New Delhi |: Rubrik (NYSE: RBRK), a global leader in cyber resilience, data protection, and AI operations, has unveiled Rubrik Agent Identity, an advanced AI-powered security solution designed to help enterprises securely manage, monitor, and control the growing number of autonomous AI agents operating across corporate environments.
The new solution, introduced as part of the Rubrik Agent Cloud platform, aims to address one of the biggest challenges facing organizations today—controlling AI agents’ identities, permissions, and actions in real time while minimizing operational and cybersecurity risks.
Addressing the Rise of Autonomous AI Agents
As organizations increasingly deploy AI agents to automate complex business processes across Software-as-a-Service (SaaS) platforms, databases, cloud environments, and APIs, ensuring secure and accountable access has become a critical concern.
Unlike traditional software, AI agents can independently execute tasks on behalf of employees, making decisions and interacting with enterprise systems at machine speed. However, many organizations still rely on static credentials and lack comprehensive visibility into what these agents are accessing and performing.
To bridge this gap, Rubrik Agent Identity enables enterprises to:
- Monitor every AI agent and Model Context Protocol (MCP) server in real time
- Control permissions for every individual tool call
- Deliver just-in-time access tokens
- Enforce identity-aware security policies
- Prevent unauthorized or high-risk actions before execution
AI Securing AI
According to Dev Rishi, General Manager of AI at Rubrik, traditional identity management systems were designed for human users—not autonomous AI systems.
“Agents are no longer just synthesizing information; they are acting on behalf of employees. Static credentials were never designed for autonomous actors. Agent Identity enables enterprises to decide who can do what with AI agents and enforces those permissions at every tool call with scoped, short-lived access.”
He added that Rubrik Agent Cloud provides organizations with the ability to govern AI agent activities, enforce identity-aware policies, and perform semantic policy evaluation before sensitive actions are executed.
Growing Security Concerns Around AI Agents
Rubrik highlighted findings from its Zero Labs research, which underscore the urgency of stronger AI governance.
According to the survey:
- 86% of global IT and cybersecurity leaders believe AI agents will outpace their organization’s existing security controls within the next year.
- Only 23% of organizations currently have complete visibility into AI agents operating within their environments.
The company warned that unmanaged AI agents could create a “shadow workforce”, capable of bypassing traditional security boundaries using overly broad credentials.
Four Pillars of Rubrik Agent Cloud
With the introduction of Agent Identity, the Rubrik Agent Cloud platform now consists of four integrated security pillars:
1. Agent Observability
Provides real-time monitoring of every AI agent and Model Context Protocol (MCP) server operating across the enterprise.
2. Agent Identity
Controls AI agent permissions at the individual tool-call level using AI-driven access management.
3. Agent Runtime Security
Uses SAGE, Rubrik’s AI governance framework, to enforce policies, detect abnormal behavior, and prevent security violations before execution.
4. Agent Rewind
Enables organizations to undo unintended or destructive AI actions, allowing rapid recovery from autonomous agent errors.
Three-Step Framework for Securing AI Agents
Rubrik has introduced a structured approach to strengthen enterprise AI security:
Build an Agent Identity Inventory
Organizations can automatically discover and catalog:
- AI agents
- MCP servers
- AI skills
- Plugins
This helps eliminate unmonitored or unauthorized shadow AI.
Implement Least-Privilege Access
Access permissions can be restricted to specific users, groups, MCP servers, and tools using On-Behalf-Of federation, ensuring AI agents receive only the permissions required for each task.
Enforce Just-In-Time Permissions
Instead of granting permanent access, the system generates short-lived security tokens for every individual tool call, ensuring permissions are validated immediately before execution.
Real-Time Runtime Security
Before any AI agent executes a tool call, the request passes through three independent security checkpoints:
- Behavioral Analysis: AI evaluates the context, requested action, input parameters, and potential business impact.
- Access Policy Enforcement: Security policies are verified using infrastructure-level controls enhanced by Rubrik’s SAGE framework.
- Identity Verification: The system authenticates the AI session and issues a short-lived authorization token valid only for that specific operation.
If an AI agent attempts an unauthorized modification or operation outside its approved permissions, the action is blocked instantly before execution.
In cases where an autonomous agent performs an unintended action, Agent Rewind enables organizations to quickly reverse the changes, supporting faster recovery from AI-related incidents.
Integration with Enterprise Identity Platforms
Rubrik Agent Identity integrates seamlessly with leading enterprise identity providers, including:
- Okta
- Microsoft Entra ID
These integrations allow organizations to extend existing enterprise identity frameworks to autonomous AI agents without creating separate identity infrastructures.
Additionally, the MCP Gateway acts as a centralized security checkpoint for all API-based and MCP-enabled enterprise resources.
Supporting Enterprise AI Adoption
With the launch of Agent Identity, Rubrik continues to advance its vision of Agentic Cyber Resilience, enabling organizations to confidently deploy AI agents while maintaining strong governance, security, and compliance.
As enterprises increasingly rely on AI-powered automation, solutions like Rubrik Agent Identity are expected to play a vital role in ensuring that autonomous systems operate securely, transparently, and in accordance with organizational policies.
The launch reinforces Rubrik’s commitment to helping businesses protect critical data, identities, workloads, and AI-driven operations against the evolving landscape of machine-speed cyber threats and intelligent automation.