Companies already know how to issue an employee account, grant access and shut it off when the person leaves. AI agents create the same identity problem with an extra twist: they can act continuously, call tools and delegate to other agents. Okta and 11 other vendors are trying to turn that problem into a shared architecture.1, 2
AI agents can call tools, access data and delegate work across systems, so companies need to know which agent is acting, who owns it, what it can access and how to stop it. Okta and 11 other founding vendors created the Blueprint Alliance around a shared reference architecture. It is a vendor-led blueprint, not yet a universal standard.1, 2

| Question | Why it matters | Control |
|---|---|---|
| Where is the agent? | Unregistered or shadow agents can act without a clear owner. | Discovery and registration |
| What can it do? | Standing credentials can let an agent reach more systems than a task requires. | Task-scoped authorization |
| What is it doing? | Delegation and tool calls can make activity hard to trace. | Runtime monitoring and audit |
| How do we stop it? | A compromised or misbehaving agent needs a fast off-switch. | Revocation, containment and recovery |
An agent identity has to be more than an API key
The Blueprint Alliance says agents should be treated as first-class identities. The idea is that an organization should be able to discover an agent, tie it to an accountable owner, grant permissions for a specific task, record delegation to sub-agents and revoke access when the work ends or risk appears.1, 2
Delegation makes the identity chain harder
A human may authorize one agent, which then calls another service or sub-agent. The alliance argues that delegation should stay traceable so a security team can reconstruct who authorized the original action and which identities acted along the way. That is closer to a chain of custody than a single login event.1
The control point has to sit in the runtime path
Okta's September product update shows how one vendor is implementing the idea. Its Agent Gateway is designed to sit between agents and enterprise tools, apply identity and policy on tool calls and produce a shared audit trail. Okta also says resource connections can be reviewed through identity certification campaigns.3
A practical agent identity lifecycle
- Discover and register the agent before it can act broadly.
- Assign an accountable human or business owner.
- Grant only the task-specific permissions the agent needs.
- Preserve a traceable record when the agent delegates work.
- Monitor actions and tool calls while the agent is running.
- Revoke or quarantine the identity when the task ends or risk appears.
A coalition blueprint is not the same as a standard
The founding members include AWS, CrowdStrike, Databricks, Docker, Google Cloud, Lovable, Okta, Proofpoint, Salesforce, ServiceNow, Wiz and Zscaler. Their agreement matters because those products sit in different layers of the enterprise stack. It does not mean the market has adopted one technical standard or that interoperability is finished.1
This extends the control problem in S&C's enterprise-browser analysis. A browser can enforce policy around human work. Agent identity asks how to enforce ownership, permission and revocation when the actor is software. It also complements the Muse permissions story, which showed how much access a personal agent may need.
The important shift is that identity is no longer only about proving which person signed in. In an agentic company, security also has to answer which software actor is acting, on whose authority, with which permissions and whether that authority can be withdrawn immediately.
Sources and methodology
Sources checked September 28, 2026. Dates and periods for individual figures are stated beside them.
- Okta: Blueprint Alliance launch ↗Accessed 2026-09-28
- Okta: Governing agentic execution blueprint ↗Accessed 2026-09-28
- Okta Support: What's New in Okta for AI Agents ↗Accessed 2026-09-28
Scope and assumptions
The Blueprint Alliance is a vendor-led coalition and its architecture is not a universal industry standard.
Some Okta capabilities announced in September 2026 were not yet generally available, so the article separates current controls from planned product features.
The article explains identity and governance concepts rather than evaluating the security effectiveness of any vendor implementation.
Continue reading
Island Raised $400M at a $6.4B Valuation. Why Is an Enterprise Browser Worth That Much? →
Meta’s AI Can Send Emails and Make Purchases. What Should You Let It Touch? →
Google’s Security Agent Found 500+ XSS Bugs. The Trick Was Proving the Exploit →