AI Security

Okta’s Oktane bet: identity security now means governing the agent, not just the human.

Sep 22 Oktane newsroom: Agent SSO, Agent-to-Agent Connections, Resource Access Certifications GA; Agent Gateway + endpoint shadow discovery planned Q3; Kill Switch expansion + Configuration Designer planned Q4. Blueprint Alliance. Pricing Undisclosed.

Sep 24, 2026 · 5 min read

The IdP just stopped being a human SSO perimeter story. At Oktane 2026, Okta is selling lifecycle identity for agents — discover them, authorize what they connect to, enforce in the tool-call path, certify privileges over time, and contain with a kill switch.

On 22 September 2026, Okta’s newsroom published the primary under the title matching the screenshot buyers saw: New Okta for AI Agents innovations increase visibility into agent behavior, secure connections at runtime, and enforce continuous agent governance. This essay is dated September 24, 2026. The Okta press release is the primary source here.

The blueprint is four questions — company framing. Across B2B, B2C, and ecosystem partners, Okta’s “secure agentic enterprise” on-ramp answers: Where are my agents? What can they do? What are they doing? How do I respond? That is the architecture language. The product package announced that day maps onto it.

Where are my agents? Okta already registers known agents into Universal Directory as a single source of truth — direct registration or import from platforms such as AWS Bedrock and Salesforce Agentforce, plus shadow agents interacting through the browser. New at Oktane: Shadow AI Agent Discovery for Endpoints, which surfaces unmanaged agents running on employee devices. Planned generally available in Q3 (Okta primary).

What can they do? Resource Connections already govern data path and connection type (authorization servers, vaulted credentials, service accounts, SaaS apps, MCP servers). Extensions announced: Agent SSO brings Cross App Access to all SSO customers so teams can swap non-expiring keys for short-lived, identity-governed tokens; Agent-to-Agent Connections set which agents may call which others and capture an auditable handoff chain; Configuration Designer visually maps agent-to-resource connections (planned Q4); Resource Access Certifications review agent connections over time to catch standing or excessive permissions. Per Okta availability: Agent SSO, Agent-to-Agent Connections, and Resource Access Certifications are generally available today.

What are they doing? System Log already captures agent events for SIEM streaming. Agent Gateway sits in the execution path between agent and tool call — policy enforcement and logging at runtime. Planned GA in Q3. That is the hot-path bet: identity not as a login event, but as continuous authorization on every tool invocation.

How do I respond? Admins can already deactivate an agent in the console and block new sessions. Okta is planning to expand kill-switch capabilities to Agent Gateway in Q4 — for gateway-connected agents, deactivate at the gateway and revoke every active token plus shut down in-flight sessions. Containment language is concrete; ship date is planned, not claimed as GA today.

Quotes from the primary. Ric Smith, President of Products and Technology at Okta: the same access that makes agents powerful also makes them dangerous; Okta’s goal is visibility and runtime assurance so agents move from unmanaged risk to competitive advantage. Ryan Barnes, Director of IT at MJS Packaging: moving fast with AI agents should not mean sacrificing control; Okta for AI Agents is framed as governance to deploy across the enterprise while eliminating security blind spots. This is company-sourced customer color, not independent CyberMerge diligence.

Blueprint Alliance — standards theater or interoperable containment? Okta also announced the Blueprint Alliance, a cross-industry coalition aligned on principles: treat every agent as a first-class identity, scope access to the task rather than standing access, keep delegation traceable, monitor runtime continuously, enable instant and reversible containment, and adapt governance at AI speed. Okta’s PR body does not fully roster founding members. SiliconANGLE (Duncan Riley, Sep 22, 2026) names founding members including AWS, CrowdStrike, Google Cloud, Databricks, Docker, Lovable, Proofpoint, Salesforce, ServiceNow, Wiz, and Zscaler alongside Okta; that roster is per SiliconANGLE, not Okta PR-body fact. SiliconANGLE also reports alliance citation of Gartner predicting the average global Fortune 500 enterprise will have more than 150,000 agents in use by 2028, and that only 13% of organizations think they have the right AI agent governance — that is Gartner cited by the alliance / SiliconANGLE, not a CyberMerge-verified count. Same secondary notes interoperability testing across MCP, OCSF, and the Shared Signals Framework. Underwrite whether joint tests produce real cross-vendor containment signals — or conference coalition optics.

Competitive surface — same agent problem, different wedges. Same Featured week: Island is selling an agentic control plane via the enterprise browser; Omada is folding EmpowerID runtime authorization into IGA; Jamf is buying Keep Aware browser BDR into Apple-native AI governance. Okta’s wedge is identity-native runtime plus Universal Directory as system of record. Different beachheads. Same question boards should ask: who sits in the path when an agent calls a tool, and can you revoke mid-session?

POV. Identity security is being redefined from human SSO perimeter to agent lifecycle control. Three capabilities are GA today; Agent Gateway and endpoint shadow discovery are planned Q3; Configuration Designer and gateway kill-switch expansion are planned Q4. The strategic bet is whether enterprises will put Okta in the hot path for every tool call — and whether Blueprint Alliance members actually exchange Shared Signals that trigger containment across control planes. Pricing, packaging, and attach for Okta for AI Agents / Agent Gateway: Undisclosed in the primary. ARR and share: Undisclosed.

Underwrite sheet — sourced only: Okta newsroom Sep 22, 2026 (Oktane) — four questions; Shadow AI Agent Discovery for Endpoints (Q3 planned); Agent SSO / Agent-to-Agent Connections / Resource Access Certifications GA today; Configuration Designer (Q4 planned); Agent Gateway (Q3 planned); Kill Switch expansion to gateway (Q4 planned); Ric Smith + Ryan Barnes quotes (primary); Blueprint Alliance principles (primary); founding member roster + Gartner 150k / 13% figures attributed to SiliconANGLE / alliance citation; Okta for AI Agents pricing Undisclosed. Agents as first-class identities — underwrite the GA vs planned dates, not the slide.

Sources