← Back to Tracker

What Okta's agent-identity releases mean for ad accounts

A dated record of Okta's agent-identity releases from Feb 12 to Aug 24, 2026 — Agent Discovery, Okta for AI Agents, Cross App Access, Agent Gateway, and Agent SSO — translated into what each changes for AI agents and automations connected to ad accounts. It flags which pieces are production-ready with General Availability and which are still Early Access or announced-only.

Platform
Okta
Change category
policy
Effective date
0-08-24
Change type
opt-in feature
Impact level
moderate

The freshest item in Okta’s agent-identity release log is now generally available: Agent SSO, announced August 24, registers XAA-capable AI agents as first-class identities in Universal Directory and is included in core Okta SSO at no extra cost. [1] For an ad account, that changes the question from “which tool has access?” to “which named agent identity acted, under whose ownership, and how quickly can access be revoked?”

AI agent nodes with identity badges passing through a gateway toward ad dashboards and an audit log

That is a useful operational standard for media buyers. It is not the same thing as finished protection for Google Ads, Meta, Amazon Ads, or any other advertising platform. Okta’s announcements establish a sequence of capabilities and availability labels; the advertiser consequences below are an interpretation of what those capabilities could change when agents, browser extensions, MCP tools, and API automations touch campaign systems.

Okta’s agent-identity release log

The register keeps the dates and status labels separate. General Availability, Early Access, research release, and announcement-only language describe what Okta said was available at the time; they should not be read as proof that every component is ready for a production ad-account workflow.

DateProduct or capabilityAvailability as announcedSourceWhat it could affect for an ad-account agent
Feb. 12, 2026Agent Discovery in ISPMAnnouncedOkta press release [2]Surfaces shadow AI through OAuth consent and browser signals, including Google Chrome integration; useful for finding extensions, grants, or automations no one has inventoried.
Mar. 16, 2026Secure agentic enterprise blueprintAnnouncementOkta Showcase press release [3]Sets the identity, authorization, and governance direction for agents, including marketing use cases, but is not itself an access control deployed inside an ad platform.
Mar. 16, 2026Okta for AI AgentsEarly AccessOkta announcement [4]Introduces an agent identity provider intended to give agents identifiable, governed access rather than leaving ownership in scattered credentials or sessions.
Apr. 30, 2026Okta for AI AgentsGeneral AvailabilityOkta product materials [5]Moves the agent-identity service to GA as announced; the practical effect still depends on whether the connected advertising tools accept and enforce the relevant identity and authorization signals.
Jun. 23, 2026Cross App Access ecosystem expansion25+ partners; Enterprise-Managed Authorization extension for MCPOkta press release [6]Provides a standards-oriented way to authorize an agent moving between tools. For media operations, that could make an MCP call or cross-application handoff more attributable than a shared connector.
Jul. 22, 2026Agent Gateway; Agent-to-Agent Connections; Resource Access Certifications for AI AgentsResearch release; General Availability; Early Access, respectivelyOkta product-innovations announcement [7]Addresses runtime mediation, agent-to-agent communication, and recurring access review in different stages. The mixed status is important: the governance promise is not one uniformly shipped control.
Aug. 24, 2026Agent SSOGeneral AvailabilityOkta press release [1]Registers XAA-capable agents as first-class identities in Universal Directory, creating a clearer owner and audit subject for agent sign-ins and revocation.

Read as a sequence, the releases fill different gaps. Discovery is about finding access that already exists. Agent identity is about naming the actor. Cross App Access is about authorization when the actor reaches another application or tool. Gateway and certification work address runtime and ongoing review. Agent SSO gives an XAA-capable agent a first-class directory identity. Those are related controls, not interchangeable labels.

The first problem is often the access nobody remembers approving

Agent Discovery is the most immediately recognizable problem for a media buyer: an OAuth consent grant, a browser extension, or a connected assistant can outlive the person who installed it. Okta says the February release uses OAuth-consent and browser signals to discover shadow AI, with Google Chrome integration included in the announcement. [2]

That does not prove discovery of every advertising integration. It does offer a better inventory question than asking each team member what they think is connected. An account review can start by matching discovered applications and grants to an owner, business purpose, requested scopes, and last known use. If nobody can explain a connection, it should be treated as an unresolved access record rather than harmless technical clutter.

Keys, browser extensions, API connectors, and chat tools converging into a named governance hub with a disconnect switch

Okta’s own March announcement names marketing as an agent use case, including an agent that monitors customer sentiment. [3] That is a legitimate bridge to advertising operations, but it remains a bridge made here—not a claim that Okta validated the stack against Google Ads, Meta, Amazon Ads, or a specific campaign incident.

Naming the agent helps, but authorization decides the reach

Okta for AI Agents develops from Early Access on March 16 to General Availability on April 30. [4][5] The important change for account operations is conceptual but concrete: an agent can be represented as an identity with ownership and policy context, rather than being understood only through the human account, API key, browser session, or vendor connection it happens to use.

