Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

Okta for AI Agents vs Workday Agent System of Record

Okta for AI Agents

Okta offering that gives AI agents a first-class identity so organizations can discover, onboard, protect, and govern them

Workday Agent System of Record

Workday system of record to find, add, register, configure, monitor, and manage AI agents

Short answer

Okta says Okta for AI Agents gives AI agents a first-class identity; Workday Agent System of Record (ASOR), set up in each Workday tenant, registers and manages agents.⁠Source 1, Source 2, Source 3 Okta says it manages agents from any vendor, and admins define which resources each can access; ASOR governs agents’ access with Workday security policies and groups.⁠Source 4, Source 5, Source 6

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both register agents from several sources, give agents their own identities, let admins deactivate agents, and keep audit records of agent events.⁠Source 1, Source 2, Source 7, Source 8, Source 9, Source 10, Source 11
Where they differ
In Okta, the resources an agent can access include MCP servers and other agents.⁠Source 5, Source 12, Source 13 ASOR sits in each Workday tenant; for agents working with Workday, tools are Workday APIs.⁠Source 2, Source 3
Running both
Okta’s docs list Workday Agent System of Record among the apps Okta can import agents from.⁠Source 14
Public sources · checked 2 October 2026
  • Offered
  • Preview
  • Not publicly documented

Okta for AI Agents

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedAgent identity and credentials⁠Source 15
  • Registry and governance: OfferedUniversal Directory with human owners⁠Source 16
  • Traffic between agents, tools, and models: PreviewAgent Gateway for MCP tools⁠Source 17
  • Agents across organizations: Not publicly documented

Workday Agent System of Record

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedAgent System User per agent⁠Source 10
  • Registry and governance: OfferedAgent Registry in Management Hub⁠Source 2
  • Traffic between agents, tools, and models: OfferedAgent Gateway for Workday APIs⁠Source 18
  • Agents across organizations: Not publicly documented

At a glance

TopicOkta for AI AgentsWorkday Agent System of Record
Where it sitsAn Okta org subscribed to Okta for AI Agents.⁠Source 12Each Workday tenant, set up separately: there is no current way to migrate its configuration between tenants.⁠Source 3
Agent identityOkta says agents get an identity in Universal Directory, alongside workforce users, with cryptographic credentials; owners are optional.⁠Source 15, Source 16A unique Workday identity per agent, using Agent System User accounts governed by Workday security policies and groups.⁠Source 6, Source 10
Agents it coversOkta says it manages agents from any vendor.⁠Source 4 Custom-built agents can be added by hand; agents from apps such as Workday Agent System of Record and Salesforce Agentforce can be imported.⁠Source 7, Source 14Workday-built, partner-built, and self-built agents; external ones are registered through the ASOR API.⁠Source 2, Source 9 Some Workday agents, including those for HiredScore, are not part of ASOR.⁠Source 2
Pricing modelA separate subscription that can be added to an Okta suite plan.⁠Source 1, Source 19 A list price is not publicly documented.No additional specific SKU is needed to use ASOR.⁠Source 2 Registering Workday-built agents in production needs a Flex Credits policy opt-in.⁠Source 2 A credit’s price is not publicly documented.
Generally availableOkta announced general availability in a post dated 29 April 2026.⁠Source 20 Okta says customers can request Agent Gateway, in preview, as a research release.⁠Source 4Generally available since February 2026.⁠Source 21 It announced its Agent Gateway in June 2025.⁠Source 22

What each one is

Okta for AI Agents

Okta for AI Agents is an Okta product, sold as a separate subscription, to discover, manage, and secure the AI agent lifecycle in an Okta org.⁠Source 1, Source 23 Okta says agents are registered in Universal Directory alongside workforce users; admins can define which resources each can access.⁠Source 5, Source 16

Workday Agent System of Record

Workday Agent System of Record (ASOR) is a functional area you enable in a Workday tenant to find, register, configure, monitor, and manage AI agents.⁠Source 2, Source 3 Its Agent Management Hub manages Workday-built, partner-built, and self-built agents, each with a unique Workday identity.⁠Source 2, Source 10

