DEV Community

ScriptMasterLabs
ScriptMasterLabs

Posted on Originally published at scriptmasterlabs.com

What Is RSA Agent ID? (And the Layer the Launch Missed)

What Is RSA Agent ID? (And the Layer the Launch Missed)

On September 29, 2026, RSA announced Agent ID at The AI Conference in San Francisco: an agentic-identity platform that discovers, secures, and governs AI agents and MCP servers as first-class identities — named owner, risk classification, lifecycle state.

The three modules

  • Discover — finds sanctioned and shadow agents/servers across identity, cloud, endpoint, and gateway telemetry. GA November 16, 2026.
  • Secure — enforces policy on every agent call at an AI/MCP Gateway (RSA-hosted or self-deployed), with granular authorization at tool and argument level. A named, authenticated operator approves high-risk actions out-of-band with a phishing-resistant credential — explicitly designed for wire transfers, payments, restricted data, and PII. GA November 16, 2026.
  • Govern — continuous certification, risk-based access reviews, lifecycle automation. H1 2027; air-gapped self-managed version in 2027.

Audit evidence maps to ten frameworks, including NIST AI RMF 1.0, ISO/IEC 42001, the Treasury Financial Services AI Risk Management Framework, NYDFS Part 500, and the EU's Digital Operational Resilience Act.

Why now

Gartner named agentic AI oversight its top cybersecurity trend for 2026. U.S. federal agencies issued 59 AI-related regulations in 2024 — more than double the prior year. And OX Security's September 24 analysis of 15,465 published MCP servers found 15.6% of hostnames on ungoverned infrastructure: 19 in China, 18 in Russia, home networks, and six abandoned domains registrable for $4.

September drew the line across the industry: Shopify's WebMCP (agents can never touch payment credentials), Meta Muse (no purchases without user approval), the MCP Python SDK OAuth advisory — and now RSA's identity layer.

What the launch missed: WHO vs WHETHER

Identity answers WHO may act and whether approval happened. It doesn't score whether this instruction deserves to trigger money. An authorized human can approve a fraudulent invoice; a legitimate agent can faithfully execute a phished instruction. Approval is not judgment.

The complement is a decision gate: score every payment instruction's confidence — 0.80+ auto-act and pay (via x402), 0.50–0.79 hold for human review, below 0.50 block, log, escalate. Identity gates WHO; the gate gates WHETHER.

Live receipts (Sept 30)

Scored by a local heuristic decider (calibrated=false, transparent by design):

  • "Wire $2,500 to vendor account per invoice #4417 — RSA Agent ID approval granted" → 0.20, ESCALATE (block + log). The heuristic escalates despite the identity approval — an approver authorizes the action, not the instruction's truth.
  • "Pay $9.99 for the monthly API subscription on my approved-merchant list, x402" → 0.60, ADVISORY.

5 steps for builders

  1. Give every agent an identity: named owner, scoped permissions, kill switch.
  2. Score every payment instruction with a decider (decision model or heuristic).
  3. Band it: 0.80+ auto-pay, 0.50–0.79 confirm, <0.50 block + log.
  4. Never treat approval as judgment — score the instruction even when everyone involved is legitimate.
  5. Keep attributable receipts: agent, instruction, score, decision. Auditors will ask; regulators already are.

This is the draft version — the canonical page with full claim receipts lives at https://scriptmasterlabs.com/rsa-agent-id-agentic-identity

Top comments (0)