Product1 publisher3 min readPublished
Okta puts an enforcement point between AI agents and the tools they call
Agent Gateway enforces policy on each tool call and logs it as it happens, while deactivating an agent in the console today only blocks new sessions. Okta says revoking live tokens and cutting sessions in flight is planned.
The Product Desk · Product desk

What happened
- Okta used the opening day of its Oktane conference in Las Vegas to announce runtime enforcement and a wider kill switch for its Okta for AI Agents platform.
- A feature called Shadow AI Agent Discovery for Endpoints extends discovery to employee laptops and desktops, looking for unmanaged agents running on those machines.
- Okta and 11 other vendors, among them AWS, CrowdStrike and Google Cloud, formed the Blueprint Alliance to rework Okta's March agent security framework into an open, multivendor reference architecture.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- decision Whoever owns identity has to decide whether agent traffic routes through one more hop, and accept that the inspection point becomes a dependency of every tool call an agent makes.
- constraint Until gateway revocation ships, an agent already holding a live token sits outside what the console can stop, so offboarding a person and offboarding their agent remain two separate jobs.
- exposure Endpoint discovery will surface assistants on staff machines that nobody registered, and that inventory lands on the identity team's desk before any policy covers it.
- precedent The alliance's compromise-response section gives buyers a vendor-neutral question list, and suppliers outside the twelve will be asked to answer it in security reviews.
The difference between what Okta had and what it is adding is where in the sequence the check happens. Agent events land in Okta's System Log, and customers stream that to a security information and event management system, so the review happens after the tool call already went through [6]. Agent Gateway sits in the path itself, enforcing policy and logging each interaction as it happens [4].
The kill switch is split across the two. Deactivating an agent from the admin console blocks new sessions today [7]. The part an incident responder needs, every active token revoked and every session in flight shut down, is what Okta plans to do once an agent is routed through the gateway [8]. The announcement as reported does not include availability dates or pricing [24].
Okta describes an employee linking an AI assistant to everyday tools, handing it a path into sensitive systems without realizing, then leaving the company with the agent still running in the background, ungoverned [3]. "The challenge businesses face is the same access that makes agents powerful also makes them dangerous," said Ric Smith, president of products and technology at Okta [5].
The provisioning-side change ships in the same release and gets less stage time. Agent SSO extends Cross App Access, which Okta debuted in June 2025, to all of its single sign-on customers, so a non-expiring key can be swapped for a short-lived token tied to an identity [11]. The non-expiring key is why the departed employee's assistant keeps working at all. Shadow AI Agent Discovery for Endpoints then looks for unmanaged agents running on staff laptops and desktops [9].
Gartner, cited by the alliance, expects the average global Fortune 500 enterprise to be running more than 150,000 agents by 2028 [16]. In the same release Gartner said only 13% of organizations think they have the right AI agent governance in place, which leaves 87% who do not [17][18]. Okta's Resource Access Certifications review agent connections over time to catch standing or excessive permissions [13]. Reviewing 150,000 of them once each a year works out to about 411 reviews a day [23].
The March blueprint was built around where agents run, what they can reach and what they do [19]. The alliance version adds what an enterprise does when an agent is compromised: containment through token revocation, session termination or network quarantine, and a staged, auditable path for restoring it afterward [20]. Members are testing interoperability across the Model Context Protocol, the Open Cybersecurity Schema Framework and the Shared Signals Framework, with the goal that a threat signal raised by one member's runtime monitor triggers action across every connected control plane [21]. "No single technology or vendor can secure the agentic era alone," said Daniel Bernard, chief business officer at CrowdStrike [22]. Wiz holds a seat of its own next to Google Cloud, six months after Google closed its $32 billion purchase of it [15].
The first thing to settle is whether you can name every agent holding a credential an employee minted through an OAuth link. The second is whether, if that employee leaves tomorrow, anything cuts the agent's session while it is running. A team that answers yes to the first and no to the second is buying the gateway for the revocation, and revocation is the piece Okta describes as planned [8].
What to watch
- A general availability date and a price for gateway-routed token revocation and session termination.
- The alliance's first published joint test results, which would show whether one member's threat signal actually moves another member's controls.
- Whether identity vendors outside the twelve publish a competing agent blueprint or sign on to this one.