SecurityBrief India - Technology news for CISOs & cybersecurity decision-makers
India
Rubrik launches Agent Identity for AI agent controls

Rubrik launches Agent Identity for AI agent controls

Wed, 5th Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Rubrik has launched Agent Identity, a product for managing and controlling AI agents' access and permissions. It extends the company's Agent Cloud platform.

The launch addresses a growing problem as businesses test and deploy AI agents across software applications, databases, and APIs. Many organisations lack enough visibility into what those agents can access or do once they operate at scale.

Agent Identity is designed to monitor agents and model context protocol, or MCP, services at runtime and assign permissions for each tool call as actions are requested. The approach is intended to replace broad standing access with short-lived permissions tied to individual actions.

Rubrik is positioning the product around identity controls for autonomous software actors rather than human users. That reflects a broader shift in corporate technology as companies move from using generative AI for information tasks to using agents for automated operational work.

Research from the company's Zero Labs unit found that 86% of global IT and security leaders expect AI agents to outpace their organisation's security guardrails within the next year. The same research found that 23% report full visibility into the agents operating in their environments.

Those figures point to a gap between adoption and oversight. If agents are given broad, persistent credentials, a compromised or faulty system could make changes across connected systems before security teams detect the activity.

How it works

Agent Identity forms part of a broader model Rubrik describes as "Govern, Control, and Prove" across an AI agent's lifecycle. Within Agent Cloud, the company groups its offering into four areas: observability, identity, runtime security, and Agent Rewind, a function intended to reverse unwanted actions.

The identity element starts with an inventory of active AI agents, MCP servers, skills, and plug-ins. The aim is to give companies a clearer record of which autonomous systems are active in their environments and reduce the risk of untracked systems operating outside formal oversight.

A second part focuses on least-privilege access. Customers can assign access to specific MCP servers and tools by user and group through on-behalf-of federation, using existing identity structures instead of setting up separate directories for AI systems.

The final stage issues short-lived tokens for each tool call. Under that model, access is checked at runtime before an action proceeds, rather than relying on static credentials that remain in place over time.

At the centre of the system is an MCP Gateway that acts as a checkpoint for API-based and MCP resources. Every MCP tool call is evaluated through three stages before execution: behavioural analysis, access policy enforcement, and identity verification.

Behavioural analysis is handled through SAGE, the company's semantic governance framework. Rubrik says SAGE assesses the requested tool call, its context, input parameters, and potential operational impact before the action is allowed to proceed.

Policy checks are then carried out at the infrastructure layer, with context from SAGE, before the system authenticates the agent session and creates a token scoped to that single tool call. Unauthorised write or modification attempts can be blocked before execution if they fall outside explicit policy scope.

Identity partners

The product integrates with Okta and Microsoft Entra ID, allowing organisations to extend existing enterprise identities to autonomous machine actors. That means companies can apply current identity frameworks to AI agents rather than introducing separate identity stores for them.

This interoperability may matter for large businesses that already rely heavily on identity platforms to manage access for staff, contractors, and services. By linking AI agents into those frameworks, security teams may be able to apply policy more consistently across human and machine users.

Dev Rishi outlined the company's view of the challenge facing customers as AI systems take on wider operational roles. "Agents are no longer just synthesising information, they are acting on behalf of employees and using the access models we built for humans. Static credentials were never designed for autonomous actors," said Dev Rishi, General Manager of AI, Rubrik.

He also described how the access model is intended to work in practice. "Agent Identity lets enterprises decide who can do what with agents and enforces it at each tool call, at the moment of action, with scoped, short-lived access. With Rubrik Agent Cloud, enterprises can govern agent activity, enforce identity-aware policies, and apply semantic policy evaluation before sensitive actions execute," said Rishi.

The launch comes as security suppliers race to respond to the spread of agentic AI in corporate environments. As more companies connect autonomous systems to operational data and business software, the question of how to audit, limit, and reverse their actions is becoming a central issue for security and risk teams.

Rubrik also said concern over recovery is rising, with 88% of leaders in its research worried about meeting recovery time objectives as agent-related threats scale.