The focus of Okta’s annual Oktane 2026 conference is squarely on tracing and controlling agents across more environments, even providing a kill switch to cut off compromised agents’ access. Okta for AI Agents’ expansions point to the identity provider having a greater say in agentic matters, but the newly formed Blueprint Alliance highlights how Okta can’t (and doesn’t intend to) control AI on its own.
The models powering agents across enterprises pose inherent risks that AI labs try to teach out of them. The recent sweep of AI-led hacks has shown the likes of OpenAI and Anthropic are fallible; protecting the world from the ill effects of the technology is proving to be an altogether human affair. “When we talk about alignment issues, that’s not the business we’re in,” says Ric Smith, President of Products and Technology at Okta.
Instead, Okta is focused on allowing for centralized control over identity management, which has rather emphatically expanded with the rise of functional AI agents over the past year or so. In the main, though, Okta’s view isn’t all that different now compared to the pre-ChatGPT era. Smith continues: “Our stance has always been that we want to be agnostic to all the tools in the enterprise because most of our customers operate in a heterogeneous environment.”
A blueprint for AI security
The newly formed Blueprint Alliance was cofounded by Okta, among the likes of AWS, Google Cloud, CrowdStrike, Salesforce, ServiceNow, Wiz and Zscaler. The alliance has brought to life a reference architecture that proposes standardizing and interoperating across vendors, all from the perspective of answering specific pointed questions about agentic behavior. The where, what, and how behind agents are covered, including integration with access policies, gateways, monitoring and governance, among many more considerations.
Although Smith concedes that agentic behavior is expanding volume and a level of automation around access requests and governance, he says the principles behind securing agents are very similar to how Okta has always governed human identities.
Part of said governance revolves around agent discovery. The truth is that employees will use AI whether you want them to or not, unless one’s organization is universally aligned. At some scale, you simply can’t stop people from using AI to speed up their everyday work, particularly to make rote tasks more efficient. This makes discovery of unmanaged agents critical to bringing their access under control. Smith points to an integration with CrowdStrike that helps organizations detect such agents on employee devices.
Okta reaches the endpoint
Okta’s focus has been on SaaS identity management. Now, the endpoint is becoming a key surface for the vendor to manage. An expansion to Okta for AI Agents appropriately called Shadow AI Agent Discovery for Endpoints will land later this year, helping uncover otherwise hidden agents on company laptops.
Existing Okta offerings are also expanding, such as Cross App Access now becoming available to all SSO customers via Agent SSO. Non-expiring keys can thus be swapped out for short-lived, identity-governed tokens that comply with Zero Trust principles while battling what Okta describes as “user consent fatigue”.
Other additions revolve around interactivity between agents and resources and agents and agents. OpenAI’s conspiracy of colluding agents illustrates the risk of ungoverned communication. Agent-to-Agent Connections lets administrators define which agents can call which other agents, and under which circumstances, while recording those handoffs. Further refinements to Okta for AI Agents involve greater temporal and organizational insights, to keep track of structural failings or risks due to the introduction of AI.
Conclusion: picking your lane
Ric Smith emphasizes that customers lead the charge on additions to Okta’s platform. That is, of course, only natural: software should resolve problems as they surface. Then again, this means Okta’s agentic solution, its most rapidly growing product ever according to Smith, is a bellwether both for how agentic AI can be secured, and for where organizations are currently at risk or failing to address deep security concerns. We don’t need to point to AI misalignment for potential trouble and outsource responsibility to the model makers; even the most well-behaved LLM can leak secrets if you let it and don’t explicitly tell it not to, or indeed prevent it from accessing data.
Also read: Okta agrees to buy Permiso: identity graph meets identity fabric