The differences that matter

  1. What each one controls

    Okta for AI Agents

    Okta admins can define which resources each agent can access, including MCP-protected ones, and can limit token scopes for some resource types.⁠Source 5

    Workday Agent System of Record

    Workday security policies and groups set each agent’s access; an Agent Interaction Policy sets which users may use delegate-mode skills.⁠Source 6, Source 24

    Both vendors use the name Agent Gateway: Okta says its preview gateway checks tool calls made through it; Workday’s routes third-party agents’ Workday API traffic.⁠Source 4, Source 18

  2. Acting for a user

    Okta for AI Agents

    A manually added agent can act for a user only if that user is signed in to the agent’s linked app.⁠Source 15

    Workday Agent System of Record

    Acting for a user, an agent gets only what both may do, and the audit log names both; on its own, only its permissions count.⁠Source 10

  3. Agents calling other agents

    Okta for AI Agents

    For agent-to-agent calls, Okta issues tokens scoped to one resource that expire, and admins can set which agents may invoke others.⁠Source 4, Source 13

    Workday Agent System of Record

    A registered outside assistant, such as Google Gemini Enterprise, can be enabled to call Workday’s Self-Service Agent over A2A for an authorized user.⁠Source 25

    Okta’s agent-to-agent connections use token exchange with Cross App Access, which extends OAuth.⁠Source 1, Source 12 Okta for AI Agents’ docs don’t mention the A2A protocol.

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicOkta for AI AgentsWorkday Agent System of Record
Network exposureWhether agents need an inbound endpoint is not publicly documented. Okta’s Agent Gateway, in preview, has an Okta-hosted URL.⁠Source 26Third-party agents reach Workday APIs through Agent Gateway, a single regional endpoint.⁠Source 18 Inbound endpoint needs: not publicly documented.
IdentityAgents added by hand identify with a client ID, secret, key pair, or metadata document.⁠Source 15Unique identity per agent.⁠Source 10 External agents use OAuth 2.0 or signed JWTs; tokens for third-party (self-built) agents last 4 hours.⁠Source 2, Source 10, Source 27
Access changes and revocationOkta says deactivating an agent immediately blocks new sessions; removing a resource connection denies future access requests to it.⁠Source 8, Source 28Deactivating an agent hides it from users; the change may take up to a minute to reach Agent Gateway.⁠Source 2, Source 18
Audit trailAgent events land in Okta’s System Log; log streaming sends them to Amazon EventBridge or Splunk Cloud.⁠Source 23, Source 29An audit trail report covers agent transactions; delegated actions name agent and user.⁠Source 10, Source 11 SIEM export is not publicly documented.
ComplianceOkta says the company holds SOC 2 and ISO 27001; its Core SKU is generally available for FedRAMP and HIPAA.⁠Source 30, Source 31Workday says its SOC 2 report covers Workday Enterprise Products; ASOR isn’t named.⁠Source 32 ISO 42001 covers Workday Platform.⁠Source 32

