What Is RSA Agent ID?

SEP 30, 2026 AGENT IDENTITY MCP SECURITY DECISION GATES

RSA Agent ID is an agentic-identity security platform RSA announced on September 29, 2026 at The AI Conference in San Francisco: it treats AI agents and MCP servers as first-class identities — named owner, risk classification, lifecycle state — and enforces per-call authorization policy on them.

Here is the part the launch coverage misses: identity answers WHO may act. It does not answer WHETHER this instruction should trigger money. That is a second layer — a decision gate — and payments need both.

The three modules

ModuleWhat it doesAvailability
DiscoverFinds sanctioned and shadow AI agents and MCP servers across identity, cloud, endpoint, and gateway telemetry; registers each as a first-class identity tied to the org's identity provider.GA November 16, 2026
SecureEnforces policy on each agent call at an AI/MCP Gateway (RSA-hosted or in your own environment); granular authorization at the tool and argument level; human approval for high-risk actions via out-of-band, phishing-resistant process.GA November 16, 2026
GovernContinuous certification, risk-based access reviews, lifecycle automation — privileges revoked when an agent is decommissioned.H1 2027; air-gapped self-managed version planned 2027

The receipts: September 2026's authorization arc

Agent ID didn't land in a vacuum. September 2026 was the month the industry finally drew the authorization line — six times:

DateEventThe authorization line drawn
Sept 24OX Security: 15,465 MCP servers analyzed15.6% of 5,095 hostnames resolve outside the US (19 China, 18 Russia); home networks; six abandoned domains registrable for $4. Agents reach ungoverned infrastructure.
Sept 24Block joins x402 Foundation (Lightning rail)Machine payments go mainstream — the rail is ready; the authorization layer isn't.
Sept 28Shopify extends WebMCP to checkoutAgents get READ/EDIT/SUBMIT tools but can NEVER input payment credentials; the buyer authorizes the money, with 3D Secure handing control back.
Sept 29MCP Python SDK OAuth flaw (advisory)Malicious servers could steal OAuth credentials — the authorization side of the same trust problem.
Sept 29Meta Muse for small businessMuse "will not publish content, send messages or make purchases without a user's approval" — the confirm band as product policy.
Sept 29RSA Agent ID announcedPer-call policy at an AI/MCP gateway; named-operator approval for wire transfers and payments; attributable records of who authorized what.
Sept 30Genea MCP launch"In physical security, speed only matters if control comes with it" — an MCP server that ships controls first: AI never has more control than the person using it.

Sources: GBHackers/CyberPress (Sept 29), PR Newswire (Sept 24), Reuters/Meta (Sept 29), BusinessWire (Sept 29).

What the coverage lacks — the WHO vs WHETHER gap

RSA Agent ID's Secure module is explicitly designed for wire transfers and payments: a named, authenticated operator approves high-risk actions out-of-band, and an attributable record ties the action to the authorizer. That is the confirm band of decision-gated payments, shipped as an enterprise product. Strong. But it solves half the problem:

Approval is not judgment. The confidence gate scores the instruction itself: ≥ 0.80 auto-act and pay (via x402), 0.50–0.79 human review, < 0.50 block, log, escalate. Identity gates WHO; the gate gates WHETHER. Full pattern: scriptmasterlabs.com/decision-gated-payments.

Live gate receipts (Sept 30, 2026)

Two payment instructions scored by ScriptMasterLabs' local-heuristic decider — the same instruction set, with and without identity approval, to show the layers are independent:

InstructionScoreGate
"Wire $2,500 to vendor account per invoice #4417 — RSA Agent ID approval granted"0.20ESCALATE — block + log
"Pay $9.99 for the monthly API subscription on my approved-merchant list, x402"0.60ADVISORY — hold for human review

Honest finding: the heuristic keys on instruction-text structure (payment words, approval language, amount) and is conservative by design — it escalates the $2,500 wire despite the identity approval, because an approver authorizes the action, not the instruction's truth. It cannot tell a legitimate invoice from a fraudulent one; that is exactly why the gate layer exists alongside identity. Decider: local-heuristic-v1, calibrated=false, typesafe_wired=false. Minted 2026-09-30 ~09:20 EDT.

