Delinea Launches Runtime Authorization to Secure Unpredictable AI Agent Actions

2 Sources

Share

Delinea announced runtime authorization technology to address the security challenges posed by AI agents. Traditional identity controls fail when agents spawn temporary identities and access multiple systems. The platform enforces policy on every action in real-time, ensuring granular visibility and compliance without slowing operations.

News article

Delinea Addresses AI Agent Security Gaps

Delinea introduced runtime authorization technology to tackle the growing security challenges posed by AI agents accessing enterprise systems. Art Gilliland, CEO at Delinea, announced the platform at Black Hat USA, emphasizing that traditional identity and privilege controls cannot manage the risks posed by AI agents that rapidly spawn temporary identities, access multiple systems, and vanish after task completion

1

. Unlike persistent human users or narrowly defined machine identities, AI agents create unpredictable access patterns that demand a fundamentally different security approach.

"The security industry spent years solving credential theft, but AI agents have introduced a new problem: authorized access doing unauthorized things," Gilliland stated

2

. Perfect credential hygiene no longer prevents agents from tearing through production environments in milliseconds. The perimeter has moved inside the session, requiring security teams to enforce policy on actions as they execute rather than relying on front-door access controls.

Real-Time Authorization Replaces Traditional Scanning

Delinea's approach focuses on securing the assets AI agents interact with rather than attempting to discover and catalog every agent. Traditional methods of gaining visibility, scanning for everything, setting policy, and then enforcing simply do not work for AI agents, according to Gilliland

1

. Organizations need to identify where sensitive data resides and what systems require protection, then apply real-time authorization at those critical touchpoints.

The platform distinguishes between human access and AI agent activity using the same credentials, applying different permissions based on whether a connection is agent-driven or human-driven before granting access

2

. This agent-specific policy activates at the moment of connection, ensuring appropriate controls are in place before the first action runs. The system evaluates each agent action in real-time to determine whether it should be allowed, creating a complete audit trail of agent behavior for compliance and business operations.

Policy Enforcement on Every Action

The Delinea Platform enforces policy on every action within a session, not just when the session opens. A single AI-driven session can carry dozens of tool calls, each with a different risk profile

2

. The platform evaluates and enforces policy on each tool call individually, allowing it, blocking it, or requiring human approval before execution. When an agent misbehaves, the blast radius stays contained.

Real-time authorization sits in line within the protocol, providing organizations with granular visibility across every connection. Agents reach databases, SSH hosts, Kubernetes clusters, and cloud consoles directly, and the platform authorizes and records each connection through a single control point across every protocol

2

. Security teams maintain consistent policy and a complete audit record regardless of how agents were deployed or which systems they accessed.

Eliminating Standing Credentials and Non-Deterministic Behavior

The platform eliminates standing credentials that attackers could exploit. Agents never hold credentials directly. Instead, the system injects them just-in-time at the moment of access, scoped to the specific task rather than inherited from the person who deployed the agent, and revokes them automatically when the task completes

2

. Because credentials are never exposed to the agent, there is no lingering exposure between sessions.

This approach addresses the non-deterministic behavior unique to AI agents. Unlike humans who won't scan through every file or machines that operate within discrete parameters, AI agents will do whatever it takes to solve assigned problems

1

. Agents may scan through systems like SharePoint, find additional credentials, and use them to elevate privileges. Authorizing access at the front door is insufficient because the real risk emerges from what the AI does next. This combination of non-deterministic behavior with machine capability explains why real-time authorization has become essential, not just front-door access controls.

Complete Accountability and Compliance

Every tool call, database query, and SSH command is recorded and tied to a named identity, providing teams with the ability to investigate, respond, and defend every access decision

2

. This level of visibility enables organizations to record and monitor agent activity, demonstrating for compliance exactly what each agent did. Unlike static access controls, the system surfaces patterns across sessions, making it valuable for security, compliance, and business operations.

Delinea announced customers are already using the technology, though specific adoption numbers were not disclosed

1

. The platform allows organizations to move quickly without breaking systems, balancing security requirements with operational speed. As AI agents become more prevalent in enterprise environments, the shift from traditional identity governance models to runtime authorization represents a fundamental change in how organizations must approach agent security.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved