Technology-Led Response: The Blueprint Alliance

On September 22, at its Oktane conference in Las Vegas, Okta announced the Blueprint Alliance, a coalition of twelve technology companies with an open reference architecture for securing AI agents. AWS, CrowdStrike, Databricks, Docker, Google Cloud, Lovable, Proofpoint, Salesforce, ServiceNow, Wiz, and Zscaler are the other founding members. The release leans on Gartner's projection that the average Fortune 500 enterprise will be running more than 150,000 agents by 2028, and on its finding that only 13% of organizations think they have the right agent governance in place.

Before a risk leader lets any of those agents make a decision that reaches a customer or a ledger, four questions need answers. What is the business goal of the agent? What business process does it execute? What assets does it utilize? What policies govern it? Each question bridges each of the four risk objectives in the IRM Navigator Model: Performance, Resilience, Assurance, and Compliance. Answer all four and the agent is covered on every objective. Leave one open and two objectives are exposed. The question for the blueprint is whether it answers them.

The blueprint has four questions of its own, and Figure 1 shows the pillar the Alliance built under each: Where are my agents? What can they do? What are they doing? How do I respond? They are the right questions for a security team. Table 1 lines them up against the business questions. Three of the four pair off. Nothing on the blueprint's side asks what business goal an agent is designed to achieve.

Figure 1. The Blueprint Alliance reference architecture: four security questions, each with the pillar built to answer it. Source: Blueprint Alliance, Governing Agentic Execution, September 2026.

The business asks The blueprint asks
1. What is the business goal of the agent? No counterpart
2. What business process does it execute? What are they doing? How do I respond?
3. What assets does it utilize? Where are my agents?
4. What policies govern it? What can they do?

Table 1. The four business questions a risk leader asks about any AI agent, beside the Blueprint Alliance's four security questions. Source: Wheelhouse Advisors; Blueprint Alliance.

Twelve Vendors Agreed on the Security Core, and Only the Security Core

Daniel Bernard, CrowdStrike's chief business officer, said in the release that no single technology or vendor can secure the agentic era alone. That line carries more weight than the usual coalition boilerplate, because of who signed under it. Salesforce sells MuleSoft Agent Fabric as the control plane for agents from any vendor, underneath the AIforce interface it unveiled at Dreamforce in September. ServiceNow sells AI Control Tower. Both companies have claimed the job of governing everyone else's agents, and both have now agreed to a shared architecture, which is an admission that an enterprise running agents across Salesforce, ServiceNow, AWS, and Google Cloud has no single place to stand and govern them from. What twelve vendors could agree on is the security core they have in common. The most useful line in it for a risk function is the requirement that every registered agent have a named human owner.

It is also Okta's blueprint. The document expands one Okta published in March, and Okta used the same keynote to add runtime enforcement and a wider kill switch to its own Okta for AI Agents product. Microsoft is not a member, though its Entra competes with Okta in identity and its Agent 365 sat among the vendor towers in the Journal's September 18 article. No frontier model provider is a member either. The cross-vendor integrations that would let a threat detected in one runtime trigger action in another are still being built and tested, by the members' own account. Until they ship, the blueprint is a checklist its members agree on rather than a standard anyone can test against.

The Blueprint Fully Answers Only One of the Four

The four business questions are the first four objects of the independent risk record the Journal described on September 18: goals, processes, assets, policies, then the risks and controls attached to them. Measured that way, the blueprint answers one in full, two in part, and never asks the first. That is what happens when a security coalition takes on a risk problem.

Security professionals have the phrase backwards when they call their work security and risk. Risk comes first. Security is one kind of control, applied to particular technology risks once the enterprise knows which risks matter, and for most of the profession's history the risk in that phrase has meant compliance under a friendlier name. That was a tolerable shortcut when technology was organized by system. An agent crosses systems and acts, so its losses land in Performance and Resilience, where a compliance program has never kept the books. Integrated Risk Management was defined to put security inside the risk program rather than the other way around. A blueprint written for CISOs by the vendors who sell to them starts from the controls those vendors know how to build. Table 2 shows the two objectives each question bridges and how far the blueprint gets.

Business question Risk objectives bridged How the blueprint answers it
1. Business goal Assurance and Performance Not answered. Purpose is enforced as a boundary on the task, never as a standard for the result.
2. Business process Performance and Resilience Partial. Watches execution, maps the systems the process runs through, and contains and restores the agent; never records the process, its criticality, or its recovery.
3. Assets Resilience and Compliance Answered. How the agent came into being, what it is built from, where it pulls from, and its security posture.
4. Policies Compliance and Assurance Partial. Access policy is in the architecture; business thresholds and risk appetite are left to the system integrators.

Table 2. The two IRM Navigator Model risk objectives each business question bridges, and how far the Blueprint Alliance architecture goes toward answering it. Source: Wheelhouse Advisors.