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

Okta for AI Agents and Workday Agent System of Record compared on 18 criteria
Okta for AI AgentsWorkday Agent System of Record
What it is
What it is and who it’s forAn Okta product to discover, manage, and secure the AI agent lifecycle in an Okta org; Okta says it gives agents a first-class identity.⁠Source 1, Source 23Set up in each Workday tenant to find, register, configure, monitor, and manage AI agents built by Workday, partners, or the customer.⁠Source 2, Source 3
MaturityOkta announced GA in a post dated 29 April 2026.⁠Source 20 On 22 July 2026, Okta said customers could request Agent Gateway, in preview.⁠Source 4Generally available since February 2026.⁠Source 21 Workday announced its Agent Gateway in June 2025.⁠Source 22
Control
Agent registry and discoveryAgents are added by hand or imported from builder platforms.⁠Source 7 Okta says they sit in Universal Directory and can be given human owners.⁠Source 16, Source 20The Agent Management Hub lists Workday-built, partner-built, and self-built agents with their status.⁠Source 2 Agents for HiredScore and Evisort are not part of ASOR.⁠Source 2
Identity and access controlAgents added by hand identify with a client ID, secret, key pair, or metadata document.⁠Source 15 Admins set the resources each agent can access.⁠Source 5Each agent has a unique Workday identity, governed by security policies and groups.⁠Source 6, Source 10 Acting for a user, an agent gets only what both may do.⁠Source 10
Ownership, policy, and revocationAgents added by hand take optional owners, up to five individuals.⁠Source 15 Okta says admins can deactivate an agent and set which agents may call others.⁠Source 4, Source 8Admins set each agent’s skills and who can access it.⁠Source 2 Generated ASOR agent accounts and their OAuth clients stay disabled until the agent is activated.⁠Source 6
Audit log and observabilityAgent events land in Okta’s System Log, which can stream to Amazon EventBridge or Splunk Cloud.⁠Source 23, Source 29 Agent Gateway, in preview, shows 30 days of tool calls.⁠Source 33An audit trail report covers agent transactions; delegated actions record the agent and the user.⁠Source 10, Source 11 Per-agent analytics reports cover Workday-built agents only.⁠Source 2
Connection
How agents connectOkta issues agent-to-agent tokens, and the caller sends its token to the agent it calls.⁠Source 12, Source 13 Agent Gateway, in preview, can be an agent’s remote MCP endpoint.⁠Source 26Third-party agents must route Workday API traffic through Agent Gateway, a single regional endpoint.⁠Source 18 Outbound-only use is not publicly documented.
Agents across organizationsNot publicly documented (checked 2 October 2026)ASOR manages partner-built agents; a definition can carry an ID locating each one in the partner’s system.⁠Source 2, Source 34 Partner-held controls are not publicly documented.
Protocol supportMCP servers as agent resources; Agent Gateway for MCP tools is in preview.⁠Source 5, Source 17 Okta for AI Agents’ docs don’t mention the A2A protocol.Registration is based on the A2A Agent Card.⁠Source 34 Outside assistants can call the Self-Service Agent over A2A; tool search can filter by SOAP, REST, or MCP.⁠Source 25, Source 35
Frameworks, models, and clouds supportedOkta says it manages agents from any vendor, agents built in-house with code such as Python or LangChain, and agents in purchased software.⁠Source 1, Source 4, Source 14Registration records an external agent’s platform, or OTHER.⁠Source 34 In 2025 Workday announced ASOR registration for Azure AI Foundry and Copilot Studio agents.⁠Source 36
Operations
Deployment options and data residencyA subscription on an Okta org; Okta says its Core SKU registers agents in the org’s regulated cell.⁠Source 12, Source 31 Agent Gateway, in preview, has an Okta-hosted URL.⁠Source 26Set up in each Workday tenant.⁠Source 3 Agent Gateway endpoints: US, EU, UK, Canada, Australia, Singapore, India, Japan.⁠Source 18 Self-hosting: not publicly documented.
Compliance attestationsOkta says the company holds SOC 2 and ISO/IEC 27001 certifications.⁠Source 30 It says its Core SKU is generally available for FedRAMP and HIPAA environments.⁠Source 31, Source 37Workday says its SOC 2 report covers Workday Enterprise Products.⁠Source 32 Its ISO 42001 certificate covers named products including Workday Platform; ASOR isn’t named.⁠Source 32
Support and SLAOkta suites include online support 24 hours a day, five days a week; Premier Success Plans are sold separately.⁠Source 19Workday says its company-wide support is 24/5, with severity 1 cases 24/7/365, or 24/7/365 with Success Plans.⁠Source 38 An ASOR uptime SLA is not publicly documented.
Time and effort to get runningAn Okta org subscribed to Okta for AI Agents.⁠Source 12 Okta lists prebuilt integrations with Salesforce Agentforce, Amazon Bedrock AgentCore, and ServiceNow AI Platform.⁠Source 20Enable the ASOR functional area and set its security policies.⁠Source 3 Registering an external agent includes finding the IDs of the Workday APIs it will use.⁠Source 9
Pricing model and public pricesOkta says it is a separate subscription, which its pricing page lists as an add-on to suite plans.⁠Source 1, Source 19 A list price is not publicly documented.No additional specific SKU for ASOR.⁠Source 2 Workday-built agents in production need a Flex Credits policy opt-in.⁠Source 2 A credit’s price is not publicly documented.
Building
Agent building toolsNot publicly documented (checked 2 October 2026)You provide an external agent’s definition through an API.⁠Source 2 Workday announced the low-code Flowise Agent Builder for Workday’s separate Workday Build in 2025.⁠Source 39
Model accessNot publicly documented (checked 2 October 2026)Workday’s AI agents use large language models.⁠Source 2 Which models ASOR supports or includes is not publicly documented.
Integrations and ecosystemImports agents from apps such as Workday Agent System of Record and Salesforce Agentforce.⁠Source 14 Okta lists Slack and Notion among Cross App Access apps.⁠Source 1In February 2026, Workday said more than 65 partners were connecting agents to ASOR.⁠Source 21 Workday says partner agents reached its Marketplace in June 2025.⁠Source 22

