Watchlight AI
Back to Blog
Agent Runtime GovernanceAI Agent AuthorizationIdentityIAMDelegated AuthorityCISO

Identity Says Who. Agent Runtime Governance Says Whether.

Aldo PietropaoloAugust 21, 20268 min read
Share

In 2026, enterprise identity stopped treating AI agents as an afterthought. Agents are now first-class identities that carry authority delegated from a human, and the identity industry has moved quickly to give them tokens that say so.

That is the right move. It is also only half of the problem.

The identity layer grew up fast

Two announcements frame where the market is.

In June 2025, Okta introduced Cross-App Access, an OAuth extension that lets an AI tool request access to an application through Okta rather than through a manually consented integration. Okta evaluates the request against enterprise policy and issues the agent a token for that specific user's data. It brings visibility and brokered issuance to agent-to-app access.

In March 2026, Ping Identity went further with Identity for AI, a set of components that manage an agent as a distinct identity type and, notably, enforce delegated entitlements at runtime through an agent gateway. Ping's own framing is worth quoting, because it validates something we have argued since we defined this category:

In an agentic enterprise, the system of record is not sufficient. The system that enforces decisions at runtime becomes the system of control.

I agree with that sentence completely. When an identity vendor says the point of control has moved to runtime, the whole industry is converging on the same conclusion. The question is what "enforce at runtime" has to mean to actually hold.

Your identity provider issues the agent's identity and a scoped token. Watchlight governs what the agent does with it at runtime and proves it. The identity provider registers the agent and issues a token where sub is the human and act is the agent. Watchlight AI Beacon verifies the delegated authority before execution, returns allow, require approval, or deny, and records the human to agent to action chain as signed lineage. Runtime verdicts propagate back to the identity provider via CAEP.

A token is a grant, not a guarantee

An attenuated actor token is a precise, useful thing. It says the subject is a human, the actor is an agent, and the scope is a task. On the emerging standards it can even carry cryptographic constraints on how far it may be delegated onward.

But a token describes what an agent may do. It does not, by itself, decide whether each action the agent actually takes stayed inside that grant. Between issuance and consequence sits everything that makes agents different from the applications identity was built for:

  • An agent takes hundreds of steps autonomously, at machine speed, faster than anyone reviews them.
  • It hands work to sub-agents and tools that run with their own privileges, and authority can widen at each hop.
  • Individual actions can each be permitted while the sequence adds up to something no one approved.
  • The same token can be legitimate for one task and out of bounds for the next, depending on the intent the agent declared.

Issuing the token is necessary. It is not sufficient. Someone still has to decide, at the moment of every action and across the entire delegation chain, whether the agent stayed within what was granted, and then produce a record an auditor can trust. That is runtime governance, and it is a different job from identity.

What "enforce at runtime" has to mean

For runtime enforcement to be worth relying on, three properties are not optional.

It has to be deterministic. An authorization decision cannot depend on a language model making a probabilistic judgment inside the trust path. The same action, under the same delegated authority, has to produce the same decision every time, against formal, versioned policy. Anything less is not enforcement, it is a suggestion.

It has to govern the whole chain, not a single hop. When Agent A delegates to Agent B, and B calls a tool, the enforcement point has to validate that the child's authority is a strict subset of the parent's, never wider, across every link. This is exactly the property the new Attenuating Authorization Tokens draft formalizes as a capability lattice, where a child's capabilities are always a subset of its parent's and the chain verifies offline. It is a good standard. It also describes semantics an enforcement layer has to actually run, on every spawn, and reject when a child tries to widen scope.

It has to prove what happened. The unique liability with agents is not only stopping the wrong action, it is being able to reconstruct, after the fact, who initiated a chain, how authority flowed through it, which policy was evaluated, and what was decided. Ordinary logs show that a tool was called. They do not carry the delegation chain or the decision. A tamper-evident, signed record of the chain in action is the artifact a regulator, an incident responder, and a board actually want, and it is the piece the identity layer does not hold.

Two layers, one control story

None of this competes with your identity provider. It sits downstream of it.

Your IdP decides who the agent is and issues the scoped token. Agent Runtime Governance decides whether this specific action, under this specific delegated authority, is allowed, enforces that decision before the action executes, and records the chain as proof. When a runtime verdict changes the picture, quarantine an agent, revoke a delegation subtree, the same standards that carry identity signals, Shared Signals and CAEP, can carry that verdict back to the IdP so the identity fabric reflects reality.

This is why the honest positioning is complementary. Okta and Ping are building the issuance and identity story for agents, and doing it well. The standards they are building on, RFC 8693 token exchange with its actor and subject claims, the attenuation drafts, the SCIM agent resource, are the same primitives a runtime governance layer consumes. Watchlight AI Beacon already enforces the attenuation semantics those drafts formalize, deterministically, and records the result as signed execution lineage. It is designed to be IdP-neutral, so whichever provider issues your agents' tokens, the runtime layer works the same way underneath.

Identity says who. Governance says whether.

The industry got the first half right. Agents are identities, and they should carry delegated, scoped authority instead of impersonating a human. The second half is the one that decides whether all of that holds when an agent starts acting: a deterministic runtime layer that enforces the grant across the whole chain and proves what happened.

Identity establishes who the agent is. Agent Runtime Governance establishes whether it may do this, right now, and leaves proof that it did or did not. You need both.

SEE HOW IT FITS
Watchlight AI Beacon is the runtime enforcement and proof layer downstream of your identity provider. See how it fits your IdP, or request a demo.
Found this useful? Share it with your network.
Watchlight AI Beacon

Put runtime governance in front of every agent action

Watchlight AI Beacon is available now, fully on-premises and air-gapped. Request a demo to see it in your environment.

Request a Demo
Recommended Workshop

Agent Governance Readiness Assessment

Evaluate your governance posture against the 12 principles. Get a maturity score and roadmap.

2-3 days · Download one-pager (PDF)

We value your privacy

We use cookies to enhance your browsing experience, analyze site traffic, and personalize content. You can choose to accept all cookies or customize your preferences. Learn more