real-time supply chain attack defence is blocking malicious packages before installation. Security teams can set detailed policies such as a minimum package exposure period.