Skip to content
AI.info

The Pulse

Opal Launches Zero to Give AI Agents Just-in-Time Access

Opal Security has launched Opal Zero, a platform that evaluates AI-agent access requests in real time and writes scoped, time-bound permissions into existing MCP gateways. The company says the product supports Claude, OpenAI, Cursor, Databr

Opal Launches Zero to Give AI Agents Just-in-Time Access

AI.info Team ·

“Long standing credentials for AI agents are basically full compromise with a delay timer.”

Mrityunjay Gautam, chief information security officer at Instacart

Opal Security launched Opal Zero on September 17, pitching it as an access-governance system for enterprise AI agents that decides permissions when an agent asks for them rather than leaving broad credentials in place.

The product evaluates each request against security policy and organizational context, then sends a scoped, time-bound decision to the MCP gateway an organization already operates. Opal says the approach avoids adding a second proxy to the request path while giving security teams a record of the decision and its reasoning.

Opal Zero is built for agents running across Claude, OpenAI, Cursor, Databricks Unity Gateway and other platforms. The company says it was developed with design partners including Faire, Databricks, Elastic and Superhuman.

Paladin makes the access decision

The central component is Paladin, a reasoning model inside Opal Zero. According to Opal, Paladin examines an agent’s owner, declared purpose, current access, potential blast radius, credential lifetime and recent activity before deciding whether a request fits policy.

Opal’s launch materials give the example of an agent described as a testing tool but connected to an HR system containing stock-compensation information. That mismatch between declared purpose and reachable resources becomes part of the decision context. The agent submits the request through Opal’s MCP server, while Paladin records its reasoning and produces an audit trail.

Opal Chief Product Officer Sameer Mehta said the system can also draw on operational context from tools such as Slack, Jira and PagerDuty. A privileged request made during an active incident, he said, may be treated differently from the same request under ordinary conditions.

From inventory to enforcement

Opal Zero combines five functions. Inventory collects agents from systems including Okta, Microsoft Entra, Anthropic, AWS Bedrock AgentCore, OpenAI and Cursor, then maps each agent to an owner, purpose and reachable resource.

Risk Center identifies unowned or dormant agents, standing privileges, access beyond an agent’s stated purpose and connections to sensitive resources. The product routes remediation to the relevant owner, who can assign ownership, revoke access or deactivate the agent.

Policy Insights examines real agent behavior instead of treating each access request as an isolated ticket. Opal says it scores policies on access hygiene, approval efficiency, right-sizing and time to access, and estimates the waiting time and unused access created by existing rules.

Gateway Sync then writes each decision into the organization’s existing MCP gateway as a policy specifying what the agent may reach, for how long, whose approval applies and when the permission ends. The launch supports Databricks Unity Gateway and AWS AgentCore Gateway, with Opal saying the system can work with any MCP gateway.

Opal cites a large identity-governance gap

Opal says its research found that more than 96% of non-human identities have no recorded purpose and that only 10% of their access had been reviewed in the previous year. The company uses those figures to frame agent governance as an ownership and authorization problem, not only an inventory problem.

The launch also reflects Opal’s effort to apply the same governance model to people, service accounts and agents. Its product materials describe an agent as having an owner, a business purpose, an access record and review obligations comparable to those applied to human identities.

That model places limits on what Opal Zero claims to do. The platform does not replace the identity provider or the MCP gateway. Instead, it supplies a decision layer that determines whether a particular request should receive temporary, narrowly scoped access.

Claude, Unity Gateway and Okta integrations

At launch, Opal says it is integrating with Anthropic’s Claude Compliance API, Claude Code administrative controls and Enterprise-Managed Authorization for MCP connectors. Those connections are intended to bring Claude deployments, API keys and managed agents into the same access graph as other identities.

The Databricks integration sends decisions to Unity Gateway, which controls access from model calls and MCP tools through to underlying data. Opal also supports Okta Cross App Access, an authorization standard for agent-to-application connections, and says those connections can be assigned owners, reviewed and revoked under the same rules.

Databricks Staff Systems Engineer Jack Zaldivar Jr. said Unity Gateway provides a single place to see what agents can reach, while Opal Zero helps express those permissions in policy. Superhuman’s Head of Corporate IT and Security Den Potapenko described the product as moving beyond inventory toward real-time, policy-driven decisions.

A $30,000 launch offer

Opal says Opal Zero is generally available at the end of September. The company is offering the platform for $30,000 for a 12-month term through December 30, with the launch offer covering inventory, Risk Center, Policy Insights, Paladin and Gateway Sync.

The pricing is based on human headcount rather than the number of agents, according to Opal’s product page. The company says organizations with fewer than 3,000 employees qualify for the launch offer, while larger organizations must inquire about an enterprise package.

For security teams, the product’s practical test will be whether real-time decisions can reduce standing permissions without slowing agents that need access to complete work. Opal’s announced design is specific: the permission should be narrow, tied to a purpose, recorded and removed when its time or task ends.

Source

Opal Security

Explore

More articles