Skip to content

Security2 publishers3 min readPublished

Okta's Blueprint Alliance gives buyers a six-point checklist for AI agent identity

Okta and 11 vendors including AWS, Google Cloud and CrowdStrike signed six shared principles for securing AI agents under a new Blueprint Alliance. Buyers can put the list to vendors in procurement now, while Okta's release describes a reference architecture with no stated way to test compliance.

The Watch · Security desk

Illustration accompanying Okta's Blueprint Alliance gives buyers a six-point checklist for AI agent identity

What happened

  • Okta and 11 other vendors, among them AWS, Google Cloud, CrowdStrike, Salesforce, Wiz and Zscaler, announced the Blueprint Alliance for securing AI agents.
  • Members agreed six principles: per-agent identity, task-scoped access, traceable delegation, continuous runtime monitoring, instant reversible containment and adaptive governance.
  • At its Oktane conference in Las Vegas, Okta added Agent Gateway, a policy-enforcing and logging intermediary for agent traffic, and endpoint discovery of shadow agents.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Buyers can write the six principles into RFPs and contracts and ask each signatory to demonstrate them, a request that vendors who signed the list will find hard to refuse.
  • exposure Agents left running after an employee leaves keep whatever access they were granted until someone finds and revokes them; discovery tied to a named owner is the control aimed at that gap.
  • constraint Until Okta ships its kill switch, its own product cannot be tested against the principle that containment be instant and reversible.
  • contradiction Coverage describes a path to an open standard, but with only principles and a reference architecture published, a vendor's claim to be aligned with Blueprint is self-reported and has to be checked feature by feature.

Okta frames the problem as an identity gap in which shadow agents multiply, credentials cross trust boundaries and agents execute beyond their intended scope [8]. For an attacker, all three come down to one asset: a working credential held by software that nobody is watching. The architecture's discovery layer is meant to catalog every agent, whether internally built, imported from SaaS and third parties, or unmanaged shadow AI [7]. Each is then registered as a distinct identity with an accountable human owner or team [7]. I'd expect the third-party agents to be the hardest to inventory, since their credentials are used from infrastructure the buyer does not run.

The coverage is narrow by design. According to Okta's release, the architecture addresses governance once agents are deployed and complements separate work on model security and supply chain integrity [18]. A poisoned model or a tampered agent package sits outside it.

Five of the six principles describe something a vendor can demonstrate in a pilot [4]. A buyer can ask to see every agent listed with its owner, the task an access grant is scoped to, the delegation chain from human to agent to tool, the runtime log, and an agent revoked and then restored. The sixth, that governance "adapts at the speed AI moves," has no test a buyer can run [4].

Of Okta's own Oktane releases, Agent Gateway maps to the scoping and runtime-monitoring principles [10]. Endpoint discovery answers the first of the architecture's four questions, "Where are my agents?" [6][10]. The kill switch that would revoke active tokens and terminate sessions when an agent is deactivated is still described as planned [11].

The status of the work depends on who describes it. SC World, summarizing Silicon Angle, wrote that the alliance is working to evolve Okta's initial framework into an open standard [14]. Okta's release calls the result an open, multi-vendor reference architecture, grown from a blueprint Okta first introduced in March 2026 [5]. The release does not describe a specification or a compliance test. Okta plus the 11 companies it named makes 12 vendors, the count SC World also gave [3]. Two outside organizations, GE Appliances and World Central Kitchen, signed on as strategic advisors to help refine and validate the approach [15].

The case for urgency rests on a Gartner forecast cited in Okta's release: more than 150,000 agents in use at an average global Fortune 500 enterprise by 2028, against 13% of organizations that think they have the right agent governance in place [9].

"To do so responsibly requires establishing governance that is as dynamic as the agents themselves," said Brian Stoll, chief technology officer of World Central Kitchen [16].

"Unlocking that value at scale requires strong governance, clear visibility into where agents operate, what they can access and how they make decisions," said Mandar Deo, chief digital technology officer at GE Appliances [17].

What to watch

  • Whether the alliance publishes a specification with conformance criteria or hands the architecture to a standards body.
  • When Okta ships the kill switch that revokes active tokens and terminates sessions on deactivation.
  • Whether other signatories ship features that trace delegation across vendor boundaries, the principle that depends most on cooperation between them.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories