Okta, Inc. (OKTA)
NASDAQ: OKTA · Real-Time Price · USD
205.36
+8.74 (4.45%)
At close: Sep 23, 2026, 4:00 PM EDT
205.98
+0.62 (0.30%)
After-hours: Sep 23, 2026, 7:59 PM EDT
← View all transcripts

The Oktane Call 2026 Investor Summit

Sep 23, 2026

Summary

The summit introduced a comprehensive industry blueprint for securing AI agents, emphasizing collaboration, open standards, and new identity models. Key product launches like Agent SSO and Okta for AI Agents showcased real-world impact, with customer stories and demos highlighting productivity, security, and innovation gains.

Todd McKinnon
CEO and Co-Founder, Okta

You are part of the biggest Oktane ever. Thank you for being here. It was one year ago that we introduced this simple but powerful concept, and that was, to secure AI, we needed a powerful new identity type. An identity type where every AI agent got their own identity. I've been on a plane this last year almost every week, talking to all of you about your challenges and what you're looking to get out of this technology, and the feedback has been amazing. So thank you for meeting with me, thank you for informing us on this journey and help us build the right thing for the industry at this time. I ran across this quote recently, and I thought it was an accurate reflection of our industry right now.

Talent hits a target that no one else can hit, but genius hits a target no one else can see." AI agents, they promise to do both. I think as an industry, we're focused on the talent side of this right now. We're looking at our existing processes, making them more effective, making them more efficient, getting cost optimization. But the real prize, the real potential is genius. How do we get to that product breakthrough that no one even knew was possible? How do we invent new things? How do we discover new cures for diseases? This is the potential of AI. So how are we going to make that happen? How do we get there? I think watching this technology the last couple of years, we have an intuitive feel for this. It's about more connections. The models get better when you give them more data.

Systems get better when you connect them to more other systems to allow them to take actions. That is how we get to genius. That is how we get to genius. We also know, living in the world right now, that this comes with risk. Every process you optimize, you hear a headline about a cyberattack, someone taking advantage of this technology and breaking in. We all understand that, when we're looking for the cure for disease, we could unleash something like a bioweapon, and that's risk. As an industry right now, we're being forced to choose. We either lock it all down and don't connect AI to anything, and get the security. That's no good. We don't want to lock it down. Or we let it connect to everything, free it up, and go for the innovation. It's not a great choice.

How do we get the best of both worlds here? The solution is simple, not easy, but simple, and that is visibility and control. Bringing visibility and control is how we break this deadlock and get security and innovation. At Okta, our vision as a company is to free everyone to safely use any technology. I feel like the luckiest guy in the world leading this company at this time. We're at exactly the perfect moment. We have to bring visibility and control to this industry right now. That is how we're going to enable all of you to safely use any technology. We're the perfect company at the perfect time, and it's incredibly motivating to all of us to go make this happen and change the industry.

We've been at this for a while, 17 years, and if you are unclear how long that is, here's a picture of me right about the time I started Okta, and our daughter getting ready to go play some basketball on a Saturday. This little girl, she's going to be like this forever. This past weekend, in case you were wondering how long 17 years is, we dropped her off at university. Very excited for her. It's definitely a little bit melancholy. Her first day on campus, she called me to complain about having too many systems to log into. I said, "Julia, evidently, 20,000 customers isn't enough. We need 20,001. We'll get to work on that." Every month, 58 billion authentications, 58 billion connections between people and machines, and the technology and the resources you need to be effective and productive.

We're in the perfect position to help match security and innovation by solving the challenges of our industry. A key part of doing that is standardization. Technology is too complex. It's too isolated. It doesn't work well together. To bring innovation and security together, we're going to need standardization on a massive scale. Today, we're going to talk about that in three sections. The first section is the blueprint for the secure agentic enterprise. Second, Agent SSO, a powerful new standard that enables agents to connect seamlessly to resources. Finally, Okta for AI Agents. Let's start with the blueprint. People ask me, "Todd, what's your biggest competition?" They expect me to mention another vendor or a platform. The answer is something different, actually. Our biggest competition is confusion. When I talk to all of you're confused.

Every vendor is coming at you saying that their solution is the one solution that will help you secure everything, will help you create all the AI you need, and lead your organization to glory. You all know intuitively that reality is quite different. What's happening in our industry right now is every layer of the technology stack is being transformed by AI. It's not just one new group of vendors or tools or companies, it's every layer of the stack, from infrastructure to applications to data to agents you're building yourself, agents startups are selling you. No one company can secure agents alone. It's not realistic. We're talking about a complete transformation of the technology stack. We took this feedback, and we're going to do something about it.

We went out and we've locked arm in arm with some of the leading companies in our industry to create a Blueprint Alliance. All these companies, industry leaders, AWS, CrowdStrike, Salesforce, and many others, they're motivated by the same thing we are. Confusion is their competition as well, and we need to work together to clarify that. The Blueprint Alliance, working together, is centered on four key questions. The first question is: Where are my agents? Second question is: What can they do? Thirdly: What are they actually doing? Fourth is: How do I respond? If we answer these four questions, it'll clarify that confusion and put us all on this journey toward building the secure agentic enterprise. The teams have been together, the top product and engineering people from these companies have been together hammering this out in quite a sophisticated level of detail.

And just like a blueprint for a building, it has the electrical sub plan, it has the structural plan, it has the plumbing plan. Our blueprint is broken down into four sections. The first section answers the question: Where are my agents? This is about visibility and control. This is about an agentic registry, so you can keep agents from multiple systems coordinated and give them all a unique identity. The second question is about: What can they do? What connections can they make? What do they have the permissions to do? Making sure those permissions match the appropriate entitlements that those agents need. This is also about governance of the life cycle of the agent, to make sure that an agent today and tomorrow and a month and a year from now still needs the access that it is granted.

The third pillar is the runtime pillar. It is actually: What are the agents actually doing? What is the intent of the call or the application for that agent? And how does it match up with the actual performance and the actual execution? This is things like network monitoring and other types of monitoring and observability so that we can see that the agents are doing actually what we think they should be doing.