Which to choose

Choose Okta for AI Agents if

  • You want agents registered in Okta, which Okta says puts them alongside workforce users, with optional human owners.⁠Source 15, Source 16
  • Your agents come from many vendors and from in-house code, and you want one place to register them.⁠Source 4, Source 14, Source 20
  • You want to control which agents may call other agents, with Okta issuing resource-scoped tokens that expire.⁠Source 4, Source 13
  • You want agent events in Okta’s System Log, which log streaming can send to Amazon EventBridge or Splunk Cloud.⁠Source 23, Source 29

Choose Workday Agent System of Record if

  • Your agents mostly work in Workday, and each should have a unique Workday identity under your existing security policies and groups.⁠Source 2, Source 6, Source 10
  • You want an agent acting for a user limited to what both may do, with audit entries naming both.⁠Source 10
  • You already run Workday and want agent governance in the same tenant, with no additional specific SKU to buy for ASOR.⁠Source 2, Source 3
  • You want outside assistants, such as Google Gemini Enterprise, to call Workday’s Self-Service Agent over A2A.⁠Source 25

Questions buyers ask

Does either one build agents?

Okta can register custom-built agents and import agents from builder platforms.⁠Source 7 Agent-building tools in Okta for AI Agents are not publicly documented. ASOR takes an external agent’s definition through an API.⁠Source 2 In 2025 Workday announced a low-code agent builder for Workday’s separate Workday Build.⁠Source 39

How is each one priced?

Okta says Okta for AI Agents is a separate subscription.⁠Source 1 Its list price is not publicly documented. ASOR needs no additional specific SKU.⁠Source 2 Workday-built agents in production need a Flex Credits policy opt-in.⁠Source 2 Credit prices are not publicly documented.

Do they support MCP and A2A?

Okta can grant agents access to MCP-protected resources.⁠Source 5 Okta for AI Agents’ docs don’t mention the A2A protocol. Workday bases registration on the A2A Agent Card, can let registered outside assistants call its Self-Service Agent over A2A, and lists MCP as a tool type.⁠Source 25, Source 34, Source 35

Can either one connect agents across organizations?

Okta’s docs describe agents in the customer’s own org.⁠Source 23 Bringing in or reaching another organization’s agents, with access that organization controls, is not publicly documented. ASOR manages partner-built agents in your tenant.⁠Source 2, Source 3 Controls held by the partner company are not publicly documented.

