Skip to content

Rubrik introduces “Agent Identity” for AI agent access control

In brief: Rubrik is introducing Agent Identity, a just-in-time access control system for AI agents that combines time-limited tokens, policy checks before every action, and an undo function, with integration into Entra ID and Okta.

Rubrik is expanding its Agent Cloud with the security solution “Agent Identity,” which controls autonomous AI agents’ access to applications and data according to the just-in-time principle. For CISOs, this addresses a key gap: traditional permission concepts are designed for human users with permanent credentials, not for autonomously acting agents.

Rubrik has unveiled “Agent Identity,” a new component of the Rubrik Agent Cloud designed to control AI agents’ access to enterprise applications, databases, and APIs. Rather than granting agents permanent, extensive permissions, according to the vendor each individual tool call receives a time-limited access token. Before every action, the platform checks identity, applicable security policies, and the context of the requested operation; unauthorized actions are blocked immediately.

The solution consists of four building blocks: continuous monitoring of all AI agents and Model Context Protocols (MCP), identity-based access control, ongoing policy checks, and an undo function called “Agent Rewind,” which allows erroneous actions by autonomous agents to be reversed. In addition, the platform creates an inventory of active agents, MCP servers, and plugins to make previously uncontrolled AI applications within the enterprise visible.

For CISOs, it is relevant that, according to Rubrik, Agent Identity can be integrated with existing identity solutions such as Microsoft Entra ID and Okta. This allows existing identity and permission concepts to be extended to autonomous agents without building additional directory services. The principle of least privilege is intended to ensure that agents only access the resources actually necessary for their specific task.

Before every tool call, access goes through several verification steps: analysis of the requested operation and its context, comparison against security policies, and authentication of the agent session. For example, if an agent attempts to perform write access or data changes without the corresponding authorization, the action is automatically prevented, according to Rubrik. For security officers, this provides a practical approach to closing the governance gaps in identities and permissions that arise as agent adoption increases.


Source: www.it-daily.net · Published August 6, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: