AIToday
Large Language ModelsAI Business & IndustrySiliconANGLE AIPublished: Sep 29, 2026, 06:00 JST

1Password ties AI agent access to individual tasks

1Password ties AI agent access to individual tasks

3 Key Points

  1. What happened

    1Password CTO Nancy Wang said at Okta's Oktane event that agents need just-in-time, task-based access, and the company recently turned that into a task-scoped privileged access product.

  2. Why it matters

    Because an agent can show up in an audit log as the person it works for, security teams may struggle to attribute actions to software versus a human, according to Wang.

  3. What to watch

    1Password and Okta are backing shared identity standards so an agent's verified identity can carry across their systems; the test is whether that context travels between vendors.

WHO IT HITSSecurity and identity teams at companies deploying AI agents will need ways to attribute agent actions separately from the employees those agents act for, and to limit each agent to one task at a time.

Not sure about something? Ask the AI

Questions and answers are published on this page.

Summaries like this, in your inbox every morning.

Context & Analysis

The problem 1Password is describing is not that agents are new, but that they blur a line identity systems were built around. An agent logs in, carries credentials and acts on someone's behalf, so it has characteristics of both a human and a machine. That overlap is what makes the audit trail ambiguous: an agent may appear as the person it works for even though software took the action. Nancy Wang's answer is to stop treating the agent as a fixed account and instead verify it task by task, the way you would check an intern's work before letting them move to the next project.

That thinking has already been packaged into a product. 1Password rejects standing privilege for humans, machines and agents alike, granting access just in time and checking why it is needed, and it recently turned that into a privileged access product scoped to a single task. The company's Credential Broker releases secrets only when needed, without exposing them to the agent or the underlying model.

The piece that is still in motion is portability. 1Password and Okta are backing shared identity standards so an agent's verified identity and authorization context can carry across their systems. For security teams, the practical question is whether that context survives the trip between vendors; if it does not, the distinction between who authorized an action and what performed it may remain hard to reconstruct.

FAQ
What did 1Password actually launch?
1Password recently turned its just-in-time access idea into a privileged access product scoped to a single task, according to CTO Nancy Wang.
How does 1Password keep credentials away from the AI model?
Its Credential Broker releases secrets only when needed, without exposing them to the agent or the underlying model, Wang said.
Where did Nancy Wang say this?
She spoke with theCUBE Research's Krista Case and co-host Rebecca Knight at Okta's Oktane event, in a broadcast on theCUBE.
SiliconANGLE AIRead Original Article

Get the latest Large Language Models news every morning

For example, today's edition would include:

  • Meta taps CJ Desai to lead new enterprise AI unitSiliconANGLE AI · 21m ago
  • ServiceNow's Bhakti Pitre: rogue AI agents need risk-based kill switchSiliconANGLE AI · 21m ago
  • Agentic AI uses 10 to 100 times more tokens per task: FuturumSiliconANGLE AI · 21m ago

AI-summarized, only the topics you pick: one digest a day via Email, LINE, or Slack.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.

Questions and answers are published on this page.

Related Articles

Next articleClaude Code's Boris Cherny: Black-box AI code OK only for prototypes