Agent gateway lets Okta police AI agent runtime actions

Associated Writers

Okta Introduces AI Agent Runtime Gateway to Enhance Cybersecurity

In a significant move to advance identity security, Okta Inc. has unveiled an AI agent runtime gateway, designed to oversee not just who gains access to systems, but what actions autonomous AI agents can take once inside. This gateway operates in real-time to enforce authorization decisions, enhancing security for autonomous systems.

According to Ric Smith, President of Products and Technology at Okta, this launch signifies a pivotal shift in the identity provider’s role within the cybersecurity landscape. “This transition is quite different for Okta,” he commented, noting that until now, the company had predominantly operated without being inline, which limited its capacity for real-time decision-making regarding authorizations.

Smith discussed these advancements during a conversation with theCUBE Research’s Krista Case and Rebecca Knight at Okta’s Oktane event, emphasizing runtime threat detection and intent-based authorization as critical components of their expanding cybersecurity strategy.

Strategic Positioning of the Agent Gateway

By being inline, Okta gains the ability to monitor for potential threats rather than merely providing permissions. This strategic approach is further reinforced by its recent acquisition of Permiso Security, which enhances Okta’s capabilities for threat detection. Full visibility into an AI agent’s behaviors necessitates monitoring both the input provided to the model and the subsequent actions suggested by the model.

Smith elaborated on the dual positioning required for effective AI governance, stating, “One must observe the incoming prompts while simultaneously monitoring the proposed actions.” This comprehensive oversight enables Okta to make informed judgments about whether a proposed action by an AI agent should be executed. In 2027, the company intends to integrate intent-based authorization within its agent gateway, leveraging context and available tools to guide access decisions. However, determining how to appropriately narrow permissions without impeding legitimate activities remains a complex challenge.

Smith acknowledged the intricacy of this issue, stating, “It’s a hard problem for us to solve, which is why we are dedicating significant research efforts toward it. We see this as essential for the future of managing automated workforces.”

For further insights, the complete video interview from the event, which forms part of SiliconANGLE’s and theCUBE’s comprehensive coverage of Okta’s Oktane conference, is available for viewing.

[gspeech type=full]

Share This Article
Leave a comment