1. What is the business goal of the agent? The goal bridges Assurance and Performance. Without it, nobody can measure what the agent delivered or confirm that the work was accurate and complete, because there is nothing to check against. The blueprint does know that agents have purpose. Its agent directory records intent, its access policies inspect an agent's plan before granting a privilege, and its runtime enforcement watches for drift outside the delegated task. All three ask the same question, whether the agent stayed inside its purpose. None asks whether the purpose was achieved. When the blueprint asks, on the board's behalf, whether autonomous decisions can be explained after the fact, its answer is a log of why each action was allowed, modified, or blocked. The log explains the control decision and says nothing about whether the business decision was right. An agent with a verified identity, task-scoped access, and a clean runtime log can still issue the unapproved credit that opened the Journal's September 24 article, with every control in the architecture reporting that nothing went wrong.

2. What business process does it execute? The process bridges Performance and Resilience. It is how the goal gets delivered, and it is what the enterprise has to keep running, or restore, when an agent fails. The blueprint's third and fourth questions cover that ground. What are they doing? watches the agent execute, pauses high-risk actions for sign-off, and maps every downstream system the agent acts on, which is where the process runs. How do I respond? contains the agent and brings it back. All of that acts on the agent. The blueprint knows every system the process runs through and still cannot name the process. Its risk tier scores the agent on scope, autonomy, and blast radius, not on whether the process is critical, and the only performance it measures is token usage and latency. Stop an agent halfway through a credit approval and recovery restores the agent. Nothing in the architecture restores the approval.

3. What assets does it utilize? Assets bridge Resilience and Compliance. What an agent is built from decides how far a failure spreads and where the data protection obligations land. Where are my agents? is the blueprint's largest pillar, and read closely it is an inventory of what each agent is made of and where it came from: the platform and framework it was built on, the model driving it, the skills and MCP registries it pulls from, and the environments it lives in, shadow agents included. Posture management then checks those components for vulnerabilities, misconfigurations, and provenance. The assets question is answered for the agent itself, and the answer matches how the IRM Navigator Model treats an agent: the agent belongs to the process it acts in, and what it is built from are the assets. A risk function that adopted only this pillar would close a real inventory gap.

4. What policies govern it? Policies bridge Compliance and Assurance. They are the rules an agent has to follow and the standard its work gets checked against, up to the risk appetite the board approved. What can they do? handles the access half well: task-scoped grants, separation of duties, automated access reviews, and hard guardrails that override the agent's own reasoning. It even provides for a contingent review when an action crosses a financial threshold, and uses a purchase above $1,000 as the example. Who sets that threshold, and how it relates to the enterprise's actual risk appetite, is not in the architecture. The blueprint leaves it to the global system integrators it brings in to run the operating model, a handoff taken up below. The credit policy and the appetite statement sit outside the four pillars.

Figure 2, from the research note, places the Alliance's members where the blueprint's strengths are. Five of the twelve sell security, and sit in the Compliance region. Five more sell the cloud, data, and developer infrastructure agents are built on, which has no seat on the map at all. The two workflow platforms, Salesforce and ServiceNow, sit in the Resilience region, and the AI agent control planes they built sit in the pocket beside the center, one objective short of it. Every member with a seat on the map sits on the TRM side of it. The goal sits in the ERM overlap at the top, where none of them operates, and the center is empty. That is the split the September 24 article drew between visibility and understanding, seen from the vendor side. Security teams are built for visibility: find every agent, every entitlement, every threat. Understanding is what tells them which of those matter to the business, and without it every vulnerability gets the same attention, which is why security backlogs never shrink. A security architecture for agents answers where and what. It does not ask why.

Figure 2. Four solution groups, one empty center: the market around Autonomous IRM. Security, privacy, and compliance tools sit in the Compliance region and business workflow platforms in the Resilience region; the four business questions sit on the four domain overlaps: the business goal with ERM, the business process with ORM, the assets with TRM, and the policies with GRC. Source: Wheelhouse Advisors, Why the Race to Autonomous IRM Has No Front-Runner, The RTJ Bridge, September 24, 2026 (Figure 1, revised).

The Business Questions Were Handed to the System Integrators

None of this is an oversight. The four pillars stop at the agent's execution boundary by design, and the work on the business side of that boundary goes to Section 4 of the document, Operationalizing with Global System Integrators. The system integrators supply the risk tiering. They define the dollar and regulatory thresholds that trigger human approval, tuned, in the blueprint's words, to the client's actual risk appetite. They package the evidence for examiners. The architecture secures the agent, and deciding what the agent is for, what it may not do to the business, and what its failure costs is a services task by the blueprint's own account. That is the technology-led response to Autonomous IRM in one document: agree on the security plumbing, compete on the products above it, and send the business context to the consultants. Whether those firms are the right party to answer those questions, and what they would need to answer them well, is a separate question.

