Rubrik unveils Agent Identity to govern AI agents one tool call at a time
Rubrik Inc. today unveiled Rubrik Agent Identity, a service that governs what artificial intelligence agents are allowed to do by granting access one tool call at a time. The company announced the service at the Black Hat conference in Las Vegas.
The service is an expansion of Rubrik Agent Cloud, the agent governance platform the company launched in October and made generally available for Anthropic PBC’s Claude in June. Agent Identity targets the credential layer beneath those deployments. Agents typically inherit the broad, standing permissions built for human employees, which means a single compromised or misbehaving agent can act destructively across software-as-a-service applications, databases and application programming interfaces before anyone notices.
“Agents are no longer just synthesizing information, they are acting on the enterprise on behalf of employees, and the access models we built for humans and static credentials were never designed for autonomous actors,” said Dev Rishi, general manager of AI at Rubrik. “Agent Identity lets enterprises decide who can do what with agents and enforces it per tool call, at the moment of action, with scoped, short-lived access and no standing permissions.”
Rubrik is pitching the problem as a “shadow workforce” of unmonitored machine identities. According to research from Rubrik Zero Labs, 86% of global information technology and security leaders expect AI agents to outpace their organization’s security guardrails within the next year, while only 23% say they have full visibility into the agents already running in their environments.
Agent Identity works across three functions: monitoring every agent and Model Context Protocol server at runtime, controlling access per tool call using fine-tuned models and remediating risky actions through identity, audit logs and Rubrik’s Agent Rewind feature. Customers start by building an inventory of active agents, MCP servers, skills and plugins, then scope access to specific servers and tools by user and group using On-Behalf-Of federation, which extends existing identity structures rather than replacing them. Standing permissions are eliminated by minting scoped, short-lived tokens for each individual tool call.
Enforcement happens at an MCP gateway. Every tool call clears three checkpoints before it executes: a behavioral analysis step in which Rubrik’s SAGE governance engine evaluates the intent, input parameters and likely operational impact of the request, a policy check at the infrastructure layer and an identity verification step that authenticates the agent session and issues the token scoped to that call. An unauthorized action, such as a write or modification outside an explicit policy scope, is blocked before execution.
For actions that clear the gateway and still go wrong, Agent Rewind reverses them. Rubrik has described the feature as the only one of its kind on the market. The company’s own survey work found 88% of leaders are worried about meeting recovery time objectives as agentic threats scale. Agent Identity integrates with Okta Inc. and Microsoft Corp.’s Entra ID, extending enterprise identities to machine actors without standing up a separate directory. Rubrik did not disclose pricing or a general availability date.
Rubrik, which now describes itself as “the Security and AI Operations Company,” moved into agent tooling in earnest with its acquisition of Predibase Inc. in a deal worth between $100 million and $500 million in June 2025. Rishi co-founded Predibase and served as its chief executive.
Photo: Rubrik
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more** 11.4k+ theCUBE alumni**— Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
theCUBE AIand theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.