cd /news/ai-safety/rubrik-launches-agent-identity-for-t… · home topics ai-safety article
[ARTICLE · art-86206] src=letsdatascience.com ↗ pub= topic=ai-safety verified=true sentiment=· neutral

Rubrik Launches Agent Identity for Tool-Call Governance

Rubrik launched Agent Identity on August 4 at the Black Hat conference in Las Vegas, a service that governs AI agent access at the level of individual tool calls using scoped, short-lived credentials instead of standing permissions. The product extends Rubrik Agent Cloud and enforces policies at an MCP gateway, with behavioral analysis by Rubrik's SAGE governance engine. Dev Rishi, general manager of AI at Rubrik, said the access models built for humans were never designed for autonomous actors.

read3 min views1 publishedAug 4, 2026
Rubrik Launches Agent Identity for Tool-Call Governance
Image: Letsdatascience (auto-discovered)

Rubrik unveiled Agent Identity on August 4 at the Black Hat conference in Las Vegas, introducing a service intended to govern AI agent access one tool call at a time. SiliconANGLE reports that the service creates scoped, short-lived credentials rather than standing permissions, while Rubrik's product materials describe controls for agents, MCP servers, skills, plugins, and data interactions.

Rubrik unveiled Agent Identity on August 4 at the Black Hat conference in Las Vegas, introducing a service designed to govern artificial intelligence agents' access at the level of individual tool calls. SiliconANGLE reports that the product extends Rubrik Agent Cloud and targets the credential layer used by agents interacting with SaaS applications, databases, APIs, and other enterprise systems.

According to SiliconANGLE, Agent Identity uses scoped, short-lived tokens for each tool call instead of standing permissions. The publication reports that customers begin by inventorying active agents, Model Context Protocol (MCP) servers, skills, and plugins, then define access to specific servers and tools by user and group through On-Behalf-Of federation.

"Agents are no longer just synthesizing information, they are acting on the enterprise on behalf of employees, and the access models we built for humans and static credentials were never designed for autonomous actors," Dev Rishi, general manager of AI at Rubrik, told SiliconANGLE. Rishi said the service enforces scoped, short-lived access at the moment of action.

Runtime controls at the MCP layer

Rubrik's product page states that Agent Govern centralizes discovery and policy management for agents, MCP servers, skills, and plugins. It also describes policies that can govern agent actions, tool access, application permissions, and data interactions, with rules applicable to an individual agent, tool, user, or group.

SiliconANGLE reports that enforcement occurs at an MCP gateway and that each tool call passes through checkpoints before execution, including behavioral analysis by Rubrik's SAGE governance engine. The article also describes monitoring, identity and audit-log based remediation, and Rubrik's Agent Rewind feature as parts of the product's operating model.

The access model is notable because MCP-based agent systems can turn language-model outputs into actions against external services. In comparable enterprise deployments, short-lived, narrowly scoped credentials can reduce the exposure created when an automated process is compromised or invokes an inappropriate tool. The operational tradeoff is that teams need reliable agent inventories, identity mappings, policy definitions, and logs detailed enough to investigate denied or risky calls.

SiliconANGLE cites research indicating that 86% of surveyed global IT and security leaders expect AI agents to outpace their organizations' security guardrails within the next year, while 23% report full visibility into agents running in their environments. The underlying research is not identified in the retrieved article.

Key Points #

  • 1Rubrik's new service applies authorization at each AI-agent tool call, replacing broad standing permissions with scoped, short-lived tokens.
  • 2The product covers runtime discovery and policy controls for agents, MCP servers, skills, plugins, applications, and data interactions.
  • 3Comparable agent deployments require strong identity mapping and audit telemetry to make granular authorization operationally useful at scale.

Scoring Rationale #

Agent identity and runtime authorization are increasingly important for teams deploying MCP-connected agents that can invoke enterprise tools. The announcement is a notable enterprise security product release, though the available reporting does not provide independent performance, adoption, or integration evidence.

Sources #

Primary source and supporting public references used for this report.

Practice interview problems based on real data

1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.

Try 250 free problems

── more in #ai-safety 4 stories · sorted by recency
── more on @rubrik 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/rubrik-launches-agen…] indexed:0 read:3min 2026-08-04 ·