SecurityBrief Ireland - Technology news for CISOs & cybersecurity decision-makers
Ireland
1Password launches privileged access tools for AI agents

1Password launches privileged access tools for AI agents

Wed, 29th Jul 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

1Password has launched 1Password Privileged Access, expanding its Unified Access platform into Privileged Access Management.

The offering is designed to remove standing access by creating an account only when access is requested, limiting it to a specific task, and deleting it automatically once the work is finished.

Privileged access is becoming a bigger issue as companies give more systems access to software agents as well as staff. Research from 1Password found that 40% of developers give AI agents persistent access to systems or credentials, leaving that access in place after a task has ended.

The product is built on technology from Apono, which joined 1Password in June 2026. It provisions permissions in the native policy layer of the target system across cloud environments, databases, and developer infrastructure.

That differs from traditional Privileged Access Management tools, which typically focus on monitoring or controlling existing privileged accounts. Instead, 1Password removes the persistent account once the task is complete.

Security teams can use the product to track identities and permissions across cloud, database, and Kubernetes environments. It also records requests, approvals, and access events for compliance reporting, and supports risk-based approval workflows through tools including PagerDuty, Slack, Microsoft Teams, and Jira.

AI governance

The launch comes as companies grapple with rapid AI agent adoption and the controls needed to govern non-human identities. In a separate survey, 1Password found that 65% of developers are expected or encouraged to use AI agents, while only 33% said they had a secure way to do so.

The same research found that 33% of developers using AI agents said their organisation had experienced a security incident or breach linked to overprivileged non-human identities. It also found that AI agents can access customer data, sensitive intellectual property, or employee and human resources data at 71% of companies, while 62% of technical employees reported security gaps in their employer's approach to managing agents.

Another finding pointed to operational risk from untrusted inputs. According to the research, 47% of developers said their AI agent had taken an unintended action after following instructions embedded in untrusted content such as a web page, document, email, or tool output.

David Faugno, Chief Executive Officer at 1Password, said the build-up of unused or poorly scoped access has become harder for organisations to track. "Most organizations have more standing access in their environments than they can see or justify," he said. "That invisible access creates exposure and too often, companies discover it only after an attacker does. As AI agents act on behalf of employees, access must be granted for a specific task, limited to what the work requires, and removed when the work is done."

Credential controls

Alongside the new access product, 1Password has opened a public preview of 1Password Credential Broker for GitHub Actions. The tool issues credentials scoped to individual workflow runs, aiming to reduce the use of long-lived static secrets in pipeline configurations.

Before releasing a credential, the broker verifies that the requesting identity is trusted, scopes the credential to the request, and logs the delivery. This is intended to give organisations an auditable record across infrastructure access and runtime credential use.

GitHub also commented on the release. "Developers are under constant pressure to move faster, but increasingly sophisticated software supply chain attacks have made securing CI/CD pipelines more challenging than ever," said Ben De St. Paer-Gotch, Director of Product Management at GitHub. "With 1Password Credential Broker for GitHub Actions now in public preview, engineering teams can eliminate secrets from their pipeline configurations, reducing the risk of credential theft while securely providing GitHub Actions with the credentials needed to build and ship software."

Developer exposure

1Password also introduced three additions to its Enterprise Password Manager focused on developer environments, where credentials are often stored locally or shared without clear oversight. Security teams often lack a clear picture of what credentials exist across developer tools and machines, who controls them, and whether the access is still required.

The additions include Developer Watchtower, which identifies exposed credentials in local .env files; 1Password Environments, which lets developers import existing .env files into a vault and access secrets without keeping them on disk; and Credential Governance, which gives administrators a central view of company-owned credentials across employee and shared vaults.

The changes reflect a broader shift in security priorities as AI-assisted software development spreads through engineering teams. The survey results suggest many companies are encouraging that shift before putting guardrails in place, with only one-third of developers saying they already have a secure way to use AI agents.