Security1 publisher2 min readPublished
Okta extends just-in-time privilege to AI agents and CI/CD pipelines
Okta wants entitlements for AI agents and workloads evaluated continuously instead of recertified on a schedule, on the argument that approvals accumulate and access changes in the gaps between reviews.
The Watch · Security desk

What happened
- Okta shipped new capabilities across Okta Identity Governance, Okta Privileged Access and the identity threat detection technology it bought with Permiso Security earlier this year.
- Okta Privileged Access now applies just-in-time access to humans, workloads and AI agents across databases, Kubernetes environments and network devices, so privileges end when the task does.
- Okta says a 48-Hour Integrations initiative can cut integration development from two or three months to as little as two days, on a base of more than 8,000 prebuilt integrations.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Teams that move pipelines onto vaulted, on-demand credentials end up with one secret worth stealing instead of dozens, and it is the one the pipeline uses to reach the vault.
- constraint Real-time revocation constrains how engineers work under pressure: an emergency grant made outside the governed path looks identical to an attacker's, so break-glass has to be modeled before the outage.
- decision Anyone weighing a line item for non-human identity governance is buying against Okta's reading of review-cycle gaps, because the only breach number offered covers credential abuse across the board.
- capability Behavioral detections that reach across several identity providers, clouds and SaaS tenants give defenders visibility into service accounts that no recertification cycle has ever examined.
Removing standing privilege from a workload shortens the window an attacker gets. A static service-account token works until somebody rotates it. Okta's Machine-Speed Workload Protection instead has agents, automated identities and CI/CD pipelines pull credentials from a vault as they need them, with attribution preserved to an accountable human [11]. Dynamic Kubernetes Protection is aimed at the same class of secret, the hardcoded service-account token that never expires [12].
The durable secret then becomes whatever the pipeline presents to the vault to get the short-lived one [11]. An intruder works backward to that. Just-in-time issuance shortens credential lifetime and concentrates trust in the broker.
Automated Drift Detection and Remediation is the piece that touches production hardest: it identifies unauthorized access changes and revokes rogue permissions in real time [8]. That is a control loop pointed at live systems. An out-of-band grant an engineer makes at 3am during an incident looks like drift, so the break-glass path has to be registered somewhere the remediation engine will respect it.
The approval path gets attention too. Advanced Entitlement Management for AWS tracks fine-grained permissions across developers, workloads and AI agents while maintaining separation of duties [6]. Intelligent Request Recommendations moves access requests into Slack and ServiceNow to cut approval queues and what Okta calls "blind rubber-stamping" [7].
Okta's case for all of it is that predefined permissions and periodic recertification leave gaps between review periods, as approvals accumulate and access changes [15]. "Nobody wants to slow AI down, but you can't simply hand out access and hope for the best," Okta Chief Product Officer Ely Kahn said [4]. Kahn also said enterprises need "a one-stop shop to govern, secure, and monitor every identity: humans, AI agents, and non-human workloads alike" [5].
The delivery claim is checkable. Okta says its 48-Hour Integrations initiative uses AI to build governance and privileged access integrations in as little as two days, against the two or three months that work takes now, on a base of more than 8,000 prebuilt integrations [13]. Two months is about 60 days and three is about 90, so the stated cut runs 30-fold to 45-fold [16]. Permiso, acquired earlier this year, contributes behavioral analytics, identity-risk signals and threat-informed detections that span multiple identity providers, cloud environments and SaaS applications [14][2].
The one breach figure in the announcement comes from the 2026 Verizon Data Breach Investigations Report: credential abuse accounts for 39% of breaches [9]. It measures credential abuse across breaches, and covers human credentials alongside everything else [18]. The SC World account does not list pricing or availability dates for any of the new features [17].
What to watch
- Whether Okta publishes pricing and general-availability dates, and whether the Permiso detections ship inside OIG and OPA licences or as a separate SKU.
- First customer accounts of Automated Drift Detection revoking access that an engineer granted legitimately during an incident.
- Whether the next Verizon DBIR breaks credential abuse out by human versus workload and agent identities.