Identity · CA
CrowdStrike Gives Agents Their Own Identity Provider
CrowdStrike announced Agentic Identity Provider (Agentic IdP) this week at Fal.Con 2026, part of Falcon Next-Gen Identity Security. The pitch is narrow and, for once, that's the point: before you can govern what an agent does, you have to establish what the agent *is*.
That sounds obvious until you look at how most enterprises currently handle agent identity. CrowdStrike's own framing is blunt about the status quo: traditional identity providers force organizations to represent agents through service accounts, API keys, and workload identities, and agents effectively inherit the credentials of the humans they act for. That makes it hard to tell the agent from the person, hard to govern the agent's access independently, and hard to hold anything accountable when something goes wrong.
Agentic IdP is meant to break that inheritance. It gives every agent its own trusted identity, links that identity back to the human or workload behind it, and scopes access to only what the agent needs at the moment it needs it. It's built on top of Continuous Identity, the real-time authorization layer CrowdStrike detailed at Identiverse in June using technology from its $740 million SGNL acquisition — Continuous Identity decides whether an agent should be allowed to act right now, Agentic IdP handles the prior step of establishing what the agent is in the first place.
The distinction matters more than it sounds. A separate framework review of RSAC 2026's identity launches — CrowdStrike among them — found a consistent gap: vendors could verify *who* an agent was, but none could track delegation chains between agents, catch an agent quietly rewriting its own policy, or confirm a decommissioned agent actually held zero credentials afterward. Two Fortune 50 incidents illustrated this: one where a policy modification passed every identity check and was caught by accident, another where a 100-agent Slack swarm delegated a code fix with no human approval and nobody noticed until after a commit landed.
None of CrowdStrike's three Fal.Con announcements — Agentic IdP included — carry a general availability date yet. That's worth flagging, not as a knock, but as a reminder that 'identity established' and 'behavior tracked' are still two separate engineering problems, and the industry keeps shipping solutions to the first one while the second one is where the incidents are actually happening.