Identity · CA
Okta Adds Runtime Controls and Recurring Access Reviews for AI Agents
Okta announced product updates this week aimed at a problem most agent-identity discussions still treat abstractly: what happens to an agent's permissions after the initial handshake. The company said it is shipping new capabilities within Okta for AI Agents to help organizations secure agent connections to enterprise tools and other agents at runtime, while governing these connections over time.
The announcement bundles three pieces, per Okta's own description: Agent Gateway and Agent-to-Agent Connections, which secure agents when they connect to enterprise tools and execute multi-agent workflows, plus Resource Access Certifications for AI Agents, which reviews agent connections over time to prevent standing and excessive permissions.
That last piece is the notable part. Most of the agent-identity conversation this year — A2A's signed Agent Cards, MCP's OAuth hardening, Visa and Mastercard's attestation headers for agentic payments — has focused on proving who an agent is at the moment it acts. Okta's certification feature targets a different failure mode: an agent that was granted broad access for a legitimate task last month and never had that access revoked. Standing permissions are the classic vector behind privilege-creep breaches in human IAM, and they don't disappear just because the identity in question is a bot rather than a person — if anything, agents accumulate connections faster and get audited less.
Okta frames itself as securing 'AI, machine, and human identity' at once, which is the right framing for the actual risk: an enterprise's identity graph doesn't stay clean if it treats agent credentials as a separate, lower-scrutiny category from human ones. A gateway that checks credentials at connection time answers 'is this agent who it says it is.' A recurring certification answers the harder question — 'should this agent still have what it was given six weeks ago' — which is the one that turns into a headline when someone forgets to ask it.
This is a vendor announcement, not an independent audit, so claims about effectiveness should be read that way. But the shift from point-in-time authentication toward periodic re-certification of agent permissions is a real and needed move in enterprise identity infrastructure, and it's one other identity vendors will likely have to match.