Okta Adds AI Agent Runtime Gateway, Forms Blueprint Alliance With AWS, CrowdStrike
Okta launched an AI agent runtime gateway and a wider kill switch at Oktane, and formed the Blueprint Alliance with AWS, CrowdStrike and nine other vendors.
The runtime component is Agent Gateway, which sits in the execution path between an agent and the tools it calls, enforcing policy and logging each interaction as it occurs. Okta's existing visibility into agent activity comes from agent events captured in its System Log, which customers stream to security information and event management systems for review after the fact. The gateway is also where the kill switch is headed. Administrators can already deactivate an agent from the admin console, which blocks new sessions; once an agent routed through the gateway is deactivated there, Okta plans for every active token it holds to be revoked and every session in flight shut down.
Discovery now extends to employee laptops and desktops. Okta can register known agents directly or import them from platforms such as Amazon Bedrock and Salesforce Agentforce, and shadow agents working through the browser are picked up as well. A new feature, Shadow AI Agent Discovery for Endpoints, looks for unmanaged agents running on those machines.
Once an agent is registered, the remaining additions govern what it connects to, whether an app, a Model Context Protocol server or another agent. Agent SSO brings Cross App Access, which Okta debuted in June 2025, to all of its single sign-on customers, allowing them to replace non-expiring keys with short-lived tokens tied to an identity. Rules on which agents may call which other agents come through Agent-to-Agent Connections, with each handoff recorded in an auditable chain. Resource Access Certifications review agent connections over time to catch standing or excessive permissions, and Configuration Designer draws agent-to-resource connections visually for administrators.
Okta said the product additions target agents that end up with more access than anyone intended. An employee who links an AI assistant to everyday tools can give it a path into sensitive systems without realizing it, and if that person later leaves, nothing stops the agent from running on in the background ungoverned. "The challenge businesses face is the same access that makes agents powerful also makes them dangerous," said Ric Smith, president of products and technology at Okta.
The Blueprint Alliance takes the framework behind those products outside Okta. Founding members besides Okta include Amazon Web Services Inc., CrowdStrike Holdings Inc., Google Cloud, Databricks Inc., Docker Inc., Lovable Labs Inc., Proofpoint Inc., Salesforce Inc., ServiceNow Inc., Wiz Inc. and Zscaler Inc., 12 members in total. Wiz holds a seat of its own alongside Google Cloud, six months after Google closed its $32 billion purchase of the company. "No single technology or vendor can secure the agentic era alone," said Daniel Bernard, chief business officer at CrowdStrike.
The alliance cited research from Gartner Inc. predicting that the average global Fortune 500 enterprise will have more than 150,000 agents in use by 2028, and that only 13% of organizations believe they have the right AI agent governance in place. The March version of the blueprint was built around questions about where agents run, what they can reach and what they do. The alliance's version adds how an enterprise should respond when an agent is compromised, with containment through token revocation, session termination or network quarantine and a staged, auditable path for restoring it afterward. Members have agreed on principles that include treating every agent as a first-class identity and scoping its access to the task at hand.
Members are already testing interoperability across open standards, including MCP, the Open Cybersecurity Schema Framework and the Shared Signals Framework, with the goal that a threat signal raised by one member's runtime monitor triggers action across every connected control plane. Joint test results and reference integrations will be published on a regular basis. GE Appliances and the nonprofit World Central Kitchen are serving as strategic advisers. Brian Stoll, chief technology officer at World Central Kitchen, said the organization is using agentic technology to support disaster response and needs governance "as dynamic as the agents themselves," adding that taking part in the alliance might also bring "a better night's rest for the CTO."
Of the new Okta features, Agent SSO, Agent-to-Agent Connections and Resource Access Certifications are generally available today, SiliconANGLE reported.
Editor's Summary
Okta used its Oktane conference to add runtime enforcement, endpoint discovery and expanded token revocation to its AI agent identity platform, alongside new controls for agent-to-agent and agent-to-resource access. The company also convened 12 vendors, including AWS, CrowdStrike and Google Cloud, to turn its March agent security blueprint into an open reference architecture covering compromise response and cross-vendor interoperability. The announcements respond to research cited by the alliance projecting more than 150,000 agents per large enterprise by 2028, with few organizations confident in their governance.