least privilege

opal zero ai agent access permissions a turret drum with a low domed roof

Opal Zero: A Smart Fix for Risky AI Agent Access Permissions

Opal Security says Opal Zero reaches general availability at the end of September 2026, built on a three-part definition of least privilege for agents: grants that expire, an owner for every agent, and a decision made at the point of access rather than at provisioning time. Opal Labs reports that more than 96 percent of non-human identities have no recorded purpose and only 10 percent of their access was reviewed in the past year. This article covers the Paladin reasoning model, the Risk Center, how Gateway Sync enforces without adding a proxy, what the design partners at Faire, Databricks, Elastic and Superhuman actually said, the $30,000 launch price and the claims that remain unproven.

Read more
claude and aws integrations opal late september a keystone wedge block set into the top of a low arch

Claude and AWS: Opal’s Powerful Late-September Integration Launch

Opal Security says Opal Zero reaches general availability at the end of September 2026, and the connector list is the story. It ingests agent identities from Anthropic, AWS Bedrock, OpenAI, Cursor, Okta and Entra, hooks the Claude Compliance API, admin controls for Claude Code and Enterprise-Managed Authorization for MCP connectors, then enforces decisions inside AWS Bedrock AgentCore Gateway and Databricks Unity Gateway rather than adding a proxy of its own. This article covers what the integrations actually do, how Gateway Sync differs from the first generation of agent-security tooling, the Opal Labs research behind the launch, the design partners, the $30,000 launch price and the gaps worth watching.

Read more
execution governance identity permissions ai agent behavior a solid pipe valve handwheel

Identity and Permissions Aren’t Enough to Govern AI Agent Behavior

A VentureBeat article published in partnership with Box argues that identity and permissions aren’t enough to govern AI agent behaviour, because access controls decide what an agent can reach while saying nothing about what it should do once inside. Built around an interview with Box CISO Heather Ceylan, the piece proposes execution governance: task-scoped permissions minted per task, a content layer whose classification and metadata are enforced rather than advisory, a three-tier approval model sorted by reversibility, and behavioural baselines built for agents rather than people. This article walks through the argument, the SailPoint survey numbers behind it, the 2026 sandbox-escape incidents that made it concrete, and how it interlocks with agent identity and runtime trust.

Read more
runtime trust ai agents drift expose data memory poisoned a solid ship anchor

AI Agents That Pass Authentication Can Still Drift, Expose Data, or Get Memory-Poisoned

A VentureBeat guest essay argues that AI agents which pass authentication can still drift from their objective, expose data and have their memory poisoned, because authentication verifies who an agent is while runtime trust verifies what it is doing. This piece explains the five runtime threats, the five-pillar runtime trust model (intent validation, behavioural monitoring, policy enforcement, least-privilege execution, human oversight), how it maps onto the six deployment gates in the companion essay, the 2026 research measuring memory-poisoning success rates, the OWASP and MITRE ATLAS entries that name each threat, the survey figures on the post-authentication control gap, what Microsoft, AWS and Cloudflare have shipped, and a roadmap a UK business can run with the tools it already owns.

Read more
ai agent security tools and system access a padlock shackle shut

AI Agent Security: Essential Guide to Safe Tool Access

The moment you connect a language model to a ticketing API, a finance system, a mailbox or a shell, you stop shipping a chat feature and start shipping a new class of privileged user. This guide covers the engineering work that keeps that user contained: how to classify and scope tools into risk tiers, why an agent needs its own identity and short-lived credentials rather than a shared service account, how to contain the blast radius of a single compromised run with sandboxing and default-deny egress, where to place human approval gates so they are decisive rather than theatre, what actually works against indirect prompt injection arriving through retrieved content, what to log so an incident is investigable, how to test the controls before launch, and a 90-day rollout plan with realistic costs and named owners.

Read more
CHAT