The new solution integrates with existing enterprise directories to issue short-lived permissions for individual tool calls and prevent unauthorized automated actions
At the recent Black Hat Conference, Rubrik, a data security and cybersecurity provider, announced Rubrik Agent Identity, an artificial intelligence-based solution to manage and control AI agents’ access and permissions. The release addresses a primary obstacle in enterprise agent deployment by securing autonomous actions in real time.
AI agent deployments execute automated workflows across SaaS applications, databases, and APIs. However, most organizations lack the capability to monitor and control these actions at scale. According to data from Rubrik Zero Labs, 86% of global IT and security leaders expect AI agents to outpace their organization’s security guardrails within the next year, while only 23% report full visibility into the agents operating in their environments. This unmonitored workforce bypasses traditional boundaries because systems often rely on broad, static credentials, allowing a compromised agent to trigger system-wide actions.
“Agents are no longer just synthesizing information, they are acting on behalf of employees, and using the access models we built for humans. Static credentials were never designed for autonomous actors,” said Dev Rishi, General Manager of AI at Rubrik. “Agent Identity lets enterprises decide who can do what with agents and enforces it at each tool call, at the moment of action, with scoped, short-lived access. With Rubrik Agent Cloud, enterprises can govern agent activity, enforce identity-aware policies, and apply semantic policy evaluation before sensitive actions execute.”
Delivered as an expansion of the Rubrik Agent Cloud platform, the tool allows customers to monitor every agent and model context protocol (MCP) at runtime. The architecture helps enterprises harden their posture by building an inventory to catalog active agents, MCP servers, skills, and plugins. It delegates least-privilege access to specific tools using existing enterprise identity structures and eliminates standing permissions by minting short-lived tokens per tool call. The system includes an Agent Rewind feature to undo mistakes, addressing concerns from 88% of leaders worried about meeting recovery time objectives.
To prevent unauthorized actions, every MCP tool call must clear three checkpoints before execution. The system’s SAGE framework conducts a behavioral analysis of the requested call, its context, and potential impact. Run-time security policies are verified at the infrastructure layer, and the agent session is authenticated with a token scoped to that specific transaction. Unauthorized modifications are blocked prior to execution. The solution integrates with Okta and Microsoft Entra ID, routing API and MCP resources through a unified security gateway.