Rubrik announces Agent Identity to manage AI agent access and permissions

0

Rubrik has announced Rubrik Agent Identity, a new product designed to manage and control AI agents’ access and permissions, as organisations increase deployments of autonomous agents across enterprise systems.

The company said it made the announcement at the Black Hat Conference in Las Vegas on August 4, 2026. Rubrik’s release positioned the product as a response to growing concerns that agentic systems can act with broad credentials and limited oversight, increasing the risk of unwanted or unauthorised actions.

According to Rubrik, Agent Identity is intended to address operational risks created by “agent identities” by enabling monitoring of agents and model context protocol (MCP) servers at runtime, and by issuing just-in-time permissions for each tool call. The company said the capability is delivered as an expansion of its Rubrik Agent Cloud platform.

“Agents are no longer just synthesising information, they are acting on behalf of employees and using the access models we built for humans. Static credentials were never designed for autonomous actors,” said Dev Rishi, General Manager of AI at Rubrik. “Agent Identity lets enterprises decide who can do what with agents and enforces it at each tool call, at the moment of action, with scoped, short-lived access. With Rubrik Agent Cloud, enterprises can govern agent activity, enforce identity-aware policies, and apply semantic policy evaluation before sensitive actions execute.”

Rubrik cited research from its Zero Labs unit claiming that 86% of global IT and security leaders expect AI agents to outpace their organisation’s security guardrails within the next year, while 23% report full visibility into the agents operating in their environments.

As described by Rubrik, the updated Rubrik Agent Cloud platform includes four components: Agent Observability, Agent Identity, Agent Runtime Security, and Agent Rewind, which the company said is intended to undo agent-driven mistakes.

The release also outlined an MCP Gateway, described as a unified checkpoint where each tool call is evaluated before execution. Rubrik said the process includes behavioural analysis, access policy enforcement and identity verification, with short-lived tokens scoped to a single tool call. The company said unauthorised actions would be blocked before execution.

Rubrik said the product integrates with Okta and Microsoft Entra ID to extend existing enterprise identities to autonomous machine actors, without requiring new directories.

Share.