Rubrik has introduced a new AI-based solution named Rubrik Agent Identity at the Black Hat Conference, aiming to enhance the control and management of AI agents' access and permissions. This development seeks to tackle a significant challenge in deploying enterprise agents efficiently.
As AI agent deployments advance, enabling complex, automated workflows across SaaS applications, databases, and APIs, many organisations struggle to monitor and manage agent access effectively. Rubrik's solution is designed to reduce operational risks associated with agent identities by utilising AI to monitor each agent and model context protocol (MCP) at runtime, and by delivering permissions on a per-tool call basis.
Rethinking security boundaries
Dev Rishi, General Manager of AI at Rubrik, explained, "Agents are no longer just synthesising information, they are acting on behalf of employees, and the access models we built for humans. Static credentials were never designed for autonomous actors."
The Rubrik Agent Identity system allows firms to decide which agents can perform certain actions and enforces these decisions in real time, ensuring scoped, short-lived access without standing permissions. Through the Rubrik Agent Cloud, organisations can govern agent activities, enforce identity-aware policies, and apply semantic policy evaluations before initiating sensitive actions, supported by audit logs to trace actions and facilitate confident scaling of agent deployment.
Addressing shadow workforce concerns
The Rubrik Agent Identity system allows firms to decide which agents can perform certain actions
The rise of modern AI creates an unmonitored "shadow workforce" that evades conventional security measures. These systems often utilise broad, static credentials, which could lead to disastrous, system-wide actions if a single agent is compromised. Data from Rubrik Zero Labs indicates that 86% of global IT and security leaders anticipate AI agents will surpass their organisation's security controls within the coming year, while just 23% have full visibility of the agents operating within their environments.
Rubrik Agent Identity, an extension of the Rubrik Agent Cloud platform, introduces a comprehensive "Govern, Control, and Prove" strategy for managing the entire agent lifecycle. It complements Rubrik's SAGE governance framework with four specific pillars: Agent Observability (monitor agents at runtime), Agent Identity (control access per tool call), Agent Runtime Security (enforce policies and detect errors in real time), and Agent Rewind (reverse agent errors swiftly). These features are designed to fortify enterprises' agentic identity posture quickly.
Hardening agentic identity
The architecture offers several critical capabilities, including building an Agent Identity Inventory to discover and document all active AI agents and elements, delegating least-privilege access by scoping permissions to specific MCP servers and tools, and enforcing just-in-time tokens that eliminate standing permissions by validating access at runtime.
The Rubrik Agent Identity system allows firms to decide which agents can perform certain actions
To thwart malicious or unintended actions, every MCP tool call undergoes three security checks: Behavioural Analysis (evaluates tool calls and context), Access Policy Enforcement (verifies run-time policies), and Identity Verification (authenticates sessions with short-lived tokens). If an unauthorised action is detected, it is aborted before execution, and Agent Rewind can rapidly undo any destructive action by an agent, addressing significant concerns within the sector, where 88% of leaders worry about meeting recovery time objectives as agent threats intensify.
Integration with existing frameworks
Rubrik Agent Identity integrates seamlessly with Okta and Microsoft Entra ID, extending existing enterprise identity frameworks to autonomous machine agents without the need for additional directories.
The MCP Gateway acts as a comprehensive security checkpoint for all API-based and MCP resources within the enterprise. This development underlines Rubrik's aim to provide Agentic Cyber Resilience, enabling organisations to stay ahead of machine-speed threats powered by advanced AI models.
Today at the Black Hat Conference, Rubrik, the Security and AI Operations Company, announced Rubrik Agent Identity, a powerful new AI-based solution to manage and control AI agents' access and permissions, addressing a key obstacle in enterprise agent deployment.
AI agent deployments are rapidly evolving, with the potential to execute complex, automated workflows across SaaS applications, databases, and APIs at unprecedented speed and scale. Yet most organisations lack the capability to monitor and control agent access and actions at the necessary speed and scale. Rubrik Agent Identity is designed to reduce operational vulnerabilities that stem from agent identities by allowing customers to both monitor every agent and model context protocol (MCP) at runtime using AI, and to deliver just-in-time permissions per tool call.
Traditional security boundaries
"Agents are no longer just synthesising information, they are acting on behalf of employees, and the access models we built for humans. Static credentials were never designed for autonomous actors," said Dev Rishi, General Manager of AI at Rubrik. "Agent Identity lets enterprises decide who can do what with agents and enforces it per tool call, at the moment of action, with scoped, short-lived access and no standing permissions. With Rubrik Agent Cloud, enterprises can govern agent activity, enforce identity-aware policies, and apply semantic policy evaluation before sensitive actions execute. By using audit logs to prove what happened, agent adoption can scale with confidence, avoiding potential blast radius."
Modern AI creates an unmonitored "shadow workforce" that bypasses traditional security boundaries. Because these systems often rely on broad, static credentials, a single compromised agent can trigger destructive, system-wide actions with zero visibility.
Single compromised agent
According to recent data from Rubrik Zero Labs, 86% of global IT and security pioneers expect AI agents to outpace their organisation's security guardrails within the next year, while only 23% report full visibility into the agents operating in their environments.
Rubrik Agent Identity, delivered as an expansion of the Rubrik Agent Cloud platform, establishes a unified "Govern, Control, and Prove" model across the entire agent lifecycle. The new solution operates alongside Rubrik's established SAGE governance framework, and now provides four distinct Rubrik Agent Cloud pillars:
- Agent Observability: Monitor every agent and MCP at runtime.
- Agent Identity: Control access per tool call at speed and scale using fine-tuned AI.
- Agent Runtime Security: SAGE intent-driven governance to enforce policies, and detect agent errors in real time.
- Agent Rewind: Undo agentic mistakes.
Agentic identity posture
The architecture introduces key capabilities designed to help enterprises rapidly harden their agentic identity posture:
- Build an Agent Identity Inventory: Discover and catalogue all active AI agents, MCP servers, skills, and plugins to immediately eliminate unmonitored shadow AI.
- Delegate Least-Privilege Access: Scope access to specific MCP servers and tools by user and group using On-Behalf-Of federation, extending existing enterprise identity structures rather than replacing them.
- Enforce with Just-In-Time Tokens: Eliminate standing permissions entirely by minting scoped, short-lived tokens per tool call, ensuring access is validated at runtime before execution.
Potential operational impact
To prevent malicious or erroneous actions before they occur, every MCP tool call must clear three distinct checkpoints before execution:
- Behavioural Analysis: SAGE semantically evaluates the requested tool call, its context, input parameters, and potential operational impact before execution.
- Access Policy Enforcement: Run-time security policies are verified at the infrastructure layer, enriched with SAGE context.
- Identity Verification: The agent session is authenticated, and the system mints a short-lived token specifically scoped to that single tool call.
Existing enterprise identities
If an unauthorised action is attempted, such as a write or modification without an explicit policy scope, the transaction is immediately blocked before execution. For unexpected agent behaviors, Agent Rewind instantly and precisely undoes an autonomous agent’s destructive action., addressing the widespread industry concern where 88% of leaders worry about meeting recovery time objectives as agentic threats scale.
Rubrik Agent Identity integrates seamlessly with Okta and Microsoft Entra ID, extending existing enterprise identities to autonomous machine actors without requiring new directories. The MCP Gateway provides a unified security checkpoint for all API-based and MCP resources across the enterprise. Ultimately, Rubrik Agent Identity advances the company’s vision to deliver Agentic Cyber Resilience to the customers, helping them keep pace with machine-speed attacks powered by frontier AI models.