cd /news/ai-agents/init-2026-recap-airlock-atlas-passpo… · home › topics › ai-agents › article
[ARTICLE · art-147906] src=workos.com ↗ pub= topic=ai-agents verified=true sentiment=↑ positive

init() 2026 recap: Airlock, Atlas, Passport and the builders on stage

WorkOS previewed three new products — Airlock, Atlas and Passport — during its init() 2026 conference at the SFJAZZ Center in San Francisco on October 7, 2026, with all three rolling out over the coming weeks and months. Airlock judged a coding agent's calls across Linear, Snowflake, Stripe and Gmail against company policy, denying one refund, routing another to a human approver and blocking an email; Atlas took a vibe-coded internal app live with Snowflake data, a notes database and shared sign-in; and Passport let a Mac registered once with its organization open Notion already signed in. WorkOS CEO Michael Grinich framed the keynote around an infrastructure layer for identity, permissions and secure data access as AI spreads from engineering into sales, marketing, support, finance and legal, and WorkOS first introduced Airlock at Agent Night in August.

read11 min views1 publishedOct 8, 2026
init() 2026 recap: Airlock, Atlas, Passport and the builders on stage
Image: Workos (auto-discovered)

WorkOS init() 2026 at SFJAZZ Center: live previews of Airlock, Atlas and Passport, plus talks from Aaron Levie, Nikita Shamgunov, Claire Vo, swyx and more.

On October 7, 2026, WorkOS brought init(), the conference for builders, to SFJAZZ Center in San Francisco. The theme was building with AI now that agents use software and do real work inside companies, and how those companies have to change around them. Across a full day, Michael Grinich's opening keynote and its three live WorkOS product previews gave way to three fireside chats, two panels and four lightning demos, with speakers from Box, Databricks, Cloudflare, Stripe, PostHog and more.

A lot of it ran live. Each preview had someone from the WorkOS team at the keyboard. Airlock judged a coding agent's calls across Linear, Snowflake, Stripe and Gmail against company policy, denying one refund, sending another to a human approver and blocking an email. On Atlas, a vibe-coded internal app went live with data from Snowflake, a database for its notes and shared sign-in, and an admin restricted a second app to the sales group. With Passport, a Mac registered once with its organization opened Notion already signed in. WorkOS first introduced Airlock at Agent Night in August, and all three products are previews rolling out over the coming weeks and months.

The lineup around those previews was exceptional. Box CEO Aaron Levie and Databricks VP of Engineering Nikita Shamgunov each sat down for a fireside chat. Claire Vo, host of How I AI, led a panel on who owns the agent with Josh Albrecht of Imbue, Jean-Denis Greze of Town and Dex Horthy of HumanLayer. In the afternoon, swyx moderated a panel with Rita Kozlov of Cloudflare, Tim Glaser of PostHog and Evan Conrad of San Francisco Compute. Cloudflare, Stripe and Databricks each brought a lightning demo, Michael Chan of WorkOS ran live captions on his conference badge, and the final session on the public agenda was a fireside featuring Howie Liu, founder and CEO of Hyperagent.

Grinich's case for redesigning work #

Grinich framed the day around a shift he sees inside companies. A year or two ago, AI lived in pockets, often the engineering team. Now he sees it in sales, marketing, support, finance and legal, where people want to act with it, automate what they repeat and build new things. That takes applications, access to data, identity for humans and agents, and permissions.

He closed the keynote on the factory floor. When electric motors replaced belts running from one central power source, factories mostly swapped the power source and kept their layouts, buildings and methods. AI is at that stage now, Grinich argued: companies apply it to existing processes, and knowledge work still looks like people at desks trading spreadsheets and Slack messages. He asked what you would build if intelligence were abundant, and how you secure a company when machines operate its systems at machine speed. His answer for WorkOS is an infrastructure layer for this era: identity for people and agents, permissions for autonomous systems, new interfaces between people and machines, and secure access to data and tools.

The previews build on products WorkOS already ships. Grinich described AuthKit as closer to an application development layer than a login box, since user and organization objects anchor an app's data model. Pipes, shipped late last year, manages tokens and OAuth flows for connections to outside services. Agent users in AuthKit, released a few weeks before init(), give a person an agent version of themselves with scoped-down permissions. auth.md, an open standard published this summer, gives an agent a supported way to sign up for a service instead of fighting CAPTCHAs or impersonating a person, and Radar lets teams tune controls to the human or agent behavior they want instead of blocking all automated traffic.

