At the Black Hat Conference today, Rubrik introduced Rubrik Agent Identity, an innovative AI-driven solution crafted to oversee and regulate AI agents' access and privileges. This comes as a strategic response to a major challenge in the deployment of enterprise AI agents.
The deployment of AI agents is advancing swiftly, capable of performing intricate, automated tasks throughout SaaS applications, databases, and APIs rapidly and extensively. However, many organizations struggle to manage and observe agent access and actions effectively at the necessary scale. Rubrik Agent Identity is created to address these operational vulnerabilities caused by agent identities. It empowers companies to monitor each agent and model context protocol (MCP) in real-time using AI and to provide just-in-time permissions for each tool call.
Redefining Traditional Security Models
"Agents are no longer just synthesizing information; they are acting on behalf of employees, requiring access models originally built for humans. Static credentials were never designed for autonomous actors," stated Dev Rishi, General Manager of AI at Rubrik. “Agent Identity permits enterprises to dictate agent actions and enforces controls per tool call, at the point of action, using brief, focused access and no static permissions.”
Modern AI has given rise to an unmonitored "shadow workforce," which can bypass traditional security barriers. These systems often depend on broad, static credentials, meaning a single compromised agent can lead to systemic destructive outcomes without detection.
Challenges Posed by Single Compromised Agents
Complementing Rubrik’s SAGE governance framework, it extends four key pillars
Rubrik Zero Labs reports that 86% of IT and security leaders worldwide expect AI agents will soon surpass their organizations' security barriers, with only 23% having comprehensive visibility over the agents in their environments. Rubrik Agent Identity, as part of the Rubrik Agent Cloud platform, implements a "Govern, Control, and Prove" structure throughout the agent lifecycle. Complementing Rubrik’s SAGE governance framework, it extends four key pillars:
- Agent Observability: Real-time monitoring of each agent and MCP.
- Agent Identity: Speedy and scalable access control per tool call through refined AI.
- Agent Runtime Security: Enforcement of SAGE governance policies to detect real-time agent errors.
- Agent Rewind: Quick reversal of agent-induced errors.
Enhancing Agentic Identity Security
This new architecture incorporates vital features to improve enterprises’ agentic identity security stance:
- Building an Agent Identity Inventory: Discover and catalog all AI agents, MCPs, skills, and plugins to eliminate shadow AI.
- Delegating Least-Privilege Access: Scoping access per user and group to specific MCP servers and tools using existing identity structures.
- Enforcing with Just-In-Time Tokens: Removing standing permissions by minting short-lived tokens per tool call.
Operational Impact Mitigation
To mitigate potential harmful actions, every MCP tool call undergoes three checkpoints before execution:
- Behavioral Analysis: Evaluation of tool calls, context, input parameters, and potential consequences.
- Access Policy Enforcement: Verification of runtime security policies with SAGE context at the infrastructure layer.
- Identity Verification: Authentication of agent sessions with tokens tailored for single tool calls.
If unauthorized actions are attempted, like unauthorized modifications, the transaction is blocked immediately. Unexpected behaviors are countered with Agent Rewind, addressing the concern of 88% of leaders about recovery times as agentic threats prove challenging.
Rubrik Agent Identity integrates with Okta and Microsoft Entra ID, expanding current enterprise identities to include autonomous machine actions without new directories. Through the MCP Gateway, comprehensive security checkpoints are provided for all API-based and MCP resources within an enterprise, thereby advancing Rubrik’s commitment to delivering Agentic Cyber Resilience in an era of advanced AI-powered attacks.
Today at the Black Hat Conference, Rubrik, the Security and AI Operations Company, announced Rubrik Agent Identity, a powerful new AI-based solution to manage and control AI agents' access and permissions, addressing a key obstacle in enterprise agent deployment.
AI agent deployments are rapidly evolving, with the potential to execute complex, automated workflows across SaaS applications, databases, and APIs at unprecedented speed and scale. Yet most organizations lack the capability to monitor and control agent access and actions at the necessary speed and scale. Rubrik Agent Identity is designed to reduce operational vulnerabilities that stem from agent identities by allowing customers to both monitor every agent and model context protocol (MCP) at runtime using AI, and to deliver just-in-time permissions per tool call.
Traditional security boundaries
"Agents are no longer just synthesising information, they are acting on behalf of employees, and the access models we built for humans. Static credentials were never designed for autonomous actors," said Dev Rishi, General Manager of AI at Rubrik. "Agent Identity lets enterprises decide who can do what with agents and enforces it per tool call, at the moment of action, with scoped, short-lived access and no standing permissions. With Rubrik Agent Cloud, enterprises can govern agent activity, enforce identity-aware policies, and apply semantic policy evaluation before sensitive actions execute. By using audit logs to prove what happened, agent adoption can scale with confidence, avoiding potential blast radius."
Modern AI creates an unmonitored "shadow workforce" that bypasses traditional security boundaries. Because these systems often rely on broad, static credentials, a single compromised agent can trigger destructive, system-wide actions with zero visibility.
Single compromised agent
According to recent data from Rubrik Zero Labs, 86% of global IT and security pioneers expect AI agents to outpace their organization's security guardrails within the next year, while only 23% report full visibility into the agents operating in their environments.
Rubrik Agent Identity, delivered as an expansion of the Rubrik Agent Cloud platform, establishes a unified "Govern, Control, and Prove" model across the entire agent lifecycle. The new solution operates alongside Rubrik's established SAGE governance framework, and now provides four distinct Rubrik Agent Cloud pillars:
- Agent Observability: Monitor every agent and MCP at runtime.
- Agent Identity: Control access per tool call at speed and scale using fine-tuned AI.
- Agent Runtime Security: SAGE intent-driven governance to enforce policies, and detect agent errors in real time.
- Agent Rewind: Undo agentic mistakes.
Agentic identity posture
The architecture introduces key capabilities designed to help enterprises rapidly harden their agentic identity posture:
- Build an Agent Identity Inventory: Discover and catalog all active AI agents, MCP servers, skills, and plugins to immediately eliminate unmonitored shadow AI.
- Delegate Least-Privilege Access: Scope access to specific MCP servers and tools by user and group using On-Behalf-Of federation, extending existing enterprise identity structures rather than replacing them.
- Enforce with Just-In-Time Tokens: Eliminate standing permissions entirely by minting scoped, short-lived tokens per tool call, ensuring access is validated at runtime before execution.
Potential operational impact
To prevent malicious or erroneous actions before they occur, every MCP tool call must clear three distinct checkpoints before execution:
- Behavioral Analysis: SAGE semantically evaluates the requested tool call, its context, input parameters, and potential operational impact before execution.
- Access Policy Enforcement: Run-time security policies are verified at the infrastructure layer, enriched with SAGE context.
- Identity Verification: The agent session is authenticated, and the system mints a short-lived token specifically scoped to that single tool call.
Existing enterprise identities
If an unauthorized action is attempted, such as a write or modification without an explicit policy scope, the transaction is immediately blocked before execution. For unexpected agent behaviors, Agent Rewind instantly and precisely undoes an autonomous agent’s destructive action., addressing the widespread industry concern where 88% of leaders worry about meeting recovery time objectives as agentic threats scale.
Rubrik Agent Identity integrates seamlessly with Okta and Microsoft Entra ID, extending existing enterprise identities to autonomous machine actors without requiring new directories. The MCP Gateway provides a unified security checkpoint for all API-based and MCP resources across the enterprise. Ultimately, Rubrik Agent Identity advances the company’s vision to deliver Agentic Cyber Resilience to the customers, helping them keep pace with machine-speed attacks powered by frontier AI models.