The number is almost too clean to be real. 90 non-human identities for every single human employee. That's not a projection from a sci-fi novel. That's the current state of enterprise infrastructure according to CSA surveys. And 70% of those machine identities have been granted higher access privileges than the humans who ostensibly manage them. We are not building a digital workforce. We have already built one. We just forgot to issue them ID badges. This is the vacuum Okta just stepped into with Agent SSO. And it's a bigger move than a simple product launch. It's a declaration of war over who gets to define the identity layer for the AI age. 2017 called. It wants its lessons back. But this time, the speculative mania isn't over token prices. It's over the very fabric of enterprise trust.
For the uninitiated, the Okta announcement centers on a new extension protocol dubbed XAA. It's not a revolution in cryptography. It's a combination play. They've taken the OAuth 2.0 Token Exchange framework (RFC 8693) and JWT-based client authentication (RFC 7523), which have been gathering dust in the standards library, and applied them with brutal efficiency to the AI agent workload scenario. The genius isn't in the invention. It's in the application. The real headline, the part that should scare every incumbent, is that Anthropic's Model Context Protocol (MCP)—the de facto standard for AI tool interoperability—has officially adopted XAA as part of its Enterprise-Managed Authorization extension. This is the load-bearing wall. It moves identity from the application layer, where it can be bypassed, down into the tool-calling layer where it becomes structural. The protocol isn't just about authenticating a chatbot. It's about defining the very authorization semantics for an agent acting on behalf of a principal. That's architectural. That's permanent.
Let's strip the marketing off the technical chassis. Okta is calling this a free, built-in feature of their Core SSO. Don't be naive. This is the classic Open Core maneuver, executed with the precision of a corporate raid. They are giving away the protocol to penetrate the market and establish the standard. The revenue play is the premium tier: the governance of 'non-XAA' agents, the shadow AI discovery, the access certification, and the manual owner assignment. They are not selling identity. They are selling governance over the chaos they've just exposed. The data supports this ruthlessly. 76% of organizations that granted excessive privileges suffered an identity-related security incident. 51% have no clear ownership model for their AI agents. Only 28% can trace an agent's action back to a human. The market isn't just ready for this. The market is bleeding for it.
My own experience in the 2017 ICO mania taught me to see patterns in the wreckage. I read over 500 whitepapers that year. 85% of them had no viable roadmap. They were PowerPoints with a token ticker. The current AI agent landscape feels eerily familiar. Every startup is bolting 'AI' onto their product with a layer of vapor. But this? This is different. This is infrastructure. Okta has 18,000 enterprise customers. They have the Universal Directory, a complete graph of organizational identity. By integrating agents into that existing flow, they aren't creating a new category. They are extending an existing monopoly. The cost of switching for a customer just went up exponentially. If your entire agent access policy is bound to Okta's directory, migrating to Microsoft Entra ID becomes a nightmare of policy re-creation. This is the classic 'standard lock-in' strategy. The product is the trap. The standard is the cage.
Now, let's be the contrarian in the room. The narrative says this is about security. The subtext is about data. When Okta manages your AI agents' identities, they see the call patterns. They see the tool graph. They see which agents talk to which APIs, at what frequency, and for what duration. They claim they don't access content. But the metadata—the 'AI call relationship graph'—is the most valuable dataset in enterprise technology. This graph is the foundation for the next generation of security analytics, anomaly detection, and risk management. Okta isn't just building a moat. They're building a sovereign database of machine behavior. And that data will become the basis for future premium SaaS modules. The free product is the foot in the door. The data is the furniture they plan to sell you later.
The competitive landscape is a two-horse race with a dark horse on the horizon. Okta is betting on neutrality—an open standard that works across any cloud, any SaaS, any model. Microsoft Entra Agent ID is betting on ecosystem gravity—the sheer inertia of Azure, GitHub, and Copilot. For a company deep in the Microsoft stack, Entra is the path of least resistance. For a company terrified of platform lock-in, Okta is the escape hatch. The alliance with Anthropic is the tell. Anthropic is using Okta as a shield against OpenAI's deep integration with Azure. This isn't a product war. It's a proxy war for AI model market share, fought on the battlefield of enterprise identity.
We must also address the elephant in the room: centralization risk. When you concentrate the identity of thousands of autonomous agents into a single vendor, you create a high-value target. If Okta gets breached—and they were compromised in 2022—an attacker doesn't just steal human credentials. They could potentially hijack the entire agent workforce. It's a single point of failure that could bring down the house of cards. The security product has become the attack surface. The risk isn't just technical. It's existential. And the standards vacuum doesn't help. NIST is only at the 'initiative' stage. CSA just released a v1 framework. This is the Wild West, and Okta is the sheriff, the judge, and the jury. That's a comfortable position until the posse turns on you.
Structure beats speculation every time. Okta's move is structurally sound. It addresses a verified, quantified crisis in the market. It leverages an existing customer base and directory infrastructure. It creates a standard that lowers the barrier to entry for enterprise AI adoption by solving the governance problem. But the market is not a meritocracy. It's a battlefield. The question isn't whether XAA is a good standard. It's whether it can survive contact with the Microsoft machine. The question isn't whether Okta can secure agents. It's whether a single vendor should hold the keys to the digital kingdom. As I've written for over two decades, narrative is the engine of adoption, but utility is the fuel. Here, the utility is undeniable. The narrative, however, is still being written.
So, what's the takeaway? We are witnessing the 'BlackBerry moment' of enterprise AI. BlackBerry defined the standard for mobile device management, and they won the enterprise. Then the iPhone came along and redefined the platform, leaving BlackBerry's standard irrelevant. Okta is BlackBerry. Microsoft is Apple. The XAA standard may be the BES of the AI era—dominant for a moment, but vulnerable to a platform-level shift. The next narrative isn't about which standard wins. It's about whether the standard itself will be rendered obsolete by an operating system that makes identity a default feature, not a separate contract. The question I'm asking myself isn't 'Is Okta a good investment?' It's 'Is Okta the next Nokia, or the next BlackBerry?' Both were leaders. Only one adapted. The next 18 months will tell us which one Okta is. The agents are coming. The only question is who gets to sign their paychecks.