Aug 6, 2026
Enterprise

Rubrik Agent Identity targets runtime controls for enterprise AI agents

Rubrik announced Agent Identity at Black Hat, putting per-tool-call access controls at the center of AI agent governance.

Colin Brandt

By Colin Brandt · Enterprise Reporter

· 3 min read

Rubrik Agent Identity targets runtime controls for enterprise AI agents
Photo: SiliconANGLE

Rubrik announced Rubrik Agent Identity at Black Hat on Aug. 4, positioning the product as a way to monitor AI agents and Model Context Protocol servers at runtime, grant access one tool call at a time and remediate unwanted actions. The Rubrik Agent Identity launch is a timely example of a harder enterprise problem: agents can initiate multi-step work across systems without a person deciding every next action.

Rubrik did not disclose pricing, customer figures or deployment figures in its announcement. The company said Agent Identity expands its Agent Cloud platform and integrates with Okta and Microsoft Entra ID. Those are product descriptions from Rubrik, not independent evidence of performance or adoption.

The governance issue is more specific than an agent having too much access. Dev Rishi, Rubrik's general manager of AI, told SiliconANGLE that an agent might retrieve information from Salesforce and place sensitive fields into an outbound email. Each discrete action could be permitted, while the resulting sequence is harmful. That is the gap a conventional permission review can miss.

What controls do AI agents need in production?

Bain's analysis is that governance must move from periodic documents and review boards into the control plane that governs an agent while it runs. The firm distinguishes assistants, which return work for a human decision, from systems that can open tickets, modify records and trigger workflows after receiving a goal.

That distinction has operational consequences. Bain says agents are probabilistic and can rely on foundation models, external tools, retrieval services, third-party agents and connectors that an organization does not control. Components can be assembled at runtime and changed on external schedules, creating exposure across the wider system rather than only in the model.

For security and platform teams, the practical control set is not one new policy. It is a set of controls that cover identity, behavior, context, observability and evaluation, and accountability:

  • Maintain a central registry for agents in development, pilot and production, with recorded ownership, lifecycle status, permitted models, permissions, autonomy level and a traceable human authorizer.
  • Give each agent distinct credentials and the minimum permissions needed for a defined task. Bain recommends time-bounded access rather than permanent credentials.
  • Set hard boundaries on tool use, runtime, toolchain length, compute and spending, alongside actions an agent is prohibited from taking.
  • Require human confirmation before high-stakes or irreversible actions. Logs should establish what the agent did and who authorized it.
  • Build and test containment: circuit breakers, rollback when service thresholds are breached, degradation to rules-based handling or a human, and a kill switch that has actually been exercised.

These measures fit within a broader enterprise security program, which combines technical controls with operational processes and recovery planning. They also divide responsibilities cleanly: identity limits who or what an agent may represent, behavioral limits restrict what it can do, and recovery controls address mistakes that pass earlier checks.

Rubrik says its system applies behavioral analysis, runtime policy checks and identity verification before a tool call executes, then issues a short-lived token scoped to that call. It also cited its own survey finding that 86% of IT and security leaders expect agents to outpace their organizations' guardrails within a year, while 23% reported full visibility. Those figures and the claimed controls have not been independently validated in the supplied evidence.

Carnegie Europe has separately argued that autonomous agents are creating new cyber attack surfaces and that existing EU frameworks only partly cover their deployment, monitoring and security. The checklist above distinguishes production-agent governance from chatbot-style deployments that primarily return work to a human.

This story draws on original reporting from SiliconANGLE.

More from Enterprise

All Enterprise →