Finally, all of this is incredibly valuable because it sets you up and defines how you respond. The kill switch everyone talks about is in this pillar. If something goes wrong, if it gets off track, if it is malicious or it is just an error, how do we actually disconnect it and make sure it stays in line with what we want it to do? This is all built on a common framework of risk signals. The alliance has defined what the risk signals and what the protocol format for sharing the risk signals is. Different parts of the blueprint and different components of the blueprint can share risk signals with a common understanding of what they mean.

And of course, it is consistently defined how telemetry and observability and monitoring, because the whole point of this is bringing visibility and control. So central telemetry and logging is absolutely important. There is a ton of detail here, and the keynote would be way too long to go into all of it. You get out your phone and scan this QR code. It will take you to a couple important resources. It will take you to the white paper that the alliance has defined that lays this all out. And you can also order the room service menu from here.

We are super lucky today to be joined by a leader from one of the founding members of the Blueprint Alliance. So please, let us give a warm welcome to Chet Kapoor, Vice President from Amazon. Chet?

Chet Kapoor
VP, Amazon

How's it going, Todd?

Todd McKinnon
CEO and Co-Founder, Okta

It's great to see you, Chet. Sorry about your travel problems today.

Chet Kapoor
VP, Amazon

It's called life.

Todd McKinnon
CEO and Co-Founder, Okta

Yeah.

Chet Kapoor
VP, Amazon

Right? We were supposed to be on stage together, and here we are.

Todd McKinnon
CEO and Co-Founder, Okta

Why is securing AI agents, in your view, a cross-industry challenge?

Chet Kapoor
VP, Amazon

It's really interesting. I've always been very comfortable with speed, and my mother would say probably too comfortable with speed. Recently I've gotten into a little bit of a fan of F1 racing, and I keep thinking about things and how you think about a race car and things like that. I actually think that AI is like a race car, right? We keep thinking about brakes as a way of actually slowing down. But if you really think about brakes, it actually gives you the confidence to take the corner at full speed. If you start going down that path, you realize that also AI is different from everything we've ever done in software because it's not deterministic. It's probabilistic.

The very thing that gives agents power also makes it really hard to secure because they don't follow the same path every time. The way I think about agents is they're a lot like human actors, right? With one big difference, right, that you have access to their brains. But it's very clear, the more access you give them, the more responsibility you give them, the more powerful they get. I love the four questions you bring up, and I'm sure we'll talk about it more. Like, where are your agents? What can they do? What are they actually doing? When something goes wrong, how do you respond? Because if you answer these questions for every agent, you realize that there are going to be agents all over the place, right?

AWS will do them, there'll be SaaS vendors that do them, customers will build their own agents, and they all have to work together. That's exactly why we need this Blueprint that we're working with you and many others in the alliance for.

Todd McKinnon
CEO and Co-Founder, Okta

How do you see it solving this challenge of moving customers beyond prototyping and experimenting and into production? I imagine you guys run into that a lot with your scale and your capabilities.

Chet Kapoor
VP, Amazon

It's interesting. I think the biggest thing is I talk to about five or 10 CISOs a week, and the conversation always starts from, "I want to move faster, but I need to manage risks." The interesting thing about this, where we are, it's not just a CISO discussion. With things like Mythos, it's actually become a board and a CEO-level discussion. Right? I think what customers are really[crosstalk].

Todd McKinnon
CEO and Co-Founder, Okta

Yeah, they can't avoid it. The news is hammering it every day.

Chet Kapoor
VP, Amazon

Yeah, my take is, and I think a lot of CISOs are moving, right? They're starting to think about this and saying, "I cannot be the one that says no." Right? "I've got to be the one that actually gives the guardrails and figures out a way to make it happen." They want some way to move, but they want confidence that they can actually do it. To answer the questions you brought up at a very high level for folks, is you think about they want to see, they want to govern, they want to contain everything in their environment, right? So make sure that every agent has an identity, a verified identity, and a named owner. Right? Make sure they have task-scoped access, right? What can they do, right? What are they doing? They have real-time monitoring and tracing. And then containment, right?

Do you not only stop an agent and let it back in without affecting the rest of the system? I think the biggest thing that I think that we have to land up doing as an industry is we cannot solve this problem by having more gates and manual reviews. Otherwise, you're dragging AI this race car back to the human speed. I think that's going to be a problem.

Todd McKinnon
CEO and Co-Founder, Okta

Yeah, that'd be like a safe Formula 1 race where they only went 25 miles an hour. Yeah.

Chet Kapoor
VP, Amazon

Yeah.

Todd McKinnon
CEO and Co-Founder, Okta

Not too exciting, Chet. Not too exciting.

Chet Kapoor
VP, Amazon

Yeah, no, not too exciting at all.

Todd McKinnon
CEO and Co-Founder, Okta

How are you feeling about the Blueprint Alliance helping the blueprint evolve as the industry evolves? I know that's an important part. This isn't a static thing that's going to just be here in September of 2026. It's a living, breathing thing. How are we going to make that happen?

Chet Kapoor
VP, Amazon

Here's what I think. Ultimately, we are heading towards doing things at machine speeds, right? The world we're coming from is telemetry, storage, query, and then dashboards for humans, right? The world we're heading to is you have all this telemetry, you have context, you have reasoning, and then actions by agents. If you look at those two, that's the bookends where we are and where we're heading. I think it's really important that we understand that it's about starting in learn mode, right? We call it the learn mode, which is you start with humans in the loop, right? They can approve things and over a period of time, you get humans on the loop where they only are looking at exceptions.

As time goes on, you get more confidence and you can go to autonomy. The thing that I really like about the blueprint is that we actually give folks a trusted ramp to go off and make it happen. Additionally, what I also like about this, Todd, and I know this is Oktane and I'm talking to you, this is a lot bigger than just vendor, right? It avoids vendor lock-in, and this is a lot bigger than Okta, this is a lot bigger than AWS. It's about making sure the industry can adopt and actually go off and make agents work in their environment safely with the right guardrails.

Todd McKinnon
CEO and Co-Founder, Okta

Yeah. Well said, Chet. Thank you so much for joining us. Next year, we will get you out here in person. We will make sure we have[crosstalk].

Chet Kapoor
VP, Amazon

Next time I will come in the night before.

