Vanderbilt University is extending identity governance to AI agents embedded in institutional workflows, chief information officer Shane Callahan said at Okta's Oktane event. The university manages access through OneVU, powered by Okta, across residential life, athletics, its own police department and more than $1 billion in research. The move matters because distinct agent identities with scoped access can restrict what software may do, yet leave unresolved who answers when an agent moves outside its guardrails.
Multiple roles meet scoped agent identities
Callahan spoke with theCUBE Research's Krista Case and co-host Rebecca Knight during a broadcast tied to Oktane, focused on changing identity requirements and agent accountability. He explained that one person can hold several university roles at the same time, citing his own case as student, staff member and donor, each with a different profile for working with university systems. Tracking those overlapping security profiles is very difficult, he said. That difficulty forms the baseline, since software agents now operate in the same environment alongside people with multiple affiliations and shifting permissions.
Vanderbilt plans to fit agents into established controls rather than create a parallel regime for AI. Each agent gets a distinct identity with scoped access that defines which data, systems and actions are permitted, narrowing its operating range from the start. New tools continue through the existing technology-intake program and cross-functional governance, where identity data is handled as it would be in any other system. In Callahan's framing, AI does not require rebuilding governance when intake routines, approvals and oversight responsibilities already exist and can be reused.
The background is a change in relationships among people, institutions and technology as agents enter everyday workflows. Vanderbilt feels that shift acutely because housing, athletics, policing and large-scale research each carry different access rules and risk profiles. Against that backdrop, Callahan pointed to accountability gaps that access limits alone do not close. If an agent leaves its guardrails and affects another group or company, it remains unclear whether the operator, the tool provider or another party bears responsibility, and whether cyber insurance would cover the impact.
What agent identities change for operations
For organizations adopting agents, the practical consequence is to register every agent as a managed identity with a defined scope, owner and review path. The procurement routine changes less than expected, since the same intake form, risk check and approval chain used for software can capture an agent, its data sources and permitted actions. In a small company that may mean a single register and one approver who sees all agent activity. In a large organization it means coordination across security, legal and business units to prevent duplicate, overprivileged or orphaned agent accounts.
Access control alone does not settle risk, so several conditions need verification before deployment. Buyers still need to know how agent activity is logged, how guardrails are enforced in practice, and what contracts say about harm to a third party. Useful questions for a vendor include how agent identities are issued and revoked, what prevents quiet expansion of scope, and how incidents are documented for insurers and auditors. This development alone does not show that liability rules have been clarified or that insurance policies have adapted to autonomous actions.
The marker to watch is whether intake records and insurance terms start naming agents explicitly. If Okta-based controls and institutional policies list agent identities, scopes and owners as standard fields, and insurers clarify coverage for actions outside guardrails, the model will have moved from principle to routine business practice.
