In summary
- Delinea has launched runtime authorisation capabilities that enforce policy on each individual tool call within an AI agent session, allowing, blocking or routing it to a human approver before it executes.
- Credentials are injected just-in-time and scoped to the specific task, then revoked automatically once the task completes, so the agent never holds a credential between sessions.
- Every tool call, database query and SSH command is recorded and tied to a named identity, and the capability is available now as part of the Delinea Platform with no new infrastructure required.
Identity security vendor Delinea has launched runtime authorisation capabilities for AI agents, claiming to be the only platform that enforces policy on what an agent does inside a session before it acts - not just when it connects or after something goes wrong.
Delinea's runtime authorisation evaluates and enforces policy on each individual tool call within a session, allowing it, blocking it, or routing it to a human approver before it executes. A single AI session can carry dozens of tool calls, each with a different risk profile, the company said.
The platform also injects credentials just-in-time at the moment of access, scoped to the specific task, and revokes them automatically when the task completes. According to Delinea, the agent never holds a credential between sessions, removing the standing exposure an attacker could exploit.
Every tool call, database query and SSH command is recorded and tied to a named identity, giving security teams a complete audit trail across all protocols and connection types, the company said.
"The security industry spent years solving credential theft, but AI agents have introduced a new problem: authorised access doing unauthorised things," said Art Gilliland, chief executive at Delinea.
"You can have perfect credential hygiene and still have an agent tear through your production environment in milliseconds. Recording what happened or revoking access after the fact doesn't stop that - enforcing policy on the action as it runs does."
Delinea said no new infrastructure is required, and organisations can apply Zero Standing Privilege to AI agents using the same platform already governing privileged access across their environments.
Runtime authorisation for AI agents is available now as part of the Delinea Platform.