Todd McKinnon
CEO and Co-Founder, Okta

I cannot wait. Thank you so much for being part of the alliance and helping us build the secure agentic future together.

Chet Kapoor
VP, Amazon

It was great. Good luck with the rest of the keynote. Thank you.

Todd McKinnon
CEO and Co-Founder, Okta

Thank you. Chet Kapoor, everyone. That last thing we talked about is very important. This is not an Okta product. We are locking arms with everyone in the industry to move the secure agentic enterprise forward, and it is going to take us all. Okta, as a company, our independence and our neutrality positions us perfectly to do that. We do not have a horse in the race. We are not trying to sell you a broad suite of security tools. We are not trying to sell you a bunch of applications. We are focused on identity and building the secure agentic enterprise and giving you the choice and flexibility and neutrality to make it all work for you.

A key part of this blueprint, and some very exciting developments on the standardization we are seeking, is in the What can they do pillar, and it is all around Agent SSO. Nothing gets me more exciting than SSO. I am thrilled by this. It is how we built our company. We need this for agents because the current state of things is not ideal. Here to show you this, please welcome Mallory Sword Glenn . Mallory? Mallory works in product marketing at Okta, so it is not uncommon for me to send her a message frantically seeking a new roadmap, completely updated with up-to-date delivery dates and status of all the deliverables.

Mallory, what do you do?

Mallory Sword Glenn
Director of Product Marketing, Okta

It is true. We are going to use Claude for that. I am going to try to automate a lot of the boring stuff here. To do this, Claude is going to need access to a few things to actually do this. It will need Atlassian for our product docs. It is going to need access to GitHub to go grab those product issues, and then ultimately to Slack to send you that roadmap. Right off the bat, we will get into Claude here, and what you are going to see, we are actually not connected to any of these resources. We are going to need to go through[crosstalk].

Todd McKinnon
CEO and Co-Founder, Okta

Mallory, I said fast.

Mallory Sword Glenn
Director of Product Marketing, Okta

Right. We are trying here.

Todd McKinnon
CEO and Co-Founder, Okta

I want this.

Mallory Sword Glenn
Director of Product Marketing, Okta

Let us get going. Atlassian. We will go ahead and authenticate into Atlassian. I will click here. I am going to need to type in an email, type in my password here as well once we get to it. These consent prompts, I can accept these, right, Todd? That seems okay? From here, we will do the next one. We got to do the same thing for GitHub. GitHub, we are going to run the same flow here. I am going to type in my email again. We will need to type in the password. This agent is just acting on behalf of me, so I can just approve these here. We got one more, Todd, because we got to send it to you. We are going to do the same thing for Slack. Going to authenticate into Slack here. I am going to type in my email again.

Todd McKinnon
CEO and Co-Founder, Okta

Wait a minute. Wait a minute. These models are going to take over the world, and they cannot connect to Slack?

Mallory Sword Glenn
Director of Product Marketing, Okta

That's what they say. That's what they say. We will password. Probably should have done this myself at this point. I'll accept. Would've been faster. As you saw, Todd, and as many of you probably saw, this was incredibly frustrating for me as an end user, but it was also incredibly insecure. By the end of that, you saw I was just blindly accepting consent prompts for this agent.

Todd McKinnon
CEO and Co-Founder, Okta

Clearly, this is not ideal. Clearly, you might call this a mess, there's got to be a better way, and that's why we've developed Agent SSO. It brings the same great user experience for SSO for a person to the world of AI agents. The great thing about it is we've made it available in every Okta product. You all have Agent SSO. You get Agent SSO, and you get Agent SSO, and you get Agent SSO. No additional charge. It's out there in the world for you to use and take advantage of. Mallory, once they use this, what's the experience going to be like?

Mallory Sword Glenn
Director of Product Marketing, Okta

Let's run that workflow again, this time using Agent SSO. You're going to notice something different right off the bat. I'm going to log into Claude. I'm going to use FastPass for this. Already, no passwords. Already way quicker. Before I ask Claude to pull this roadmap for you, let's see if we're actually connected to resources. If you look here, what you can see is we are. We're connected to Atlassian. We're connected to GitHub. We've got Slack. We also have a few other connections here that have been set up for us. We've got ServiceNow and Google because I need those to do other parts of my job. Notice I didn't have to do anything here. These were all ready for me right off the bat.

Todd McKinnon
CEO and Co-Founder, Okta

Now you're talking.

Mallory Sword Glenn
Director of Product Marketing, Okta

Exactly.

Todd McKinnon
CEO and Co-Founder, Okta

Now you're talking. But where's my roadmap?

Mallory Sword Glenn
Director of Product Marketing, Okta

Yes. Let's ask Claude to get to work. We'll say go ahead and send that roadmap to Todd. Now, Claude's going to get to work, and Todd, you're going to have that roadmap by the time you walk off the stage here. Something to point out for the audience, for me as an end user, this was great. My agent worked across multiple applications without ever disrupting my workflow. For my IT and security teams, also phenomenal. They were able to centralize management of all of this through Okta, and it's flexible and scalable. As we adopt more agents across more and more platforms that access more and more resources, this control will work for all of those participating agents and applications so we can keep being productive, Todd.

Todd McKinnon
CEO and Co-Founder, Okta

Love it, Mallory. Thank you so much. Give it up for Mallory. So clearly, that's amazing. Not only do I know it's amazing because I see it on the screen, I use it at work, and the experience is great. I go to Claude. It's connected to all my resources, no manual login. So why hasn't someone done this before? What's going on here? The answer is because this actually relies on standardization, and it takes a long time and a lot of work to do standardization. We've been working on this for four years now, and we're starting to make a ton of progress, and the momentum is really starting to roll. Agent SSO is based on a standard, open standard, called Cross App Access. Cross App Access, the concept is simple.

Instead of when an AI agent connects to a resource using the normal OAuth flow where you ask the user for authorization of the connection, Cross App Access specifies how the technology should, instead of doing that, it should ask the enterprise Identity Provider for the predefined policy that specifies the right grant and doesn't bother the end user and gives that visibility and control Mallory was talking about. Now, for this to work, people have to support this protocol. It's not just a protocol gets invented and is adopted. People have to adopt it. Vendors have to adopt it in their technology, and we've made a ton of progress. You can see some of the vendors here on the screen that support Cross App Access now, which is very exciting.

