Guardrails and governance to secure identity in the agentic age

Over the course of my career, I’ve been fortunate to witness – and help lead – some of the biggest shifts in identity technology. I was there when identity scaled for the web. I worked on federated SAML trust frameworks to enable single sign-on and trust between disparate organizations. I saw SaaS push identity outside the four walls of the enterprise. And I helped drive the emergence of the identity fabric to manage identity across multi-cloud and hybrid environments.

Now, we’re at the next major turning point.

We are entering the era of agentic computing. AI agents that reason, act, and make decisions on behalf of humans are not science fiction — they’re here, and they’re proliferating fast. This new computing model breaks every assumption we’ve had about identity, trust, and control, and it demands a radically new approach.

That’s why I’m thrilled to announce the launch of Strata’s Identity Orchestration for Agents: a foundational capability in our Maverics platform. This is the industry’s first solution purpose-built to secure and govern AI agents at enterprise scale.

Let me walk you through why this matters, what we’ve built, and how you can get started.

Introducing Maverics for AI Agents with Eric Olden, CEO of Strata Identity

Every major shift in enterprise technology has redefined how we think about identity. Over the past two decades, we’ve expanded the boundaries of identity again and again to keep up with new architectures, users, and trust models.

We’ve seen identity evolve over decades:

  • Web identity – We scaled to millions of users.

  • Federation / SAML – We built distributed trust for B2B and SaaS access.

  • SaaS – Identity left the datacenter and went to the cloud.

  • Multi-cloud – The identity fabric emerged to unify siloed systems.

  • Agents – Now, identity must be orchestrated across autonomous software actors operating on behalf of humans.

Each phase built upon the last. But agents aren’t just another type of service account. They challenge identity in brand-new ways: their lifecycles are ephemeral, their behaviors dynamic, their decisions autonomous.

The implication is clear: agents require identity orchestration. Delegated trust. Distributed runtime control. Federated context. And above all, scalable policy governance.

Why traditional IAM can’t handle AI agents

AI agents aren’t just a new type of identity; they’re a new class of actor entirely. They don’t follow the rules we’ve used to manage humans or machines. Instead, they operate independently, make decisions in real time, and interact with systems across cloud and on-prem environments. Traditional IAM systems were never designed for this level of autonomy, speed, or scale.

The challenges agents introduce are both new and familiar:

  • Scale: There will be 50x–80x more agents than human users in most enterprises.

  • Delegated trust: Agents act “on behalf of” users but execute independently.

  • Lack of visibility: There’s no built-in audit trail for who prompted what.

  • Cross-platform sprawl: Agents live across Google Vertex, Azure Foundry, OpenAI, LangChain, CrewAI, and more.

  • Legacy constraints: Most IAM tools weren’t designed for runtime, cross-agent authorization.

As Todd Thiemann, Principal Analyst at Enterprise Strategy Group, explains:
“As AI agents gain autonomy and blur traditional identity boundaries, enterprises face growing risks from ungoverned agent behaviors and opaque credential flows. Strata’s approach stands out by applying policy-based identity orchestration that brings the same authentication, authorization, and auditability rigor to AI agents that we expect for human users.”

This shift isn’t theoretical. It’s happening fast — and it mirrors what we saw during the rise of SaaS and multi-cloud, only now it’s happening at machine speed. Without identity guardrails, AI agents become shadow actors. And once they’re embedded across your workflows, it’s nearly impossible to rein them in.

Treat agents like people (at least to identity)

The core philosophy behind this launch is simple: agents must be treated with the same identity rigor as humans.

They need unique identifiers. Delegated access. Scoped permissions. Policy enforcement. Continuous Zero Trust authentication. Auditing and revocation. And yes, oversight.

You wouldn’t let a human roam freely through your systems with no MFA, no logging, and no policy. Why let your agents?

Grounded by customers. Designed for reality.

We didn’t build this in a lab. We partnered with forward-looking customers across finance, healthcare, defense, and critical infrastructure. These teams are already deploying agent frameworks and knew they’d need something more than static API keys or service accounts.

What they asked for was clear:

  • Don’t replace our existing IDPs – orchestrate them.
  • Make it work everywhere, from LangChain on a laptop to OpenAI agents running in the cloud to Crew.ai running behind secure perimeter air gaps.
  • Make it auditable, observable, and real-time.

That’s what we built.

Join the agentic identity movement

Starting today, we’re opening up early access to Strata’s Identity Orchestration for Agents. We invite you to:

  • See what your agents are doing
  • Control what they’re allowed to do
  • Prove who delegated the trust – and how it was enforced

Join the dozens of design partners and pioneers already exploring what agent security looks like when done right.

“We built this for the future of enterprise computing. But we also built it to run today.”

👉 Get early access now — join the waitlist

Orchestrating identity for the agentic future

Every new computing paradigm has challenged us to rethink how identity works.

Agentic computing is no different – but the pace, scale, and complexity make it the biggest challenge yet.

We don’t need to throw out everything we’ve built. We just need to orchestrate identity in a way that’s dynamic, distributed, and secure. That’s what Maverics was made for.

Let’s bring trust to the Agentic Age – together. 


Eric Olden
CEO, Strata Identity
Co-Author, SAML, IDQL and Identity Orchestration for Dummies

Learn to secure AI agents in a hands on lab!

Get hands-on with identity controls for AI agents — bind, delegate, and observe authentication and authorization policies in real time.

 

Try the Sandbox