Companies already know how to issue an employee account, grant access and shut it off when the person leaves. AI agents create the same identity problem with an extra twist: they can act continuously, call tools and delegate to other agents. Okta and 11 other vendors are trying to turn that problem into a shared architecture.1, 2

IN BRIEF

AI agents can call tools, access data and delegate work across systems, so companies need to know which agent is acting, who owns it, what it can access and how to stop it. Okta and 11 other founding vendors created the Blueprint Alliance around a shared reference architecture. It is a vendor-led blueprint, not yet a universal standard.1, 2

A practical agent identity lifecycle. Discover and register the agent before it can act broadly.: 01. Assign an accountable human or business owner.: 02. Grant only the task-specific permissions the agent needs.: 03. 3 of 6 entries shown. Selected labels are abbreviated. Full detail appears in the article.
A practical agent identity lifecycle. 3 of 6 entries shown. Selected labels are abbreviated. Full detail appears in the article.
The identity questions an agent creates1, 2
QuestionWhy it mattersControl
Where is the agent?Unregistered or shadow agents can act without a clear owner.Discovery and registration
What can it do?Standing credentials can let an agent reach more systems than a task requires.Task-scoped authorization
What is it doing?Delegation and tool calls can make activity hard to trace.Runtime monitoring and audit
How do we stop it?A compromised or misbehaving agent needs a fast off-switch.Revocation, containment and recovery

An agent identity has to be more than an API key

The Blueprint Alliance says agents should be treated as first-class identities. The idea is that an organization should be able to discover an agent, tie it to an accountable owner, grant permissions for a specific task, record delegation to sub-agents and revoke access when the work ends or risk appears.1, 2

Delegation makes the identity chain harder

A human may authorize one agent, which then calls another service or sub-agent. The alliance argues that delegation should stay traceable so a security team can reconstruct who authorized the original action and which identities acted along the way. That is closer to a chain of custody than a single login event.1

The control point has to sit in the runtime path

Okta's September product update shows how one vendor is implementing the idea. Its Agent Gateway is designed to sit between agents and enterprise tools, apply identity and policy on tool calls and produce a shared audit trail. Okta also says resource connections can be reviewed through identity certification campaigns.3

A practical agent identity lifecycle

  1. Discover and register the agent before it can act broadly.
  2. Assign an accountable human or business owner.
  3. Grant only the task-specific permissions the agent needs.
  4. Preserve a traceable record when the agent delegates work.
  5. Monitor actions and tool calls while the agent is running.
  6. Revoke or quarantine the identity when the task ends or risk appears.

A coalition blueprint is not the same as a standard

The founding members include AWS, CrowdStrike, Databricks, Docker, Google Cloud, Lovable, Okta, Proofpoint, Salesforce, ServiceNow, Wiz and Zscaler. Their agreement matters because those products sit in different layers of the enterprise stack. It does not mean the market has adopted one technical standard or that interoperability is finished.1

This extends the control problem in S&C's enterprise-browser analysis. A browser can enforce policy around human work. Agent identity asks how to enforce ownership, permission and revocation when the actor is software. It also complements the Muse permissions story, which showed how much access a personal agent may need.

The important shift is that identity is no longer only about proving which person signed in. In an agentic company, security also has to answer which software actor is acting, on whose authority, with which permissions and whether that authority can be withdrawn immediately.

Sources and methodology

Sources checked September 28, 2026. Dates and periods for individual figures are stated beside them.

  1. Okta: Blueprint Alliance launch ↗Accessed 2026-09-28
  2. Okta: Governing agentic execution blueprint ↗Accessed 2026-09-28
  3. Okta Support: What's New in Okta for AI Agents ↗Accessed 2026-09-28
Scope and assumptions

The Blueprint Alliance is a vendor-led coalition and its architecture is not a universal industry standard.

Some Okta capabilities announced in September 2026 were not yet generally available, so the article separates current controls from planned product features.

The article explains identity and governance concepts rather than evaluating the security effectiveness of any vendor implementation.

Continue reading

Island Raised $400M at a $6.4B Valuation. Why Is an Enterprise Browser Worth That Much? →

Meta’s AI Can Send Emails and Make Purchases. What Should You Let It Touch? →

Google’s Security Agent Found 500+ XSS Bugs. The Trick Was Proving the Exploit →