If you have a vendor you like that's not on this list, call them and encourage them, and make sure that they support Cross App Access. It's an open protocol. It's not an Okta specific thing. It's standardization. It's a no regrets decision. Now that you all have Agent SSO in your environment, it should be easy for them to make that decision because it's going to plug right into your environment. We made another big step forward in the last year, and that is one of the most important, biggest AI agents in the world, Claude, with Okta as the first Identity Provider involved here, now supports Cross App Access. Even more incentive for all the ISVs to get on board and support Cross App Access. Even gives a bunch of incentive for other Identity Providers to adopt this open standard.

That's because inside of MCP, Cross App Access is the way accepted by the standards bodies and the MCP folks to put enterprise authorization into MCP. Now when Claude talks to MCP, it's looking for that Cross App Access hook, and you get the experience that Mallory just showed here. To drill into this more, we're very lucky today to have one of the co-creators of MCP. It's great to have David Soria Parra from Anthropic here to talk about this. David, nice to see you.

David Soria Parra
Member of Technical Staff, Anthropic

Nice seeing you, Todd.

Todd McKinnon
CEO and Co-Founder, Okta

Yeah. So in MCP development, why was it important that it was open?

David Soria Parra
Member of Technical Staff, Anthropic

Look, open standards are really things that gives enterprises choice, and it's something that allows them to review, to secure things, and build really as an industry together. If you want to build an ecosystem, something like MCP, you really need to do it in the open. We have seen this with cloud providers from the beginning. We have seen it now with identity again, and with agents, it's once more that we see that we need common standards to truly power agentic infrastructure.

Todd McKinnon
CEO and Co-Founder, Okta

Does the openness of MCP, does the success of MCP, does it exceed your expectations?

David Soria Parra
Member of Technical Staff, Anthropic

It very much exceeds expectations.

Todd McKinnon
CEO and Co-Founder, Okta

You've kind of changed the world.

David Soria Parra
Member of Technical Staff, Anthropic

Yeah, it does exceed expectations.

Todd McKinnon
CEO and Co-Founder, Okta

You should be very proud of that.

David Soria Parra
Member of Technical Staff, Anthropic

Yeah. Absolutely.

Todd McKinnon
CEO and Co-Founder, Okta

I don't know if you've been able to get a daughter into college, but close.

David Soria Parra
Member of Technical Staff, Anthropic

No. Look, I think when you start out like that with what you try to be a standard in the world, I think you never really expect it to be that broad and that big. We are super fortunate that we have all major AI providers, we have cloud providers, we have most Fortune 500s in the world really adopt this. I'm very glad that it's been the crazy success that it's been.

Todd McKinnon
CEO and Co-Founder, Okta

Yeah. In your view, what does enterprise authorization and Cross App Access in enterprises, in your customers, what does it enable? You've talked a little bit about it, but from your perspective, what do you see?

David Soria Parra
Member of Technical Staff, Anthropic

Yeah, one thing that's important is as models get more and more capable, one of the key pieces is really for enterprises to provide models with secure and safe access.

Todd McKinnon
CEO and Co-Founder, Okta

Yeah.

David Soria Parra
Member of Technical Staff, Anthropic

Part of that is also providing a product experience that is both seamless and secure at the same time. What enterprise managed authorization really does is move away from allowing or having the consent screen in front of the user and towards pushing a lot of the security safety aspects towards the IT admin, while at the same time providing a really smooth user experience. I think that is really important for us in the world to make AI systems more broadly approachable. But also, at the same time, to really unlock a lot of the capabilities in the model, as they are connecting to your enterprise SaaS systems to your internal systems and so on.

Todd McKinnon
CEO and Co-Founder, Okta

Yeah, this OAuth protocol was invented to share your Twitter feed for the Twitter clients. I think it needs some updating.

David Soria Parra
Member of Technical Staff, Anthropic

Yeah.

Todd McKinnon
CEO and Co-Founder, Okta

You mentioned more capabilities for the enterprise. What is next for IdPs and models and security? What do you see as the big rocks left to move in terms of our effort to make this secure agentic enterprise?

David Soria Parra
Member of Technical Staff, Anthropic

Yeah, this is a good question. Look, we have built identity and authorization mechanisms for humans in mind for the last decades. A lot of these assumptions just don't work for agents anymore. There are still a lot of open questions regarding fine-grained authorization, intent-based authorization, in time provisioning of identities for agents that we need to solve as an industry together. That we need to continue to develop across AI labs, across identity providers, like Okta, across cloud providers, standards that can really power this agentic infrastructure. In many ways, it feels like the very early days of the next revolution of building this agentic infrastructure. Part of that is really building together as an industry, these standards, everyone in this room can rely on with their companies, with their enterprises.

Todd McKinnon
CEO and Co-Founder, Okta

Yeah. Well, congratulations on your success, and thanks for doing what you do with the industry and with Okta. We really appreciate you being here and sharing a little bit of the story with us.

David Soria Parra
Member of Technical Staff, Anthropic

Thank you so much.

Todd McKinnon
CEO and Co-Founder, Okta

Good to have you, David.

David Soria Parra
Member of Technical Staff, Anthropic

Take care.

Todd McKinnon
CEO and Co-Founder, Okta

All right. We talk about Agent SSO, and it is a big step forward in standardization, and we've made a lot of progress, but it's only part of the story. It can't discover agents you don't know. It can't do agent governance. It can't broker connections between different kinds of protocol. It doesn't have a kill switch in it. For that you need something more. That's why we're building Okta for AI Agents. It's our flagship product to do the identity portions of the Blueprint. The Blueprint covers many things, but a lot of the foundational parts of the Blueprint are all around identity, and that's where we focus. Okta for AI Agent is to build the identity portions of that Blueprint, while of course, working seamlessly with everything else in your environment to secure the agentic enterprise.

Okta for AI Agent is a GA product. Now, you might think it is odd that I am emphasizing that, but in the current hype cycle in our industry, let's just say it is not uncommon for products to be pre-announced and products to be pitched as they are here today, but they are really far in the future. We are very proud of the fact that Okta for AI Agents has been generally available since April. We are not stopping there. We are innovating quickly and continue to deliver more. Many of you are using the product and seeing the success. How are we able to do this? It is actually quite simple. First thing is, we organized the company in a different way. We have at Okta, an AI Takeoff Team that reports directly to me, and their job is simple.

Their job is to work with all of you and deeply understand your environment, what challenges you have, what you need to better serve your end users, improve your security posture, deep understanding of your environment. Then to take that learning and pump it directly back into the R&D team. We have reorganized the R&D team to make sure we have one unified team that gives us the priority and it gives us the bandwidth and the firepower to not only build the Okta for AI Agents product, but remember, this is seamlessly integrated across all of our products, so every member of every team, and to some degree, is also working on Okta for AI Agents. Another thing we do is I meet with the R&D team every day. I meet with them every day, removing obstacles, seeing how I can help push them along.

Now you can ask them if they think this is a good thing or a bad thing, but I like it. We are seeing a ton of success. The customers speak for themselves. There are many more, but three that really stand out are, first, Ramp. Glass is an AI agent for internal productivity at Ramp, and Dmitri Altum there is our champion at Ramp. We love working with Dmitri and the team, so thanks Dmitri for all your work. They have seen tremendous success across this productivity suite across the entire company. Yahoo, so we are going from a more emerging fintech star to an internet icon in Yahoo. Yahoo has something internally called Y!Connect, which is like an agentic system for software engineering, and they are evolving over time into more of a harness for all of R&D. This is built on Okta for AI Agents.

Okta for AI Agents brokers the connections between this agent harness and their virtual MCP servers, giving them visibility, giving them this kill switch. We are really excited to work with Bryan Meister and the team at Yahoo there. Finally, Dell Technologies is overhauling their complete company, but more specifically their customer service and success organization by having an AI platform that automates and suggests the Next Best Action for all of their services people. Dell operates 100,000 people at massive scale. They can take the learning over millions of customer interactions, and the AI crunches that and feeds it back into the Next Best Action for their people, which means better outcomes for their customers, better customer satisfaction, and what everyone wants, more revenue for Dell. It is three amazing stories, and it is not just these stories.

Okta ourselves are using this product internally, and we have had a ton of success. We have an internal AI agent called Dex, which is connected to all of our internal systems and automates a bunch of work that employees had to do manually in terms of internal operations, and we are going to save 250,000 hours this year, hours that can be spent doing more productive things like building great products for you and providing better service to you. Dex is a huge hit, and the visibility control is all based on Okta for AI Agents. When we started really using agents internally, the marketing team was actually an early adopter that took off and was innovating here. Instead of locking it down and worrying about risk of data loss, we used Okta for AI Agents to cover that risk and push that innovation forward.

Now we have a central hub where they can share these, the whole company, 100% of the company can share these AI agents, collaborate with other people and share best practices and people can use the agents. We have seen a ton of benefits in productivity, but also unexpected things. For example, if you actually get the authorization right on what tools the agents can call, you can actually save money. Up to 90% of cost of the tokens can be decreased in certain cases because the agent is not spinning through tokens, looking at tool calls. It does not even have access to call anyways. It is like unnecessary work and you can save costs there. We are moving very fast. We have a tremendous amount of focus.

We love the feedback from you, and we are using this AI Takeoff Team to make sure that this is not a big science experiment. We are building innovation in the product that is prescribed and purpose-built for your environments. We are committed to keeping up with that and keeping investing here so you have this secure agentic enterprise. We have 25 major features we have released since April, so the drumbeat is happening. You can see the breadth and the capabilities we have been releasing here. Three I think are particularly important. The first is Shadow AI Agent Discovery for Endpoints, the second is the Agent Gateway, and the third is Third-Party IdP Support.

First, we all know that in the last year, what is happening on the endpoint, mostly on your developer's laptop with CLI and client-based agents, is a big deal. Powerful, a lot of innovation, but also a lot of risk. Developers have access to tokens. Many times, they have access to production, and it is a big problem. You need visibility there. This capability integrates both with CrowdStrike and with the Okta Verify app to make sure you get complete visibility into what is going on in the endpoint, and that gets piped back into Okta for AI Agents, letting you have visibility and then make the required controls and protocols around that to make sure that you mitigate that risk.

Second is our most requested feature, and that is Agent Gateway. It's a virtual MCP server that allows you to place all of your MCP servers behind this virtual server and then use Okta for AI Agents to govern the authorizations and the permissions to groups and roles, and users across every tool in the whole catalog. It works with MCP servers you built yourself or MCP servers that every SaaS application is providing for you. It's a very important control point. It gives you complete visibility into what's happening because it's a gateway. It's a network gateway that actually is in line with the traffic. It gives you the ability to take tokens off the client and house them centrally in the gateway, which is much better for security. It allows you this kill switch, so you know that there's no way around it.

The agent has to go through this gateway. If it's calling MCP servers, you know it's going through this gateway, and you can shut it down when you need to. The last capability I'm going to talk about today here is this support for third-party IdPs. Now, we realize that not every company in the world, including my daughter's college, does not use Okta as their IdP. Now, that part of our soul internally, that's very frustrating for. We want to support those organizations with Okta for AI Agents as well. Okta for AI Agents now works with third-party MCP. So you can have your human identities in one system and still manage your Okta identities in Okta for or your agent identities in Okta for AI Agents, so you can implement this blueprint in a heterogeneous environment, which we all know the reality of every one of your environments.

It's incredibly heterogeneous. No one company can secure agents alone. We're taking this independence and neutrality incredibly seriously and investing here with supporting third-party IdPs. A lot of this conversation has been about internal productivity and how can we make our processes, existing workforce, more productive. I think that's the right place for the industry to be focused on. Sometimes the risk will be lower. I think if we really want to get to genius, if we want to have the product breakthroughs that no one thought of, grow revenue, take over a new market share, expand our organizations, fulfill our missions more, we need to get to the customer-facing activities. We're investing here as well. We support Auth for UCP in the Auth0 platform.

Auth for UCP is Universal Commerce Protocol. It's a way for the Gemini AI agent in that platform to interact with any e-commerce site that supports UCP to do account registration, shopping cart, checkout, basically make the commerce experience inside of Gemini seamless. If your e-commerce site uses Auth0 as the identity provider, now that works seamlessly with UCP. This is more of, I think, more of an emerging area for the industry. But my prediction is when we're here next year at Oktane, customer-facing agentic is going to be a huge deal, and our whole industry is going to move there. This is going to have the same kind of tension between what's the risk, should we lock it down, should we open it up for innovation?

Our principles and the governing architecture of the blueprint is going to work here as well. It applies just as much to this side of the equation as any other side. We're excited to continue to innovate here. How about we see some of this stuff? Harish. Let's welcome Harish. Harish Peri, come on out.

Harish Peri
SVP and General Manager for AI Security, Okta

All right. Thank you, thank you. What's up, Oktane? No, no, that's not going to cut it. I said, "What's up, Oktane?" That's better. That's what I'm talking about. Our customers, all of you. You are the key to our AI innovation. You're moving fast, but we're listening, we're learning, we're keeping pace. So thank you. Keep the feedback coming. One such fantastic customer is the PGA, the Professional Golfers' Association of America. Thank you so much for being an awesome customer of ours. They're on a great journey. They're transforming their whole enterprise. Let's take a look at the video. Let's roll tape.

Speaker 6

[Presentation]

Harish Peri
SVP and General Manager for AI Security, Okta

All right. Give it up for PGA. Thank you so much for being an awesome customer. Now, what's great is they're on an agentic transformation journey. They're deploying agents for their workforce, they're deploying agents for their customers, for agentic commerce. It's a complete transformation. The next couple of minutes, Mallory and I are going to show you how Okta secures AI for the PGA. Now, I want to anchor everyone in one fundamental principle, which is in Okta, every agent is a unique first-class identity. This is important. We're not representing them as users. We're not hijacking service accounts. They're a first-class identity that gets all represented here in Universal Directory. Now, every agent gets a unique cryptographic identity. They have a human owner, so if something goes wrong in the governance cycle, you know exactly who's accountable. But what's better is these agents come from everywhere.

They live in AWS, they live in Salesforce, they come from ServiceNow. They're agents that represent workforce agents, customer agents. They can be manually registered. They can be pushed in here automatically through your DevOps pipeline. It doesn't matter. This is the one-stop shop for your secure agentic enterprise. Okay, now let's dig into this. Let's answer the very first blueprint question for PGA, which is: Where are my agents? This is Okta's ISPM, Identity Security Posture Management. Now, ISPM discovers agents from across their enterprise. These are agents that are running on the endpoint. These are agents that are embedded in known platforms like AWS or Salesforce. These are agents that are running in the browser that need OAuth consent grants, and these are shadow MCP servers. It doesn't matter. They really have nowhere to hide. ISPM discovers them all.

Now, let's click into a specific type of discovery, the endpoint agent. I've spoken to so many of you on a regular basis, and the one single biggest point of heartburn is, "I have these local agents running on my peoples' endpoints. I don't know what they're up to." Well, fear not. ISPM now integrates with CrowdStrike and with our own Okta Verify so we can discover these endpoint agents and bring them into the light. We can see critical metadata like the agentic harness, the name of the agent, the associated user, and any MCP servers that this agent might be using. Let's actually click into a specific agent. Right here in ISPM, we have the AI agent graph. That gives me immediate visibility into this agent's entire blast radius. I can see who's accessing it, and I can see what resources this agent in turn is accessing.

Now, in this case, I can see it's connecting to Slack and some kind of a homegrown MCP server. This MCP server was never approved, nor was it registered. It's the perfect definition of shadow AI. Now, this is where ISPM changes from being a phenomenal UI and a phenomenal discovery tool to actually being fully integrated into our platform. Right within ISPM, I can register this shadow agent and the shadow MCP server directly into Universal Directory. Now, I want to emphasize what we just saw. We took a shadow agent, we took a shadow MCP server that was running on some laptop somewhere. We discovered it, we surfaced it, we gave it a unique identity, we brought it into the light, and now it's part of Universal Directory, all within the same platform.

No emails, no tickets, no calling somebody, no texting your friend. It just happens in one place. It's securing AI. That's what this is all about. That's pretty cool. But that was only question number one. Let's move to the second blueprint question, which is: What can these agents do? Let's click into this one specific agent. That's a sales ops agent. Now, this needs access to Salesforce and Gmail. It's a very typical kind of workforce agent that we have at a lot of our customers. This is the configuration designer. This is phenomenal because here, I can visualize the entire access graph, every connection, every other agent that it's delegating access to, every MCP server on the path from user to agent to resource.

Now, I want to emphasize a very important point here. What's incredibly important is this is not just about UI. The UI is fantastic. Huge kudos to our teams that are building this. Thank you to the customers for all your feedback. But this represents one of the biggest pain points that I hear from all of you every day, which is chain of custody. This actually shows me the entire delegation chain from a user to an agent, to potentially a sub-agent, to an MCP server, to a resource, all connected in a single unbroken log chain that is logged to our system logs and streamed out to your SIEM if you need to for threat modeling. This is huge because without this, you have no auditability, you have no traceability, and you're pretty much flying blind.

And trust me, when that end of your audit happens, this is the stuff you're going to need to tell the auditors exactly what your agents can do. Okay. That was question number two. We discovered agents. Where are my agents? What can they do? We mapped out their connections. We got to keep this rolling. Now we actually need to see what happens at runtime when these agents are executing what they were meant to do, which brings us to the third Blueprint question: What are they actually doing? You have to control what they do. You need to be able to look at exactly what tools they're talking to and shut it down if something goes wrong.

To show you that, I want to pass it over to my friend Mallory. Take it away.

Mallory Sword Glenn
Director of Product Marketing, Okta

Thanks, Harish. We'll use Agent Gateway for this. Normally, every single one of these agent-to-resource connections would be its own integration point with its own set of permissions. But Agent Gateway puts one control point in front of all of them so that I'm not managing dozens of point-to-point integrations. What this means is that I can now see and control at a really granular level what this agent can connect to and set what it's allowed to do all in one place. For our sales agents specifically, it only needs access to Salesforce, especially for the sales auditors group. We can use Agent Gateway to scope that down right now. We'll click in, and here we can see all the different tools, and we'll just click the ones that we need here. Easy enough.

