2 min Security

Rubrik secures actions in real time with agent identity

Rubrik secures actions in real time with agent identity

Rubrik Agent Identity manages access and permissions for AI agents by issuing short-lived tokens for each tool call, rather than using static, broad credentials.

“Agent Identity lets enterprises decide who can do what with agents and enforces it per tool call, at the moment of action, with scoped, short-lived access and no standing permissions,” said Dev Rishi, General Manager of AI at Rubrik.

Agent Identity operates alongside the existing SAGE (Semantic AI Governance Engine) governance framework and complements four pillars within Agent Cloud: Agent Observability, Agent Identity, Agent Runtime Security, and Agent Rewind. The latter reverses destructive actions performed by an agent.

Every MCP tool call must pass through three checks before execution. SAGE first performs a semantic assessment of the requested action and its potential impact. Next, runtime security policies at the infrastructure level are verified. Finally, the agent session is authenticated and receives a short-lived token specific to that single call. Unauthorized actions, such as a write operation outside the policy scope, are immediately blocked.

The announcement builds on Rubrik’s previous work in agentic AI. The company launched Agent Cloud for the secure deployment of AI agents and, in doing so, introduced SAGE, a small language model that analyzes the intent behind an action rather than relying solely on static guardrails.

Integrations with existing identity stacks

Rubrik Agent Identity integrates with Okta and Microsoft Entra ID. This extends existing enterprise identities to autonomous machine agents without requiring new directories. The MCP Gateway serves as a central security checkpoint for all API and MCP resources within the organization. Through On-Behalf-Of federation, organizations can restrict access to specific MCP servers and tools on a per-user and per-group basis.