New capability enables organizations to enforce security policies on AI agent activities before execution, addressing growing concerns around autonomous access to enterprise systems
Delinea has announced new runtime authorization capabilities for AI agents, extending identity security controls beyond authentication and access management to govern the actions AI systems perform after gaining access to enterprise resources.
As organizations increasingly deploy autonomous AI agents across production environments, databases, cloud platforms, Kubernetes clusters, SSH hosts, and Model Context Protocol (MCP) servers, security teams are facing a new challenge. While traditional identity and access management solutions focus on controlling access at the point of entry, they often lack the ability to monitor and control what AI agents do once a session has been established.
Delinea’s new runtime authorization capability is designed to address this gap by evaluating and enforcing security policies on every action performed by an AI agent before execution. Rather than relying on post-incident auditing or session termination after suspicious behavior occurs, the platform is intended to prevent unauthorized actions in real time.
“The security industry spent years solving credential theft, but AI agents have introduced a new problem: authorized access doing unauthorized things. The perimeter has moved inside the session, and enforcing policy on actions as they run is now critical.”
Art Gilliland, CEO, Delinea
According to the company, the solution provides a unified control layer that applies consistent policy enforcement across multiple protocols and systems, regardless of how an AI agent connects to enterprise infrastructure. Security teams receive centralized visibility and governance over agent-driven interactions with databases, servers, cloud environments, and other critical assets.
A key component of the platform is its just-in-time credential model. AI agents never directly hold privileged credentials. Instead, credentials are injected only at the moment access is required, scoped to a specific task, and automatically revoked once the task is completed. This reduces the risk associated with standing privileges and credential exposure.
The platform also distinguishes between human-driven and agent-driven connections, enabling organizations to apply policies specifically designed for autonomous systems. Every database query, tool invocation, and command executed by an AI agent is recorded and linked to a verified identity, creating a comprehensive audit trail for governance, compliance, and security investigations.
As enterprises accelerate the adoption of agentic AI, concerns around autonomous decision-making, privilege escalation, and unintended actions continue to grow. Delinea believes that runtime authorization will become a critical layer of security, allowing organizations to embrace AI-driven automation while maintaining visibility, accountability, and control.
The new capabilities are available immediately as part of the Delinea Platform, extending the company’s privileged access and identity security framework to support the next generation of AI-powered enterprise environments.
