Willow Joins Okta Cross App Access: Identity-Governed AI Agents for the Enterprise

Your teams are deploying AI agents faster than any governance framework was built to handle. The bottleneck isn't ambition. It's the secure connectivity and AI access control those agents need to work across the tools your business runs on.
Today Willow is joining Okta's Cross App Access (XAA) ecosystem. Every agent connection that flows through Willow can now inherit your existing Okta identity and policy, so AI moves forward without the security reviews, custom governance builds, and unmanaged risk that stall most enterprise deployments. Okta is the access layer for people. Willow is the access layer for agents. Cross App Access is where the two meet, and it's what makes enterprise AI governance a standards-based problem instead of a custom build.
The AI agent security risk is already here:
88% of organizations report confirmed or suspected AI agent security incidents, and 92% of organizations that experienced an AI-related breach lacked proper AI access controls. The pattern isn't that agents are inherently unsafe. It's that most are deployed on static API keys that never expire, create no audit trail, and give IT no visibility into what the agent is doing. This is the shadow AI problem, and it grows every week your teams add another tool.
That leaves security teams with a bad choice: accept unmanaged risk, or stall AI adoption entirely. Willow was built to remove that choice. XAA makes the removal standards-based.What Cross App Access (XAA) actually isCross App Access, formally the Identity Assertion Authorization Grant, is an open protocol built as an extension of OAuth and incorporated into MCP as an authorization extension. It's vendor-neutral, designed to work across any cloud, framework, or SaaS ecosystem, which makes it the practical standard for MCP authorization at enterprise scale.Instead of static API keys, XAA issues dynamic, identity-based tokens scoped to exactly what the agent needs for each task.
This is least privilege for non-human identity: each token is issued in real time through the user's active Okta identity, revocable at any point, and logged for a complete audit trail. Every agent connection flows through your central identity policy, not around it.
AI agent identity and access management, built on OktaAI agent identity and access management is the layer most stacks are missing. On-prem had Active Directory. SaaS had Okta. AI agents get Willow, and with Cross App Access, agent SSO now extends the same identity standards that govern your human workforce to every autonomous worker in your environment.What Cross App Access changes for your teams
- Automatic enterprise compliance. Agents follow the identity-based rules you already enforce. No custom AI governance to build, no new policy framework to stand up.
- Faster deployment. Skip the security reviews that have been blocking automation from going live. Teams move from pilot to production.
- A better experience. Fewer consent prompts, less approval fatigue, no loss of control.
- Secure connectivity across your stack. Agents connect to the tools your teams use under the same AI access control standards that govern people.
Why Willow adopted XAA for AI agent governance?
Willow is the control plane for every AI agent, tool, MCP, and skill in the enterprise. Agent requests pass through Willow's gateway, MCP servers, and orchestration layers, and Willow gives each one a real identity, scoped access, runtime guardrails, and an audit trail tied to a human.Cross App Access lets Willow route and govern that agent traffic through Okta's identity and policy engine directly. Developers building on Willow plug into Okta's central policy engine through XAA and inherit enterprise-grade AI agent access governance, without building custom infrastructure.This is the same model already running in production. At Wix, roughly 5,000 people use Willow every week across about 600 governed tools and MCPs, generating more than 300,000 governed tool calls a week. Innovid and Riskified run on it too. XAA extends that governance to any Okta customer through an open standard."Organizations shouldn't have to choose between adopting AI tools and maintaining visibility over enterprise access," says Aaron Parecki, Senior Director of Identity Standards at Okta. "By connecting apps with the Cross App Access protocol, security teams get more control and users get a better experience without all the OAuth consent prompts
What this means for Willow customers?
AI agents can now interact with Willow without static keys or repetitive manual consent prompts. Access is governed by your existing Okta policies, auditable in real time, and scoped to exactly what the agent needs for each task. Security defines policy once. Employees self-serve safely. That is enterprise AI governance and end-to-end enablement from the same place.Get started with Cross App Access
- Cross App Access is included in your Okta workforce SSO plan. Agent SSO brings XAA into Okta workforce plans at no extra cost and treats agents as first-class identities: okta.com/solutions/cross-app-access
- See Willow's integration in the Okta Integration Network (OIN): https://docs.withwillow.ai/docs/admin/build/mcp-servers/connectors/built-in/okta#authentication-types
- Read Okta's announcement: okta.com/blog/product-innovation/cross-app-access-enterprise-ai
Background Agents in the Enterprise
Most teams can spin up an agent. Few can deploy one their security team signs off on. Here's the framework that does both.
FAQS
Everything you need to get your Basecamp running.
Your agents are already in the wild.
Give them a Basecamp. Go from AI chaos to AI work, in minutes.