For a campaign automation, identity answers who acted. Authorization still answers what it may do. A named agent with permission to change budgets across every account is more auditable than an unnamed script, but it is not well-contained. A buyer still needs to know whether the agent can read performance data, create campaigns, edit targeting, change payment settings, or cross from one application into another.

That is where Cross App Access matters. Okta describes it as an OAuth extension and says it has been formally incorporated as the Enterprise-Managed Authorization extension for MCP, with an ecosystem of more than 25 partners including Anthropic, Zoom, Slack, Atlassian, and Canva. [6] If an agent moves from a planning or reporting tool into an advertising workflow, an explicit authorization exchange can make that handoff inspectable. It does not, by itself, establish the scopes enforced by the destination ad platform.

Revocation is the control that matters during a bad morning

Universal Logout for AI Agents is the practical endpoint of this model: if an agent identity is compromised, misbehaves, or simply no longer has a valid owner, an administrator needs a way to terminate its active access rather than hunt through every token and browser session. Okta’s 2026 materials position short-lived tokens and instant revocation as parts of the agent-identity direction. [3][5]

For an advertiser, the consequence is a shorter route from anomaly to containment. A sudden budget change, unexpected audience export, or unfamiliar campaign edit would still require investigation, but the first response could be to identify and revoke the responsible agent while preserving the event trail. The materials do not document a public ad-account breach caused by one of these systems, so the possible exposure of budgets, audience data, or payment methods is an inference about blast radius—not a reported Okta-linked incident.

The release log does not equal continuous governance

The July release makes the boundary especially visible. Okta listed Agent Gateway as a research release, Agent-to-Agent Connections as generally available, and Resource Access Certifications for AI Agents as Early Access. [7] Runtime mediation, agent-to-agent communication, and recurring access certification therefore should not be treated as one production-ready package.

A partially built security stack with solid lower blocks and translucent upper blocks

The surrounding data explains why those gaps attract attention, without proving that an attack is imminent. Okta’s March 2026 survey, conducted by Apprize360 with 292 executives and 492 knowledge workers across seven countries, found that 52% of workers had used unapproved AI tools, rising to 67% in the United States; 58% of organizations reported an AI-related security incident or close call; and 34% applied the same security controls to agents as to humans. [8]

Gravitee’s April 2026 update similarly reported excessive permissions or over-privileged access as the most consistent incident pattern, 85% with no formal accountability for agent behavior, and 48% of production agents running unsecured. [9] Its often-repeated 88% figure belongs to an earlier December 2025 wave. The April update reported 54% experiencing any incident and 34.9% confirmed incidents, while attributing the apparent decline in part to underreporting. [9] Those figures are vendor-adjacent evidence, not a measurement of ad-account compromise.

The operational gap is familiar: the buyer inherits a static key, OAuth grant, extension, or vendor connection whose owner has left or whose purpose has changed. Okta’s sequence provides a way to ask for a named identity, bounded authorization, an event record, and a revocation path. It does not remove the need to review scopes, confirm the advertising platform’s enforcement, or determine who owns the automation after launch.

What a media buyer can reasonably take from the sequence

The defensible takeaway is an audit standard, not a deployment promise. For every automation touching a paid-media account, the record should make four things answerable: which agent or integration acted, who owns it, what resources and actions it was authorized to reach, and how access can be revoked without manually dismantling the entire workflow.

Okta’s Agent Discovery and identity releases make that standard more concrete. Cross App Access gives the authorization model a path for tool-to-tool and MCP interactions. Agent SSO gives XAA-capable agents a directory identity. The July capabilities indicate where runtime enforcement and continuing certifications are headed, while their stated availability labels show why they should be evaluated separately.

As of August 28, 2026, a buyer can use the release log to inventory access and challenge unexplained ownership now. The sequence is not evidence that every agent connected to an ad account is protected, and no public source cited here ties a particular ad-account breach to Okta’s system. The useful change is narrower: agent access can increasingly be discussed as a named, authorized, and revocable event instead of an unowned connection.

References

  1. Okta brings first-class identity to AI agents with Agent SSO
  2. Okta secures the agentic enterprise with new tools for discovering and mitigating shadow AI risks
  3. Okta announces new blueprint for the secure agentic enterprise
  4. Every Agent Needs an Identity: Introducing Okta for AI Agents in Early Access
  5. Okta for AI Agents: The Universal Agent IdP
  6. Okta advances the industry standard for secure AI agent connections with expanding Cross App Access ecosystem
  7. Okta announces new innovations to secure AI agents at runtime and automate ongoing agent governance
  8. AI Agents at Work 2026: Securing the agentic enterprise
  9. State of AI Agent Security Report 2026

Primary source: https://www.okta.com

Flag an inaccuracy or a missed effect