Okta builds shared architecture for agent runtime security
Agent runtime security requires controls across the technology stack as enterprises move AI agents into production.
This week, Okta turned its agent security framework into a multivendor reference architecture through the Blueprint Alliance. The effort is intended to help buyers navigate competing vendor claims, according to Eric Kelleher (pictured), president and chief operating officer of Okta.
“One of the challenges companies have in navigating this is [that] every technology vendor they talk to from every component of the stack is telling them that they’re the one-stop shop that’s going to fix everything,” he said. “So, the biggest challenge that we have in talking to our customers is helping them navigate the confusion of understanding how to think about the problem, how to secure AI in a way that’s simple.”
Kelleher spoke with theCUBE Research’s Krista Case and co-host Rebecca Knight at Okta’s Oktane event, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed how the Blueprint Alliance brings identity and security signals together to monitor agent behavior and guide responses to risk. ( Disclosure below.)*
Okta coordinates agent runtime security across vendors
The Blueprint Alliance architecture distills agent security into four questions: where agents are, what they can do, what they are doing and how to respond. Okta layers its identity signals atop endpoint and network telemetry, Kelleher explained.
“We’ll look at what agents are connecting to and we’ll compare that against the systems that it’s been authorized to connect to, to see if there’s a disparity,” he said. “That real-time data all flows back into a system to help us identify, ‘Does something look suspicious?'”
Okta can deactivate a flagged agent to block new sessions, and it plans to expand its kill switch capabilities at the Agent Gateway to revoke active tokens and sessions. The appropriate response will depend on the agent’s behavior and the risk it poses, Kelleher noted.
“There are going to be cases where agents, as they’re exploring their intended work, end up stepping over boundaries that were not intended, where you’ll want to redirect them and bound them back in,” he said.
Here’s the complete video interview, part of SiliconANGLE’s and theCUBE’s coverage of Okta’s Oktane event:
( Disclosure: TheCUBE is a paid media partner for Okta’s Oktane event. Neither Okta Inc., the sponsor of theCUBE’s event coverage, nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)*
Photo: SiliconANGLE
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
- 15M+ viewers of theCUBE videos , powering conversations across AI, cloud, cybersecurity and more
- 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network
Are you an AWS customer? Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: https://siliconangle.com/aws-marketplace/
About SiliconANGLE Media
theCUBE AIand theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.