Airlock governs what agents can do #

Grinich described agent permissions today as two bad options: approve every action by hand, or get tired of approving and switch the prompts off, which he admitted he does in Claude Code. Airlock is his answer, a governed access layer for local and background agents. It weighs who is asking, what they want to accomplish, and which system and action they want against company policy written in natural language, then approves, denies or escalates to a human, and audits everything. WorkOS first introduced it at Agent Night in August.

At init(), Aaron Tainter of the WorkOS AuthZ team ran it against a live billing investigation. Starting from a Linear issue about a customer's higher-than-expected invoice, he asked an agent in Cursor to investigate across Linear, Snowflake, Stripe and Gmail, all connected through Pipes. The agent requests an intent token describing what it plans to do and presents it on every call, so Airlock can judge each one against policy. It found that Acme, the demo customer, had paid $1,200 for 40 seats when Snowflake showed 30, a $300 overcharge.

Three decisions followed. A $1,200 refund was denied for exceeding the policy's $500 cap. A $300 refund cleared the cap but crossed the threshold for human approval. Someone role-playing a finance approver saw the agent's reasoning and signed off, and the refund went through. When Tainter asked the agent to email the customer, Airlock blocked the send because the body contained financial data. The approved refund bought nothing for the email, which was checked on its own.

Behind those calls, enforce rules handle deterministic checks such as an endpoint, a method or a value in the request body. Runtime rules go to a governing agent, an LLM inside Airlock that reads the policy's instructions. For the refund, it checked Linear for a linked issue with valid reasoning, which a fixed rule can't easily do. Tainter said a rule typed in plain English gets translated into policy, though he didn't write one on stage. Grinich's point afterward was that with one governed permission surface, neither the harness nor any single model has to guarantee security, and the agent never sees the actual tokens.

Atlas gives internal AI apps a secure home #

Grinich opened the second preview by asking who had vibe-coded an internal tool, then how many had given it real authentication, secure connectors and a safe home for its API keys. IT teams, he said, now find vibe-coded apps deployed across a sprawl of services. Atlas is the platform he previewed for building and using internal software with AI, aimed at a company's own staff rather than its customers. You start in a Slack bot or any coding agent, build against Atlas as the backend, and coworkers can find what you made. Underneath, it handles authentication, data connectors and credentials, a database, an AI gateway, permissions, versioned deploys and analytics.

Jacobia Johnson, an engineer at WorkOS, played a new hire on day one at a fictional company called Acme. Her vibe-coded Customer 360 prototype ran on fake data, had a broken AI chat and lost its notes on every refresh. In the script, she exported data as CSV files and had Codex deploy the prototype to a live URL. Mark, the scripted colleague who holds the credentials, told her to take it down because she had just caused a data breach. The breach was staged. His list of requirements was the useful part: authentication, data access over OAuth, audit logs and a way to manage AI spend.

Johnson then asked Codex to deploy to Atlas, using its data connectors for real data, its AI gateway for the chat and a provisioned database for notes. While that ran, she showed the controls on Deal Health, an app someone on the sales team had already deployed, which pulls Salesforce opportunities and posts to Slack. Disconnecting Salesforce blocked the app until she went back through the OAuth flow. When an admin limited Deal Health to the sales group, which Atlas reads from the identity provider, her next refresh locked her out and the activity tab recorded the denial.

Customer 360 then came up live on Atlas. It pulled customers from Snowflake, kept a note across a refresh and answered through its AI feature. Signing out of Atlas also signed her out of Customer 360, because the apps share one authentication instance. Asked which apps were deployed, the Atlas Slack bot listed 14 in the demo workspace, including hers. Building an app directly from Slack was described but not shown. Grinich said building in Atlas should put you on the secure path by default, and that WorkOS staff already use it for candidate management, a month-end financial dashboard and the office's lunch orders.

Passport signs you in once, on the Mac #

The third preview went after sign-in itself. Grinich credited single sign-on with replacing sticky-note passwords, then put up social posts from people fed up with signing in all day. He proposed zero sign-in instead: open the Mac, open Slack or Linear or an internal app, and you're already in. Passport starts by enrolling the Mac once, which an IT admin can do.

