There's a new kind of actor operating inside your enterprise. It reads your pipeline data, opens pull requests, files tickets, queries customer records, and sends email. It works at machine speed, around the clock, without a human reviewing every step.
And in most organizations today, nobody can say exactly how many of these actors exist, what they can touch, or which one performed which action.
AI agents have crossed the line from generating answers to taking action. That shift is the single biggest change to the enterprise access model since the move to cloud.
But the access model hasn't kept up.
Agents inherit permissions from humans. They authenticate with static API keys, personal access tokens, and shared service accounts. They hold standing privileges that persist whether they're acting or not. None of that was built for autonomous actors. Recent data from Rubrik Zero Labs revealed a scary truth: 86% of global IT and security leaders expect AI agents to outpace their organization's security guardrails within the next year. Even scarier is that only 23% or respondents report full visibility into the agents operating in their environments.
This week at Black Hat USA, Rubrik is announcing Rubrik Agent Identity, the access plane for Rubrik Agent Cloud. It governs who can do what with agents—which users and groups can use which agents, which MCP servers and tools those agents can reach, and what scoped access each individual tool call receives at the moment of action.
Autonomous AI is transforming the enterprise, but unlocking its true potential requires a new security standard. Download the Blueprint for AI Governance and learn how to update your security posture for the AI era.
The Breach is Not One Permission, it's the Composition
Here's the scenario that keeps security leaders up at night (and it doesn't involve a compromised credential).
A business user asks an agent to summarize open opportunities and send follow-up emails to customer executives. The user has Salesforce access. The user has email access. Each permission is individually valid. But the agent composes them: it reads pipeline data, reasons over revenue context, and sends it externally—an action no one intended and no policy ever contemplated.
Human identity systems can't see this problem, let alone stop it. Human IAM answers one question: can this user access this application? Agentic AI raises a different one: can this user, through this agent, receive scoped access for this specific tool call?
That delegation chain (user to agent to tool to action) is the new control point. Existing access models were never built to answer it. So most organizations fall back to the do-nothing default: agents running on shared service accounts and embedded API keys, with broad, persistent access and no attribution.
Shadow AI compounds the problem, as developers and business users install agents, MCP servers, plugins, and skills faster than security teams can inventory them.
What Agent Identity Does
Agent Identity moves agent access from broad, standing permissions to scoped, short-lived access tied to a specific user, a specific agent, and a specific action. This evolution in identity action requires an evolution in policy:
Monitor every agent and MCP server: You cannot govern what you cannot see. Agent Identity discovers and catalogs every active agent, MCP server, skill, and plugin in your environment. This eliminates unmonitored shadow AI and gives security teams an agent identity inventory as a foundation.
Control access per tool call: Access is decided at the moment of action, not granted in advance. Agent Identity federates with your existing identity providers (Okta and Microsoft Entra ID) so agents act on behalf of a specific human with scoped, delegated access, never shared service accounts or embedded keys. Every MCP tool call receives a scoped, short-lived token minted for that call only. That means you aren’t left with standing permissions to monitor and least privilege is established at runtime.
Remediate risky actions with identity, audit, and rewind: Every tool call is attributed to a specific identity, with a full session audit trail and SIEM integration. So when an action needs to be reversed, agent rewind undoes it, precisely. That resilience matters: 88% of IT and security leaders worry about meeting recovery time objectives as agentic threats scale.
Three checkpoints before anything executes
Under the hood, every MCP tool call clears three checkpoints before it runs:
1. Behavior: Rubrik Agent Cloud's Semantic AI Governance Engine (SAGE) analyzes the intent, parameters, and values of the call to determine if an action violates established policy.
2. Access: The MCP Gateway enforces access policy at the infrastructure layer, enriched with SAGE context like intent and risk level, to determine if a request should be allowed.
3. Identity: The agent session is authenticated, and a scoped, short-lived token is minted for that specific tool call to establish the minimum access this action requires.
Here's what that looks like in practice. An enterprise connects an AI client to an internal MCP server. Without Agent Identity, the agent sees, and can call, every tool the server exposes. With Agent Identity, access policy determines which tools this user and group can reach through this agent.
Reads proceed with least privilege. Writes and modifications require explicit policy scope, without which they are blocked before execution, not flagged after.
Built to Extend Your Identity Stack, Not Replace It
Agent Identity extends the identity infrastructure you already run. It federates with Okta and Microsoft Entra ID, brings user and group context into every access decision, and deploys into the Rubrik Agent Cloud data plane with a unified checkpoint for MCP and API-based resources.
Most identity systems were built for humans. Most gateways route traffic. Most AI governance tools inspect prompts or logs. Agent Identity focuses on the moment that matters most: when an agent attempts to access a tool and act. That moment needs identity, policy, runtime context, scoped authorization, and attribution—together.
Rubrik Agent Identity also completes the Rubrik Agent Cloud governance model, a unified Govern, Control, and Prove approach across the agent lifecycle:
SAGE governs what agents do.
Agent Identity controls who can do what with agents.
Observability, audit, and agent rewind prove what happened, and undo actions when necessary.
This is aligned with the core Rubrik promise: cyber resilience. In this case, we are extending that promise to agentic AI.
Agentic Cyber Resilience is resilience you can prove for the workforce you can't always see.
Getting Started: Rapidly Harden Your Agentic Identities in Three Steps
You don't need to solve every agent identity problem in one day. But you need to close the riskiest gaps immediately, building on a framework that deepens over time:
1. Create an agent identity inventory: Discover every agent, MCP server, skill, and plugin and eliminate shadow AI
2. Delegate access via On-Behalf-Of: Agents must act for a specific human with scoped, delegated access, never shared accounts or embedded keys
3. Enforce with just-in-time tokens: Scoped, short-lived tokens per tool call that deliver least privilege at runtime (with no standing permissions)
Rubrik Agent Identity is available as part of Rubrik Agent Cloud. Come see it live at Black Hat USA, or request a demo to see how Agent Identity secures the moment your agents act.