cd /news/ai-safety/1password-launches-privileged-access… · home topics ai-safety article
[ARTICLE · art-76970] src=siliconangle.com ↗ pub= topic=ai-safety verified=true sentiment=· neutral

1Password launches Privileged Access to cut standing access for AI agents

1Password launched 1Password Privileged Access, a product that gives engineers and AI agents just-in-time access to critical infrastructure and eliminates standing access. The product, built on technology from the Apono acquisition, tracks identities and permissions across cloud, database, and Kubernetes environments to surface and reclaim unnecessary access. CEO David Faugno said most organizations have more standing access than they can see or justify, creating exposure that attackers often discover first.

read4 min views3 publishedJul 28, 2026
1Password launches Privileged Access to cut standing access for AI agents
Image: Siliconangle (auto-discovered)

1Password launches Privileged Access to cut standing access for AI agents

Identity security company 1Password today launched 1Password Privileged Access, a product that gives engineers and AI agents a single task’s worth of access to critical infrastructure and nothing that outlasts it.

The product pushes 1Password’s Unified Access platform into privileged access management, a category the company entered in June with the acquisition of Apono Inc. Privileged Access is built on the startup’s just-in-time provisioning technology. Permissions are written directly into the target system’s native policy layer across cloud environments, databases and developer infrastructure. Existing tooling stays where it is. An agent never needs the underlying credential.

Standing access is the target. It accumulates quietly as engineers, service accounts and identity and access management roles pick up permissions for one task and keep them long after the task ends. AI agents widen the blast radius. They inherit the privileges of whoever deploys them, or hold on to credentials they were handed. Recent 1Password research found that 40% of developers grant agents persistent access to systems or credentials.

“Most organizations have more standing access in their environments than they can see or justify,” said Chief Executive David Faugno. “That invisible access creates exposure and too often, companies discover it only after an attacker does.”

Privileged Access tracks identities and permissions across cloud, database and Kubernetes environments to surface access that should be reclaimed or right-sized. An account or privilege is created only when someone asks for it, and it covers the task at hand. When the session ends, it is gone.

Every request and approval is logged with full attribution. That covers audit evidence for Service Organization Control 2, the Health Insurance Portability and Accountability Act and the Payment Card Industry Data Security Standard. ISO 27001 and the European Union’s General Data Protection Regulation are handled the same way. Low-risk requests clear automatically under policy. Higher-risk ones go to a reviewer through tools such as PagerDuty, Slack, Microsoft Teams or Jira.

1Password also moved 1Password Credential Broker into public preview for GitHub Actions. The tool debuted in private beta in June. It issues credentials scoped to an individual workflow run, keeping long-lived static secrets out of pipeline configurations. Before releasing anything, the broker verifies that the requesting identity is trusted and logs the delivery.

Ben De St. Paer-Gotch, director of product management at GitHub Inc., said in the announcement that engineering teams can now strip secrets out of pipeline configurations while still giving GitHub Actions what it needs to build and ship software.

Three capabilities aimed at developer environments also reached general availability in 1Password Enterprise Password Manager. Developer Watchtower finds exposed credentials in local .env files and prompts developers to move them into 1Password, while giving administrators a view of credential risk on those machines.

1Password Environments lets developers import existing .env files into the vault and reach secrets through the company’s Model Context Protocol server, keeping them off disk and out of model context. Credential Governance gives administrators a central view of company-owned credentials sitting in employee and shared vaults, the ability to take ownership of them and control over how they are accessed over time.

The company’s enterprise vault holds more than 1.5 billion credentials and secrets. It’s used by more than 1 million developers and 180,000 businesses, including Canva Pty. Ltd., Cursor, Figma Inc., GitHub, Hugging Face Inc., MongoDB Inc., Salesforce Inc. and Wiz Inc.

Image: 1Password

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more** 11.4k+ theCUBE alumni**— Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.

About SiliconANGLE Media

SiliconANGLE,

theCUBE Network,

theCUBE Research,

CUBE365,

theCUBE AIand theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.

── more in #ai-safety 4 stories · sorted by recency
── more on @1password 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/1password-launches-p…] indexed:0 read:4min 2026-07-28 ·