Decoding the world of cybersecurity

Vendors agree blueprint for AI agents

AWS, Okta, CrowdStrike, Google Cloud, Salesforce, ServiceNow, Wiz, Zscaler, and other vendors have formed an alliance around a shared architecture for governing AI agents.

Vendors agree blueprint for AI agents
Summary
  • The Blueprint Alliance brings together major identity, cloud, security, data, and application vendors around an open reference architecture for AI agents.
  • Its principles cover agent discovery, distinct identities, task-scoped access, traceable delegation, runtime monitoring, containment, and recovery.
  • Members plan interoperability work using standards including MCP, OCSF, SSF, and CAEP, although the alliance is not itself a formal standards body.

A group of major cloud, identity, security, and software companies has formed the Blueprint Alliance to develop a shared architecture for governing AI agents across increasingly fragmented enterprise technology stacks.

Founding members include AWS, CrowdStrike, Databricks, Docker, Google Cloud, Lovable, Okta, Proofpoint, Salesforce, ServiceNow, Wiz, and Zscaler. GE Appliances and World Central Kitchen are participating as strategic advisers.

The alliance expands an agent-security blueprint first introduced by Okta earlier this year into a multi-vendor reference architecture. Its core premise is that autonomous agents should be treated as first-class identities rather than simply as extensions of the users or applications that created them.

The framework centres on four questions: where agents are, what they can do, what they are doing, and how an organisation can respond when behaviour creates unacceptable risk.

The first stage involves discovering agents and assigning each a distinct identity and accountable owner. The architecture then proposes task-scoped access rather than persistent standing privileges, including traceable delegation where an agent creates sub-agents or acts on behalf of a person.

Runtime monitoring is another pillar. The alliance argues that authentication and entitlement are insufficient once autonomous software begins making decisions, so controls need to observe behaviour in-session and understand the systems and data an agent can reach.

Response mechanisms include token revocation, session termination, rate limiting, and network quarantine, followed by a deliberate re-attestation and recovery process before a contained agent regains access.

Those ideas closely reflect the identity-governance problem Cyber Insider examined in July as AI agents and other non-human identities began multiplying across enterprise environments. What is different here is the attempt to make controls interoperable across competing platforms.

The alliance says members will test cross-vendor signal sharing and publish reference integrations using existing open standards including the Model Context Protocol, Open Cybersecurity Schema Framework, Shared Signals Framework, and Continuous Access Evaluation Profile.

That could become significant if it moves beyond a paper architecture. AI agents routinely cross vendor boundaries: an identity platform may authenticate an agent, a model provider may supply reasoning, a SaaS application may expose a tool, a cloud platform may host execution, and a separate security product may detect anomalous behaviour.

Without shared signals, each control plane can see only part of the transaction. A runtime monitor could identify malicious behaviour yet lack a reliable mechanism to revoke credentials held elsewhere, while an identity system might know an agent has valid access without knowing that its behaviour has changed.

The Blueprint Alliance is not a regulator or formal standards body, and participation by major vendors does not guarantee interoperability. Members also have commercial incentives to shape an emerging architecture around technologies they already sell.

Its breadth nevertheless distinguishes the initiative from a single-company framework. The founding group spans identity, endpoint security, cloud infrastructure, data platforms, SaaS, networking, and agent development, reflecting the number of layers involved when autonomous software acts across an enterprise.

Agent security is likely to remain fragmented while deployments are young. A shared architecture will become meaningful only if vendors can exchange risk signals and enforcement actions without forcing customers into one proprietary stack. The alliance has now defined that objective; interoperability work will determine whether it becomes operational.

×