1Password launches Privileged Access to rein in the permissions AI agents accumulate
1Password's new Privileged Access grants engineers and AI agents just-in-time access that expires when the task ends — targeting the standing permissions agents rarely give back.
On 28 July 2026, 1Password announced Privileged Access, a product aimed at a problem that has grown alongside AI agents: standing access. These are permissions granted for a task and then never revoked, quietly piling up across cloud services, databases and developer infrastructure until no one can account for them.
Privileged Access provisions just-in-time, just-enough access with zero standing privilege, then removes it automatically once the work is done. It surfaces overprivileged accounts, auto-approves low-risk requests, and routes riskier ones to a human via Slack, Teams, PagerDuty or Jira. Every request and approval is logged for SOC 2, HIPAA, PCI DSS, ISO 27001 and GDPR compliance.
Why it matters: agents now act on behalf of employees, and 1Password’s own research found 40% of developers grant those agents persistent access to systems or credentials — exposure that can spread at machine speed. Tying access to a single task, rather than a lasting grant, is a direct answer to that risk.
What to watch next: whether rival identity and secrets platforms follow with their own agent-scoped access controls, and how the separately announced 1Password Credential Broker fares in its GitHub Actions public preview. Pricing was not disclosed.
Sources: 1Password press release (28 July 2026) · SiliconANGLE
Source: original announcement ›