Agent Gateway is also where our enforcement will happen at runtime. That means every time this agent calls a tool, the gateway is going to check identity, it's going to apply the policy that we just set, and it's going to write everything back to our audit log in real time. Which brings us to that fourth Blueprint question: How do I respond? If we head over to Claude, what we'll see is we have our sales agent. Let's put ourselves in the shoes of a seller. Let's say that our seller needs a summary of their top five accounts. Go ahead and ask our sales agent for that. Our agent's going to use those managed connections that we already set up to actually pull that list from Salesforce. You'll notice how I didn't need to authenticate or consent to anything here.

Let's say our seller is going to be on the road today. They want to be able to access this list on the fly. They try to send it to their private email account, personal email account here, and when they ask, you're going to see two things happen. First, the agent refuses this request. But second, you'll see that that connection to Salesforce is now severed. Okta detected this exfiltration attempt and automatically blocked this tool call. While the prompt itself here might not have seemed malicious and the seller didn't even mean it that way, it could have ultimately left sensitive customer data sitting in an unprotected personal inbox. This is the power of having all of our authentication and authorization in one place. You can block those individual tool calls and flip a kill switch the moment this agent is asked to do something that it shouldn't.

Let's head over and see what happened behind the scenes here. In Slack, our security team got an alert right away. We'll click into this to get a little bit more detail. In it, we can see the MITRE tactic that was used here. We can see the rule, the severity, and some other details that we might want information on. Now, if I want to see even more detail on this, I can click Full Session here, and I'll see everything from this session, from the prompt to the agent tool call, all the way through to that response. Now, what you just saw was the blueprint in action, from design time to runtime. We took an agent in Universal Directory with a unique identity and a named owner. We then applied policy for this agent using least privilege access.

At runtime, we evaluated every single tool call to make sure that identity is in the loop. When that agent was asked to do something that it shouldn't, no big deal. We flipped the kill switch and cut off its access to that resource. But these internal workflows are really just one piece of the puzzle. For PGA specifically, they also serve millions of customers every day. Harish, what does this look like when it's a customer that's interacting with these agents?

Harish Peri
SVP and General Manager for AI Security, Okta

Yeah, customer-facing agents are a whole different game because you're talking about experience, you're talking about reducing friction, you're talking about people trusting you with their money for sensitive transactions. That changes the game entirely. Now, your customers, and PGA's customers, for example, are already shopping through AI tools like Gemini. It's a phenomenal experience. It's right where they live and they work, and we have to meet them where they are. They can look for products, they can compare prices, they can get personalized offers, and they can execute transactions without ever leaving the agent. This is where Auth0 comes in. Retailers can stand up a Universal Commerce Protocol or UCP server secured by Auth0, and that plugs directly into these AI ecosystems.

Let's take a look. So this is a customer who's shopping on Gemini. They're new to golf, so they're going to use Gemini to look for some golf lessons and possibly some golf merchandise to get started. Now, this agent is going to show them personalized results for this customer. This is a very complex prompt, and it's actually evaluating all of this. This is great because the customers can type in exactly what they want. They don't have to click through 15 different screens. It just works. What's more is these are personalized to this customer. They're a new customer, which means they get offered a special new customer discount. It's higher than those for existing customers. It's personalization right in their experience.

Now, the key is when it's time to check out, they actually need a PGA account. That could be a lot of work, but because they're already connected to Gemini through Google, all they have to do is to consent to link the accounts. This is huge because this customer doesn't have to type in a username and password. There's no friction. It just works. For PGA, they don't have to do any additional work. It just works. That's how awesome this is. As we continue on this journey, now this customer wants to finalize this purchase. This is where money is changing hands. We want to always make sure there is a human in the loop. The customer receives a notification on their phone, they approve, and they're on their way, all right inside their Gemini experience. It's pretty phenomenal.

Now, there's a little bit more. If this customer sees that there's an AI client that's connected to their account that they didn't approve or that looks a little bit fishy, they can kill that connection right there. Okta's job is making sure that that experience is secure enough to trust and simple enough that the customer always stays in control. We saw a lot. We saw how PGA, a phenomenal organization, is transforming themselves, becoming a secure agentic enterprise. We saw how they're rolling out workforce agents, agentic commerce experiences. We saw how we're helping them answer the four key blueprint questions: Where are my agents? What can they do? What are they doing? How do I respond if something goes wrong? Ultimately, when you bring this all together, that's what it means when we say Okta secures AI.

Now, one very important point, everything you saw here is available right now, or is expected to be available by January. This is all real stuff. We're moving tremendously fast based on your customer feedback. So thank you. Keep it coming. What's even better is we have multiple roadmap sessions throughout the day where we're going to double, triple-click into detail on every single feature. Bring us your feedback, let us know what you think. It's going to be fantastic. What do we think? Huh? What do we think? Do you like it? There we go. All right.

I'm going to have Todd come on back out. Todd, let's come on out here.

Todd McKinnon
CEO and Co-Founder, Okta

Nice job, Harish.

Harish Peri
SVP and General Manager for AI Security, Okta

Thank you.

Todd McKinnon
CEO and Co-Founder, Okta

You are the leader of the AI Takeoff Team.

Harish Peri
SVP and General Manager for AI Security, Okta

Yes, sir.

Todd McKinnon
CEO and Co-Founder, Okta

At Okta. That means you are the tip of the spear.

Harish Peri
SVP and General Manager for AI Security, Okta

That's exactly what, that's what you tell me every day. You know.

Todd McKinnon
CEO and Co-Founder, Okta

Do you like this job?

Harish Peri
SVP and General Manager for AI Security, Okta

I'm loving it. Dream job.

Todd McKinnon
CEO and Co-Founder, Okta

How many of these innovations were prompted directly from customer conversations?

Harish Peri
SVP and General Manager for AI Security, Okta

Every single one. Agent as unique identity, authorization, the governance work, the kill switch, intent authorization, everything. This is all thanks to all of you, so keep it coming.

Todd McKinnon
CEO and Co-Founder, Okta

Thank you so much, everyone. We couldn't do this without you. We really value your collaboration, and we're going to keep the ball rolling here. Thank you so much, Harish Peri.

