What Okta's agent-identity releases mean for ad accounts
A dated record of Okta's agent-identity releases from Feb 12 to Aug 24, 2026 — Agent Discovery, Okta for AI Agents, Cross App Access, Agent Gateway, and Agent SSO — translated into what each changes for AI agents and automations connected to ad accounts. It flags which pieces are production-ready with General Availability and which are still Early Access or announced-only.
- Platform
- Okta
- Change category
- policy
- Effective date
- 0-08-24
- Change type
- opt-in feature
- Impact level
- moderate
The freshest item in Okta’s agent-identity release log is now generally available: Agent SSO, announced August 24, registers XAA-capable AI agents as first-class identities in Universal Directory and is included in core Okta SSO at no extra cost. [1] For an ad account, that changes the question from “which tool has access?” to “which named agent identity acted, under whose ownership, and how quickly can access be revoked?”

That is a useful operational standard for media buyers. It is not the same thing as finished protection for Google Ads, Meta, Amazon Ads, or any other advertising platform. Okta’s announcements establish a sequence of capabilities and availability labels; the advertiser consequences below are an interpretation of what those capabilities could change when agents, browser extensions, MCP tools, and API automations touch campaign systems.
Okta’s agent-identity release log
The register keeps the dates and status labels separate. General Availability, Early Access, research release, and announcement-only language describe what Okta said was available at the time; they should not be read as proof that every component is ready for a production ad-account workflow.
| Date | Product or capability | Availability as announced | Source | What it could affect for an ad-account agent |
|---|---|---|---|---|
| Feb. 12, 2026 | Agent Discovery in ISPM | Announced | Okta press release [2] | Surfaces shadow AI through OAuth consent and browser signals, including Google Chrome integration; useful for finding extensions, grants, or automations no one has inventoried. |
| Mar. 16, 2026 | Secure agentic enterprise blueprint | Announcement | Okta Showcase press release [3] | Sets the identity, authorization, and governance direction for agents, including marketing use cases, but is not itself an access control deployed inside an ad platform. |
| Mar. 16, 2026 | Okta for AI Agents | Early Access | Okta announcement [4] | Introduces an agent identity provider intended to give agents identifiable, governed access rather than leaving ownership in scattered credentials or sessions. |
| Apr. 30, 2026 | Okta for AI Agents | General Availability | Okta product materials [5] | Moves the agent-identity service to GA as announced; the practical effect still depends on whether the connected advertising tools accept and enforce the relevant identity and authorization signals. |
| Jun. 23, 2026 | Cross App Access ecosystem expansion | 25+ partners; Enterprise-Managed Authorization extension for MCP | Okta press release [6] | Provides a standards-oriented way to authorize an agent moving between tools. For media operations, that could make an MCP call or cross-application handoff more attributable than a shared connector. |
| Jul. 22, 2026 | Agent Gateway; Agent-to-Agent Connections; Resource Access Certifications for AI Agents | Research release; General Availability; Early Access, respectively | Okta product-innovations announcement [7] | Addresses runtime mediation, agent-to-agent communication, and recurring access review in different stages. The mixed status is important: the governance promise is not one uniformly shipped control. |
| Aug. 24, 2026 | Agent SSO | General Availability | Okta press release [1] | Registers XAA-capable agents as first-class identities in Universal Directory, creating a clearer owner and audit subject for agent sign-ins and revocation. |
Read as a sequence, the releases fill different gaps. Discovery is about finding access that already exists. Agent identity is about naming the actor. Cross App Access is about authorization when the actor reaches another application or tool. Gateway and certification work address runtime and ongoing review. Agent SSO gives an XAA-capable agent a first-class directory identity. Those are related controls, not interchangeable labels.
The first problem is often the access nobody remembers approving
Agent Discovery is the most immediately recognizable problem for a media buyer: an OAuth consent grant, a browser extension, or a connected assistant can outlive the person who installed it. Okta says the February release uses OAuth-consent and browser signals to discover shadow AI, with Google Chrome integration included in the announcement. [2]
That does not prove discovery of every advertising integration. It does offer a better inventory question than asking each team member what they think is connected. An account review can start by matching discovered applications and grants to an owner, business purpose, requested scopes, and last known use. If nobody can explain a connection, it should be treated as an unresolved access record rather than harmless technical clutter.

