Delinea has released new runtime authorisation for AI agents, enforcing policy on what an agent does inside a session before it acts, not just how it connects.
The identity security vendor said the capability lets organisations evaluate, allow, block or escalate agent actions in realtime. It works across databases, cloud environments, Kubernetes clusters, SSH hosts and Model Context Protocol-connected systems.
The launch targets a gap opening up as automated systems gain access to business-critical resources. AI agents now operate autonomously across production databases, SSH hosts, Kubernetes clusters, cloud consoles and MCP servers. Delinea said most identity security approaches either verify a connection when a session opens, then audit or revoke access after the fact, or can only see traffic routed through their own server.
Neither approach, the company argued, enforces policy on what happens inside the session, action by action, before it executes. A single AI session can carry dozens of tool calls, each with a different risk profile.
Agents never hold standing credentials. Delinea injects a credential just-in-time at the moment of access, scoped to the task rather than inherited from the person who deployed the agent, and revokes it automatically when the task completes. Because the credential is never exposed to the agent, the company said, there is no lingering exposure between sessions for an attacker to exploit.
The platform evaluates and enforces policy on each tool call individually, allowing it, blocking it, or pulling in a human before it executes. When an agent misbehaves, Delinea said, the blast radius stays contained. The platform also identifies whether a connection is agent-driven or human-driven before granting access, applying agent-specific policy so the right controls are in place before the first action runs.
Delinea said it authorises and records each connection through a single control point, across every protocol agents use, giving security teams the same visibility and a complete, defensible audit record regardless of how an agent was deployed.
"The security industry spent years solving credential theft, but AI agents have introduced a new problem: authorised access doing unauthorised things," said Art Gilliland, chief executive of Delinea.
Gilliland said an organisation could have perfect credential hygiene and still have an agent tear through a production environment in milliseconds. Recording what happened or revoking access after the fact does not stop that, he said, but enforcing policy on the action as it runs does. The announcement was made in Sydney, with Delinea offering local APAC commentary.