AI News Feed
Market watch
Products & Applications

JumpCloud extends Agentic IAM to govern autonomous AI agents

JumpCloud extended its Agentic IAM service on Sept. 10, giving IT teams a unique identity, a named human owner and expiring privileges for every autonomous AI agent running inside their systems.

An agent without an owner will not run at all. JumpCloud tracks each registered agent from creation through to retirement, so administrators can see what exists and who is responsible for it.

Four capabilities make up the release. Every agent registered with JumpCloud receives a unique identity, which lets an administrator audit what the agent did or cut off its access without locking out the employee who deployed it. The platform also hunts for Model Context Protocol servers that were set up outside official channels and routes them through the JumpCloud AI Gateway.

Device trust and access policies that already govern sanctioned software now extend to AI tools. The fourth piece is a privileged access management server built on the same protocol, which JumpCloud said will ship before the end of the fourth quarter. It is intended to retire the shared application programming interface keys that agents currently pass around.

Privileged access rules now apply to agents directly, and each grant expires with the task it was issued for, so nothing broader is handed out in the meantime. According to JumpCloud, that is what allows companies to point AI at legacy systems without rebuilding them.

The release addresses a gap the company has measured. Only 21% of organizations have put governance controls around nonhuman identities, the lowest score among 10 recommended AI security practices in JumpCloud's quarterly survey of IT leaders published in July. Nonhuman identities outnumber people at 83% of the organizations surveyed.

Joel Rennich, JumpCloud's senior vice president of product management, said AI agents are "changing how identity management works." The tools move fast, he said, and the IT department has to know which agents exist, who owns them and what they can touch.

Rahul Kamdar, senior vice president of product at JumpCloud, said agents do not simply reach into systems. They "act inside them," he said, which makes identity the control plane for AI security.

Agentic IAM launched in April. JumpCloud released a version on Google Cloud in June, expanding an existing partnership with the cloud provider, and shipped its first AI features in January, shadow AI detection among them.

JumpCloud is based in Louisville, Colorado. Investors have put $408 million into the business across 10 rounds. Sapphire Ventures led the most recent, a $159 million Series F, five years ago this month, when the company was valued at $2.56 billion.

Editor's Summary

JumpCloud's Agentic IAM update places autonomous AI agents in the corporate directory, requires a named human owner for each one and limits privileged grants to a single task. The company is targeting shared API keys and unmanaged Model Context Protocol servers, two paths by which agents can reach systems outside IT oversight. JumpCloud's own July survey found governance of nonhuman identities to be the least adopted of 10 recommended AI security practices, with such identities already outnumbering people at most organizations polled.