Okta builds shared architecture for agent runtime security
SiliconANGLE Jonathan Anthony
Okta turned its agent security framework into a shared blueprint with other vendors. It’s meant to cut through the “one-stop shop” hype and make AI agents easier to control.
Based on reporting by SiliconANGLE, Jonathan Anthony — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
Okta is trying to turn agent security from a vendor pitch into something buyers can actually compare. This week, the company folded its framework into a multivendor reference architecture through the Blueprint Alliance, a move aimed at helping enterprises sort through competing claims as they push AI agents into production.
Eric Kelleher, Okta’s president and chief operating officer, said the problem isn’t a lack of products. It’s the noise around them. Every vendor says it can cover the whole stack, he said, and that leaves customers with a mess of overlapping promises instead of a clear way to think about the risk.
The architecture breaks agent security into four basic questions: where agents are, what they can do, what they are doing and how to respond. Okta then adds its identity signals to endpoint and network telemetry, looking for gaps between what an agent is allowed to access and what it actually touches. If something looks off, that data feeds back into the system to flag suspicious behavior.
And the response can be fairly blunt. Okta can deactivate a flagged agent to stop new sessions, and it plans to extend that kill switch at the Agent Gateway so it can revoke active tokens and sessions too. Kelleher also pointed out that not every boundary crossing is a full-blown incident; sometimes the right move is to steer an agent back toward its intended work.
The pitch, in other words, is not just detection. It’s coordination across vendors, with identity at the center and behavior under watch. That’s a practical answer to a very market-made problem: when everyone claims to be the whole solution, customers usually need a map more than another logo.
My take — AI-written commentary, not fact-checked reporting
The real value here is not the security theater of a bigger “platform.” It’s the unglamorous part: making vendors agree on the same map before the agents start wandering around production like they own the place. That’s the kind of boring standardization the AI market keeps pretending it doesn’t need, right up until something breaks.
Read more about this at: SiliconANGLE
Related stories
AI Security Is an Engineering Problem — How to Solve It at Every Layer of the Agent Stack
NVIDIA Blog · 1 week ago ·
30