Okta, AWS And Google Cloud Unveil Agentic Security Blueprint: Can IT Leaders Enforce It?

The Blueprint Alliance proposes a framework to help organizations strengthen agentic security, but some experts caution security challenges extend beyond a blueprint.



Okta, AWS, Google Cloud and other technology companies have formed what they call the “Blueprint Alliance” — a cross-industry coalition aimed at establishing a shared architecture for securing AI agents as they spread across enterprise environments.

The founding members, which also include CrowdStrike, Databricks, Proofpoint, Salesforce, ServiceNow, Wiz and Zscaler, say shadow agents, credentials moving across trust boundaries and agents operating beyond their intended scope are creating a new security challenge that will only widen if nothing is done about it.

The Sept. 22 announcement comes as recent research and security incidents point to weaknesses in existing approaches to managing autonomous AI systems.

AI Agent Sprawl Is Creating A Visibility Problem

As AI agents continue to crisscross identity systems, SaaS applications, data platforms and infrastructure, the organizations behind the Alliance argue that an interconnected agentic stack is needed to manage them. Gartner expects the average global Fortune 500 enterprise to have more than 150,000 agents in use by 2028, highlighting the scale of the governance challenge ahead.

[RELATED: 12 AI Policy Templates And Frameworks Every IT Leader Should Review In 2026]

The Blueprint Alliance identifies four critical areas organizations need to address: knowing where agents are, what they can do, what they are doing and how to respond.

Vijay Kumar Sridharan, vice president of software engineering at Goldman Sachs Platform Solutions, said the initiative is “pointed at the right problem,” because the biggest risks can arise from uncertainty over what an agent is authorized to do and on whose authority.

[RELATED: 91 Percent Use AI. Only 33 Percent Trust AI Agents With Real Work: Report]

“Treating every agent as a first-class identity with task-scoped access is exactly the discipline production systems need. In our world, every automated action touching customer data has to be explainable to a regulator after the fact, and 'the agent had broad standing access' is not an explanation,” he told MES Computing.

Sridharan further argues that current approaches to agentic security are flawed considering that an agent may authenticate in one system, retrieve information from another and execute an action somewhere else, leaving no single security console with visibility of the complete workflow.

Shared standards and signals between vendors are therefore necessary to maintain visibility across those boundaries, he said.

Akamai's latest research reinforces the need for that wider visibility. The company advises organizations to expand identity management beyond human users to include autonomous, nonhuman identities. This includes visibility into how agents interact with APIs and multiple software systems.

In its report, Akamai also recommends matching an agent's level of autonomy to how easily its actions can be verified and reversed, with human oversight retained for higher-risk decisions.

The Harder Problem Extends Beyond The Blueprint

The challenge facing the industry is whether organizations can translate the Blueprint Alliance's principles into security controls that work continuously once agents are deployed.

Sridharan cautioned that a reference architecture only standardizes the vocabulary. The harder problems, he maintains, arise when those principles have to work in production, where permissions can drift, delegation chains can go unaudited and containment procedures may never have been tested when something goes wrong.

Sachin Agrawal, managing director, Zoho UK, raised a similar concern from an enforcement perspective. He describes such cross-industry collaboration as “a step in the right direction” but said “it won’t solve the problem without enforcement.”

“A shared way for a business to operate offers consistency but guidance written by vendors who also sell the products carries no legal obligation,” Agrawal told MES Computing. Businesses should not wait for regulation because they need processes to “get visibility of every agent in use,” assign “a named human owner” and have “a kill switch or incident response plan that has been tested before it's needed," he said.

[RELATED: OpenAI Considering AI Kill Switch]

For midsized IT teams with the mandate to secure agents already in production, the immediate issue is therefore likely to be about discovering agents that have already appeared across SaaS environments, establishing who owns them, limiting what they can access and retaining enough evidence to reconstruct what they did.

The Blueprint Alliance may help establish a common architecture for discovering, authenticating and governing AI agents across platforms. Whether it becomes an effective security control, however, will depend less on the framework itself than on organizations' ability to discover agents, enforce permissions and maintain visibility when autonomous systems behave unexpectedly.