AI agents reason, act, and connect across model providers, data platforms, SaaS applications, and infrastructure. That creates an identity gap where shadow agents multiply, credentials cross trust boundaries, and agents execute beyond their intended scope. According to Gartner, only 13% of organizations think they have the right AI agent governance in place.
Founding members aligned on a shared set of principles:
- Treat every agent as a first-class identity.
- Scope access to the task.
- Keep delegation traceable.
- Monitor runtime behavior continuously.
- Make containment instant and reversible.
- Let governance adapt at the speed AI moves.
The Alliance expanded the blueprint for the secure agentic enterprise into an open, multi-vendor reference architecture that addresses four questions:
- Where are my agents? Discover and catalog agents, including shadow AI, and register each as a verified identity with an accountable owner.
- What can they do? Define what each agent can access, and keep permissions aligned to least privilege through ongoing governance.
- What are they doing? Monitor agent behavior at runtime to help detect data leakage, prompt injection, and anomalous activity.
- How do I respond? Contain threats with targeted actions, then restore agents through a deliberate, documented, and auditable process.
Founding members are building and testing interoperability across open standards, including MCP, OCSF, SSF, and CAEP. The goal is to help ensure that a threat signal raised by one runtime monitor can trigger real-time action across connected control planes. Members will also regularly publish joint interoperability results and reference integrations, and new members will be added over time to further refine the architecture.
Download the blueprint at blueprintalliance.ai, or learn more about Okta for AI Agents and Okta for Public Sector.