Agentic Identity
The Blueprint Alliance Signals a Shift: AI Agents Are Becoming First-Class Enterprise Identities
The Blueprint Alliance is pushing AI agent security toward a shared architecture built around identity, task-scoped authority, traceable delegation, runtime monitoring and containment. AVIKORE examines what this means for enterprise identity strategy.
The Blueprint Alliance is more than another AI security initiative. Its reference architecture points toward a fundamental change in enterprise identity: AI agents are becoming identities in their own right — with authority, delegation, behavior, lifecycle and risk that must be governed.
On September 22, 2026, AWS, CrowdStrike, Databricks, Docker, Google Cloud, Lovable, Okta, Proofpoint, Salesforce, ServiceNow, Wiz and Zscaler announced the formation of the Blueprint Alliance, a cross-industry initiative focused on securing and governing AI agents across enterprise environments.
The Alliance has developed an open, multi-vendor reference architecture for what it calls the Secure Agentic Enterprise.
The announcement matters.
But the more important development is the architecture behind it.
For identity leaders, the Blueprint represents another strong signal that the enterprise identity model is expanding beyond humans and conventional machine identities.
The next identity domain is already emerging:
Agentic Identity.
The Important Part Isn't the Alliance. It's the Architecture.
AI agents introduce a different security problem from traditional applications or service accounts.
An agent may be created in one platform, authenticate through another, invoke tools across several systems, access enterprise data, delegate activity to another agent and make decisions dynamically during execution.
That makes the traditional question —
"Who has access?"
— insufficient.
Enterprises increasingly need to answer:
What agent is acting?
Who or what authorized it?
What is it allowed to do right now?
What authority has been delegated to it?
What is it actually doing?
Can we stop it immediately?
These are identity questions as much as they are AI security questions.
The Blueprint Alliance organizes its reference architecture around four operational questions:
- Where are my agents?
- What can they do?
- What are they doing?
- How do I respond?
That progression is significant.
It moves agent security from simple authentication toward continuous identity governance and runtime control.
1. Every Agent Becomes an Identity
The first Blueprint principle is foundational:
Every agent is a distinct security identity.
This is an important architectural shift.
Organizations have spent decades building identity programs around employees, contractors, partners and customers. More recently, identity teams have had to confront the explosive growth of non-human identities such as:
- Service accounts
- API credentials
- Workload identities
- Certificates
- Secrets
- Cloud service principals
- Kubernetes identities
- Automation accounts
AI agents add another layer.
An agent may possess credentials, invoke APIs, access enterprise data, execute transactions and act on behalf of a human, application or another agent.
That means an enterprise must be able to identify the agent itself — not merely the credential the agent happens to use.
A mature agentic identity model therefore needs to answer:
- What is this agent?
- Where did it originate?
- Who owns it?
- What system registered it?
- What identity represents it?
- What credentials can it use?
- What resources can it access?
- What is its lifecycle state?
- When should it be suspended or decommissioned?
Without this foundation, enterprises risk creating the AI equivalent of unmanaged service accounts — except potentially operating with far greater autonomy.
2. Authorization Moves From Standing Access to Task-Scoped Authority
Traditional enterprise authorization frequently relies on relatively persistent permissions.
A user receives a role.
A service account receives privileges.
An application receives API access.
The Blueprint proposes a more dynamic model for agents:
Access should be scoped to the task rather than granted as standing authority.
That distinction matters because agents may operate autonomously and across multiple systems.
Consider an AI procurement agent authorized to help purchase equipment.
It may need temporary authority to:
- Read an approved request.
- Query approved suppliers.
- Compare pricing.
- Create a purchase order.
- Submit the transaction for approval.
It does not necessarily need permanent access to every procurement function simply because it participates in that workflow.
Agentic authorization therefore pushes identity architecture toward:
Purpose-bound access + least privilege + short-lived authority + contextual enforcement.
This is materially different from assigning an agent a broad role and leaving it active indefinitely.
3. Delegation Becomes Part of the Identity Chain
One of the most consequential challenges in agentic systems is delegation.
A human may authorize an agent.
