
What happened
Okta launched a multivendor reference architecture, the Blueprint Alliance, for agent runtime security. It frames the problem in four questions: where agents are, what they can do, what they're doing and how to respond.
Why it matters
Okta compares what agents connect to against what they are authorized to reach, then can deactivate a flagged agent to block new sessions. This gives buyers one architecture instead of competing vendor claims, according to Okta's president and chief operating officer.
What to watch
Okta says it plans to expand its kill switch capabilities at the Agent Gateway to revoke active tokens and sessions. The appropriate response will depend on the agent's behavior and the risk it poses.
WHO IT HITSEnterprise security teams moving AI agents into production are the audience: they get a single reference architecture for monitoring agent behavior and shutting down suspicious agents, rather than stitching together each vendor's own claims.
Summaries like this, in your inbox every morning.
Okta used its Oktane event this week to turn its agent security framework into a multivendor reference architecture through the Blueprint Alliance. The company's framing of the problem is deliberately simple: the architecture distills agent security into four questions — where agents are, what they can do, what they are doing and how to respond. Underneath that, Okta layers its identity signals atop endpoint and network telemetry, so the question becomes whether an agent is touching systems it was never authorized to reach.
The motivation Okta gives is buyer confusion. Eric Kelleher, Okta's president and chief operating officer, said every technology vendor customers talk to, from every part of the stack, claims to be the one-stop shop that fixes everything. The Blueprint Alliance is positioned as an answer to that noise rather than another competing pitch.
What the architecture can do today is narrow but concrete: Okta can deactivate a flagged agent to block new sessions, and it plans to expand its kill switch capabilities at the Agent Gateway to revoke active tokens and sessions. The outcome here appears to hinge on how the response is calibrated — Kelleher noted there will be cases where agents step over unintended boundaries while exploring their intended work and need to be redirected and bounded back in. For security teams putting agents into production, the practical test is likely whether one shared architecture can replace a patchwork of vendor claims.
For example, today's edition would include:
AI-summarized, only the topics you pick: one digest a day via Email, LINE, or Slack.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.
Omdia principal analyst Todd Thiemann surveyed 400 security leaders; the top inhibitor to AI agent identity se…
Meta said on September 28 it will offer its AI models and agents to companies and developers, starting with Mu…

Pope Leo told a news conference on his flight back to Rome that expert concerns about AI destroying humanity "…

Chipmaker AMD agreed to acquire World Labs, the AI startup founded by industry pioneer Fei-Fei Li, for $8.2 bi…

Anthropic's Thariq Shihipar said on the Latent Space podcast that agent security may become one of the definin…

Anthropic announced Claude Sonnet 5.5 on September 28
