ComputerWeekly

Okta debuts agentic lifecycle management tools, AI kill switch


Setting out to help its customers answer pressing questions such as, ‘where are my agents?’, ‘what can they do?’, ‘what are they doing?’ and ‘how do I respond?’, Okta has become the latest in a string of cyber firms to debut new security capabilities to manage artificial intelligence (AI) agents.

The identity and access management (IAM) house unveiled a range of innovations that collectively build on a vision first outlined this time last year at Okta’s 2025 Oktane event, where CEO Todd McKinnon proudly proclaimed that AI security and identity security were becoming indistinguishable as he launched the first iteration of Okta for AI Agents.

As Okta’s customers descended once more on Las Vegas, Nevada for Oktane 2026 in the wake of a string of high-profile mishaps in which mismanaged agents went rogue, Okta for AI Agents is now being enhanced to better manage agentic risk while providing agents with enough access to accomplish appropriate tasks, all the while ensuring humans retain visibility and control.

Okta invited conferencegoers to consider a scenario in which an employee links an AI agent to their everyday tools to work faster but unintentionally give it approved access to sensitive systems. Then, when they leave the company, the agent effectively becomes an orphan, running in the background “ungoverned and unknown”.

Okta for AI Agents, it claimed, will eliminate the danger from this sort of scenario, bringing centralised governance and end-to-end agent lifecycle management, runtime policy enforcement, and should all else fail, a ‘last resort’ kill switch.

“The challenge businesses face is the same access that makes agents powerful also makes them dangerous,” explained Okta president of products and technology Ric Smith.

“For over a decade, Okta has continuously modernised how the workforce authenticates and connects to every app they use. That same discipline extends to AI agents. Our goal is to give enterprises the visibility and runtime assurance they need to turn AI agents from an unmanaged security risk into a massive competitive advantage.”

Embracing agents

James Simcox, chief product officer and chief operating officer at UK-based fintech firm Equals Money, is among the Okta customers to have wholeheartedly embraced agentic AI, in some cases rebuilding basic business processes from scratch after finding traditional workflows do not always translate effectively to agents.

“Across the business we’ve got agents running almost everywhere. You can call us up now to book an FX [foreign exchange] transaction on the phone where the entire interaction will be agentic – it sounds like a human, it feels like a human,” he said.

“[But] if we enable financial transactions in that agentic environment, how we secure it is very, very difficult,” he added.

Echoing McKinnon’s thesis that non-human identities are now to some extent akin to human ones, Simcox said that Equals Money now treats its AI agents as, essentially, staff members with specific roles, permissions and identities – not mere service accounts.

To comply with the UK and Europe’s complex regulatory environments, Equals Money has implemented an agentic platform that continuously audits the ‘thinking’ process and behaviours of every agent so that the company can justify any decision taken by the agent, like suspending a fraudulent account – in court if needed, since deploying a customer-facing agent presents a far higher liability risk in the financial services sector.

Additionally, the firm assigns its agents specific, tightly-defined roles – such as changing customer email addresses – with highly-limited permissions to stop oversharing or unauthorised access to out-of-scope metadata.

And to mitigate any lingering friction between Equals Money’s engineering and security teams, said Simcox, the organisation has implemented a multi-modal review process where one agent must review code written by another before it can be released.

“The way that I’m seeing the Okta products evolve for me is exactly what I want, which is good. It is now about how do we control agents as relevant entities,” said Simcox, looking ahead to the latest introductions.

“The thing I’m really excited to get my hands on is the piece around the kill switch functionality,” he added. “It’s very hard currently for us to stop an agent if it’s doing something that it shouldn’t be doing.”

Blueprint for a safe agentic stack

Meanwhile, Okta has also teamed up with a crowd of other suppliers, including the likes of Amazon Web Services (AWS), CrowdStrike, Databricks, Docker, Google Cloud, Proofpoint, Salesforce, ServiceNow, Wiz and Zscaler to form a cross-industry coalition – the Blueprint Alliance – that aims to help customers operate agentic stacks as single unified, governed systems.

The founding members of the coalition propose to align towards a shared set of principles – or blueprint – to secure AI agents in which every agent is treated as a ‘first class’ identity, access is scoped to tasks, delegation is traceable, runtime behaviour is subject to continuous monitoring, containment is instant and reversible, and governance is adaptable to the rapid evolution of AI.

The same four big questions at the heart of Okta’s tech enhancements also sit at the heart of the blueprint, with the ultimate goal being a zero-trust, agentic control plane that gives technology leaders a means to scale agentic deployments safely and securely.

According to Steven Tamm, senior vice president of ecosystem at Okta, the supplier originated the blueprint because it recognised customers would need a consistent architecture to secure agents, governing identity, access and execution across the entire stack, without shutting out the autonomy that makes agents useful in the first place.

“Getting there required founding members across the Blueprint Alliance to align on a shared approach rather than each vendor solving it alone. We’re glad to have contributed to that work, and we look forward to the industry building and testing against it as we help secure the future of AI,” he said.

Domestic equipment giant GE Appliances and charity World Central Kitchen have both signed on to serve as strategic advisors and will help the alliance refine and validate approaches to securing agentic AI as they continue to develop in the future.

“AI agents have the potential to transform manufacturing by accelerating problem-solving, improving quality and strengthening collaboration across the value chain. Unlocking that value at scale requires strong governance, clear visibility into where agents operate, what they can access and how they make decisions,” said Mandar Deo, GE chief digital technology advisor.

“GE Appliances is bringing a real-world manufacturing perspective to help shape and validate a secure, scalable architecture that can operate across complex industrial environments – while maintaining accountability, trust and human controls.”

Brian Stoll, chief technology officer at World Central Kitchen – which was established by celebrity chef and restaurateur José Andrés – added: “In order to support the urgent technology demands of disaster response on a global scale, World Central Kitchen is embracing the dynamic benefits of agentic technology.

“To do so responsibly requires establishing governance that is as dynamic as the agents themselves,” said Stoll. “We are looking forward to participating in the Blueprint Alliance for this exact reason: to help establish principles, processes, and tooling for agentic discovery, ownership, runtime control, and observability – not to mention a better night’s rest for the CTO.”



Source link