That agent may invoke another agent.
The second agent may access an API.
That API may trigger an automated workflow.
The resulting transaction may ultimately change an enterprise system of record.
The question is no longer simply:
Which identity performed the action?
Enterprises may need to reconstruct the complete authority chain:
Human → Agent → Agent → Tool → Resource
The Blueprint Alliance explicitly identifies traceable delegation as a core principle.
For enterprise identity architecture, this creates a new requirement:
Identity must preserve not only authentication, but the provenance of authority.
Security teams should be able to determine:
- Who initiated the action?
- Which agent received the authority?
- What authority was delegated?
- Was further delegation permitted?
- Which downstream agent or tool executed the action?
- What resource was affected?
- Was the final action within the original intent?
This is where agentic identity begins to diverge significantly from conventional machine identity management.
4. Provisioning Controls Are No Longer Enough
Traditional IAM programs are heavily focused on establishing and reviewing access:
Provision → Authenticate → Authorize → Review → Deprovision
Agents complicate this model because authorization alone does not determine behavior.
An agent can authenticate correctly.
It can possess valid authorization.
And it can still take an undesirable action during execution.
That is why another Blueprint principle focuses on runtime monitoring.
For agentic systems, identity context increasingly needs to follow the agent during execution.
This creates a more continuous control model:
Identity → Authority → Execution → Observation → Risk Evaluation → Response
Identity governance and runtime security therefore begin to converge.
The enterprise does not simply need to know what an agent *could* do.
It needs visibility into what the agent is doing now.
5. Agentic Identity Requires a Containment Model
Human identity programs already have established response mechanisms.
An account can be disabled.
A session can be terminated.
Credentials can be revoked.
Privileged access can be removed.
Agentic systems need equivalent controls — potentially operating much faster.
The Blueprint calls for containment that is immediate and reversible.
That introduces an important architectural question:
Can the enterprise revoke an agent's authority while it is operating?
Organizations will need controls capable of:
- Suspending an agent
- Revoking delegated authority
- Terminating active sessions
- Blocking downstream actions
- Invalidating credentials or tokens
- Isolating compromised workflows
- Restoring operation after investigation
An AI agent without an effective containment mechanism represents a fundamentally different risk from a conventional application process.
The Emerging Agentic Identity Control Loop
The Blueprint architecture can be interpreted through an identity lens as a continuous control loop:
Discover → Identify → Authorize → Delegate → Observe → Evaluate → Contain → Recover
This is an important evolution.
Traditional identity programs have often treated governance as a periodic process.
Agentic environments increasingly require governance to become continuous and execution-aware.
The distinction is critical.
A quarterly access review cannot determine whether an autonomous agent should be permitted to execute a specific action occurring right now.
Human Identity → Non-Human Identity → Agentic Identity
Enterprise identity has been expanding for years.
Human Identity
Employees, contractors, partners and customers.
The primary questions were:
- Who are you?
- Should you have access?
- What role should you have?
- Is your access still appropriate?
Non-Human Identity
Service accounts, workloads, APIs, certificates, secrets and automation.
The questions expanded:
- What workload is this?
- Who owns it?
- Where is its credential?
- What system depends on it?
- When should it rotate or expire?
Agentic Identity
AI agents introduce another dimension.
Now enterprises must ask:
- What agent is this?
- Who created and owns it?
- On whose behalf is it acting?
- What task is it authorized to perform?
- What authority was delegated?
- Can it delegate that authority further?
- What is it doing at runtime?
- Is its behavior consistent with its purpose?
- Can its authority be revoked immediately?
This is why simply placing AI agents inside an existing IAM model may not be sufficient.
The identity itself is becoming more dynamic.
So is the authorization model.
So is governance.
What the Blueprint Alliance Does — and Does Not — Represent
The Blueprint Alliance is important, but enterprises should be precise about what has been announced.
The Blueprint is an open, multi-vendor reference architecture developed by participating technology companies.
Alliance members have stated that they intend to test interoperability across existing open standards and protocols, including MCP, OCSF, SSF and CAEP, and publish reference integrations and interoperability results.
