CrowdStrike gives AI agents an identity provider, parallel SOC investigations and package blocking

CrowdStrike Holdings Inc. today announced three additions to its Falcon platform: an identity provider built for artificial intelligence agents, a rebuilt investigation layer that runs multiple Charlotte AI agents across security domains at once, and a feature that blocks malicious open-source packages on the endpoint before their embedded code can run.

All three were detailed at the company’s Fal.Con 2026 conference in Las Vegas this week.

The identity product, the CrowdStrike Agentic Identity Provider or Agentic IdP, fills a gap in Continuous Identity. That’s the real-time authorization model CrowdStrike detailed at Identiverse in June, built on technology from its $740 million acquisition of SGNL Inc. Continuous Identity decides whether an agent should be allowed to do something at a given moment. Agentic IdP handles the step before that, establishing what the agent is in the first place.

Companies currently stand in for agent identity using service accounts, application programming interface keys and workload identities. None of those were designed for software that takes autonomous action on a person’s behalf and delegates work to sub-agents.