Menu
AI & EMERGING TECH

RSA Launches Agent ID to Secure AI Agents With Human Approval and MCP Controls

Uday Patil Sep 30, 2026 6 min read 3 views
RSA Launches Agent ID to Secure AI Agents With Human Approval and MCP Controls

RSA has introduced RSA Agent ID, a new identity-security platform designed to help organizations discover, control and govern AI agents operating across enterprise environments.

The platform is aimed primarily at government, financial services and other highly regulated organizations where autonomous agents may interact with sensitive data, business systems, APIs and external tools. Rather than treating an AI agent simply as another application or service account, RSA is positioning each agent as a managed identity with a named human owner, defined permissions and an auditable lifecycle.

That approach addresses a growing problem for enterprises deploying agentic AI: an organization may know which employees and applications have access to a system, but it may have far less visibility into which autonomous agents are operating, what permissions they hold and which human is ultimately responsible for their actions.

RSA Agent ID Is Built Around Discover, Secure and Govern

According to RSA’s Agent ID solution brief, the platform is divided into three modules that cover different stages of an AI agent’s identity lifecycle.

ModulePrimary function
RSA Agent ID DiscoverFinds known and unknown AI agents and MCP servers, registers them and associates them with an owner, risk level and lifecycle state.
RSA Agent ID SecureEnforces policy on agent calls through an AI/MCP Gateway and can require authenticated human approval before sensitive actions are executed.
RSA Agent ID GovernApplies access reviews, continuous certification and lifecycle governance to AI agents.

The Discover component is particularly important for environments where teams may deploy agents without centralized security oversight. RSA says the system can correlate signals from identity, cloud, endpoint and gateway sources to identify both sanctioned and so-called shadow AI agents.

Each discovered agent can then be registered as a managed identity with an accountable human owner. For security teams, that changes the question from simply asking whether an AI system exists to determining who owns it, what resources it can reach and whether those permissions are still justified.

AI/MCP Gateway Checks Agent Actions Before Execution

The enforcement layer is handled through RSA Agent ID Secure and its AI/MCP Gateway. RSA says calls passing through the gateway can be checked against organizational policy before they reach the requested tool or resource.

This matters because modern AI agents can do more than generate text. Depending on their permissions, agents may call APIs, query databases, interact with cloud services, initiate workflows or modify production systems.

Traditional identity systems may establish whether an identity is authenticated and what permissions it has. Agentic systems introduce another problem: deciding whether a specific autonomous action should be permitted at the moment it is requested.

RSA says its gateway can enforce policy at the call level and require an authenticated human operator to approve selected high-risk actions. An organization could, for example, require human authorization before an agent initiates a financial transaction or accesses particularly sensitive information.

This type of runtime control closely matches the broader security challenge covered in our AI agent security enforcement analysis: visibility into autonomous systems is useful, but organizations also need a way to constrain what an agent can actually do when it begins interacting with real infrastructure.

Human Ownership Is Central to the Model

One of the more notable parts of RSA Agent ID is its emphasis on tying AI activity back to a responsible person.

RSA says discovered agents can be assigned named owners, while sensitive actions routed through the gateway can require approval from an authenticated human operator. The platform also records activity so organizations can maintain an audit trail covering agent access decisions and gateway-mediated actions.

That accountability model becomes more important as organizations move from conversational assistants to agents capable of carrying out multi-step operations independently.

An agent may be created for a legitimate task but later accumulate additional integrations, credentials or permissions. Without lifecycle controls, those privileges can remain active even after the agent’s original purpose changes or the agent is no longer needed.

RSA says Secure can revoke access when an agent is decommissioned, while Govern is designed to continuously review and certify agent access rather than relying only on periodic manual reviews.

Agent Identity Is Becoming Part of Enterprise AI Security

RSA’s launch reflects a broader shift in enterprise security. AI-agent risk is increasingly becoming an identity and authorization problem as much as a model-security problem.

An organization can harden an AI model against prompt injection and still face significant risk if the agent using that model has excessive cloud permissions, unmanaged credentials or unrestricted access to sensitive tools.

For that reason, agent identity is likely to sit alongside least privilege, runtime authorization and human oversight as organizations build more mature agentic-AI security programs.

CyberUpdates365 covers these broader risks in our AI-Era Threats and Agentic Security guide, including how autonomous systems expand the traditional attack surface beyond users, endpoints and conventional applications.

Integration With Existing Identity and Security Platforms

RSA says Agent ID is designed to work with existing enterprise identity and security infrastructure rather than creating an entirely separate identity layer.

The company lists integrations with RSA ID Plus, Microsoft Entra ID, Okta, AWS IAM, CrowdStrike and Microsoft Defender, among others. The goal is to correlate agent activity and permissions with systems that organizations already use for identity, cloud access and endpoint security.

RSA also says the AI/MCP Gateway can be deployed in environments controlled by the customer, including private-cloud and on-premises deployments. The company’s documentation describes support for high-assurance deployment models while noting that some capabilities, including parts of sovereign and air-gapped discovery, are planned for future releases.

What Security Teams Should Evaluate

  • Inventory which AI agents and MCP servers are currently operating in the environment.
  • Assign a named human owner to every production agent.
  • Review the cloud, application and data permissions granted to each agent.
  • Identify actions that should require human approval before execution.
  • Ensure agent access can be revoked immediately when an agent is retired or behaves unexpectedly.

The important point is that deploying more autonomous AI should not automatically mean granting more standing privilege. Organizations need to know which agent is acting, what authority it has and whether a sensitive action should proceed before the underlying system executes it.

For enterprises already experimenting with agentic workflows, the practical next step is to inventory existing agents and MCP integrations before expanding their permissions. Unknown or ownerless agents should be treated as an identity-governance gap rather than simply another AI experiment.

Official and Primary Sources

Uday Patil
About The Author

Uday Patil

Uday Patil is a Cybersecurity Researcher, DevSecOps Engineer, and the Founder of CyberUpdates365. Specializing in Threat Intelligence and Zero-Day vulnerability analysis, Uday is dedicated to breaking down complex cyber threats into actionable insights. His mission is to empower developers, security teams, and aspiring tech talent with rapid alerts, practical guidance, and career mentorship.