What happened
Omada, an identity governance and administration (IGA) provider, has acquired EmpowerID to bolster its capabilities in managing and securing AI agents within enterprise environments. The acquisition integrates EmpowerID’s runtime agent governance technology into Omada’s existing platform, which the company claims will allow organizations to enforce security policies on AI agents in real time. EmpowerID CEO and co-founder Patrick Parker will join Omada as chief innovation officer to oversee the integration and further development of these identity security features.
Omada announced the acquisition of EmpowerID to enhance its 'Agent Governance' solution, which was originally introduced in June. The acquisition is intended to address the challenge of governing AI agents that operate autonomously within enterprise systems.
The combined platform is designed to provide a single source of truth for all identities, including human users, applications, and AI agents. It aims to unify lifecycle management, access certification, and authorization services under one framework.
A key of the integrated offering is 'runtime authorization,' which allows for access decisions to be made at the moment of a request. This is intended to replace traditional, slower audit-based security models with immediate enforcement capabilities.
Patrick Parker, the CEO of EmpowerID, will transition to the role of chief innovation officer at Omada to lead the integration of the acquired technology and drive future development in identity security.
Why it matters
As enterprises increasingly deploy autonomous AI agents that interact with sensitive systems at machine speed, traditional identity management tools—designed primarily for human users—often fail to provide adequate oversight. By shifting from post-hoc auditing to runtime authorization, Omada aims to prevent unauthorized agent actions before they occur. This development is significant because it addresses the 'governance gap' where agents operate with permissions that are often poorly defined or monitored, potentially exposing organizations to security risks or compliance failures. The integration promises a unified fabric for managing human, application, and identities, providing continuous compliance evidence and granular control over what agents are permitted to do during active operations.
The rapid proliferation of AI agents in the enterprise has outpaced the development of security controls. Because agents can execute tasks at high speeds, traditional identity governance—which often relies on periodic reviews—is insufficient to prevent potential breaches or policy violations.
By implementing runtime authorization, organizations can theoretically stop an the moment it attempts an action outside of its defined scope. This represents a shift from reactive monitoring to proactive, automated security enforcement.
The integration provides a unified view of entitlements and relationships, which simplifies compliance. By recording every decision and grant in real time, organizations can generate continuous compliance evidence, reducing the burden of manual preparation for audits.
Interactive Mechanism: How It Actually Works
Explore the underlying technology behind this development interactively.
crm_get_transaction(id='4092').What most distinguishes an AI agent from a basic chatbot?
What to watch next
The primary focus will be on the technical integration of EmpowerID’s runtime authorization engine into Omada’s existing IGA platform. While Omada claims this will provide real-time control, the practical effectiveness of these 'stop' mechanisms across diverse enterprise software stacks remains to be proven in production environments. Additionally, stakeholders should monitor how Omada balances the complexity of managing non-human identities alongside traditional human access management without introducing significant or operational friction. Specific details regarding the pricing, licensing models for the new agent governance features, and the timeline for full platform integration were not disclosed in the announcement.
The market will be watching to see how effectively Omada can scale these governance controls across complex, heterogeneous enterprise environments.
The company has not provided specific details on the availability or pricing of the integrated agent governance features, nor has it clarified if these capabilities will be sold as an add-on or integrated into existing tiers.
The success of this acquisition will depend on how well the 'runtime authorization' can be applied to various third-party AI agents and legacy systems without disrupting business workflows.