Matt Davidson, an engineer on the Enterprise Identity team who builds single sign-on for a living and hates signing in, ran the demo. He signed in once to register the Mac with his organization. Passport then listed his work apps, among them Datadog, GitHub, Granola, Linear, Notion and Slack, along with access to Airlock. With automatic sign-in off, Notion asked for a passkey he didn't have. With it on, Notion opened already signed in to FooCorp, his imaginary company.

Next he asked Claude which Airlock integrations he could reach through Passport. Claude listed GitHub, Linear, Slack, Datadog, incident.io and Snowflake, and reported that Notion wasn't connected. App sign-in and agent access are separate states, and the demo showed both: Notion the app had signed him in moments earlier, while Notion as an Airlock integration for his agent hadn't been set up. Grinich said Passport's device provisioning is integrated with macOS and can happen the first time a new employee opens the laptop, and that the MCP connections behind Airlock show up on the device automatically.

Morning: agent ownership, Neon and a programmable badge #

Matt Carey of Cloudflare gave an agent a Durable Object as its home, plus a stateful workspace and a browser running inside a Worker, then had it crawl and screenshot example.com. His case for the setup was that one container per agent doesn't scale.

Claire Vo's panel on who owns the agent brought together Josh Albrecht, cofounder and CTO of Imbue, Jean-Denis Greze, CEO of Town, and Dex Horthy, cofounder of HumanLayer. Albrecht held that you can't punish an agent, so accountability stays with people. Greze described what Town learned when users approved everything no matter how fine-grained the controls: a separate agent now judges each tool call, safe calls go through, and dangerous or uncertain ones still go to a person. Albrecht pressed him on liability when that judge gets it wrong. Horthy argued that an agent working for several people should get only the access they all share, with its actions audited to each of them.

In his fireside chat, Nikita Shamgunov of Databricks explained how Neon narrowed itself to one small idea, a database that is just a URL, and how database creation jumped once Replit's agent began provisioning databases for people who didn't know they were creating one. Getting recommended by agents, he said, takes publishing factual material, working with partners and harness owners, and supporting whatever launches next in the agent world right away, with auth.md as his example.

Before lunch, Michael Chan signed in to his conference badge with the WorkOS device grant flow and ran live captions on it. The badge page has the projects and guides for programming the badge.

Afternoon: Levie, swyx's panel and two more demos #

After lunch, Aaron Levie called AI largely an industrial technology whose enterprise adoption means a decade of diffusion work: changing workflows, getting data where agents can use it, setting access controls and deciding where the human sits. Engineering automated first, he argued, because its output can be tested and verified. He had spent that morning with a bank working through when an agent should be allowed to send a wire transfer.

Rami Banna of Stripe followed with a lightning demo in which an agent that had no WorkOS account used the Stripe Projects skill to provision one, along with credentials for his app.

On swyx's panel, Rita Kozlov said agents have good brains but not great hands yet, and described a new Cloudflare CLI with descriptive, self-describing commands, designed for agents that guess. Tim Glaser said PostHog's self-driving product could generate many pull requests, but the human was still the bottleneck, and people wanted fewer, higher-quality ones. Evan Conrad's view was that most token usage should go to verification and validation.

Anthony Giuliano, who works on developer relations for Neon at Databricks, ran the last lightning demo of the day: DressCode, an outfit app whose infrastructure is declared in one neon.ts file, with Postgres by default plus an AI Gateway, storage buckets and functions. The public agenda ended the program with a fireside chat with Howie Liu, followed by closing remarks from Grinich.

Thanks for building with us #

Thank you to every speaker, moderator, panelist and demo builder who took the stage, to our sponsors Stripe, Databricks and Cloudflare, and to everyone who spent October 7 with us at SFJAZZ.

All three products from the keynote are previews rolling out over the coming weeks and months. The Airlock page and the Passport page both take early access requests, and we shared our Atlas announcement on the day of the keynote.

── more in #ai-agents 4 stories · sorted by recency
── more on @workos 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/init-2026-recap-airl…] indexed:0 read:11min 2026-10-08 · —