Harish Peri
SVP and General Manager for AI Security, Okta

Thank you, Todd. Thank you.

Todd McKinnon
CEO and Co-Founder, Okta

Okay, now we're going to hear from a great Okta customer that's really on a roll and been with us for a while.

Speaker 6

[Presentation]

Todd McKinnon
CEO and Co-Founder, Okta

We're super lucky, so let's get loud and bring out an amazing leader from a great company, Doug Schmitt, CIO and President at Dell Technologies. Doug?

Doug Schmitt
CIO and President, Dell Technologies

Hello, Todd. Great to be at Oktane.

Todd McKinnon
CEO and Co-Founder, Okta

Thank you for being here, my friend.

Doug Schmitt
CIO and President, Dell Technologies

Yes.

Todd McKinnon
CEO and Co-Founder, Okta

Dell has been on this agentic journey for longer than most other companies. What started it? How did you get there? It has been a while now.

Doug Schmitt
CIO and President, Dell Technologies

It has been a long journey. I think, actually, you have to start back about six, seven years ago, actually. We actually started by digitizing our processes. It has been a digital journey for a while, where we looked at everything and we said, with machine learning and where we were headed with the ability to do data science, we had a huge opportunity in front of us with structured data. So seven, eight years ago, we started digitizing our processes, seeing where things were at on the structured data. Then let us carry that through when AI really started with unstructured data, and we thought, "Wow, this is really a huge opportunity." And we saw four major platforms we could build inside of Dell about two-three years ago, actually about three years ago.

Those were around our supply chain, our direct sales team, as well as our services, Next Best Action , then our incredible development programs that we had in terms of our R&D. We started building the AI around those platforms. We could see where agents were coming, where they would do work autonomously or together, then help build that around. It has been an incredible journey.

Todd McKinnon
CEO and Co-Founder, Okta

Around that time, you made the, I think, the really prescient decision that every agent was going to have an identity. What gave you that insight? Or what was that? Again, you were ahead of your time on that.

Doug Schmitt
CIO and President, Dell Technologies

Well, I think maybe[crosstalk].

Todd McKinnon
CEO and Co-Founder, Okta

I mean, I would love to say it was my idea, but I think it was your idea.

Doug Schmitt
CIO and President, Dell Technologies

Well, we met with you, clearly, you and your team, almost two years ago. Once you had the platforms built and you could see agents could work together autonomously or standalone, observability. Look, it's all about observability. What we knew, and then when we were talking to you, was if we could see it, we could manage it. You had to have that observability, and it built into the agents right away, as well as we had to have them tracked so we could see, hey, where are these agents being used? What are they being used for? More importantly, who's using them? From there, you start to build backwards and say, "Okay, how are we going to do that?" That's when we started.

Todd McKinnon
CEO and Co-Founder, Okta

This is all in context of an overall, really, I would call it massive run of transformation and success at Dell. We're talking about a lot of the internal efficiencies, but you guys are trying to get to genius. You're thinking about the external and customer facing. How does that fit into this equation for you?

Doug Schmitt
CIO and President, Dell Technologies

Well, I think if you saw where the journey was after the observability, and we knew we could start to track that, get it into the architectural plans. We actually started looking at the platforms and saying, "Okay, you're going to have to have agent to agent, so you could have identification inside of there." We also started then quickly identifying, you're going to have grandparent, parent, child relationship with those agents, everything that you've been showing up here this afternoon or this morning. From there, what we could see is that what we could do is stitch things together end to end internally, if that makes sense. These platforms could now start speaking together from those agents, have manager agents.

What that really does, that really opened up a whole new area of agentic, which is the key to all of this is really about what we're providing our customers, their end-to-end outcome and experience, that horizontal. Well, those agents gave us that ability to start delivering on that promise.

Todd McKinnon
CEO and Co-Founder, Okta

It's really transformational. Thousands and thousands and thousands, and I'm sure more people are joining the live stream right now, IT leaders, security leaders, general people, what's your advice? You've led this transformation. What impact do you have for the room?

Doug Schmitt
CIO and President, Dell Technologies

I don't know that I'm qualified to give advice because we're still in the learning. I think we're in the early stages of all of this, right? I'm drinking from a fire hose like everyone is. But what I do believe is that this is beyond just a technology change. This is a business model change. To that end, it has to be an all-in experience. What I mean by that is it can't just be IT led and driven. This has to be a company led and driven program. You have to rethink how you're doing things. Business models are changing. AI native is out there. It's going to be a competition, or it's going to assist you with your business model.

Then, I will tell you what I always tell my team, it's three things, speed, speed. This is moving at a faster pace every day.

Todd McKinnon
CEO and Co-Founder, Okta

Yeah. It is super exciting. Thank you for your collaboration and your partnership. It is great to work with the Dell team.

Doug Schmitt
CIO and President, Dell Technologies

As always, it is a great partnership.

Todd McKinnon
CEO and Co-Founder, Okta

We are excited to deliver for you, and we are also very appreciative to get the input and help us push forward on our roadmap and work together.

Doug Schmitt
CIO and President, Dell Technologies

Well, great, Todd. Always good to see you.[crosstalk].

Todd McKinnon
CEO and Co-Founder, Okta

Thank you so much, Doug.

Doug Schmitt
CIO and President, Dell Technologies

Thank you for inviting me to talk today.

Todd McKinnon
CEO and Co-Founder, Okta

Doug Schmitt. Absolutely. Doug Schmitt from Dell. Give it up for Doug. This is absolutely critical that we do this together. We need to build this secure agentic enterprise. Here's my ask of all of you. I want you to download the Blueprint. I want you to join the alliance. I want you to encourage your vendors to embrace the Blueprint and get that clarity in the market and avoid the confusion. I want you to encourage everyone to support Cross App Access. I want you to help us all on this journey for massive standardization. It's the only way we're going to get the visibility and control we need, and it's the only way we're going to be able to get the security and the innovation. It's how, together, we're going to get to genius, and we're going to do it.

The last thing, I want you to buy Okta for AI Agents. I'll just come out and say it. Talent hits the target no one else can hit, but genius hits the target no one else can see. Let's get that visibility and control. Let's change the world together. Let's get to genius. Thank you so much. Enjoy the rest of Oktane.