Control Access and Audit Agent Activity
Configure scopes and resource connections for AI agent workload identities, enable user-context token exchange with ID-JAG, and audit agent activity in the Okta System Log.
Registering an AI agent in Okta establishes its identity, but registration alone does not restrict what that identity can access. This course covers the authorization layer: configuring OAuth scopes and access policies, connecting agents to specific resources through resource connections, and limiting each agent to the minimum permissions it needs. You'll also configure Cross-app access (XAA) to enable agents to act on behalf of authenticated users, with user identity preserved through Okta's ID-JAG token exchange flow. Once agents are scoped and connected, the Okta System Log shows two distinct event types (M2M token grants and XAA token exchange events) that together answer who authorized an agent's access and why it was permitted. The course closes with procedures for responding to an access incident, including deactivating resource connections, deactivating agents, and revoking active tokens.
By the end of this course, you'll be able to:
- Configure OAuth scopes and access policies on an authorization server to grant a workload principal the minimum access it needs.
- Connect a workload principal to an authorization server by adding a resource connection to the agent's profile.
- Configure delegations and XAA to enable an AI agent to act on behalf of an authenticated user using ID-JAG token exchange.
- Verify that an agent's access is restricted to its granted scopes by testing permitted and denied requests.
- Interpret M2M token grant and XAA token exchange events in the Okta System Log to determine who authorized an agent's access and why it was permitted.
- Deactivate a resource connection, deactivate an agent, and revoke active tokens to respond to an access incident.