The Core Problem Agent Identity Is Solving
When an AI agent gets compromised or simply misbehaves, it doesn’t pause and ask for permission. It acts — using whatever credentials it was handed at deployment. Those credentials are typically scoped for a human, which means they’re far too permissive for an autonomous actor.
Rubrik frames this as a “shadow workforce” problem. Research from Rubrik Zero Labs suggests 86% of IT and security leaders expect AI agents to outpace their organization’s security guardrails within the next year. Only 23% say they have full visibility into the agents already running in their environments. That’s a significant blind spot.
How Agent Identity Actually Works
The service operates across three functions: monitoring, controlling, and remediating.
- Monitoring covers every agent and Model Context Protocol (MCP) server at runtime, building an inventory of active agents, skills, and plugins.
- Controlling access happens per tool call — not per session, not per deployment. Rubrik mints scoped, short-lived tokens for each individual tool call, eliminating standing permissions entirely.
- Remediating risky actions uses identity records, audit logs, and a feature called Agent Rewind, which is positioned as capable of reversing actions that cleared the gateway but still caused problems.
The Three-Checkpoint Gateway
Every tool call passes through an MCP gateway before it executes. The three checkpoints are:
- Behavioral analysis — Rubrik’s SAGE governance engine evaluates the intent, input parameters, and likely operational impact of the request.
- Policy check — enforcement at the infrastructure layer against defined access policies.
- Identity verification — authenticates the agent session and issues a token scoped specifically to that call.
If a tool call falls outside explicit policy scope — say, a write or modification it shouldn’t be making — it’s blocked before execution. Not logged after the fact. Blocked before.
Identity Without a Separate Directory
One practical detail worth noting: Agent Identity integrates with Okta and Microsoft Entra ID using On-Behalf-Of federation. That means enterprises can extend their existing identity structures to machine actors rather than standing up a separate directory just for agents.
That’s a meaningful design choice. It reduces operational overhead and keeps machine identities inside the same governance frameworks already in place for human employees.
Context: Where This Fits in Rubrik’s Broader Direction
Agent Identity is an expansion of Rubrik Agent Cloud, which the company launched in October and made generally available for Anthropic’s Claude in June. The new service targets the credential layer beneath those deployments — the part that determines what agents are actually allowed to touch.
Rubrik’s move into agent tooling accelerated with its acquisition of Predibase in mid-2025, a deal reportedly valued between $100 million and $500 million. Dev Rishi, who co-founded Predibase and served as its CEO, now leads AI at Rubrik and is the face of this launch.
The company now describes itself as “the Security and AI Operations Company,” a positioning shift that signals where it sees its market heading.
What’s Still Unknown
Rubrik has not disclosed pricing or a general availability date for Agent Identity. That makes it difficult to assess fit for smaller teams or evaluate total cost of ownership against alternatives.
The Practical Takeaway
If your organization is deploying AI agents — or planning to — the permission model you’re using almost certainly wasn’t designed for autonomous actors. Agent Identity is positioned to close that gap by enforcing access at the most granular level possible: the individual tool call.
The integration with existing identity providers like Okta and Entra ID lowers the adoption barrier. The Agent Rewind capability addresses the recovery question that most agent security tools don’t answer at all.
Watch for pricing and GA details before committing, but the architecture here is worth understanding now — because the agents are already running.
Comments (0) No comments yet
Want to join this discussion? Login or Register.
No comments yet. Be the first to share your thoughts!