Louisville, Colo. – September 15, 2026 -- JumpCloud Inc. has extended its identity and access management platform to govern AI agents alongside human employees and devices, addressing a gap where only 21% of IT teams have adopted governance controls for autonomous agents.
JumpCloud ties every AI agent to a verified human owner and lifecycle record
The platform now treats each AI agent as a distinct identity, tracked from creation to retirement. Agents registered in JumpCloud cannot operate without an assigned human owner, giving IT teams a centralized view of every agent in use across the organization.
New controls trace agent actions back to human owners to curb shadow AI
JumpCloud links every human and agent login to the automated tasks performed, allowing IT to trace agent activity and generate automatic audit logs. Joel Rennich, senior vice president of product management at JumpCloud, said IT teams need to know which agents exist, who owns them, and what they can access as these tools operate at increasing speed.
Privileged access management now applies temporary, expiring permissions to agents
The platform applies PAM rules directly to AI agents, granting least-privilege access that automatically expires once a task is complete. This allows organizations to connect AI agents to legacy systems without costly infrastructure upgrades. Rahul Kamdar, senior vice president of product at JumpCloud, said identity has become the control plane for AI security as agents act inside systems rather than merely accessing them.
Four new capabilities target hidden AI deployments and shared credential risks
JumpCloud's AI Agent Identity & Access feature assigns each agent a unique identity, letting admins revoke access instantly without disrupting the associated employee. A Shadow AI to Secure MCP Connection tool automatically detects hidden Model Context Protocol setups and routes them through the JumpCloud AI Gateway. Enforced Approved SaaS Access applies uniform security and device-trust policies across AI tools and applications. A PAM MCP Server, scheduled before the end of Q4 2026, will replace shared API keys with a zero-setup PAM agent that locks permissions to isolated agent identities.