The Blueprint: What the hell are my agents doing? AWS, Databricks, Google, CrowdStrike, Docker, Lovable, Proofpoint, Salesforce, ServiceNow, Wiz, Zscaler and Okta launched the Blueprint Alliance on September 22, publishing a whitepaper and multi-vendor reference architecture to govern enterprise AI agents as a "unified, governed system." The founding members said they are building and testing interoperability across open standards including MCP, OCSF, SSF and CAEP, citing research that only 34% of organisations secure agents with the same rigor as human users. Docker CTO Tushar Jain said a secure agentic future "depends on leaders throughout the industry coming together to develop a baseline approach organizations can use to extend trust beyond the model to the environments where agents execute. "I ain't tryna change you, just give you some game/to make the transition from the street to the fame” Jay-Z, The Blueprint. Jay Z wasn’t who AWS, Databricks, Google and other prominent software firms had in mind when they decided to call their new coalition the Blueprint Alliance – but the bars above from his Blueprint album’s titular track are oddly apposite, as the alliance looks to take scrappy agentic stacks to primetime, as an open “unified, governed system.” The new consortium other founding members include CrowdStrike, Databricks, Docker, Lovable, Proofpoint, Salesforce, ServiceNow, Wiz, and Zscaler have teamed up, they said today, to help organisations “address four core challenges: Where are my agents? What can they do? What are they doing? How do I respond?” Members said they are: "Building and testing interoperability across open standards, including MCP, OCSF, SSF, and CAEP. The goal is to help risk signals trigger coordinated action across connected control planes." Some of the Blueprint Alliance https://blueprintalliance.ai/blueprint-alliance-whitepaper.pdf?ref=thestack.technology ’s priorities illustrated in a new multi-vendor reference architecture, below are as follows: Encourage builders and buyers alike to treat “every agent as a first-class identity,” scope agent access tightly, monitor runtime behavior continuously, and “enable containment that is instant and reversible.” The goal is to “help risk signals trigger coordinated action across connected control planes,” the founding members said, citing research they didn’t specify from whom that suggests only 34% of organisations secure agents “with the same rigor as human users. This gap between adoption and governance creates significant risk…” One of the many challenges enterprises face at the moment, the Alliance noted in a whitepaper published on September 22, is that they typical “ingest diverse agent architectures that vary by origin, framework, and compute boundary” – an approach that serves to some degree “as a hedge against rapidly shifting agentic capabilities.” These often underpin a sprawling mess of “internally developed AI capabilities ranging from fully custom implementations built with raw code such as Python and LangChain running on general-purpose compute e.g., Kubernetes or Serverless Functions , to agents constructed using provider-specific agentic frameworks that natively handle the runtime, memory, and workflow orchestration,” sitting alongside “purpose-built, third-party AI products often built on or integrated with SaaS that operate as entirely independent entities within the enterprise software ecosystem.” Commenting on the Alliance’s launch, Tushar Jain, CTO, Docker, said a secure agentic future “depends on leaders throughout the industry coming together to develop a baseline approach organizations can use to extend trust beyond the model to the environments where agents execute. We're looking forward to working with Okta and the other founding members to turn that shared blueprint into real interoperability.” Abhi Sawant, VP of Engineering, Platform Security, Google Cloud, added in a canned statement that “we are excited to collaborate with Okta and the Blueprint Alliance to establish open standards that advance zero-trust governance, traceable delegation, and seamless protection across the entire agent lifecycle." For now, it’s a reference architecture and a whitepaper. Moving forwards, the alliance’s members will “regularly publish joint interoperability results and reference integrations to serve as the connective tissue for a multi-vendor security ecosystem.” Watch this space.