For AI agents to drive better outcomes, they need to reason, act, and connect across model providers, data platforms, SaaS applications, networks, and infrastructure. This interconnected agentic stack requires vendors to come together to close an identity gap where shadow agents multiply, credentials cross trust boundaries, and agents execute beyond their intended scope. That gap will only widen: Gartner predicts that by 2028, an average global Fortune 500 enterprise will have over 150,000 agents in use, while only 13% of organizations think they have the right AI agent governance in place.
Today, Okta, together with Amazon Web Services (AWS), CrowdStrike, Databricks, Docker, Google Cloud, Lovable, Proofpoint, Salesforce, ServiceNow, Wiz, and Zscaler, announced the formation of the Blueprint Alliance, a cross-industry coalition formed to help organizations operate their agentic stack as a unified, governed system.
Commenting on the announcement from Oktane in Las Vegas, Dan Mountstephen, SVP and GM Okta APJ, said, “In APJ’s highly complex regulatory and multi-cloud ecosystem, securing the agentic workforce isn’t something any single vendor can accomplish alone. By establishing a shared architecture alongside industry leaders, the Blueprint Alliance ensures APJ enterprises can answer the critical questions—where agents exist, what they access, and how they behave—enabling secure, compliant AI transformation at scale.”
Founding Alliance members have aligned toward a shared set of principles for securing AI agents — treating every agent as a first-class identity, scoping access to the task rather than granting standing access, keeping delegation traceable, monitoring runtime behavior continuously, enabling containment that is instant and reversible, and ensuring governance adapts at the speed AI moves.
Guided by these principles, the Alliance evolved and expanded the blueprint for the secure agentic enterprise, first introduced in March 2026, into an open, multi-vendor reference architecture. It provides organizations with a standardized way to address four core challenges: Where are my agents? What can they do? What are they doing? How do I respond?
“As AI agents rapidly scale across enterprise environments, organizations need the flexibility to connect best-of-breed identity, security, and runtime solutions across heterogeneous stacks. Google Cloud delivers a comprehensive, end-to-end agent platform and robust security capabilities, built with an enduring commitment to open, interoperable architectures that give customers full freedom of choice. We are excited to collaborate with Okta and the Blueprint Alliance to establish open standards that advance zero-trust governance, traceable delegation, and seamless protection across the entire agent lifecycle.” – Abhi Sawant, VP of Engineering, Platform Security, Google Cloud
“The future of AI is agentic, and securing it starts with zero trust. By working with the Blueprint Alliance, Zscaler is helping to create a practical framework for controlling how AI agents connect, act, and access data across modern enterprise environments.” – Raveesh Chugh, VP of Strategic Technology Partnerships, Zscaler
Four Core Challenges Every Secure Agentic Enterprise Must Address
Efforts across model security and supply chain integrity provide important foundations for securing agents, and this architecture complements them by addressing the governance layer once agents are deployed. It secures various kinds of agents, from workforce agents to customer- and partner-facing agents, operating across organizational boundaries and accessing different resources.
By covering this scope, it gives organizations a zero-trust, agentic control plane and technology leaders a concrete way to scale agentic deployments securely, addressing four core challenges:
Where are my agents? Enterprises cannot govern or protect agents they do not know exist.
● AI agent development, discovery, and identity: Detect and catalog each agent, from internally built agents to imported SaaS and third-party agents to unmanaged shadow AI. Register every agent as a distinct, verified identity with an accountable human owner or operational team.
● AI agent security posture management: Continuously evaluate each agent for vulnerabilities and misconfigurations, then register every validated agent as a distinct, verified identity with an accountable human owner or operational team.
What can they do? Once an agent has a verified identity, it needs explicit boundaries before it is allowed to act.
● Access policies: Scope access to the task rather than standing privilege, and keep delegation traceable end-to-end as agents spawn sub-agents and act on behalf of humans.
● Governance: Keep entitlements aligned to least privilege through automated access reviews, separation of duties, and joiner-mover-leaver discipline applied to agent
scope, ownership, and model versions.
What are they doing? Visibility and identity are ineffective without inline runtime monitoring of agents.
● Runtime authorization and monitoring: Enforce access policies inline through gateways that sit in the execution path, and continuously observe agent behavior in-session to catch data leakage, prompt injection, and anomalous activity.
● Resource access: Continuously track and defend the downstream target an agent can reach, from MCP servers and SaaS apps to data stores and payment systems, so the blast radius of an agent is known.
How do I respond? When monitoring detects a threat, the enterprise needs automated, precise controls that stop an agent instantly and restore it when appropriate.
● Response and enforcement: Leverage risk signals to neutralize a threat with targeted containment, rate-limiting, token revocation, session termination, or network quarantine, without disrupting the broader ecosystem.
● Access recovery: Restore a contained agent through re-attestation and staged re-enrollment, verifying reinstatement is deliberate, documented, and auditable.
All of these pillars are supported by the foundational elements of execution context and risk signals, which are continuously fed by runtime telemetry, logging, and observability. Together, these act as the connective tissue that enables the system to see risk patterns and respond in concert.
Alliance Members Commit to Deeper Interoperability
The Alliance will continue to advance the architecture, translating it into an active, working commitment across the agentic stack:
● Cross-vendor signal sharing: Founding members are building and testing interoperability across open standards, including MCP, OCSF, SSF, and CAEP, helping ensure that a threat signal raised by one runtime monitor triggers real-time action across all connected control planes.
● Publishing reference integrations: Founding members will regularly publish joint interoperability results and reference integrations to serve as the connective tissue for a multi-vendor security ecosystem.
