AI News Feed
Market watch
Cybersecurity

Okta launches AI agent runtime gateway to police agent actions inline

Okta has launched an AI agent runtime gateway that sits in the path of attempted agent actions and enforces authorization at runtime, according to SiliconANGLE. Intent-based authorization is planned for 2027.

Smith said sitting inline marks a new role for the company. "That is a very different transition for Okta," he said. "Dominantly, we had not been inline, so with us moving in that direction, it means that we can do a lot more decision-making in terms of what we authorize."

Being inline also lets Okta watch for threats rather than simply grant permissions, Smith said, and that logic drove the company's acquisition of Permiso Security, which adds detection capabilities as Okta expands further into cybersecurity. Full visibility into an agent's behavior, however, requires observing both the prompt entering the model and the actions it proposes.

"You really have to sit in two positions around these models," he said. "One is on the front end of it so that you can capture the conversation being presented. Then, based on the Gateway that we've already announced, we already sit on the back end of the model where we can capture all of the actions that the model ultimately wants to take and then also make decisions around that."

Combining those vantage points could allow Okta to judge whether a proposed action should proceed, Smith said. In 2027, the company plans to add intent-based authorization to its agent gateway, using an agent's context and permitted tools to inform access decisions. Determining how narrowly to scope those permissions without blocking legitimate work remains an open research question.

"It's a hard problem for us to solve, and so that's why we're hard at work doing all the research around it," Smith said. "But we think that is pay dirt in terms of what actually has to happen with the agent workforce."

Editor's Summary

Okta has launched an AI agent runtime gateway that places the identity provider inline with attempted AI agent actions, enforcing authorization decisions at runtime rather than only at login, and its acquisition of Permiso Security adds detection capabilities to that position. Okta plans to add intent-based authorization to the gateway in 2027, a step Smith said depends on research into scoping agent permissions without blocking legitimate work. The shift moves the company further into cybersecurity by governing agent behavior after access is granted.