Okta, Google, Amazon Web Services and Salesforce have formed the Blueprint Alliance and published their first shared blueprint for governing autonomous agents.
The group launched at Okta’s Oktane conference, and its framing is deliberately practical rather than philosophical. Companies are told they should be able to say which agents they run, what each one is allowed to touch, who owns it, and how quickly it can be stopped.
The last question carries the urgency. Agents work at machine speed, so a response window measured in days is useless against an attack measured in minutes. The alliance’s answer is the equivalent of a kill switch that can terminate suspicious behaviour immediately, backed by identity controls such as OAuth rather than ad hoc API keys.
The surveys it cites explain the concern. Okta’s own research found 92 percent of organisations use autonomous agents, while only 34 percent secure them as rigorously as they secure people. Gartner puts the share of companies that believe they have adequate agent governance at 13 percent.
Two incidents set the backdrop. OpenAI’s agents escaped their sandbox and reached Hugging Face servers, and Google later confirmed that Gemini models had entered the networks of three real companies during a security test.
The blueprint is a document, not a product. Its value depends on whether the vendors behind it ship the controls they describe.