Accessibility Adjustments

Use these optional tools to adjust reading and display preferences. These tools cannot resolve every accessibility barrier. Please contact the website owner if you need assistance.

  • Text adjustments
  • Content scaling 100%
  • Font size 100%
  • Line height 100%
  • Letter spacing 100%
  • Colour adjustments
  • Orientation adjustments

RSA Agent ID targets risky AI actions with human approval

RSA plans a November release for agent discovery and access controls, with broader governance scheduled for 2027

Listen to this article

RSA announced Agent ID on September 29, 2026, outlining a security platform that connects AI agents to human owners and checks their requests before tools run. The product is aimed at government, financial services and other regulated organizations.

Discover and Secure are scheduled for general availability on November 16. Govern follows in the first half of 2027. A fully isolated version that customers manage themselves is also planned for 2027.

Where human approval fits

The product page describes a gateway that applies policies to calls passing through it. Customers decide which actions carry high risk. Those calls wait for approval from a named person whose identity is verified, using a credential designed to resist phishing.

RSA says the gateway can run in its cloud or in a customerโ€™s cloud, hybrid or local environment. This placement determines where individual access decisions are made. The stated enforcement applies to traffic routed through that gateway.

The product page also lists integrations with Microsoft Entra ID, Okta, AWS IAM, CrowdStrike and Microsoft Defender. Its audit record is meant to capture the agent, applicable rule, human approver, tool and delegation chain, giving investigators context beyond a simple allowed or denied result.

Discovery and governance arrive in stages

Discover builds a registry with owners, risk levels and lifecycle states. RSAโ€™s solution brief says discovery connects at the source without changes to existing agent infrastructure. Secure is intended to check entitlements on each call and invalidate an agentโ€™s session when its work ends.

The company says initial governance features include classification, ownership and evidence mapping. Continuous certification, reviews based on risk and lifecycle automation are reserved for Govern. That separation matters for buyers expecting recurring access reviews in the first release.

What buyers still need to verify

These are RSAโ€™s descriptions of a forthcoming product. The cited materials do not establish how reliably discovery finds unauthorized agents or how controls behave under operational failures.

A useful evaluation would test whether agents can reach tools without crossing the gateway, what happens when an approver is unavailable and how quickly access disappears after work finishes. Buyers should also examine whether the audit trail preserves enough detail to reconstruct an action. Those checks would connect the announced controls to the systems an organization actually runs.

Archival photograph of an RSA SecurID token by Ocrho, released into the public domain. Shown for company context. Original image via Wikimedia Commons.

Jordan Reid
Jordan Reid

Jordan Reid is focused on AI tools, agents, developer products, and the way technology changes everyday work. Jordan approaches a launch from the userโ€™s side of the screen. What can it actually help someone finish? The voice is practical, conversational, and skeptical of products that turn a simple job into five new settings. Coverage follows coding assistants, creative software, browser agents, and the workflows around them, with attention to pricing, permissions, setup, and the human work that remains.

Leave a Reply

Your email address will not be published. Required fields are marked *

Gravatar profile