Okta has turned its agent security framework into a multivendor reference architecture called the Blueprint Alliance, introduced this week at its Oktane event. The model reduces runtime protection to four control questions and combines identity signals with endpoint and network telemetry. President and COO Eric Kelleher said the effort addresses buyer confusion, as vendors in every layer of the stack claim to solve agent security alone. For enterprises moving AI agents into production, the move offers a shared basis for monitoring behavior and selecting responses.
How the Blueprint Alliance is organized
Okta outlined the architecture during Oktane in an interview with theCUBE Research's Krista Case and co-host Rebecca Knight. Kelleher described the Blueprint Alliance as a way to help buyers navigate competing vendor claims and think about protection in a simpler way. The problem, in his account, is that suppliers from each component of the stack present themselves as a single place to fix everything, which leaves security and identity teams without a common frame. The Alliance is therefore positioned as a reference, not a single product, that brings identity and security signals together to track agent behavior and guide the response to risk.
The architecture distills agent security into four questions: where agents are, what they can do, what they are doing and how to respond. Okta contributes identity context on top of endpoint and network telemetry, then compares what each agent connects to against the systems it was authorized to use. Any disparity feeds into real-time analysis that flags suspicious activity, in Kelleher's description. That flow of live data back into a central view is meant to answer whether something looks suspicious and to support a proportionate action rather than a single fixed block.
The background is the shift of AI agents from pilots into production, which requires controls across the technology stack rather than inside one tool. As agents act across endpoints, networks and connected systems, identity becomes the link between an authorized permission and an observed connection. Okta's argument is that no single stack vendor covers that full chain, despite marketing claims to the contrary. The Blueprint Alliance therefore collects signals from different layers and interprets them together, so teams can see location, permission, behavior and response as parts of one runtime problem.
What this means for companies running agents
For companies operating agents, the practical value is a clearer checklist for procurement and operations. An inventory question comes first, followed by permission mapping, continuous monitoring of actions, and a defined response path. In larger organizations this can align identity, endpoint and network owners around the same telemetry and the same decision rules. In smaller firms without separate functions, the same four questions can structure conversations with suppliers about what is already covered and what still needs integration work. The distinction matters in working situations such as support automation or internal process agents that touch several systems at once.
The enforcement side remains staged. Okta can now deactivate a flagged agent to block new sessions, while broader kill-switch functions at the Agent Gateway to revoke active tokens and sessions are described as planned expansion. Kelleher noted that the appropriate response depends on behavior and risk, including cases where agents step beyond intended boundaries during normal exploration and should be redirected and bounded. Buyers should therefore clarify what stops immediately versus what stays active, how authorization lists are maintained, and what this architecture does not replace in endpoint or network controls.
A concrete marker to follow is whether the planned Agent Gateway capability to revoke active tokens and sessions reaches production and how Alliance participants implement the four-question model. Adoption in real deployments, rather than event presentations, will show whether identity plus endpoint and network telemetry produces consistent detection and response. If those pieces appear together, the shared architecture will have moved from guidance to operating practice.
