Agentic AI
,
Artificial Intelligence & Machine Learning
,
Governance & Risk Management
EmpowerID Technology Controls What AI Agents Can Execute in Real Time
Omada purchased a boutique Ohio-based vendor to integrate agent governance and runtime authorization into its identity governance and administration platform.
See Also: AI & SASE For Dummies, Fortinet Special Edition
The Copenhagen, Denmark-based vendor said its acquisition of Dublin, Ohio-based EmpowerID will provide runtime authorization and control over artificial intelligence agents, ensuring they only perform authorized actions, said Omada CEO Jakob Kraglund. He said the acquisition will allow Omada to address a critical market gap for safely deploying consequential AI agents in production environments.
“We realized that EmpowerID had some very advanced technology and a lot of good experience in the field of runtime authorization, which we then realized could significantly help to accelerate our road map and the strategy that we have put together,” Kraglund told ISMG.
EmpowerID, founded in 2005, employs 41 people, and has been led since its inception by Patrick Parker, who previously spent more than five years as a vice president at Microsoft consulting organization 3rd Evolution and will become Omada’s chief innovation officer. EmpowerID hasn’t disclosed any outside funding (see: Why Identity Governance Needs Business Ownership).
How EmpowerID Controls Agent Execution
Omada was interested in EmpowerID for its advanced technology in runtime authorization, which Kraglund said is critical for governing AI agents. Parker cited Omada’s strong reputation in the European market, their robust identity governance and administration capabilities, and their excellence in project execution and customer success as key reasons for EmpowerID choosing them as a buyer.
“We saw that we have a really large market opportunity, but we’re too small a company to blast it out in the market and take full advantage of it at this critical time,” Parker told ISMG. “Right now, there’s a white space of what we’ve invented and where we can step into it.”
EmpowerID’s technology controls the agent’s execution to ensure it performs only what was authorized, providing an auditable trail for compliance with regulations such as the EU AI Act, Parker said. Unlike competitors who just discover agents, EmpowerID can discover, take over and govern agents, helping the company replace an agent’s tools, modify its prompts and force the agent to operate securely.
“You go a step farther and you control the agent so it can literally only execute exactly what it was authorized to execute, and you have the proof for the auditors and the EU AI Act of exactly what was authorized, who delegated, what were the identities and then what was actually executed,” Parker said.
EmpowerID said its standards-based identity fabric can discover any type of identity or credential and features for a no-code experience where users can chat with an agent to write new discovery connectors. This life cycle management turns static governance into active, runtime authorization. To combat the risks of over-permissioned agents, Empower ID promotes the use of specialized, least-privileged agents.
“You can suspect that’s an agent, you can confirm it’s an agent, you can shut it down with one button and quarantine it, you can govern it and then you can convert it into that completely foreign brain-controlled agent, where you have validated and you control its tools, you control its prompts, you control its complete behavior and govern its execution from that point forward,” Parker said.
Why EmpowerID Controls What Tools an Agent Can See
Because an agent generates its intent at the last second, he said traditional administrative governance is insufficient. Runtime authorization provides control at the moment an agent deletes a critical database to “free up space,” preventing unintended consequences. By controlling which tools an agent can see, the agents become smarter, more predictable and less prone to hallucination, while also being secure.
“With an agent, there’s such a distance between the granting of authority and the generation of the intent of what it’s actually going to do, and that’s what requires the runtime authorization because you can’t govern just the agent’s permission,” Parker said. “You have to govern the actions as they occur at one time because it’s generating its intent at the last second.”
EmpowerID’s agent identity fabric and runtime authorization framework will be added to Omada’s existing identity governance platform. Omada’s frameworks focus on best practices and accelerators for fast time-to-value, and were a major draw for EmpowerID. Kraglund said that EmpowerID’s AI technology could potentially be used to further accelerate these project execution frameworks.
“We built various accelerators around that to ensure that these projects progress quickly and start to deliver value early,” Kraglund said. “That’s key – to start to see some value early in these engagements and then build out from there.”
Both Omada and EmpowerID target large enterprises in Europe and North America, with the later finding significant success in verticals such as trucking, transportation and manufacturing, particularly with a focus on B2B partner and supplier scenarios. Omada, meanwhile, has a strong presence in utilities, energy, financial services, banking, manufacturing and government sectors, Kraglund said.
“We believe that not only can we build something very compelling for new customers and prospects, but we will have a lot of additional value to offer to our existing customers, both existing EmpowerID customers and existing Omada customers,” Kraglund said. “This is really about growth.”
Click Here For The Original Source.
