1Password Restricts AI Agent Permissions to Single Tasks to Stop Credential Leakage
CTO Nancy Wang details how just-in-time authorization and credential brokers isolate secrets from autonomous software models.

Enterprise identity architectures are struggling to track autonomous artificial intelligence agents that blend human authorization with automated execution. Because agents log in with user credentials and act on an employee's behalf, audit logs frequently record actions under the human worker's name rather than distinguishing the software delegate, obscuring accountability across corporate networks.
Addressing the issue at Okta's Oktane conference in an interview on theCUBE, SiliconANGLE Media’s livestreaming studio reported by SiliconANGLE , AgileBits Inc. Chief Technology Officer Nancy Wang explained that organizations must treat agents as hybrid entities. "Is it a machine? Is it a human? The right answer is [that] it’s probably both," Wang said. "Which is why it makes it actually even more important to understand what is the identity this agent is acting as."
To eliminate visibility gaps, 1Password is enforcing an authorization model that eliminates standing privileges for human workers, service accounts, and automated agents. Permissions are issued dynamically on a just-in-time basis and tied to specific operational requirements. 1Password recently packaged this approach into a privileged access product scoped to verify and authorize one task at a time.
Wang compared the operational model to verifying work across discrete milestones. “Just like you would verify whatever an intern does before you allow them to move on to the next project, [it’s the] same thing with agents,” Wang said. “You just want that agent to prove that it actually finished its last task with the right level of permissions, doing the right thing before you allow it to move on to the next task.”
To maintain authorization context across platforms, 1Password and Okta are supporting shared identity standards. Under this setup, 1Password's Credential Broker releases secrets strictly when needed during task execution, ensuring underlying models and agent runtimes never directly inspect or store the credentials.
Wang noted that identity boundaries will increasingly shift to remote execution layers as desktop software gives way to cloud sandboxes. “I think that all of our apps are going to become thin clients and that most of the code will be written in remote sandboxes,” Wang said. “Secure access needs to happen in the cloud.”
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.