AI Security
CrowdStrike Gives AI Agents Identities; Runtime Proof Comes Next
CrowdStrike introduced Agentic IdP at Fal.Con on September 2. The company says it can register discovered agents with cryptographically verifiable identities, enrich risk context, broker short-lived least-privilege access, and maintain attribution to a human or workload. The blog also covers unreleased features, so availability and enforcement effectiveness must be verified per capability.
Citation-ready: CrowdStrike introduced Agentic IdP on September 2, 2026, to register AI agents, broker short-lived access, add risk context, and link agent actions to the humans or workloads they represent.

What happened and why it matters
No. Registration creates an identity anchor, while authorization still depends on principal and task context, token scope and lifetime, delegation chains, policy evaluation, revocation, downstream enforcement, logs, and tested failure behavior.
Official CrowdStrike launch and product account
Primary reference: CrowdStrike: Agentic Identity Provider announcement. Kaleido Field checked the event date and the article's attributed facts against this source.
| Source date | September 2, 2026 |
|---|---|
| Checked by Kaleido Field | September 3, 2026, 09:20 CST |
| Source function | current agent-security analysis separating discovery, registration, cryptographic identity, principal linkage, short-lived access, real-time risk context, action attribution, current availability, future features, and enforcement outcomes |
The principal cannot disappear behind the agent
An agent may act for a user, service, workflow, or another agent. A durable identity record should show who requested the task, which agent instance and version ran, the declared purpose, delegated chain, resource, action, scope, and expiration.
If a downstream system sees only a shared service account, the strongest policy and attribution fields can be lost at the enforcement point.
Revocation has to reach the resource
A policy engine can decide that risk changed, but safety depends on how quickly active tokens, sessions, browser state, database connections, and delegated agents stop working. Partial failure and network delay belong in the test plan.
Teams should exercise stale credentials, compromised principals, nested delegation, scope escalation, policy conflicts, offline resources, revocation latency, replay, log gaps, and recovery before relying on continuous-access language.
Evidence boundary
Official launch description: named identity, registration, context, access, attribution, and Continuous Identity roles. CrowdStrike product claims: cryptographic verifiability, real-time contextual enforcement, and immediate revocation. Availability boundary: the company states that the blog includes unreleased services or features still in development and subject to change. Not established: capability-by-capability general availability, supported agent and resource coverage, policy latency, false revocations, bypass resistance, delegation integrity, log completeness, independent security testing, or production incident outcomes.
FAQ
What does Agentic IdP register?
CrowdStrike says it registers discovered AI agents in a directory and links them to owners and users.
What access model is described?
Short-lived, tightly scoped access combined with continuous risk-aware authorization.
Is every feature generally available?
The blog explicitly says it discusses unreleased services or features that remain in development.