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

44 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Okta brings first-class identity to AI agents with Agent SSO Okta · checked Back:abcdefghij

  2. Source 2: About Workday Agents (Workday Administrator Guide) Workday · checked Back:abcdefghijklmnopqrstuvwxyz2728

  3. Source 3: Set Up Agent System of Record (Workday Administrator Guide) Workday · checked Back:abcdefghi

  4. Source 4: Okta announces new innovations to secure AI agents at runtime and automate ongoing agent governance Okta · checked Back:abcdefghij

  5. Source 5: AI agent resource connections (Okta Help Center) Okta · checked Back:abcdefg

  6. Source 6: Setup Considerations: Agent Security (Workday Administrator Guide) Workday · checked Back:abcdef

  7. Source 7: Add and register AI agents (Okta Help Center) Okta · checked Back:abcd

  8. Source 8: New Okta for AI Agents innovations increase visibility into agent behavior, secure connections at runtime, and enforce continuous agent governance Okta · checked Back:abc

  9. Source 9: Register External Agents (Workday Administrator Guide) Workday · checked Back:abc

  10. Source 10: Concept: Agent Security (Workday Administrator Guide) Workday · checked Back:abcdefghijklm

  11. Source 11: FAQ: Agent Security (Workday Administrator Guide) Workday · checked Back:abc

  12. Source 12: Set up AI agent token exchange (Okta Developer) Okta · checked Back:abcdef

  13. Source 13: Agent-to-agent connections (Okta Help Center) Okta · checked Back:abcd

  14. Source 14: Apps that support AI agent imports (Okta Help Center) Okta · checked Back:abcdef

  15. Source 15: Add AI agents manually (Okta Help Center) Okta · checked Back:abcdefg

  16. Source 16: Okta for AI Agents (product page) Okta · checked Back:abcde

  17. Source 17: Agent Gateway (Okta Help Center) Okta · checked Back:ab

  18. Source 18: Concept: Workday Agent Gateway (Workday Administrator Guide) Workday · checked Back:abcdef

  19. Source 19: Plans & pricing (Okta) Okta · checked Back:abc

  20. Source 20: Okta for AI Agents is now generally available Okta · checked Back:abcde

  21. Source 21: The Workday Agent System of Record Is Now Generally Available Workday · checked Back:abc

  22. Source 22: Workday Announces New AI Agent Partner Network and Agent Gateway Workday · checked Back:abc

  23. Source 23: Okta for AI Agents (Okta Help Center) Okta · checked Back:abcdef

  24. Source 24: Concept: Agent Interaction Policy (Workday Administrator Guide) Workday · checked Back to text

  25. Source 25: Connect External Agents to Workday Using A2A (Workday Administrator Guide) Workday · checked Back:abcd

  26. Source 26: Add an Agent Gateway (Okta Help Center) Okta · checked Back:abc

  27. Source 27: Concept: External Agent ASU Considerations (Workday Administrator Guide) Workday · checked Back to text

  28. Source 28: Connect AI agents to resources (Okta Help Center) Okta · checked Back to text

  29. Source 29: Log streaming (Okta Help Center) Okta · checked Back:abc

  30. Source 30: Okta Security Trust Center | Powered by SafeBase Okta · checked Back:ab

  31. Source 31: Okta is the first independent and neutral identity platform to bring AI agent governance to highly regulated environments Okta · checked Back:abc

  32. Source 32: Workday Compliance | Workday US Workday · checked Back:abcd

  33. Source 33: View Agent Gateway activity (Okta Help Center) Okta · checked Back to text

  34. Source 34: ASOR API Documentation v1.2 (Workday/asor on GitHub) Workday · checked Back:abcd

  35. Source 35: Concept: ASOR Agent Resource Search API (Workday Administrator Guide) Workday · checked Back:ab

  36. Source 36: Workday and Microsoft to Deliver Unified AI Agent Experience for the Enterprise Workday · checked Back to text

  37. Source 37: Discover and assess AI agents (Okta Help Center) Okta · checked Back to text

  38. Source 38: Workday Support | Workday US Workday · checked Back to text

  39. Source 39: Workday Unveils Workday Build, Giving Developers the Tools to Build the Future of Work Workday · checked Back:ab

  40. Source 40: Your company's private network Blocks.ai · checked Back to text

  41. Source 41: Network requirements Blocks.ai · checked Back to text

  42. Source 42: Solutions: Agent sprawl Blocks.ai · checked Back to text

  43. Source 43: Solutions: Partner networks Blocks.ai · checked Back to text

  44. Source 44: Pricing Blocks.ai · checked Back to text