Okta Expands AI Agent Security With New Identity Governance Tools

Okta has introduced a new set of identity security capabilities designed to help organizations securely manage AI agents as they become more deeply integrated into enterprise applications and business workflows.

The announcement expands the company’s Okta for AI Agents platform with new tools that verify agent identities, control access to enterprise resources in real time and continuously govern permissions as AI agents take on more complex responsibilities.

Securing AI Agents at Runtime

One of the biggest additions is Agent Gateway, a new identity-aware gateway that sits between AI agents and enterprise applications.

Rather than allowing AI agents to store long-lived credentials, Agent Gateway verifies both the AI agent and the user behind each request before issuing temporary credentials at runtime. This approach is intended to reduce the risk of stolen credentials, prompt injection attacks and unauthorized access to enterprise systems.

The gateway works with a variety of AI platforms, including coding assistants, enterprise AI applications and third-party agent frameworks, allowing organizations to secure AI agents without modifying their underlying code.

Supporting Multi-Agent Workflows

As enterprises increasingly deploy multiple AI agents that collaborate with one another, Okta is also introducing Agent-to-Agent Connections.

The feature enables organizations to authorize and monitor communications between AI agents while maintaining a complete record of every interaction.

Security teams can define which agents are permitted to communicate, enforce least-privilege access policies and create audit trails that document every delegated action. The goal is to make complex multi-agent workflows easier to secure while reducing the need for custom authorization logic.

Addressing Long-Term AI Governance

In addition to controlling access during runtime, Okta is introducing Resource Access Certifications for AI Agents, which focuses on ongoing identity governance.

The capability automatically reviews and validates agent permissions over time, helping organizations remove outdated access when projects end or AI responsibilities change.

By continuously reviewing permissions, organizations can reduce privilege creep, simplify compliance efforts and maintain visibility into both human and AI identities accessing enterprise resources.

Managing AI Agents Across Platforms

Okta says the new capabilities are designed to support AI agents regardless of vendor, allowing organizations to manage identities across a mix of internally developed and third-party AI systems.

The company estimates that many organizations rely heavily on purchased AI applications rather than building them internally, making consistent identity management increasingly important as AI adoption accelerates.

Together with existing Okta for AI Agents capabilities, the platform enables organizations to register AI agents as managed identities, enforce least-privilege access, monitor agent activity and deactivate compromised or unauthorized agents.

Availability

Agent-to-Agent Connections is now generally available.

Agent Gateway is currently available through a research release, while Resource Access Certifications for AI Agents is available through an early access program.

The Bottom Line

As AI agents begin handling higher-value enterprise workflows, identity management is becoming a critical part of AI security. Okta’s latest additions focus on treating AI agents as managed identities, giving organizations more control over how agents access enterprise systems, collaborate with one another and retain permissions over time. By combining runtime authorization with ongoing governance, the company is positioning its platform to address one of the emerging security challenges of enterprise AI.