Decoding the world of cybersecurity

Omada buys EmpowerID for agent identity controls

Danish identity-governance vendor Omada has acquired EmpowerID, adding runtime controls for AI agents to a platform traditionally focused on human and non-human identities.

Omada buys EmpowerID for agent identity controls
Summary
  • Omada has acquired EmpowerID and plans to integrate runtime agent-governance capabilities into its identity platform.
  • The deal extends identity governance beyond people and service accounts to autonomous software acting inside enterprise systems.
  • EmpowerID chief executive Patrick Parker will join Omada as chief innovation officer.

Danish identity-governance company Omada has acquired EmpowerID as access-control vendors extend identity governance from people and service accounts to autonomous AI agents.

The company said the transaction will bring EmpowerID’s runtime agent-governance technology into its identity governance and administration platform, allowing identity, entitlement, and risk information to influence access decisions while an agent is operating.

EmpowerID chief executive and co-founder Patrick Parker will join Omada as chief innovation officer and support integration of the acquired technology.

Identity governance has traditionally concentrated on questions such as who has an account, which systems that account can access, who approved those permissions, and whether access should be removed when a person’s role changes.

Machine identities complicated that model by adding service accounts, workloads, application identities, API credentials, and other non-human principals that can exist at far greater scale than a workforce. Autonomous agents add another layer because software can not only possess access but use it repeatedly to make decisions and take actions with limited human involvement.

Omada says the combined platform will maintain a common view of identities, entitlements, and relationships while applying runtime authorisation to requests from people and agents. It also plans to record grants, decisions, and reviews as ongoing compliance evidence.

Those are product claims that will need to be demonstrated in deployments, but the acquisition reflects a wider architectural problem. An AI agent’s effective privilege may be assembled from several systems: the identity under which it operates, API permissions, delegated user rights, credentials available in its environment, tools it can call, and the data those tools expose.

Traditional access reviews may capture some of those elements without showing what the agent can actually do when they are combined. A permission that appears narrow in isolation can become more consequential when an autonomous workflow is allowed to invoke several systems in sequence.

That is pushing identity programmes towards runtime context. Conventional governance often works through provisioning, approval, certification, and removal processes, many of which operate on scheduled cycles. Agent activity can occur continuously and at machine speed, creating demand for controls capable of changing or blocking access between periodic reviews.

The shift is already visible across the identity market. Identity practices are increasingly being organised around human, machine, privileged, customer, and AI identities, rather than treating non-human access as a separate technical problem.

The market is consequently drawing together areas that were previously sold or managed independently: identity governance, privileged access, workload identity, API security, AI governance, and policy enforcement.

For regulated organisations, the audit question is likely to become more demanding as well. Establishing that an agent had permission at a particular point may not be enough. Organisations may need to show who owned it, why its access existed, which actions it performed, whether each action remained within policy, and how rapidly authority could be withdrawn.

The deal therefore reflects a change in the object being governed. Enterprise identity programmes designed around employees joining, moving, and leaving now have to account for software identities that can be created rapidly, operate continuously, and act across several systems without waiting for a person to perform each step.

Whether consolidated identity platforms can deliver that control effectively remains an implementation question. The direction is clearer: agent security is becoming an identity problem as much as an AI-model problem.

×