Summary is AI-generated, newsdesk-reviewed
  • Rubrik unveils AI-driven Agent Identity at Black Hat, revolutionising enterprise security with dynamic permissions.
  • AI agents create security vulnerabilities; Rubrik Agent Identity offers real-time monitoring and control.
  • New solution enhances agent lifecycle governance, improving security across SaaS, APIs, and databases.

Rubrik has introduced a new AI-based solution named Rubrik Agent Identity at the Black Hat Conference, aiming to enhance the control and management of AI agents' access and permissions. This development seeks to tackle a significant challenge in deploying enterprise agents efficiently.

As AI agent deployments advance, enabling complex, automated workflows across SaaS applications, databases, and APIs, many organisations struggle to monitor and manage agent access effectively. Rubrik's solution is designed to reduce operational risks associated with agent identities by utilising AI to monitor each agent and model context protocol (MCP) at runtime, and by delivering permissions on a per-tool call basis.

Rethinking security boundaries

Dev Rishi, General Manager of AI at Rubrik, explained, "Agents are no longer just synthesising information, they are acting on behalf of employees, and the access models we built for humans. Static credentials were never designed for autonomous actors."

The Rubrik Agent Identity system allows firms to decide which agents can perform certain actions and enforces these decisions in real time, ensuring scoped, short-lived access without standing permissions. Through the Rubrik Agent Cloud, organisations can govern agent activities, enforce identity-aware policies, and apply semantic policy evaluations before initiating sensitive actions, supported by audit logs to trace actions and facilitate confident scaling of agent deployment.

Addressing shadow workforce concerns

The Rubrik Agent Identity system allows firms to decide which agents can perform certain actions

The rise of modern AI creates an unmonitored "shadow workforce" that evades conventional security measures. These systems often utilise broad, static credentials, which could lead to disastrous, system-wide actions if a single agent is compromised. Data from Rubrik Zero Labs indicates that 86% of global IT and security leaders anticipate AI agents will surpass their organisation's security controls within the coming year, while just 23% have full visibility of the agents operating within their environments.

Rubrik Agent Identity, an extension of the Rubrik Agent Cloud platform, introduces a comprehensive "Govern, Control, and Prove" strategy for managing the entire agent lifecycle. It complements Rubrik's SAGE governance framework with four specific pillars: Agent Observability (monitor agents at runtime), Agent Identity (control access per tool call), Agent Runtime Security (enforce policies and detect errors in real time), and Agent Rewind (reverse agent errors swiftly). These features are designed to fortify enterprises' agentic identity posture quickly.

Hardening agentic identity

The architecture offers several critical capabilities, including building an Agent Identity Inventory to discover and document all active AI agents and elements, delegating least-privilege access by scoping permissions to specific MCP servers and tools, and enforcing just-in-time tokens that eliminate standing permissions by validating access at runtime.

The Rubrik Agent Identity system allows firms to decide which agents can perform certain actions

To thwart malicious or unintended actions, every MCP tool call undergoes three security checks: Behavioural Analysis (evaluates tool calls and context), Access Policy Enforcement (verifies run-time policies), and Identity Verification (authenticates sessions with short-lived tokens). If an unauthorised action is detected, it is aborted before execution, and Agent Rewind can rapidly undo any destructive action by an agent, addressing significant concerns within the sector, where 88% of leaders worry about meeting recovery time objectives as agent threats intensify.

Integration with existing frameworks

Rubrik Agent Identity integrates seamlessly with Okta and Microsoft Entra ID, extending existing enterprise identity frameworks to autonomous machine agents without the need for additional directories.

The MCP Gateway acts as a comprehensive security checkpoint for all API-based and MCP resources within the enterprise. This development underlines Rubrik's aim to provide Agentic Cyber Resilience, enabling organisations to stay ahead of machine-speed threats powered by advanced AI models.

In case you missed it

Hikvision solution boosts Muçum flood preparedness
Hikvision solution boosts Muçum flood preparedness

When Brazil’s Taquari River threatens to overflow, the Municipality of Muçum no longer waits and watches—it knows. Using Hikvision’s water-level detection...

Responsible AI adoption starts with governance
Responsible AI adoption starts with governance

The eagerness to adopt AI in physical security is increasing as teams want to implement technology solutions for faster, smarter operations. At the same time, the conversations sur...

Solink's AI agents boost efficiency of existing infrastructure with automation
Solink's AI agents boost efficiency of existing infrastructure with automation

Deploying artificial intelligence (AI) tools should be seen as a business initiative rather than a technology initiative, says Martin Soukup, CTO of Solink, a cloud-based video sec...