Delinea Delivers Runtime Authorization for AI Agents, the Only Platform to Enforce Policy on Actions Before They Execute

Delinea, the identity security platform for governing what humans, machines, and AI agents do once they have access, is releasing runtime authorization capabilities for AI agents. The platform becomes the only one to enforce policy on what agents do inside a session before they act, rather than just verifying how they connect.

AI agents now operate autonomously across production databases, SSH hosts, Kubernetes clusters, cloud consoles, and MCP servers. Most identity security approaches either verify a connection when a session opens and audit or revoke access after the fact, or can only see traffic routed through their own server, leaving direct connections outside their view. Delinea’s new capabilities enforce policy on what happens inside the session, action by action, before execution.

“The security industry spent years solving credential theft, but AI agents have introduced a new problem: authorized access doing unauthorized things,” said Art Gilliland, CEO at Delinea. “You can have perfect credential hygiene and still have an agent tear through your production environment in milliseconds. Recording what happened or revoking access after the fact doesn’t stop that, enforcing policy on the action as it runs does. The perimeter has moved to inside the session, and no one has figured out how to address that until now.”

Runtime Authorization Capabilities

The runtime authorization system delivers consistent policy and a complete audit record regardless of how agents connect. Agents reach databases, SSH hosts, Kubernetes clusters, and cloud consoles directly, not only through an MCP server. The Delinea Platform authorizes and records each connection through a single control point across every protocol agents use, giving security teams the same visibility and enforcement regardless of how the agent was deployed or which systems it reached.

The platform eliminates standing credentials for attackers to exploit. The agent never holds a credential. Delinea injects it just-in-time at the moment of access, scoped to the task rather than inherited from the person who deployed it, and revokes it automatically when the task completes. Because the credential is never exposed to the agent, there is no lingering exposure between sessions.

Policy is enforced on every action, not just when the session opens. A single AI session can carry dozens of tool calls, each with a different risk profile. The Delinea Platform evaluates and enforces policy on each tool call individually, allowing it, blocking it, or pulling in a human before it executes. When an agent misbehaves, the blast radius stays contained.

The platform applies policy built specifically for agents, not retrofitted from human access controls. It identifies whether a connection is agent-driven or human-driven before granting access and applies agent-specific policy at the moment of connection so the right controls are in place before the first action runs.

Every tool call, database query, and SSH command is recorded and accountable to a specific identity. When something goes wrong, teams have the ability to investigate, respond, and stand behind every access decision that was made.

“AI agents were accessing our production systems and we had no way to know what they were actually doing once they were in,” said Dhruv Kumar, Infrastructure Product Manager at Telnyx. “With Delinea, every action is now tied to a named identity and recorded at the action level. That’s what gave us the confidence to keep moving forward with AI without taking on risk we couldn’t see.”

Runtime authorization for AI agents is available now as part of the Delinea Platform. No new infrastructure is required, and organizations can apply Zero Standing Privilege to AI agents where risk demands it. Delinea will demonstrate these capabilities at Black Hat (booth #2367) and Ai4 (booth #946), both taking place August 4-6 in Las Vegas. For more information, visit delinea.com.

Leave a Reply

Your email address will not be published. Required fields are marked *