At the 2026 Black Hat conference, security and AI operations firm Rubrik (NYSE: RBRK) introduced Rubrik Agent Identity, an AI-powered solution designed to manage and control AI agent access and permissions, addressing a critical barrier to enterprise deployment.
As AI agents perform complex automated workflows across SaaS applications, databases, and APIs, most organizations lack the speed and scale needed to monitor agent behavior and permissions. Rubrik Agent Identity aims to reduce operational vulnerabilities from agent identities by allowing customers to monitor agents at runtime and grant instant permissions for each tool call.
Dev Rishi, General Manager of AI at Rubrik, noted: "Agents are no longer just synthesizing information; they are acting on behalf of employees and using the access models we built for humans. Static credentials were never designed for autonomous executors. Agent Identity lets enterprises define what an agent can do, and enforce it with every tool call, providing scoped, short-lived access credentials at the moment of action."
Currently, modern AI creates an unmonitored "shadow workforce" that bypasses traditional security boundaries. Data from Rubrik Zero Labs shows that 86% of global IT and security leaders expect AI agents to outpace organizational security defenses within the next year, with only 23% having full visibility into agents in their environments.
As an extension of the Rubrik Agent Cloud platform, Rubrik Agent Identity establishes a unified governance model covering the entire agent lifecycle, offering four core functions: agent observability (runtime monitoring), agent identity (tool-call-level access control), agent runtime security (policy enforcement and real-time detection), and agent rollback (reversing erroneous actions). The architecture quickly strengthens the identity security posture through three steps: establishing an agent identity inventory, delegating least-privilege access, and enforcing access control via instant tokens.
At the MCP gateway level, each tool call must pass through three checkpoints—behavioral analysis, access policy enforcement, and identity verification—before execution, with unauthorized operations immediately blocked upon detection. Rubrik Agent Identity already integrates seamlessly with Okta and Microsoft Entra ID, extending existing enterprise identities to autonomous machine executors.
Comments