Okta has announced new identity governance, privileged access management and identity threat detection capabilities designed to secure human users, AI agents and other non-human identities as enterprises expand autonomous workflows.
The company said the innovations address governance gaps created by static permissions, traditional credential vaults and delayed access reviews. The new capabilities are intended to give CIOs, CISOs and AI leaders more automated control over access decisions, reduce standing privileges and support the secure adoption of AI.
“Nobody wants to slow AI down, but you can’t simply hand out access and hope for the best,” said Ely Kahn, chief product officer at Okta. “Enterprises need a one-stop shop to govern, secure, and monitor every identity: humans, AI agents, and non-human workloads alike.”
Within Okta Identity Governance, the planned capabilities include advanced entitlement management for Amazon Web Services, AI-supported access-request recommendations and automated drift detection and remediation. The AWS capability is designed to provide centralised tracking of fine-grained permissions across developers, workloads and AI agents.
Intelligent Request Recommendations will analyse request history, usage patterns and resource sensitivity to help approvers automate lower-risk requests and identify anomalies for human review. Automated Drift Detection & Remediation will continuously identify unauthorised access changes and revoke rogue permissions, moving organisations away from periodic compliance audits towards ongoing control.
Okta is also introducing 48-Hour Integrations. Using artificial intelligence to expand its catalogue of more than 8,000 pre-built integrations, the company said new governance and privileged-access integrations could be delivered in as little as 48 hours, compared with the previous manual process of two to three months.
The company is extending just-in-time access through Okta Privileged Access to databases, Kubernetes environments, network devices, CI/CD pipelines and AI agents. Features include automated vaulting and rotation of database secrets, protection against long-lived Kubernetes credentials and machine-speed authorisation for automated identities.
Okta is also expanding identity threat detection and response through technology from Permiso Security, following its acquisition of the company. The combined capabilities are intended to use identity risk signals, behavioural analytics and threat-informed detections across identity providers, cloud environments and SaaS applications.
The developments are relevant to cyber recovery planning in Asia for 2026 and 2027, where identity compromise, cloud access and third-party exposure are likely to remain central recovery concerns. INTERPOL reported more than 135,000 ransomware-related attacks across Asia and the South Pacific in 2024.
Recovery programmes will increasingly need to include privileged-access revocation, identity restoration, token invalidation and validation of machine and AI-agent permissions, alongside immutable backups and system restoration.









