The Shadow AI Problem

AI agents are already running in your environment without Okta oversight. This course introduces the governance framework you'll use to bring shadow AI under control.

rate limit

Code not recognized.

About this course

AI agents are already running in your environment, and most arrived without an OAuth consent screen you approved or an owner you assigned. This course introduces the shadow AI problem: agents embedded in SaaS apps, built on agent-builder platforms, or written from scratch in raw code, all reaching sensitive data outside Okta's governance. You'll learn why unmanaged agents create audit blindness and over-privileged access, and how treating every agent as a Workload Principal, an identity with an owner, credentials, and a lifecycle, closes that gap. The course introduces the five governance questions you'll answer for any agent action, and previews the four-phase lifecycle, detect, register, authorize, and govern, that the rest of this learning path walks you through.

By the end of this course, you'll be able to:

  1. Identify the three types of AI agents in your environment and explain why each should be managed as a Workload Principal under the same lifecycle rules as human users.
  2. Detect shadow AI by filtering the Okta System Log and reviewing the Applications list.
  3. Apply the five governance questions to any agent action: who owns it, which agent acted, when, under what policy, and how to disable it safely.
  4. Move a shadow agent through the four phases of the governance lifecycle: detect (ISPM + SAM), register (Universal Directory), authorize (Managed Connections), and govern (Access Requests, Certifications, System Log).

About this course

AI agents are already running in your environment, and most arrived without an OAuth consent screen you approved or an owner you assigned. This course introduces the shadow AI problem: agents embedded in SaaS apps, built on agent-builder platforms, or written from scratch in raw code, all reaching sensitive data outside Okta's governance. You'll learn why unmanaged agents create audit blindness and over-privileged access, and how treating every agent as a Workload Principal, an identity with an owner, credentials, and a lifecycle, closes that gap. The course introduces the five governance questions you'll answer for any agent action, and previews the four-phase lifecycle, detect, register, authorize, and govern, that the rest of this learning path walks you through.

By the end of this course, you'll be able to:

  1. Identify the three types of AI agents in your environment and explain why each should be managed as a Workload Principal under the same lifecycle rules as human users.
  2. Detect shadow AI by filtering the Okta System Log and reviewing the Applications list.
  3. Apply the five governance questions to any agent action: who owns it, which agent acted, when, under what policy, and how to disable it safely.
  4. Move a shadow agent through the four phases of the governance lifecycle: detect (ISPM + SAM), register (Universal Directory), authorize (Managed Connections), and govern (Access Requests, Certifications, System Log).