News

Blueprint Alliance Targets Common Security Model for AI Agents

Okta and a group of major cloud, security, data and application vendors have launched the Blueprint Alliance, an industry effort to create a shared architecture for securing AI agents across enterprise environments.

The 12 founding members are AWS, CrowdStrike, Databricks, Docker, Google Cloud, Lovable, Okta, Proofpoint, Salesforce, ServiceNow, Wiz and Zscaler. GE Appliances and World Central Kitchen are participating as strategic advisors. The coalition was announced by Okta on Sept. 22.

The effort expands an earlier Okta framework into an open, multi-vendor reference architecture intended to address a basic problem with enterprise AI agents: an agent can be created in one system, authenticated through another, access tools and data from several others, and be monitored by yet another security platform.

The Alliance is focused less on how agents are built and more on how organizations can govern them consistently across vendor boundaries.

Blueprint Alliance Architecture
[Click on image for larger view.] Blueprint Alliance Architecture (source: Blueprint Alliance).

Four Parts of the Architecture
The Blueprint Alliance architecture organizes agent security around four questions: Where are my agents? What can they do? What are they doing? How do I respond?

Those questions translate into several practical areas:

  • Discover agents operating across development platforms, SaaS products and other environments, then register validated agents with identifiable owners.
  • Limit what agents can access through scoped permissions and traceable delegation rather than broad standing privileges.
  • Monitor agent behavior at runtime, including tool use, data access, anomalous activity and possible prompt-injection or data-loss events.
  • Respond to incidents through actions such as revoking tokens, terminating sessions or quarantining an agent.

The reference architecture also covers development-related systems. Its whitepaper includes agent frameworks, code repositories, CI/CD environments, code assistants, tool registries, Model Context Protocol servers and command-line tools among the components that may need to be discovered or governed.

That makes the initiative relevant to development teams deploying agents that interact with internal APIs, MCP tools, databases, SaaS applications or other agents. The architecture calls for those connections and permissions to remain visible and controllable as agents move from development into production.

Cross-Vendor Interoperability
A major part of the Alliance's work will be testing how security information and controls can move between products from different vendors.

The initial architecture references several existing standards and protocols, including MCP for agent-to-tool interactions, the Open Cybersecurity Schema Framework for security telemetry, and the Shared Signals Framework and Continuous Access Evaluation Profile for exchanging risk information.

The goal is for one part of an enterprise stack to be able to detect a risk condition and pass that information to another control point that can act on it. Depending on the implementation, that could include revoking access or containing an agent whose behavior has changed.

The Alliance says members will build and test reference integrations and publish results as interoperability work progresses. Specific cross-vendor implementations and performance results were not documented in the launch announcement.

Founding member Lovable also published a developer-oriented explanation of its participation, describing organizations that may have internally built agents, agents imported through SaaS platforms and locally running agents that all need to be inventoried and governed under a common model.

The Alliance's whitepaper recommends that organizations begin with foundational capabilities such as unified logging, telemetry and agent discovery rather than attempting to deploy every control at once.

The architecture is available for community use, and the Alliance says it will continue evolving as members test integrations and additional participants become involved. Timelines for individual vendor integrations have not been published.

About the Author

David Ramel is an editor and writer at Converge 360.

Featured

Subscribe on YouTube