Okta plans intent-based authorization for its agent gateway in 2027
Okta wants to extend authorization from the front door to agent runtime, but scoping permissions without blocking legitimate work remains unsolved.
Ric Smith, president of products and technology at Okta, said at the company's Oktane event that Okta plans to add intent-based authorization to its agent gateway in 2027, using an agent's context and permitted tools to decide whether a proposed action should proceed.
The agent gateway is an already launched Okta product that sits in the path of actions an AI agent attempts, enforcing authorization decisions at runtime. Smith said Okta had dominantly not been inline before, and moving into the request path lets it do far more decision-making around what it authorizes. The company's acquisition of Permiso Security adds detection capabilities to this push.
Smith acknowledged that scoping permissions narrowly enough to block dangerous actions without blocking legitimate work is an open research problem. Note that the interview was published by SiliconANGLE's theCUBE, a paid media partner for the Oktane event.
Sources:https://siliconangle.com/2026/09/29/agent-gateway-lets-okta-police-ai-runtime-actions-oktane