The platform evaluates individual tool calls before execution, helping organisations control how AI agents interact with databases, cloud consoles and critical infrastructure.
Delinea has introduced runtime authorisation capabilities designed to govern the actions performed by AI agents during active sessions.
Available through the Delinea Platform, the capability evaluates each action before execution, allowing organisations to approve or block a request or require human intervention. Delinea said this approach extends identity security beyond verifying how an AI agent connects to a system.
AI agents increasingly operate autonomously across production databases, Secure Shell (SSH) hosts, Kubernetes clusters, cloud consoles and Model Context Protocol (MCP) servers. Conventional identity security controls frequently authenticate access when a session begins, while monitoring or revoking it after an incident occurs.
Delinea’s runtime authorisation model applies policy to individual tool calls within a session. Each database query, SSH command or tool request can be evaluated according to its risk profile before it is allowed to proceed.
“The security industry spent years solving credential theft, but AI agents have introduced a new problem: authorised access doing unauthorised things,” said Art Gilliland, CEO at Delinea.
“You can have perfect credential hygiene and still have an agent tear through your production environment in milliseconds. Recording what happened or revoking access after the fact doesn’t stop that. Enforcing policy on the action as it runs does. The perimeter has moved to inside the session, and no one has figured out how to address that until now.”
The platform provides a central control point for agent connections across databases, SSH hosts, Kubernetes clusters and cloud consoles, regardless of whether the agent connects directly or through an MCP server. Delinea said this enables organisations to maintain consistent policy enforcement and audit records across the protocols used by AI agents.
Credentials are injected just in time when access is required and scoped to the specific task rather than inherited from the person who deployed the agent. The credential remains hidden from the agent and is revoked automatically when the task is completed, reducing the risks associated with standing privileges and exposed credentials.
The platform also distinguishes between human-driven and agent-driven connections before granting access. Agent-specific policies can therefore be applied before the first action within a session is performed.
Every tool call, database query and SSH command is recorded and linked to a named identity. This provides security teams with an audit trail to support investigations, incident response and access-governance requirements.
Delinea said organisations can apply Zero Standing Privilege principles to AI agents through the existing platform without deploying additional infrastructure.
Runtime authorisation for AI agents is now available through the Delinea Platform.
Source: Tahawul Tech