That is meaningful industry coordination.
However, organizations should distinguish between:
an industry reference architecture
and
a ratified technical standard with demonstrated interoperability across enterprise environments.
The Blueprint is currently the former.
Its importance is therefore not that the industry has solved agentic identity governance.
Its importance is that major identity, cloud, security, data and enterprise technology providers are increasingly converging on a common architectural problem:
AI agents require identity, authorization, observability and governance that can operate across technology boundaries.
What Enterprise Identity Leaders Should Do Now
Organizations do not need to wait for every standard or product category to mature before preparing for agentic identity.
The first step is not necessarily buying another security platform.
It is understanding the emerging identity estate.
Identity and security leaders should begin asking:
- Which AI agents exist in our environment today?
- Who owns each agent?
- How is each agent identified and authenticated?
- Which human, application or process can authorize it?
- What resources can it access?
- Does it have standing access or task-specific authority?
- Can it delegate authority to another agent or tool?
- Can we trace actions through the full delegation chain?
- Can we observe agent behavior during execution?
- Can we immediately revoke or contain its authority?
- What happens when the agent, its owner or its purpose changes?
- Which team is accountable for governing it?
If those questions cannot be answered, the organization may already have an Agentic Identity governance gap.
Executive Takeaway
The Blueprint Alliance should not be viewed simply as another AI security announcement.
It is evidence of a broader architectural shift.
AI agents are becoming active participants in enterprise systems. They can authenticate, receive authority, access resources, invoke tools, delegate activity and execute actions.
That means they increasingly need to be governed as identities.
But agentic identity cannot rely exclusively on the controls built for human users or conventional service accounts.
The emerging model requires identity to become:
Discoverable.
Task-aware.
Delegation-aware.
Runtime-aware.
Continuously governed.
Immediately containable.
The enterprises that prepare for this transition now will be better positioned to adopt autonomous AI without allowing identity risk to scale alongside it.
Board Considerations
Boards and executive leadership do not need to understand every emerging AI protocol.
They should, however, understand the governance implications.
Three questions are increasingly important:
Do we know which autonomous agents are operating inside the enterprise?
Do we know what authority they have and who is accountable for that authority?
Can we stop an agent quickly if its behavior creates unacceptable risk?
As enterprise AI moves from assistants that generate information to agents that execute actions, these questions become part of enterprise risk management — not merely technical architecture.
Recommended Next Step
Before deploying agentic AI broadly, establish an Agentic Identity baseline.
Inventory existing and planned agents and document, at minimum:
Agent → Owner → Purpose → Identity → Authority → Delegation → Resources → Runtime Controls → Containment → Lifecycle
This creates the foundation for an enterprise Agentic Identity governance model without prematurely locking the organization into a particular vendor architecture.
AVIKORE Perspective
Identity architecture is entering another transition.
For years, enterprise IAM focused primarily on humans.
Cloud computing, automation and APIs forced identity programs to expand toward non-human identities.
Autonomous AI now introduces identities capable not only of authenticating, but of reasoning, receiving delegated authority and taking action.
That changes the governance problem.
AVIKORE's view is that enterprises should begin treating Human Identity, Non-Human Identity and Agentic Identity as connected components of one enterprise identity strategy — while recognizing that each requires different governance and control models.
Identity for what's next. Human · Non-Human · Agentic
Research Sources
Primary sources are the Blueprint Alliance reference architecture and Okta's September 22, 2026 formation announcement; the analysis, framing and recommendations here are AVIKORE's own.
*AVIKORE Insights examines developments shaping enterprise identity strategy across Human Identity, Non-Human Identity and Agentic Identity.*
Research sources
Market and vendor material reviewed as evidence during research — cited for context, not as endorsement.
Related insights
What Is Agentic Identity?
A practitioner-led definition of agentic identity — why an AI agent is technically a non-human identity but a distinct governance class, why authentication is necessary but not sufficient, and how delegated authority becomes the central control problem.
AI Agents Just Changed the NHI Conversation
Why agentic identity is less about another account type and more about controlling delegated authority across enterprise systems.