RSA has unveiled Agent ID, a platform intended to discover, secure and govern AI agents across cloud, on-premises and air-gapped environments. The product treats agents as identities that need named owners, risk tiers, lifecycle states and enforceable permissions rather than as ordinary software processes.
Its three modules cover discovery, action control and governance. RSA says Agent ID Discover can find sanctioned and unsanctioned agents and Model Context Protocol servers; Secure checks calls through an AI/MCP gateway; and Govern applies certification, access reviews and lifecycle controls. Customers can designate actions such as wire transfers or access to sensitive records as requiring authenticated human approval.
That is particularly relevant to financial institutions because agent permissions are becoming a new form of privileged access. Traditional identity and access management was built around people, applications and service accounts. An autonomous agent can combine credentials, tools and delegated authority in ways that make ownership and evidence harder to establish.
RSA's availability claims and framework mappings are vendor statements and will require customer validation. Even so, the architecture points towards a practical control model: discover every agent, bind it to a responsible human, constrain each tool call and preserve an audit trail.
