Identity security platform Delinea has introduced runtime authorisation capabilities for AI agents. The platform is the first to enforce security policies on specific actions within a session before they execute, rather than simply monitoring the initial connection. This approach prevents autonomous agents from performing unauthorised tasks even when using valid credentials, offering real-time protection across databases, Kubernetes clusters, and cloud consoles.
AI agents now operate autonomously across production databases, SSH hosts, Kubernetes clusters, cloud consoles, and MCP servers. Most identity security approaches fall into two categories: those that verify a connection when a session opens and audit or revoke access after the fact, and those that can only see traffic routed through their own server, leaving direct connections outside their view. Neither goes beyond credential hiding to enforce policy on what happens inside the session, action by action, before it executes. Delinea does.
“The security industry spent years solving credential theft, but AI agents have introduced a new problem: authorized access doing unauthorized things,” said Art Gilliland, CEO at Delinea. “You can have perfect credential hygiene and still have an agent tear through your production environment in milliseconds. Recording what happened or revoking access after the fact doesn’t stop that enforcing policy on the action as it runs does. The perimeter has moved to inside the session, and no one has figured out how to address that until now.”
Runtime authorization for AI agents delivers:
Consistent policy and a complete audit record, regardless of how agents connect. Agents reach databases, SSH hosts, Kubernetes clusters, and cloud consoles directly, not only through an MCP server. The Delinea Platform authorizes and records each of those connections through a single control point, across every protocol agents use. Security teams get the same visibility and enforcement regardless of how the agent was deployed or which systems it reached.
No standing credential for an attacker to exploit. The agent never holds a credential. The Delinea Platform injects it just-in-time at the moment of access, scoped to the task rather than inherited from the person who deployed it, and revokes it automatically when the task completes. Because the credential is never exposed to the agent, there’s no lingering exposure between sessions.
Policy enforced on every action, not just when the session opens. A single AI session can carry dozens of tool calls, each with a different risk profile. The Delinea Platform evaluates and enforces policy on each tool call individually allowing it, blocking it, or pulling in a human before it executes. When an agent misbehaves, the blast radius stays contained.
Policy built specifically for agents, not retrofitted from humans. The Delinea Platform identifies whether a connection is agent-driven or human-driven before granting access, applying agent-specific policy at the moment of connection so the right controls are in place before the first action runs.
A complete, defensible record of every action, tied to a named identity. Every tool call, database query, and SSH command is recorded and accountable to a specific identity. When something goes wrong, teams have the control to investigate, respond, and stand behind every access decision that was made.
The same enterprise-grade platform governing privileged access across thousands of enterprise environments now governs AI agents connecting to those same systems. No new infrastructure is required, and organizations can now apply Zero Standing Privilege to AI agents where risk demands it.





