AIToday
Large Language ModelsAI Safety & AlignmentTop Companies' AI MovesAI Business & IndustryTop Companies AIPublished: Oct 2, 2026, 06:30 JST

Idira gives AI agents SPIFFE identities, MCP tool limits

Idira gives AI agents SPIFFE identities, MCP tool limits

3 Key Points

  1. What happened

    Palo Alto Networks' Idira shipped August features to govern AI agents — MCP access policies limiting which tools an agent can run, SPIFFE identities and short-lived tokens for Google Gemini Enterprise agents, and near-real-time account sync from Privilege Cloud.

  2. Why it matters

    Agents become registered, auditable identities rather than shadow scripts borrowing someone else's token, and machine identity shifts from stored static secrets toward workloads proving what they are — the platform's own "identity where you can, secrets where you must" idea.

  3. What to watch

    Sync latency is described as "close to real time" and rollouts finished region by region, so whether the tightest least-privilege controls hold in day-to-day operations is likely the test. Note the APIs now hide authenticator configuration without permission.

WHO IT HITSIdentity and security teams managing machine and AI-agent credentials in enterprise environments gain controls to scope each agent's access and replace static credentials with short-lived ones; platform admins also face stricter visibility limits on authenticator configuration.

Not sure about something? Ask the AI

Questions and answers are published on this page.

Summaries like this, in your inbox every morning.

Context & Analysis

Idira's August release is the first in a monthly series that reads the platform's release notes and pulls out changes worth attention. The company frames the batch around two shifts: machine identity moving from static secrets toward workloads that prove what they are and receive short-lived credentials, and AI agents becoming identities to register, govern, and audit rather than "shadow scripts running around with someone else's token."

The agent-side changes converge on giving each agent a governable identity. MCP access policies link the users who can start a session, the agents they operate through, and the specific tools on an MCP server. Separately, agents can now be linked to cloud-native identifiers such as an AWS ARN or an app ID during registration, matching a newly registered agent to one already in discovered inventory. For agents on the Google Gemini Enterprise Agent Platform (formerly Vertex AI), Secure Workload Access issues unique SPIFFE identities and short-lived tokens with trust domains and policy managed centrally.

On the workload side, Idira reduced friction: workloads can be edited in place from the Workloads page, while authenticators without permission now show only their type and Service ID. On secrets, unmanaged secrets can be deleted synchronously from Secrets Hub, and account changes from Privilege Cloud sync to Secrets Manager SaaS shortly after they happen. A secret read now reflects Privilege Cloud changes in close to real time rather than after the next sync cycle, which is the practical payoff — though whether that latency holds across all regions is the kind of thing operations teams will likely test.

FAQ
What is SPIFFE and how does Idira use it?
SPIFFE is an open standard that gives workloads a verifiable identity document instead of a stored secret. Idira's Secure Workload Access issues SPIFFE identities and short-lived tokens to agents on the Google Gemini Enterprise Agent Platform.
What do the new MCP access policies actually control?
They tie together the users who can start a session, the agents they operate through, and the specific tools an agent can call on a given MCP server. This keeps an agent limited to the tools its job actually needs.
What changed for Privilege Cloud account sync?
Account creations, property updates, deletions, and password rotations from CPM and the Secrets Rotation Service now push to Secrets Manager SaaS automatically. The regional rollout completed in August with us-east-1.
Top Companies AIRead Original Article

AI news that matters for your work, delivered every morning.

Pick your industry and the AI tools you use, and get news related to your work every day.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.

Questions and answers are published on this page.

Related Articles

Next articleCanon starts free AI tool rollout for PIXUS