Okta brings first-class identity to AI agents with Agent SSO (GA)

Tag: S-2026-08-24-okta-agent-sso-ga Type: article (vendor press release) Author(s): Okta, Inc. (corporate); quoted: Ric Smith, President of Products and Technology Date of source: 2026-08-24 Date ingested: 2026-08-28 Authority weight: medium — primary corporate press release, self-interested; GA fact reliable, capability claims vendor-asserted; the release doubles as an upsell for the paid tier Raw file: S-2026-08-24-okta-agent-sso-ga in /_raw_sources/

What it claims

Okta announced general availability of Agent SSO (24 Aug 2026), building the open Cross App Access standard into core Okta SSO (20,000+ customers) at no additional cost. For agents that support Cross App Access, Okta registers the agent as a first-class identity in Universal Directory alongside human employees and issues short-lived, identity-governed tokens instead of stored credentials/static API keys; administrators manage agent policy through the same console and workflows used for employees, moving agent authorization “from individual applications to the enterprise identity provider”. The release frames the problem with Okta’s own survey: only 34% of organisations apply the same security controls to AI agents as to human workers, and most agents today “operate as anonymous traffic with no owner, no policy, and no audit trail”, across three populations — agents built in-house, agents embedded in purchased software, and shadow agents deployed without approval.

The paid tier, Okta for AI Agents (GA since May 2026), extends this to non-Cross-App-Access agents: shadow-agent discovery via browser/endpoint/network detection, assignment of named human owners, agent-to-agent connections, runtime enforcement, access certifications, approval workflows and a deactivation “kill switch”. Cross App Access is described as an open, vendor-neutral OAuth extension, formally incorporated as the Enterprise-Managed Authorization extension for MCP; out-of-the-box integrations include Anthropic (Claude), Atlassian, Slack, Notion, Datadog and others.

Notable quotes

  • “Only 34% of organizations apply the same security controls to AI agents as they do to human workers.” (citing Okta’s AI Agents at Work 2026 report)
  • “They operate as anonymous traffic with no owner, no policy, and no audit trail.” (on agents using static keys/OAuth grants)
  • “Just as Single Sign-On centralized human access decisions at the identity provider, Agent SSO moves agent authorization from individual applications to the enterprise identity provider.”

What’s speculative vs. asserted

Asserted: GA date, inclusion in core SSO at no cost, the Cross App Access mechanism, the Universal Directory registration model, the May 2026 GA of Okta for AI Agents, integration list. Vendor-asserted/unverified: the 34% statistic (Okta-commissioned survey); the effectiveness of shadow-agent discovery; “runtime enforcement” (mechanism undisclosed). Scope limits stated by Okta itself: Agent SSO covers only Cross App Access-capable agents — everything else requires the paid tier. Independent commentary surfaced in search (not fetched) reportedly argues coverage is limited (“does not govern every agent”) — noted, unverified. No regulatory standard is named in the release; DORA ICT access-management, EU AI Act Art. 14/26 human-oversight/deployer duties and ISO 42001 access-control relevance are this vault’s read-across.

Topics this feeds

Open questions raised

  • What audit evidence does Agent SSO retain (token issuance logs, per-agent access records), for how long, and in what form — Art. 12 / SS1/23-grade or operational-log-grade?
  • How does Okta’s agent registry reconcile with the four other inventory claimants tracked on AI Governance Platforms (governance-platform, SecOps, identity-startup, compliance-automation)?
  • Does bundling agent identity free into core SSO commoditise the venture-funded agent-identity cohort (Hush Security et al.)?