Summary
- RSA Agent ID discovers AI agents and MCP servers and registers them with an owner, risk tier and lifecycle state.
- Secure applies policy at tool and argument level and can require named human approval for higher-risk actions.
- Discover and Secure are due on 16 November, with Govern planned for the first half of 2027.
RSA is extending identity governance to AI agents, treating autonomous software as an entity that needs an owner, an explicit permission boundary and an auditable record of the actions it performs inside regulated organisations.
RSA Agent ID was presented at World Summit AI in Amsterdam on 7 October and is intended for finance, government and other environments where agents may reach sensitive data or execute consequential tasks. The platform is divided into Discover, Secure and Govern components covering identification, runtime control and continuing access review.
Discover is designed to locate agents and Model Context Protocol servers across identity systems, cloud environments, endpoints and gateways, including software that has not been formally approved. Each discovered agent can then be registered with a named owner, risk tier and lifecycle state linked to identity infrastructure already used by the organisation.
That architecture borrows from controls already applied to employees, service accounts and machines. Security teams generally need to know what has access, who is responsible for it, how that authority was granted and when it should be withdrawn, while AI agents complicate the exercise because they can be created quickly and connected dynamically to tools.
Permissions follow individual actions
Agent ID Secure is intended to enforce policy when an agent attempts to use an external tool through RSA’s AI/MCP Gateway. Controls can operate at tool and argument level rather than granting broad permission simply because the agent is connected to a service.
The distinction becomes important when one tool supports actions with very different consequences. An agent might be permitted to retrieve a customer record while requiring human approval before changing it or initiating another transaction, preventing a single application-level permission from becoming authority over every function available through that application.
RSA says organisations will be able to require identified and authenticated operators to approve designated higher-risk actions through a separate channel. Access can also be removed when an agent reaches the end of its lifecycle, reducing the chance that permissions persist after the workflow or software that needed them has disappeared.
Techopia recently reported that AI agents widen the attack surface through the data, systems and identities they are allowed to use. RSA approaches the same operational problem from the identity layer by making the authority behind each agent explicit and reviewable.
The governance layer arrives later
The product will not become available as one complete system. RSA says Discover and Secure are due for general availability on 16 November, while Govern is planned for the first half of 2027 and will add continuous certification, risk-based access reviews and further lifecycle automation.
That release sequence means organisations evaluating Agent ID initially receive discovery and runtime enforcement rather than the entire governance model described by the platform. They will still need to assess how reliably the system discovers agents across heterogeneous environments, how ownership is assigned and how gateway policy affects production workflows.
Identity controls also cannot determine whether every decision made by an agent is correct. A properly authenticated agent can act on flawed information, misunderstand an instruction or make a poor judgement while remaining within its formal permission boundary.
The controls instead answer a narrower but increasingly necessary question: whether software was authorised to take an action and whose authority sat behind it. As agents move from generating information towards invoking applications, those records become more important to incident investigation, compliance and internal accountability.
Conventional identity systems were designed around relatively stable populations of people, service accounts and machines. Agents can be assembled for temporary tasks, call additional agents and connect to different tools as workflows change, creating an identity population that may grow and disappear considerably faster.
For regulated organisations, knowing that an AI platform had access to a system will provide limited accountability when investigators cannot determine which agent acted, what it was permitted to do and which human owner was responsible for that authority. RSA is betting that those questions will move into mainstream identity governance as agent deployment expands.












