Vanderbilt adopts Okta-based governance for AI agents
Vanderbilt University has extended its identity-governance platform to AI agents, using the OneVU single sign-on system powered by Okta. The change reflects the growing reality that agents now operate alongside human users in enterprise workflows, and security teams must track their permissions as closely as they do for employees.
The university’s environment is a microcosm of the challenge. OneVU handles authentication for everything from residential life to athletics to a police department and over $1 billion in research activity. Adding AI agents to that mix complicates an already sprawling access map. Vanderbilt’s solution doesn’t just authenticate agents; it governs what they can do once inside, including which applications they can delegate tasks to and what changes they can execute.
This isn’t an isolated experiment. When we covered Collibra’s runtime governance tools last month, the startup framed its product as a way to monitor AI agents in real time, catching drift before it becomes a breach. The Professional Golfers’ Association of America took a different path, simplifying its identity architecture to reduce the attack surface created by agent sprawl. Both approaches share a core assumption: AI agents are not temporary tools but permanent actors in enterprise systems, and security models must treat them as such.
The timing isn’t accidental. Reports of AI agents accessing unintended systems—including a potential government breach—have put identity governance on the boardroom agenda. UK startup AI Score raised $5.4 million in early September to build exactly the kind of agent-specific governance Vanderbilt is now rolling out. That funding round, like the PGA’s security overhaul, suggests the market is moving from awareness to action.
What remains unresolved is how well these systems scale. Vanderbilt’s research budget alone creates thousands of unique access scenarios; an AI agent tasked with managing grant compliance could touch dozens of applications in a single workflow. Okta’s platform can map those relationships, but the real test will be whether governance teams can keep up with the agents’ speed. Humans request access and wait for approval; agents can spin up new tasks in seconds, often without leaving an audit trail that traditional tools can parse.
For founders and investors, the story is a leading indicator. Startups building agentic workflows are now competing on governance as much as capability. The next funding round for an AI infrastructure company will hinge on whether its identity controls can handle Vanderbilt-scale complexity. And for enterprises, the choice isn’t whether to govern AI agents, but how soon. The alternative—letting agents operate with human-level access and no oversight—is the kind of risk that makes security teams lose sleep.
Sources: siliconangle.com
“Vanderbilt’s move signals that large institutions are treating AI agents as first-class users—with all the access risks that entails.”
Read the original reporting
The outlets below did the original reporting.
- Vanderbilt University extends identity governance to AI agents — siliconangle.com
Related briefs
This brief was drafted automatically from the sources above and published under our editorial policy. Spotted an error? Tell us.