The strongest objection to this reading is that cross-vendor monitoring supplies the independence a single-platform control plane lacks. On September 18 the Journal asked why humans are still doing the checking when the vendor that builds the agents is also the vendor that checks them, and named ServiceNow's AI Control Tower among four towers grading their own homework. Four days later ServiceNow signed an architecture under which CrowdStrike or Zscaler can watch its agents. That is the first structural answer to the question, and for security it is a real one. What crosses the vendor boundary, though, is a threat signal. The business context does not cross with it. The record the September 18 article asked for holds the enterprise's goals, processes, and policies, including the risk appetite the board approved. The Alliance's directory holds the agents. Twelve vendors pooling what they can see of an agent still cannot tell whether its work was accurate and complete, or whether the result stayed inside the appetite the board set, because none of them holds the standard to check it against. Independence across platforms is a management job, and no control plane, shared or not, is built to do it.

So does the blueprint answer the business questions? Assets, yes. Process and policy, half, with the other half sent to services. The goal, no. Risk leaders evaluating agent platforms this quarter should keep the blueprint as the technical floor and open every evaluation with the four business questions. That is the procurement change the September 24 article called for, and the twelve vendors who wrote the blueprint are the first it applies to. The technology-led response has not produced a front-runner, meaning a solution that can answer for every agent a company runs, on every platform, against the company's own standard. Wheelhouse Advisors maps the market around that open center in its September 24 RTJ Bridge research note, Why the Race to Autonomous IRM Has No Front-Runner, which places the four solution groups in Figure 2 inside Autonomous IRM by the objective each one lacks, and names what belongs in the center in its October 1 note, Autonomous IRM Is the Management Plane, Not Another Control Plane. The whitepaper calls its architecture a unified agentic control plane, and that is the right name for it. The Blueprint Alliance has published the most complete shared control plane to date. The October 1 note explains why that is a different thing from the management plane: a control plane produces the evidence the management plane reads, and reading that evidence against the company's own standard is a job none of the twelve has taken on. Both analyses are available exclusively on The RTJ Bridge at wheelhouseadvisors.com/rtj-bridge.

References

Okta, Inc. “Industry Leaders Form the Blueprint Alliance to Advance a Shared Architecture for Securing AI Agents.” September 22, 2026. https://www.okta.com/newsroom/press-releases/industry-leaders-form-the-blueprint-alliance/

Blueprint Alliance. “Governing Agentic Execution: An Architectural Blueprint for the Secure Agentic Enterprise.” Whitepaper, September 2026. https://www.okta.com/content/dam/resources/en_us/whitepapers/Blueprint%20Alliance%20Whitepaper-Sep18-Final.pdf

Gartner. “Gartner Identifies Six Steps to Manage Artificial Intelligence Agent Sprawl.” April 28, 2026. https://www.gartner.com/en/newsroom/press-releases/2026-04-28-gartner-identifies-six-steps-to-manage-artificial-intelligence-agent-sprawl

SiliconANGLE. “Okta Adds AI Agent Runtime Gateway, Forms Blueprint Alliance with AWS and CrowdStrike.” September 22, 2026. https://siliconangle.com/2026/09/22/okta-adds-ai-agent-runtime-gateway-forms-blueprint-alliance-with-aws-and-crowdstrike/

Wheelhouse Advisors. Ori Wellington. “If Vendors Are Building Their Own AI Guardrails, Why Are Humans Still Doing the Checking?” The RiskTech Journal, September 18, 2026. https://www.wheelhouseadvisors.com/risktech-journal/if-vendors-are-building-their-own-ai-guardrails-why-are-humans-still-doing-the-checking

Wheelhouse Advisors. John A. Wheeler. “Stop Treating Embedded AI Agents Like Shadow AI.” The RiskTech Journal, September 24, 2026. https://www.wheelhouseadvisors.com/risktech-journal/stop-treating-embedded-ai-agents-like-shadow-ai

Wheelhouse Advisors. John A. Wheeler. “Why the Race to Autonomous IRM Has No Front-Runner.” The RTJ Bridge, September 24, 2026. https://www.wheelhouseadvisors.com/rtj-bridge/why-the-race-to-autonomous-irm-has-no-front-runner

Wheelhouse Advisors. John A. Wheeler. “Autonomous IRM Is the Management Plane, Not Another Control Plane.” The RTJ Bridge, October 1, 2026. https://www.wheelhouseadvisors.com/rtj-bridge/autonomous-irm-is-the-management-plane-not-another-control-plane

John A. Wheeler

John A. Wheeler is the founder and CEO of Wheelhouse Advisors, a global risk management strategy and technology advisory firm. With over three decades of experience spanning executive management, finance, risk management, audit, and IT, John is a world-renowned expert in integrated risk management technology, executive leadership, and corporate governance.

https://www.linkedin.com/in/johnawheeler/
Next
Next

IRM Market Brief: September 22 to 29, 2026