Okta’s own March announcement names marketing as an agent use case, including an agent that monitors customer sentiment. [3] That is a legitimate bridge to advertising operations, but it remains a bridge made here—not a claim that Okta validated the stack against Google Ads, Meta, Amazon Ads, or a specific campaign incident.
Naming the agent helps, but authorization decides the reach
Okta for AI Agents develops from Early Access on March 16 to General Availability on April 30. [4][5] The important change for account operations is conceptual but concrete: an agent can be represented as an identity with ownership and policy context, rather than being understood only through the human account, API key, browser session, or vendor connection it happens to use.
For a campaign automation, identity answers who acted. Authorization still answers what it may do. A named agent with permission to change budgets across every account is more auditable than an unnamed script, but it is not well-contained. A buyer still needs to know whether the agent can read performance data, create campaigns, edit targeting, change payment settings, or cross from one application into another.
That is where Cross App Access matters. Okta describes it as an OAuth extension and says it has been formally incorporated as the Enterprise-Managed Authorization extension for MCP, with an ecosystem of more than 25 partners including Anthropic, Zoom, Slack, Atlassian, and Canva. [6] If an agent moves from a planning or reporting tool into an advertising workflow, an explicit authorization exchange can make that handoff inspectable. It does not, by itself, establish the scopes enforced by the destination ad platform.
Revocation is the control that matters during a bad morning
Universal Logout for AI Agents is the practical endpoint of this model: if an agent identity is compromised, misbehaves, or simply no longer has a valid owner, an administrator needs a way to terminate its active access rather than hunt through every token and browser session. Okta’s 2026 materials position short-lived tokens and instant revocation as parts of the agent-identity direction. [3][5]
For an advertiser, the consequence is a shorter route from anomaly to containment. A sudden budget change, unexpected audience export, or unfamiliar campaign edit would still require investigation, but the first response could be to identify and revoke the responsible agent while preserving the event trail. The materials do not document a public ad-account breach caused by one of these systems, so the possible exposure of budgets, audience data, or payment methods is an inference about blast radius—not a reported Okta-linked incident.
The release log does not equal continuous governance
The July release makes the boundary especially visible. Okta listed Agent Gateway as a research release, Agent-to-Agent Connections as generally available, and Resource Access Certifications for AI Agents as Early Access. [7] Runtime mediation, agent-to-agent communication, and recurring access certification therefore should not be treated as one production-ready package.

The surrounding data explains why those gaps attract attention, without proving that an attack is imminent. Okta’s March 2026 survey, conducted by Apprize360 with 292 executives and 492 knowledge workers across seven countries, found that 52% of workers had used unapproved AI tools, rising to 67% in the United States; 58% of organizations reported an AI-related security incident or close call; and 34% applied the same security controls to agents as to humans. [8]
Gravitee’s April 2026 update similarly reported excessive permissions or over-privileged access as the most consistent incident pattern, 85% with no formal accountability for agent behavior, and 48% of production agents running unsecured. [9] Its often-repeated 88% figure belongs to an earlier December 2025 wave. The April update reported 54% experiencing any incident and 34.9% confirmed incidents, while attributing the apparent decline in part to underreporting. [9] Those figures are vendor-adjacent evidence, not a measurement of ad-account compromise.
The operational gap is familiar: the buyer inherits a static key, OAuth grant, extension, or vendor connection whose owner has left or whose purpose has changed. Okta’s sequence provides a way to ask for a named identity, bounded authorization, an event record, and a revocation path. It does not remove the need to review scopes, confirm the advertising platform’s enforcement, or determine who owns the automation after launch.
What a media buyer can reasonably take from the sequence
The defensible takeaway is an audit standard, not a deployment promise. For every automation touching a paid-media account, the record should make four things answerable: which agent or integration acted, who owns it, what resources and actions it was authorized to reach, and how access can be revoked without manually dismantling the entire workflow.
Okta’s Agent Discovery and identity releases make that standard more concrete. Cross App Access gives the authorization model a path for tool-to-tool and MCP interactions. Agent SSO gives XAA-capable agents a directory identity. The July capabilities indicate where runtime enforcement and continuing certifications are headed, while their stated availability labels show why they should be evaluated separately.
As of August 28, 2026, a buyer can use the release log to inventory access and challenge unexplained ownership now. The sequence is not evidence that every agent connected to an ad account is protected, and no public source cited here ties a particular ad-account breach to Okta’s system. The useful change is narrower: agent access can increasingly be discussed as a named, authorized, and revocable event instead of an unowned connection.
References
- Okta brings first-class identity to AI agents with Agent SSO
- Okta secures the agentic enterprise with new tools for discovering and mitigating shadow AI risks
- Okta announces new blueprint for the secure agentic enterprise
- Every Agent Needs an Identity: Introducing Okta for AI Agents in Early Access
- Okta for AI Agents: The Universal Agent IdP
- Okta advances the industry standard for secure AI agent connections with expanding Cross App Access ecosystem
- Okta announces new innovations to secure AI agents at runtime and automate ongoing agent governance
- AI Agents at Work 2026: Securing the agentic enterprise
- State of AI Agent Security Report 2026
Primary source: https://www.okta.com