update
May 14, 2026
By Teun
Okta expands AI agent security to Bedrock and other identity systems
Okta expanded its AI agent security platform to Amazon Bedrock and other agent ecosystems, while also opening support to customers using non-Okta identity providers. The company said the move is meant to help enterprises discover, onboard, protect and govern AI agents across mixed vendor environments.
Okta Inc. said today that it is expanding Okta for AI Agents to cover any agent ecosystem, any enterprise resource and any identity provider, including a new integration with Amazon Web Services Inc.’s Amazon Bedrock. The company also said the platform will work with organizations that use identity systems other than Okta for human users, such as Microsoft Corp.’s Entra ID and Ping Identity Holdings Corp.
The update is aimed at enterprises that are already deploying AI agents across multiple builder platforms and resource types. According to Okta, those deployments create gaps when identity tools are tied too closely to a single vendor stack, because IT teams may lose visibility into where agents come from, what they can access and who is responsible for them.
“The agentic enterprise doesn’t fit neatly into one vendor’s ecosystem,” said Chief Product Officer Ely Kahn. “Okta for AI Agents is the only platform built for that reality, securing the full agent lifecycle - discover, onboard, protect and govern, while meeting customers where they are.”
The Amazon Bedrock integration gives teams a way to assign Bedrock-built agents a dedicated identity, attach a human owner and enforce access policies at scale. Okta said administrators can also define which resources those agents can reach, which authentication methods they use and which scopes they receive.
The platform includes what Okta calls shadow agent discovery, which monitors OAuth consent grants on managed browsers such as Google Chrome to identify agents that may be operating outside formal oversight. It can also import Bedrock agents directly into Okta through the Okta Integration Network.
Okta said it treats each agent as a first-class identity and applies baseline security policies to it. Administrators can shut down a misbehaving agent with a single kill switch, while system logs capture tool calls and authorization decisions for export into a security information and event management system, or SIEM. A SIEM is the software security teams use to collect and analyze logs from across the environment.
The company also said access governance features now extend to agents. That means user access requests and periodic certifications, which are common for human identities, can be used for Bedrock-based agents as well. Okta said the workflows automate requests for access to those agents and require regular review of that access.
Beyond Bedrock, Okta said agents can be imported under governance from Salesforce Inc.’s Agentforce and ServiceNow Inc.’s AI Platform. Integrations for DataRobot Inc., Boomi Inc., Glean Technologies Inc., Google Cloud’s Vertex AI and Workday Inc. are planned for later.
The second part of the announcement widens access for customers that already use another identity provider for workforce users. Okta said organizations running Entra ID, Ping Identity or similar systems can layer Okta on top to manage agent identities without replacing their existing setup.
Okta described the result as a single control plane for agent identity across software-as-a-service applications, application programming interfaces, Model Context Protocol servers, service accounts and secrets. The company framed the move as a response to agent sprawl, a reference to the growing number of nonhuman identities that can be difficult to track and govern if security is added late.
The announcement follows Okta’s earlier rollout of Okta for AI Agents and shows the company pushing to define agent identity as a separate category from traditional workforce and customer identity products.