Okta, Amazon Web Services (AWS), CrowdStrike, Databricks, Docker, Google Cloud, Lovable, Proofpoint, Salesforce, ServiceNow, Wiz and Zscaler have formed the Blueprint Alliance, a multi-vendor coalition developing a shared reference architecture for securing enterprise artificial intelligence agents.
The group said the framework is intended to help organizations identify where agents operate, define what they can access, monitor what they are doing and contain them when necessary. It builds on an agentic-enterprise blueprint introduced by Okta earlier this year.
The initiative extends a direction already visible in enterprise identity products. TNGlobal reported in August that Okta launched Agent SSO to register AI agents as managed identities and govern their access with short-lived credentials and central policies.
Shared principles focus on agent identity
Alliance members have agreed on principles that include treating every agent as a first-class identity, granting access based on the task rather than relying on standing permissions, keeping delegation traceable, monitoring runtime behavior and making containment rapid and reversible.
Those principles address a practical challenge emerging as organizations deploy autonomous and semi-autonomous software agents across multiple cloud services, applications and data systems. An agent may need to act on behalf of a user while crossing several trust boundaries during a single workflow.
Traditional identity and access controls were designed mainly around people, service accounts and applications. Agentic systems can create additional complexity because permissions may be delegated dynamically and because an agent can take actions across systems without a human approving every step.
Reference architecture spans multiple vendors
The Blueprint Alliance is positioning its work as an open, multi-vendor reference architecture rather than a single-company product. That approach is significant because enterprise AI agents often operate across infrastructure from multiple providers.
GE Appliances and World Central Kitchen are serving as strategic advisers to help test the framework against real-world operating requirements, according to the alliance announcement.
The group has not yet demonstrated that following the architecture will eliminate agent-related security failures. Its value will depend on how consistently participating vendors implement identity, delegation, monitoring and containment controls across their products, and whether those controls remain interoperable as agent frameworks evolve.
Agent governance becomes an enterprise security layer
As agent deployments move from experiments into business workflows, organizations are increasingly treating agent identity as a separate governance problem rather than an extension of API-key management. The question is shifting from whether an agent can connect to a system to whether its authority can be scoped, observed and revoked throughout a task.
The Blueprint Alliance gives major cloud, cybersecurity, data and software vendors a venue to align on that problem. The next test will be whether the reference architecture produces common technical controls and interoperable implementations rather than remaining primarily a set of design principles.

