Unsanctioned agents. Borrowed credentials. Agents exceeding orders. These are the things that keep enterprise security teams up at night. Software vendors have shipped tools to rein them in, but Okta argues those efforts are piecemeal. It’s like trying to empty the ocean with a teaspoon. That’s why on Wednesday at its annual Oktane conference, the cybersecurity firm announced the creation of the Blueprint Alliance. It’s a consortium of technology providers, global system integrators, and strategy industry advisors aimed at crafting an “open multi-vendor architecture” that becomes the standard for governing enterprise agents at scale.
Founding members joining Okta include Amazon Web Services (AWS), Google Cloud, Salesforce, ServiceNow, CrowdStrike, Databricks, Docker, Zscaler, Proofpoint, Lovable, and Wiz. The group also counts GE Appliances and World Central Kitchen as strategic advisors. Okta said all participants are in agreement that a shared, universal set of principles is needed to secure agents:
“Every agent needs to be treated as a first-class identity; access needs to be scoped to a specific task,” Eric Kelleher, Okta’s president and chief operating officer, said in a press briefing. “Delegation needs to be traceable, so we know who authorizes an agent to take an action. Runtime behavior needs to be monitored continuously so we know what the agents are doing and that it’s what was intended. Containment needs to be instant and reversible.”
Okta first published its blueprint for securing the agentic enterprise in March, outlining three questions for security and IT teams to ensure agents don’t run amok. This announcement is meant to highlight that others also share that vision. Kelleher pointed out that while companies have their own ways of securing AI on their platforms, those solutions are limited to one part of the enterprise. With agents moving across platforms, data, applications, devices, networks, and infrastructure, no one has visibility beyond their jurisdiction.
“The risk of unsecured, ungoverned agents is fundamentally an industry problem, not a problem for one company,” he said. “It requires an industry solution, and the reality is, it’s going to take all of us working together.” Along those lines, Kelleher emphasized that the Blueprint Alliance is not an Okta product, but one that belongs to the industry.
As Okta explained it, members of the Blueprint Alliance do more than provide their name to an organization. “The goal…is to bring clarity to the industry on what the issues are that customers need to consider, and then to bring clarity on how to address those issues,” Kelleher said. Every member of this group, he added, plays a role “either in technology, network, or in thought leadership in how to bring the industry to address these issues.”
Each member has committed to building and testing interoperability across Model Context Protocol (MCP), the Open Cybersecurity Schema Framework (OCSF), the Shared Signals Framework (SSF), and Continuous Access Evaluation Profile (CAEP). This is meant to ensure that threat signals raised by a runtime monitor automatically trigger real-time responses across all connected control planes. In addition, the group plans to regularly publish their joint interoperability results and reference integrations.
But the Blueprint Alliance notably lacks the model makers, such as OpenAI and Anthropic. Kelleher acknowledged the exclusion, but said that, while Okta maintains great partnerships with frontier model makers, this phase of the consortium is intended to focus on addressing the four challenges the enterprise has: where are my agents? What can they do? What are they doing? How do I respond? “It’s what the industry really needs right now,” he said.
Another prominent absence is Microsoft, whose Entra is one of the largest enterprise identity platforms in the market—and Okta’s most direct competitor. Its absence leaves Okta as the only identity provider among the founding members, in a consortium whose central premise is that agent identity requires shared standards.
Kelleher shared that the blueprint is expected to evolve to address new use cases as models and infrastructure become more capable and organizations deploy agents at a much greater scale than they do today.
“Securing the agentic enterprise requires more than identity controls. It requires governance, orchestration, and the ability to trace every decision and action an agent takes,” Bhakti Pitre, ServiceNow’s vice president for AI platform security and governance, said in a statement. “The Blueprint Alliance brings together the full stack to answer the critical questions every organization is asking…ServiceNow looks forward to working with Okta and our partners to make this standard work in practice, so enterprises can scale AI confidently and securely.”
Disclosure: I’m attending Okta’s Oktane conference as the company’s guest, with travel and accommodation expenses covered. However, what I write reflects my own reporting and analysis. No one reviewed or approved my posts before publication.
