LAS VEGAS — On Wednesday, Okta CEO Todd McKinnon outlined a plan to adapt Okta’s core identity technology to manage AI agents and push the company deeper into cybersecurity, beyond its 17-year core business helping users securely access business accounts.
“We’re in the perfect position to help match security and innovation by solving the challenges of our industry,” McKinnon said during the Oktane keynote.
That challenge, McKinnon said, is putting AI agents on a tight leash and rallying the industry behind Okta’s Blueprint Alliance – a multi-vendor security coalition.
Over the past year the mission has been to “secure AI” with a “powerful new identity type,” he said. McKinnon then outlined the company’s future path moving beyond the front door toward agent management, runtime security and open standards.
[See Related: Okta, 11 Rivals Launch AI Agent ‘Blueprint Alliance’]
The mechanics leverage Okta’s core identity, authorization and policy infrastructure, revamped for Agent SSO for connections, endpoint discovery for visibility, Agent Gateway for runtime control and a kill switch for wrangling stray AI. Agent Gateway is the key step beyond login: it sits inline between agents and the MCP servers and tools they call, giving Okta a point to enforce permissions, log activity and cut off access.
But McKinnon also acknowledged the limits of an Okta-only solution. “No one company can secure agents alone. It’s not realistic,” he said.
That is the premise behind the Blueprint Alliance, announced Tuesday with 12 founding companies spanning cloud, cybersecurity, data and enterprise software, including AWS, CrowdStrike, Google Cloud, Salesforce, ServiceNow, Wiz and Zscaler. The group is trying to establish a common architecture for identifying agents, limiting what they can do, monitoring them at runtime and containing them when something goes wrong.
Guardrails Without the Brakes
AWS executive Chet Kapoor joined McKinnon virtually during the keynote and argued that the controls cannot become another layer of human approvals that slows agents back to human speed. The goal, he said, is common guardrails that work whether agents come from cloud providers, SaaS vendors or customers themselves.

“This is a lot bigger than Okta. This is a lot bigger than AWS,” Kapoor said.
Dell Technologies offered the customer-side version of the same problem. Taking the keynote stage, Dell CIO and President Doug Schmitt said the company has spent years weaving AI into supply chain, sales, services and software development, with agents increasingly working independently and with one another. That forced Dell to give agents identities and track where they are being used, by whom and with what access.
“If we could see it, we could manage it,” Schmitt said.
Another Okta pillar showcased Wednesday was Agent SSO, built on the open Cross-App Access standard, which moves authorization decisions away from individual users clicking through OAuth consent prompts and back to enterprise policy.
Channeling his inner Oprah, McKinnon told the crowd: “You all have Agent SSO. You get Agent SSO, and you get Agent SSO.” The capability is now generally available to Okta SSO customers, extending Cross-App Access across the company’s existing SSO base.
The keynote then showed the idea working with Claude, connecting the assistant to Atlassian, GitHub, Slack, ServiceNow and Google without forcing the user through a string of separate login and consent screens.
Standards Are the Glue

Anthropic’s David Soria Parra, a co-creator of MCP, joined McKinnon on stage to explain the standards piece. Soria Parra said open standards give enterprises choice and let vendors “build really as an industry together,” while McKinnon stressed that Cross-App Access is not an Okta-only protocol and must be adopted broadly to work.
Once an agent has authenticated, the more consequential questions begin. What applications can it call? Which data can it reach? Can it hand work – and authority – to another agent? What is it actually doing with those permissions? And who gets to shut it down when something goes sideways?
That is where Okta’s Harish Peri, SVP and GM of AI Security, sees the harder problem. In an interview ahead of the keynote, Peri described enterprises already using supervisor agents that delegate work to sub-agents, which may in turn call other tools or MCP servers. Okta’s role, he said, is to preserve the “chain of custody” from user to agent to sub-agent to resource.
Peri later took the keynote stage as Okta’s AI-security chief, underscoring how far the company’s ambitions now extend beyond login and access. That shift is also visible in Okta’s August acquisition of Permiso Security, which adds identity threat detection and response across cloud, SaaS and other identity systems — territory that puts Okta more squarely inside the broader cybersecurity stack.
Okta is also opening that agent-security layer to customers using rival identity providers. McKinnon said companies can keep human identities in another IdP while managing agent identities through Okta for AI Agents, an important concession to the heterogeneous environments the Blueprint is supposed to secure.
Blueprint Meets Reality
The Blueprint is more than a logo wall with members pledging cross-vendor signal sharing and reference integrations spanning permissions, delegation, runtime monitoring and containment. But with Microsoft, OpenAI and Nvidia absent from the founding roster, the coalition still has to prove that interoperability works in practice.
Agent SSO and Agent-to-Agent Connections are available today, while Agent Gateway and Shadow AI Agent Discovery for Endpoints won’t arrive until Q3. Configuration Designer and expanded runtime kill-switch capabilities are planned for Q4.

Wall Street analysts pressed on the same question later Wednesday. BMO’s Keith Bachman noted that multiple vendors are chasing the emerging governance and orchestration layer, while Citi’s Fatima Boolani asked what comes after adding names to the Blueprint roster.
Asked during an Okta investor summit call, also on Wednesday, what comes next for the Blueprint Alliance, McKinnon said customer adoption will be the real test. “If it does not get that kind of traction, it is not going to be super successful.”
That uncertainty is part of the reason customers want a seat at the table. “None of us are as smart as all of us,” World Central Kitchen CTO Brian Stoll told SPB. With the technology changing so quickly, he said, the value of Blueprint is being able to “compare notes and help each other figure this out as we go.”
World Central Kitchen joined the Blueprint Alliance only days earlier and has not yet deployed Okta’s agent-security products.
For Okta, identity may be the starting point for securing AI, but making it work at enterprise scale will require runtime controls, common standards and enough of the industry willing to use them.