Security1 publisher2 min readPublished
Blueprint Alliance coalition aims to build agentic AI security standards around four key questions, lists six identity principles as governance guidance
Okta has gathered a dozen-odd technology companies into the Blueprint Alliance to write open security and interoperability standards for AI agents. The standards are still unwritten, and the six principles published so far are identity-management rules, the category Okta sells.
The Watch · Security desk

What happened
- Okta CEO Todd McKinnon told the Oktane keynote audience that "No one company can secure AI agents alone."
- The alliance says its open, freely shared standards will answer four questions: where agents are, what they can do, what they are doing, and how to respond.
- Members commit to interoperability across four existing open standards: MCP, OCSF, the Shared Signals Framework and the Continuous Access Evaluation Profile.
- Okta's Jeremy Kirk said a risk signal passed from CrowdStrike into Okta could drive workflows such as stepping up MFA or logging a user out of the application.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- contradiction Okta warns buyers off vendors that promise to fix all of AI security while it leads a framework whose principles describe Okta's own product category.
- decision Buyers can hold every agent-security pitch, Okta's included, to the alliance's four questions and ask what signals the product passes to other vendors' tools.
- constraint Until the standards are devised, containing a compromised agent depends on the signals a buyer's current tools already exchange. The alliance adds nothing to incident response yet.
SC Media described the six guiding principles on the alliance website as identity-management principles [9]. In order: every agent is a distinct security identity; access is scoped to the task, not standing; delegation is traceable end-to-end; runtime behavior is monitored, not just provisioned; containment is instant and reversible; governance adapts at the velocity of AI [9]. SC Media wrote that it is not clear how a data-security provider could implement those principles, though such a vendor might have an easier time with the four questions [10].
Okta's executives made the case against single-vendor claims themselves. "Every security vendor offers to fix all your problems with AI," Okta President and COO Eric Kelleher said at a press briefing after the keynote [4]. "But in reality, it's going to take collaboration at every part of the stack," he said, "not just identity, but endpoints, integrations, et cetera." [5] SC Media put identity providers like Okta on its list of vendors that still claim to have the one solution for locking down AI instances [16].
Okta executives told SC Media the alliance is not a bid for industry dominance [19]. "Nobody else was taking the initiative to do it, so we wanted to actually come forward because we're big on standards, big on neutrality," said Sandeep Kumbhat, Okta's Global Field CTO [6]. The report identifies the membership only as a dozen-odd companies and gives no date for the standards [20].
Kumbhat described the planned output as reference architecture. "The idea is anything from a reference-architecture perspective, nothing proprietary gets built," he said. "These are more standard API calls or standard protocol calls. So the intent is never to actually build sophisticated integrations. It is more to share things, share signals on an existing protocol." [12] If the standards are devised, tools in different parts of the software stack should be better able to share information and act quickly on rogue or compromised agent behavior, according to Jeremy Kirk, Okta's director of threat intelligence [13].
The principle closest to what an attacker exploits is task-scoped access in place of standing access [9]. Travis Tripp, chief technologist for the HPE GreenLake Platform, described that risk at an Oktane breakout session. "We've got a brain in a jar making predictions, and when you give it a tool and credentials, you get consequences," Tripp said [15].
What to watch
- Publication of the full member roster, and whether any data-security or network-security vendor signs on to the six identity principles as written.
- A first reference architecture that defines which agent events members send over the Shared Signals Framework and CAEP.
- Shipping products from two or more members that exchange agent risk signals and trigger containment without custom integration.