CrowdStrike is expanding its identity security strategy to autonomous AI agents with the launch of Agentic IDP, a new capability designed to give agents verifiable identities and replace standing privileges with real-time, risk-aware access decisions.
Introduced during Fal.Con 2026, Agentic IDP is aimed at a growing identity challenge for enterprises, as AI agents operate autonomously, at machine speed, and often with significant system privileges, making traditional identity controls difficult to apply.
“Most research has AI agents outnumbering humans somewhere around 90 to 1 – i.e. for every human employee in an organization, there are up to 90, and in some cases, even more agents running around,” said AJ Shipley, Chief Product Officer, CrowdStrike.
CrowdStrike replaces standing privileges with continuous identity
CrowdStrike acquired SGNL earlier this year, and Shipley says this acquisition and its continuous identity approach are intended to replace static authorization with real-time, risk-aware access decisions.
This move from standing privileges to continuous identity means access can be granted only when needed and revoked once the task is completed.
“This is why we acquired SGNL earlier this year. We integrated it with our Falcon Platform to deliver continuous identity and what that allowed us to do is replace static policies and standing privileges with real-time, risk-aware authorization,” said Shipley.
“We’re able to grant access the moment it’s needed, not before, and then revoke that access the moment it’s no longer necessary,” Shipley continued.
For MSPs, MSSPs and other channel partners, the rise of autonomous agents could create a new identity security requirement across customer environments. As enterprises deploy more agents, partners may increasingly be called on to help customers discover those identities, limit their privileges, enforce just-in-time access and maintain an auditable record of agent activity.
Agentic IDP gives AI agents verifiable identities
Shipley described the Agentic IDP as a system for registering agents as trusted identities and assigning them cryptographically verifiable identifiers.
These identities cannot be spoofed or shared, and every decision is then made by CrowdStrike’s continuous identity approach.
The goal is to eliminate blind spots and prevent agents from operating through static service accounts or credentials.
“Guardian discovers every agent the moment it comes online and then Agentic IDP is able to register it as a trusted identity,” Shipley explains. “So you have one authoritative directory with no blind spots.”
Just-in-time access limits autonomous agent privileges
Agents will also receive narrowly scoped tokens for the minimum necessary time, while actions remain tied to the human or workload that initiated them.
This is intended to preserve traceability even when agents operate at high speed.
“Those agents are never given standing credentials. We’re able to broker access between those agents through tokens that are scoped to the least privilege necessary in order to accomplish the task,” said Shipley.
“Now, every action gets bound to the human or the workload that initiated it, no matter how fast an agent is able to move, is always traceable, it’s always auditable, and it’s always accountable,” he added.





