AI & Agent Identity
Identity, permissions and accountability for AI agents and non-human actors. Standards, incidents and practical controls for agentic systems running in production.
Four takeaways from the New York Identity Summit
Thirty per cent of enterprise applications never reach the IDP, only half the room could prove who has access to what, and session timeouts are quietly doing more damage than step-up prompts.
The new MCP specification makes agent tool calls something you can actually govern
Stateless requests, the method and tool name exposed in HTTP headers, and a tighter OAuth story. MCP is moving from convenient to controllable.
Cyera is paying about $1 billion for Oasis, betting identity and data are one problem
A data security company buying a non-human identity company is a wager that "who is accessing this" and "how sensitive is it" stop being separate questions.
Saviynt's Zuma moves agent access decisions to runtime
Standing entitlements answer whether an agent can reach Salesforce. Saviynt's pitch is that the question worth answering is what the agent is trying to do right now.
Okta buys Permiso and keeps walking towards the SOC
The ITDR acquisition brings identity risk signals and behavioural analytics in-house, and Okta is explicit that the destination is the security operations centre.
A hidden image can turn an AI coding agent against its own repository
Ghostcommit buries prompt injection in a committed image that review tools skip and agents read.
OpenAI will gate its most capable cyber models behind a physical key
Identity used to gate a capability rather than data. From 1 September, Trusted Access for Cyber needs a hardware-backed passkey.
The AI agent authorization draft, explained
OAuth, workload identity and consent records, assembled into one model for agents acting on your behalf. It is one person's draft, not a standard.