8 min Security

The AI agent presents a new identity puzzle

The AI agent presents a new identity puzzle

Agents have been given their own identity within Okta solutions. Where previously only human and machine identities existed, the agent represents a middle ground. How does one integrate these AI systems in a way that minimizes friction while maximizing security? We’ll discuss this at Okta’s AI Identity Summit in Amsterdam.

Richard Wainwright, Distinguished Strategic Advisor at Okta, explains that it’s important to clearly understand the nature of an agent within the IT environment. “[An agent] is not software. It is, however, still technology. Nevertheless, you must realize that an agent will behave more like a human [within IT infrastructure].” Hence the need to provide them with identities and use these as the basis for your overview of these agents.

Agent identity in practice

It’s not surprising that Okta has given agents a unique identity. This allows the Okta platform to draw a clear distinction along two new lines, in addition to human and machine identities, between humans and agents, and between agents and “traditional” machines. On the one hand, humans are the weak link in security, although many don’t like the blame game this supposedly implies. Regardless: be persuasive enough, and even the best identity verification mechanisms can be bypassed, for example, through social engineering. The machine side is, as you’d expect, more binary: previously, it was unthinkable to “convince” a SaaS solution as a cyber attacker, you’d instead exploit a software flaw or use stolen credentials for it.

That simple concept alone could already create more than enough complexity. Examples include administrators who, for the sake of convenience, granted maximum privileges for data access, or developers who may roll out an application with speed as the priority and security an afterthought. There are many more problems like these; however, agents introduce a much more complex concept right from the start. It’s therefore wise to keep a close eye on the rise of AI agents from the start, so that the resulting complexity remains manageable.

Things can easily go wrong

Andreas Linnemann, CISO and Technical IT Manager at Greenwheels, finds this taxonomy of people-agents-machines very useful for his own use case. “You limit a machine account to specific permissions and grant personally identifiable access to personal accounts. It’s good to use a middle ground for agentic AI.” Linnemann describes a problem that stems from one of the benefits of agents: they are versatile. If you’ve set up an identity that agents can use for a specific task requiring some, but limited, freedom of action, it’s natural to use that same agent for another task. Many AI workloads are periodic or sporadic. A developer could easily extend an agent identity that’s already linked to an LLM API to yet another application. If another one follows, and so on, an agent identity gradually gains the level of access that cyberattackers dream of.

So that’s not an option. As Wainwright of Okta explains, if you disable that agent, you may suddenly find yourself shutting down all sorts of other things within your organization. While an agent “kill switch” is appealing when the agent is exploited or simply isn’t doing what it’s supposed to as a non-deterministic factor within IT, it can have all sorts of unintended consequences.

Read also: Okta acquires Permiso: identity graph meets identity fabric

The illusion of control

The Okta setup is neat and easy to follow. As is often the case in the IT world, you can create very nice diagrams that illustrate a solid logic. But Greenwheels, like so many others, is not a greenfield project. Just as employees come and go, the use of agent and admin accounts shifts. New applications, new uses, but not always a reassessment of what’s happening in an IT environment. “You can never have 100 percent control,” Linnemann explains. “It’s a bit like footpaths in a park. You can lay a sidewalk, but people sometimes just walk across the grass. They create their own paths. If they can do something to make things easier for themselves, they’ll do it. You can limit that, but I don’t think you can ever completely guard against it.”

This is a battle Okta has been waging for years. But it’s not so much a battle against the user, on the contrary, it’s a battle against friction. Company representatives regularly tell us that they have to constantly reevaluate this consideration. Yet a common thread can be discerned. It revolves around minimizing hard breakpoints for verifying an identity when that cannot be done based on context. A known IP address, regular login behavior, and accessing known sources are all signals that make a single biometric verification sufficient. If there is anything unusual about the location, the timing, and/or the access to sensitive data, this can lead to an additional verification step. For agents, that paradigm is still maturing. But Wainwright states that Okta is “implementing the techniques and mechanisms we’ve already put in place at a new scale.”

Crucially, responsibility does not suddenly shift. Managing agent identities is Okta’s domain, but what those agents do falls under the business side or IT management, depending on the setup. We’ve mentioned this before, but for this reason, Okta refers to a “fabric” rather than just a “platform.” The identity fabric is malleable, flexible, and versatile. “Unless you have a fabric and the tools to monitor what agents are doing, you have no way of figuring out how the situation arose,” says Wainwright. That situation could involve anything, such as accessing sensitive data or a single larger AI tool activating multiple sub-agents. “The great thing about Okta is that because we link an agent action to a user as the owner, we can see and reconstruct the workflow.”

Keep the basics (and the people) in mind

For many organizations, agentic dreams are still just that: dreams. The practical day-to-day reality often revolves around the basics. Greenwheels, too, ran into all-too-familiar problems with its previous identity solution: support was set to end, and there was no built-in Multi-Factor Authentication (MFA). Okta Customer Identity Cloud (formerly Auth0) proved to be the solution for Greenwheels to address both of these issues. Four years ago, Greenwheels had also made the full transition to the cloud, which aligns perfectly with Okta’s SaaS model.

We sometimes get a proverbial slap on the wrist when we say that people are the weakest link in security. Earlier in this article, some readers may have sighed at that statement. Linnemann of Greenwheels turns this on its head and implicitly assumes human error. The most important thing, he says, is that there is a no-blame culture within the organization. “If I blame someone for clicking on a suspicious link, they won’t tell me about it again if something goes wrong.” He emphasizes that there are no such things as “stupid” questions when it comes to security. Employees should therefore feel free to report that a suspicious message arrived via email, WhatsApp, or Teams. Different tools require different forms of identification, and Greenwheels uses MFA or QR scans depending on the context.

Conclusion: Stay traceable

With the rise of AI systems, the possibilities for non-human input are far-reaching. That means maintaining an overview remains a challenge. And solutions like Okta can lend a hand, but the systematic application of the ideas behind them is up to the organizations that adopt the tools. Assigning an agent to an identity with just-in-time access and the appropriate scale can be done systematically, but that depends on a solid foundation. The concept, as Wainwright emphasizes, revolves around realism. A service account that you use for agents will accumulate use cases and, consequently, privileges. An agent account within Okta’s Identity Fabric is built on these nuanced elements.

Many organizations wonder what the return on investment for AI is or will be. This starts with understanding exactly what agents mean within an organization. If they aren’t even traceable as legitimate internal agents, or if employees are using shadow AI tools, then there’s little meaningful to say about their usefulness. With proper oversight, agent tasks can be tied to human users who are accountable for the behavior of their AI tools.

Linnemann also notes that Greenwheels does not use a single AI model. Instead, there is a provider that offers multiple LLMs. This allows users to choose for themselves whether Claude, Gemini, or another model best suits their use case. If they build an agent, it can be traced back via Okta. That’s where the visibility into AI begins, and with it, the start of an answer to the question of what these agents deliver. Without that overview, you won’t know what benefits (and risks) these agents present for you.