AI agents are in the enterprise. The question is no longer whether to deploy them. It is how to secure them.
At Oktane 2026 this week, Okta answered that question with a reference architecture, a coalition, and a protocol. Todd McKinnon, Okta's CEO and co-founder, used his keynote to introduce the blueprint for the secure agentic enterprise: a multi-vendor framework designed to help organisations maintain visibility and control as they deploy autonomous agents across every layer of the stack. The announcement came alongside two product launches: Agent SSO, a new single sign-on layer built for AI agents rather than humans, and Okta for AI Agents, a suite of tools including shadow agent discovery, an agent gateway, and support for third-party identity providers.
The backdrop is the same governance gap that this publication has covered repeatedly over the past month. Gartner predicts the average Fortune 500 enterprise will operate more than 150,000 AI agents by 2028, up from fewer than 15 in 2025. Only 13% of organisations believe they have the right governance in place. The blueprint is a direct response to that gap, and its significance is twofold: it treats agents as first-class identities rather than code, and it does so through an open, multi-vendor coalition rather than a proprietary stack.
The architecture in plain terms
The blueprint is built around four operational questions that every security and IT leader is already asking:
- Where are my agents?
- What can they do?
- What are they doing?
- How do I respond?
Each question maps to a pillar of the architecture. Discovery and identity registration answer the first. Access management answers the second. Runtime authorisation and monitoring answer the third. Active containment, including verified kill switches and rollback capability, answers the fourth.
The key principle is that an AI agent is not a service account, an API key, or a piece of software that sits outside the identity perimeter. It is an active business entity with the ability to inherit privileges, query databases, call downstream APIs, spawn sub-agents, and trigger financial transactions. Traditional network perimeter defences do not map cleanly onto that behaviour. The blueprint shifts security from the network edge to a unified, zero-trust, agentic control plane.
The Blueprint Alliance
No single vendor can secure the agentic enterprise, and Okta is explicit about that. The blueprint was developed by the Blueprint Alliance, a coalition that includes AWS, CrowdStrike, Databricks, Google Cloud, Salesforce, and ServiceNow. The alliance has committed to setting standards, developing integrations, and exchanging risk information between its members.
The coalition model matters because AI agents traverse models, data stores, and infrastructure that no one vendor owns. A single-platform approach would create new silos. A shared architecture, published openly, allows enterprises to build governance once and apply it everywhere an agent operates. Matt Ellard, SVP and General Manager for EMEA at Okta, described the practical benefit in terms of signal exchange: member companies will federate their agent registries with each other, exchange threat signals, and use shared data to stop shadow AI before it proliferates.
Agent SSO and Okta for AI Agents
The two product announcements bring the blueprint into operation. Agent SSO is built on Cross App Access, an open protocol that enables secure agent-to-app and app-to-app connections. It gives enterprises a common mechanism to find agents, define what they can do, and respond when something goes wrong. Unlike traditional SSO, which authenticates a human user once and maintains a session, Agent SSO is designed for non-deterministic, asynchronous, multi-hop execution where a human may have logged off hours before an agent completes its task.
Okta for AI Agents adds the practical layer. It includes Shadow AI Agent Discovery for Endpoints, which scans devices and browser traffic to find unauthorised agent deployments; an Agent Gateway that acts as a controlled entry point for agent-to-system interactions; and support for third-party identity providers so that enterprises are not locked into a single identity stack. Combined, these give security teams the same visibility into AI agents that they have had for human employees for the past two decades.
What the Oktane announcements mean for enterprise buyers
Buyers evaluating AI agent platforms should treat identity and governance as primary procurement criteria, not afterthoughts. The Okta blueprint makes this easier by giving enterprise architects a standard against which to evaluate vendor claims. If a platform cannot answer the four operational questions, it is not enterprise-ready.
Specifically, buyers should look for three capabilities. First, agent discovery: the ability to inventory every agent operating inside the corporate perimeter, including those deployed by individual employees through consumer-grade tools. Second, runtime monitoring: continuous observation of what agents are doing, not just what they were authorised to do at setup. Third, containment: the ability to suspend, quarantine, or terminate an agent in real time, with a clear rollback path. These three capabilities map directly onto the blueprint, and they should appear on every enterprise RFP for agentic AI platforms.
What it means for suppliers
For vendors in the agentic AI market, the blueprint raises the bar for what enterprise buyers will expect. Products that ship without integration into standard identity providers, without runtime audit trails, and without policy enforcement will find it increasingly difficult to pass procurement review in regulated industries. The Blueprint Alliance is not a regulatory body, but its members collectively define the architectures that most enterprises already run. Alignment with the blueprint is therefore becoming a de facto market requirement.
Suppliers should also note the coalition's emphasis on shared risk signals. As Matt Ellard put it, member companies will exchange threat data and federate agent registries. That means a security incident involving an agent in one enterprise can propagate as a protective signal to others. Vendors that can participate in that exchange, by emitting and consuming standardised risk signals, will be more valuable partners than those that operate as closed systems.
The Agentic Expo angle
Agentic Expo 2027, taking place at Olympia London on 23-24 March 2027, exists at the intersection of capability and trust. The Okta announcements this week confirm that the market is moving from pilot to production, and that the primary obstacle to production-scale deployment is not model performance but identity and governance infrastructure.
For buyers, the questions to ask exhibitors are straightforward. Does your platform integrate with existing identity providers? Can it discover and inventory agents across SaaS, cloud, and local environments? Does it provide real-time runtime controls and a verified kill switch? These are no longer specialist security questions. They are the defining procurement criteria for agentic AI at scale.
For suppliers, the message is equally clear. Governance is not a feature to add in version two. It is the foundation on which enterprise deals will be won or lost between now and March 2027. The vendors who treat identity as a first-class layer in their architecture are the ones who will close the largest contracts.
Sources: Okta Newsroom, "Oktane 2026: AI agents are in the enterprise — now what?" 26 September 2026; Okta Newsroom, "Setting the standard for the secure agentic future," 26 September 2026; Okta, "Blueprint for the Secure Agentic Enterprise," published September 2026; Gartner, "Gartner Identifies Six Steps to Manage AI Agent Sprawl," 28 April 2026.