September’s product updates add more direct ways to build agent-ready experiences, place policy around AI activity, connect verification capabilities, [support frontline workers](https://www.pingidentity.com/en/resources/blog/post/verifying-trust-frontline-workers.html), unify everyday access, and move identity data and configuration across environments. The grouped stories continue the direction outlined in [August’s Ping Product Corner](https://www.pingidentity.com/en/resources/blog/post/august-2026-product-updates.html), where identity verification, biometrics, orchestration, and protection came together.

The result is a clearer path from experimentation to governed deployment, with less custom work for builders and fewer disconnected tasks for administrators.

## This Month’s Highlights

- **Agentic AI updates**give developers more ways to build and security teams more ways to govern machine-driven activity.
- **Verification connectors**, zero-knowledge biometrics, frontline flows, and a unified portal improve how people establish and use access.
- **Configuration promotion** and cross-system provisioning give administrators a more consistent operating model.

## Identity for AI

### **AI-First Headless Identity Reaches More Development Workflows**

[AI-first headless identity](https://www.pingidentity.com/en/resources/blog/post/headless-identity-accelerates-agentic-enterprise.html) lets people, developers, and now AI agents use Ping’s identity services wherever they work, without being tied to one interface. September saw the addition of remote MCP, Marketplace MCP, and React Native support for DaVinci to AI-first headless identity, giving developers more direct ways to connect agents and extend identity to mobile experiences without tying the interface to the identity layer.

### **PingOne Privilege Enterprise Personal Agent Access brings Runtime Control to AI agents**

As employees and developers bring personal AI agents into everyday work, security teams need visibility and control without slowing innovation. [Enterprise Personal Agent Access](https://press.pingidentity.com/2026-09-01-Ping-Identity-Secures-Claude-Personal-Agents-From-Discovery-to-Action), delivered through PingOne Privilege, can discover supported personal agents, link each session to the user and device behind it, and apply policy to the resources and actions the agent requests. Organizations can allow, deny, log, require approval, or revoke activity in real time, helping make agent-assisted work more secure and accountable. Read the official announcement.

### **PingOne Protect Introduces Agent-Driven Authentication**

AI agents are becoming part of everyday work, but security teams still need to know what is accessing their applications. PingOne Protect now helps recognize [supported AI agents](https://docs.pingidentity.com/pingone/release_notes/index.html#ai-agent-type-detection) and apply the right level of protection to each one. The result is better visibility, more informed risk decisions, and greater confidence as AI becomes part of the workforce. See the workflow and testing guide.

## New Marketplace Flows

### **Give Frontline Workers a Faster Start**

A new flowpack has been added to the Ping Identity Marketplace: [Verified Trust for Frontline Workers - Onboarding and Access](https://marketplace.pingone.com/item/verified-trust-frontline-workers-onboarding-and-access). It provides prebuilt workflows for creating a verified frontline worker identity and delivering biometric access on shared devices.

This solution is designed for organizations in retail, manufacturing, logistics, education, food and beverage, field service, and other operational environments where workers share devices, work in shifts or lack a dedicated corporate endpoint. It helps organizations get frontline employees, contractors, seasonal workers, and agency staff ready for work quickly while maintaining individual accountability across shared devices, kiosks, and tablets.

## Orchestration Connectors

### **Add Identity Verification to DaVinci Flows with Less Setup**

Adding identity verification to onboarding and re-verification journeys is now easier with the new Identity Verification Use Case connector in PingOne DaVinci. With two ready-to-connect capabilities, teams can add PingOne Verify checks for government IDs and facial liveness without building complex flow logic. The result: faster implementation, fewer nodes, and smoother experiences for users. [Learn more in the connector documentation](https://docs.pingidentity.com/connectors/identity_verification_connector.html) and [release notes](https://docs.pingidentity.com/connectors/relnotes/connectors_release_notes.html#september-2).

### **PingOne Recognize Connector is now in Early Access**

Bring privacy-preserving facial biometrics and current liveness capabilities into DaVinci flows through a productized [PingOne Recognize connector path](https://docs.pingidentity.com/connectors/relnotes/connectors_release_notes.html#the-pingone-recognize-connector-is-now-available-early-access). Teams can design enrollment and authentication experiences without building a separate integration from scratch. The connector uses a headless SDK with DaVinci Forms or custom HTML components, so organizations can shape the experience while PingOne Recognize handles camera capture, liveness detection, face processing, and verification.

## Identity Operations

### **Provisioning Extends Across Entra ID and Snowflake**

Identity lifecycle work often spans more than one directory or data platform. [New Microsoft Entra ID and Snowflake provisioners](https://docs.pingidentity.com/pingone/release_notes/index.html) cover user and group synchronization, group membership, and Snowflake role administration, giving teams a more consistent way to keep access aligned as people and responsibilities change.

## A Broader Operating Model for Modern Identity

September’s releases give product teams, security leaders, and administrators practical ways to apply identity across AI, frontline operations, and everyday access management. Look out for the Ping Product Corner next month for more platform developments, releases, and updates.

Ready to Explore the Platform?

Discover the future of identity security with one trial for all use cases.   
 Reach out to your account rep for more information.

[Try Ping today](https://www.pingidentity.com/en/try-ping.html) 

## Frequently Asked Questions

### Which September update is most relevant to teams building AI-enabled applications?

The AI-First Headless Identity enhancements are the clearest fit for developers building AI-enabled applications and agent workflows. Remote MCP, Marketplace MCP, and React Native support for DaVinci provide more flexible ways to connect identity services to development and mobile experiences.

### How can security teams govern personal AI agents?

PingOne Privilege can discover supported personal agents, associate each session with the responsible user and device, and apply policies to allow, deny, log, require approval, or revoke activity. PingOne Protect helps recognize supported AI agents and apply appropriate protection as they access applications.

### What is the role of the new verification connector?

The Identity Verification Use Case connector packages PingOne Verify checks for government IDs and facial liveness, making it easier to add onboarding and re-verification steps to DaVinci journeys with less custom flow logic.

### What does the Unified End User Portal change for users?

It gives users one place to manage their accounts, access applications, complete MFA, and maintain profile information instead of requiring them to move between separate experiences.

### What can administrators manage with the September operations updates?

Administrators can promote identity configuration across environments with more control over resources, dependencies, variables, reviewable plans, and auditability. They can also use the new Entra ID and Snowflake provisioning capabilities to synchronize users, groups, group memberships, and Snowflake roles.