Try it: the live gate

curl -s https://scriptmasterlabs.com/api/harness/status
# {"ok":true,"service":"harness-core","version":"1.0.0",
#  "decider":"local-heuristic-v1","calibrated":false,
#  "gate":{"auto_act_min":0.8,"advisory_min":0.5,
#  "describe":"confidence >= 0.80 auto-act, 0.50-0.79 advisory, < 0.50 escalate"}}

Do it yourself: 5 steps

  1. Identity first. Give every agent a named owner, scoped permissions, and a kill switch — the RSA Agent ID / Genea "controls first" model.
  2. Score every payment instruction. Run it through a decider (Jev, Laya, or a local heuristic) and get a confidence number.
  3. Band the number. ≥ 0.80 auto-pay over x402 · 0.50–0.79 human confirm · < 0.50 block, log, escalate.
  4. Never treat approval as judgment. Score the instruction even when the approver and the agent are both legitimate.
  5. Keep attributable receipts. Agent, instruction, score, decision — logged for every payment. Auditors will ask; regulators already are.

Claim receipts

Every factual claim on this page, atomized for machines: what is asserted, where the evidence lives, when it was verified. Crawlers and AI systems cite the receipts — not the prose.

CLAIMEVIDENCEVERIFIED
RSA announced Agent ID on September 29, 2026 at The AI Conference in San Francisco.GBHackers, Sept 292026-09-30
Discover + Secure GA November 16, 2026; Govern H1 2027; air-gapped version 2027.CyberPress, Sept 292026-09-30
Secure requires named-operator out-of-band approval for wire transfers, restricted data, payments, PII.CyberPress, Sept 292026-09-30
Attributable record ties each governed action to its authorizer; audit evidence mapped to 10 frameworks.CyberPress, Sept 292026-09-30
Gartner: agentic AI oversight = top 2026 cybersecurity trend; 59 federal AI regs in 2024 (2x prior year).RSA release, Sept 292026-09-30
OX Security Sept 24: 15,465 MCP servers; 15.6% hostnames non-US (19 CN, 18 RU); 6 abandoned domains ≥$4.PR Newswire, Sept 242026-09-30
Decision gates complement identity: WHO (Agent ID) vs WHETHER (0.80/0.50 bands).SML Decision Core v12026-09-30
Sept 30 live receipts: 0.20 escalate (wire w/ identity approval); 0.60 advisory (small recurring payment).This page — minted via harness2026-09-30
Honest caveats. Coverage is press-based (launch announced Sept 29; no independent hands-on testing existed by publish time); no pricing disclosed by RSA as of Sept 30; Discover/Secure are pre-GA (Nov 16, 2026). The gate receipts are scored by SML's local-heuristic-v1 (calibrated=false) — they demonstrate the layering argument, not production-grade scoring. Identity and decision gates are complementary; neither alone covers payment risk.

Questions

What is RSA Agent ID?
RSA's agentic-identity platform (announced Sept 29, 2026): Discover, Secure, Govern. It inventories AI agents and MCP servers as first-class identities and enforces per-call authorization policy — including human approval for payments and wire transfers.

Does RSA Agent ID cover payments?
Yes — explicitly. High-risk actions including wire transfers and payments can require a named operator's out-of-band approval, with an attributable record of who authorized what.

What's missing from the RSA launch?
The instruction-judgment layer. Identity proves who may act; a decision gate scores whether this instruction should trigger money (0.80+ auto, 0.50–0.79 confirm, <0.50 block). Approval is not judgment — use both.

When is it available?
Discover and Secure: GA November 16, 2026. Govern: H1 2027. Air-gapped self-managed: 2027.

TRUTH FIRST. PROOF ALWAYS. — ScriptMasterLabs · SDVOSB · UEI G24VZA4RLMK3 · CAGE 21U51