Okta and Deloitte expand APJ alliance around AI identity governance
Okta and Deloitte are expanding their APJ partnership around identity governance as organizations introduce more AI agents and non-human identities.
Okta and Deloitte have formed an alliance across Asia Pacific and Japan focused on identity governance and access management as organizations introduce more AI agents and automated systems.
The companies said the work will target financial services, government, healthcare, and other industries managing complex technology and regulatory environments. It will combine Deloitte's cyber, identity, and business consulting work with Okta's Workforce Identity and Customer Identity platforms.
A key area of focus will be managing access for AI agents and other non-human identities. These systems can connect to enterprise applications and data, requiring organizations to track what they can access and what actions they are permitted to perform.
The use of AI agents creates additional identity requirements around authentication, authorization, access policies, and oversight as they connect to enterprise systems and data.
Governing AI agent access
The US National Institute of Standards and Technology is examining standards-based approaches for identifying and authorizing software and AI agents, including issues around identification, authorization, auditing, and non-repudiation.
Singapore's Infocomm Media Development Authority recommends limiting AI agents' access to tools and data and defining actions that require human approval under its Model AI Governance Framework for Agentic AI.
An updated version of the framework published in May 2026 provides examples of how those controls can be applied. One case study describes Dayos allowing an IT agent to automate lower-risk tasks such as password resets while preventing it from making higher-risk changes to permissions.
Another case study covers Tencent's CodeBuddy, which requires human approval by default for actions such as editing files, running shell commands, and making network requests.
Okta and Deloitte said the alliance will integrate identity controls into broader security, technology, and AI programs.
"Across APJ, organizations are moving quickly, but many still lack visibility into how AI is being used across their organizations," Dan Mountstephen, senior vice president and general manager for APJ at Okta, said. "As AI agents connect to more systems and data, organizations need greater visibility and control over what they can access and how they operate."
Identity controls in regulated industries
Deloitte said the alliance will also address identity management as organizations modernize legacy technology environments and introduce cloud and AI systems.
Australian prudential guidance already addresses access controls beyond individual user accounts. The Australian Prudential Regulation Authority's CPG 234 states that access is typically granted to users, special-purpose system accounts, and information assets such as services and other software.
The guidance states that access should be provided only where there is a valid business need and retained only for as long as it is required.
"Identity now sits at the intersection of security, customer experience, regulatory compliance and AI governance," Liz Douglass, partner for cyber at Deloitte, said.