
What happened
Palo Alto Networks' Idira shipped August features to govern AI agents — MCP access policies limiting which tools an agent can run, SPIFFE identities and short-lived tokens for Google Gemini Enterprise agents, and near-real-time account sync from Privilege Cloud.
Why it matters
Agents become registered, auditable identities rather than shadow scripts borrowing someone else's token, and machine identity shifts from stored static secrets toward workloads proving what they are — the platform's own "identity where you can, secrets where you must" idea.
What to watch
Sync latency is described as "close to real time" and rollouts finished region by region, so whether the tightest least-privilege controls hold in day-to-day operations is likely the test. Note the APIs now hide authenticator configuration without permission.
WHO IT HITSIdentity and security teams managing machine and AI-agent credentials in enterprise environments gain controls to scope each agent's access and replace static credentials with short-lived ones; platform admins also face stricter visibility limits on authenticator configuration.
Summaries like this, in your inbox every morning.
Idira's August release is the first in a monthly series that reads the platform's release notes and pulls out changes worth attention. The company frames the batch around two shifts: machine identity moving from static secrets toward workloads that prove what they are and receive short-lived credentials, and AI agents becoming identities to register, govern, and audit rather than "shadow scripts running around with someone else's token."
The agent-side changes converge on giving each agent a governable identity. MCP access policies link the users who can start a session, the agents they operate through, and the specific tools on an MCP server. Separately, agents can now be linked to cloud-native identifiers such as an AWS ARN or an app ID during registration, matching a newly registered agent to one already in discovered inventory. For agents on the Google Gemini Enterprise Agent Platform (formerly Vertex AI), Secure Workload Access issues unique SPIFFE identities and short-lived tokens with trust domains and policy managed centrally.
On the workload side, Idira reduced friction: workloads can be edited in place from the Workloads page, while authenticators without permission now show only their type and Service ID. On secrets, unmanaged secrets can be deleted synchronously from Secrets Hub, and account changes from Privilege Cloud sync to Secrets Manager SaaS shortly after they happen. A secret read now reflects Privilege Cloud changes in close to real time rather than after the next sync cycle, which is the practical payoff — though whether that latency holds across all regions is the kind of thing operations teams will likely test.
Pick your industry and the AI tools you use, and get news related to your work every day.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.
Applied Materials reported record revenue for its fiscal third quarter on Aug

Eli Lilly's Brian Lewis detailed LillyPod at CoreWeave's Fully Connected 2026, an Nvidia DGX SuperPOD B300 sys…

Berkshire invested an additional $10 billion in Alphabet via private stock purchase, buying $5 billion of Clas…

Sell ratings are 13.1% of 61 analyst recommendations on Tesla — the lowest share since April 2023, down from a…

On Micron's fiscal Q4 2026 earnings call, CEO Sanjay Mehrotra said humanoid robots are expected to need memory…

Marvell Technology trades at 25.1 times sales versus 3.0 times for the S&P 500, with 79% of fiscal Q2 2027 rev…
