Daily Tech Briefing
AI 科技速览

每天 5 分钟内学习 AI。获取最新的人工智能新闻,理解其重要性,并学习如何将其应用于您的工作。

AI 快讯
SiliconANGLE AI · 2026/8/4 13:00:56
Rubrik unveils Agent Identity to govern AI agents one tool call at a time

Rubrik unveils Agent Identity to govern AI agents one tool call at a time

AI 中文解读
Rubrik公司在黑帽大会上发布了Agent Identity新服务,核心亮点是给AI智能体装上“授权阀门”——不让AI凭默认权限乱跑,而是每一步操作都单独验证许可。通俗说,以前企业让AI干活,AI拿着员工的门禁卡,到处能进;现在改成了每开一扇门都要临时刷一次卡,用完就失效。Rubrik调查显示,86%的IT安全主管担心AI智能体一年内就会突破现有安全防线,但只有23%的人能看清自家企业里到底跑着哪些AI。这项服务就像给AI配了个“监督员”,实时盯着它们用了什么工具、调了哪些数据,发现越权立刻叫停,还支持“时光倒流”撤销危险动作。对普通人来说,以后企业用AI处理报销、客服、数据查询时,就不用担心某个AI发疯乱删文件或泄露隐私了。密码、权限这类传统防护本来就是为人类设计的,挡不住行动力爆表的AI,现在终于有了针对性的“缰绳”,企业也敢放手让AI干更多活了。
UPDATED 09:00 EDT / AUGUST 04 2026 SECURITY Rubrik unveils Agent Identity to govern AI agents one tool call at a time by Duncan Riley Rubrik Inc. today unveiled Rubrik Agent Identity, a service that governs what artificial intelligence agents are allowed to do by granting access one tool call at a time. The company announced the service at the Black Hat conference in Las Vegas. The service is an expansion of Rubrik Agent Cloud, the agent governance platform the company launched in October and made generally available for Anthropic PBC’s Claude in June. Agent Identity targets the credential layer beneath those deployments. Agents typically inherit the broad, standing permissions built for human employees, which means a single compromised or misbehaving agent can act destructively across software-as-a-service applications, databases and application programming interfaces before anyone notices. “Agents are no longer just synthesizing information, they are acting on the enterprise on behalf of employees, and the access models we built for humans and static credentials were never designed for autonomous actors,” said Dev Rishi, general manager of AI at Rubrik. “Agent Identity lets enterprises decide who can do what with agents and enforces it per tool call, at the moment of action, with scoped, short-lived access and no standing permissions.” Rubrik is pitching the problem as a “shadow workforce” of unmonitored machine identities. According to research from Rubrik Zero Labs, 86% of global information technology and security leaders expect AI agents to outpace their organization’s security guardrails within the next year, while only 23% say they have full visibility into the agents already running in their environments. Agent Identity works across three functions: monitoring every agent and Model Context Protocol server at runtime, controlling access per tool call using fine-tuned models and remediating risky actions through identity, audit logs and Rubrik’s Agent Rewind feature. Customers start by building an inventory of active agents, MCP servers, skills and plugins, then scope access to specific servers and tools by user and group using On-Behalf-Of federation, which extends existing identity structures rather than replacing them. Standing permissions are eliminated by minting scoped, short-lived tokens for each individual tool call. Enforcement happens at an MCP gateway. Every tool call clears three checkpoints before it executes: a behavioral analysis step in which Rubrik’s SAGE governance engine evaluates the intent, input parameters and likely operational impact of the request, a policy check at the infrastructure layer and an identity verification step that authenticates the agent session and issues the token scoped to that call. An unauthorized action, such as a write or modification outside an explicit policy scope, is blocked before execution. For actions that clear the gateway and still go wrong, Agent Rewind reverses them. Rubrik has described the feature as the only one of its kind on the market. The company’s own survey work found 88% of leaders are worried about meeting recovery time objectives as agentic threats scale. Agent Identity integrates with Okta Inc. and Microsoft Corp.’s Entra ID, extending enterprise identities to machine actors without standing up a separate directory. Rubrik did not disclose pricing or a general availability date. Rubrik, which now describes itself as “the Security and AI Operations Company,” moved into agent tooling in earnest with its acquisition of Predibase Inc. in a deal worth between $100 million and $500 million in June 2025. Rishi co-founded Predibase and served as its chief exe
分享
阅读原文