Rubrik unveils Agent Identity to secure AI actions in real time
Rubrik launched Agent Identity at Black Hat to secure AI agents with real-time access control. The platform addresses a major visibility gap, with only 23% of leaders reporting full oversight of agents despite 86% expecting them to outpace security guardrails. Key features include runtime monitoring, just-in-time tokenization, and integration with Okta and Microsoft Entra ID.

*this image is generated using AI for illustrative purposes only.
Rubrik (NYSE: RBRK) announced Rubrik Agent Identity at the Black Hat Conference, introducing a new AI-based solution to manage and control access and permissions for autonomous AI agents. The product aims to address a critical obstacle in enterprise agent deployment: the lack of capability to monitor and control agent actions at scale. With AI agents increasingly executing complex workflows across SaaS applications, databases, and APIs, organizations face heightened risks from unmonitored "shadow workforces" that bypass traditional security boundaries using static credentials. Rubrik Agent Identity is designed to reduce these operational vulnerabilities by providing real-time monitoring and just-in-time permissions.
The solution operates as an expansion of the Rubrik Agent Cloud platform, establishing a unified "Govern, Control, and Prove" model across the entire agent lifecycle. It integrates with Rubrik’s established SAGE governance framework to provide four distinct pillars: Agent Observability, Agent Identity, Agent Runtime Security, and Agent Rewind. According to Dev Rishi, General Manager of AI at Rubrik, static credentials were never designed for autonomous actors. "Agent Identity lets enterprises decide who can do what with agents and enforces it at each tool call, at the moment of action, with scoped, short-lived access," he said.
Market Context and Visibility Gaps
Data from Rubrik Zero Labs highlights the urgency of this development. Eighty-six percent of global IT and security leaders expect AI agents to outpace their organization’s security guardrails within the next year. Despite this rapid adoption, only 23% report full visibility into the agents operating in their environments. Furthermore, 88% of leaders worry about meeting recovery time objectives as agentic threats scale. The new architecture is designed to eliminate unmonitored shadow AI by discovering and cataloging all active AI agents, Model Context Protocol (MCP) servers, skills, and plugins.
Key Capabilities and Architecture
Rubrik Agent Identity introduces a three-step process to harden agentic identity posture. First, it builds an Agent Identity Inventory to discover active components. Second, it delegates least-privilege access by scoping permissions to specific MCP servers and tools via On-Behalf-Of federation. Third, it enforces access with just-in-time tokens, minting scoped, short-lived tokens per tool call to ensure runtime validation.
| Pillar | Function |
|---|---|
| Agent Observability | Monitor every agent and MCP at runtime |
| Agent Identity | Control access per tool call using fine-tuned AI |
| Agent Runtime Security | Enforce policies and detect errors via SAGE |
| Agent Rewind | Undo agentic mistakes instantly |
To prevent malicious or erroneous actions, every MCP tool call must clear three checkpoints before execution. Behavioral Analysis uses SAGE to semantically evaluate the requested tool call, its context, and potential impact. Access Policy Enforcement verifies run-time security policies at the infrastructure layer. Finally, Identity Verification authenticates the agent session and mints a short-lived token specific to that single tool call. If an unauthorized action is attempted, such as a write operation without explicit policy scope, the transaction is blocked before execution.
Ecosystem Integrations and Recovery
Rubrik Agent Identity integrates seamlessly with Okta and Microsoft Entra ID, extending existing enterprise identities to autonomous machine actors without requiring new directories. The MCP Gateway provides a unified security checkpoint for all API-based and MCP resources across the enterprise. For unexpected agent behaviors that slip through defenses, the Agent Rewind feature allows enterprises to instantly and precisely undo destructive autonomous actions. This capability directly addresses the industry concern regarding recovery time objectives in the face of scaling agentic threats.
What the Numbers Show
The disparity between adoption expectations and current visibility is stark. While 86% of leaders anticipate agents outpacing security guardrails, only 23% have full visibility into their environments. This 63-percentage-point gap suggests that most enterprises are deploying autonomous actors without adequate monitoring infrastructure. Rubrik’s solution targets this blind spot by shifting from static credential management to dynamic, tool-call-level enforcement, aiming to close the visibility gap before security breaches occur.
How might the introduction of just-in-time token enforcement impact the performance latency of high-frequency autonomous AI workflows in enterprise environments?
What potential competitive threats could emerge from major cloud providers (e.g., AWS, Azure, Google Cloud) developing native identity management features for AI agents?
How will regulatory bodies likely evolve data privacy and liability frameworks to address errors or malicious actions committed by autonomous agents despite security guardrails?

































