Skip to content
TECH CEO Daily

1Password CTO says AI agent access should be scoped to one task at a time

1Password's technology chief says agents should prove each task was done correctly before getting access for the next, an approach reflected in products it launched in July.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 11Password CTO Nancy Wang said at Oktane 2026 that AI agents need just-in-time, task-based access with credentials kept out of models.
  • 21Password Privileged Access, generally available since July 28, 2026, grants access per task and revokes it when sessions end.
  • 3Credential Broker launched as a public preview; in July, 1Password said it was still building more controls for AI agents.

The news

1Password CTO Nancy Wang said at Okta's Oktane 2026 conference that AI agent access should be granted one task at a time, SiliconANGLE reported on September 28, 2026. The approach mirrors access-control products 1Password launched in July.

Speaking with theCUBE Research, Wang described agents as hybrid identities that act partly like machines and partly like people; asked which they are, she said the answer is "probably both." She compared the model to supervising an intern, according to SiliconANGLE: an agent should prove it finished its last task with the right permissions before it moves to the next one.

Wang's pitch draws on 1Password Privileged Access, which 1Password, whose legal name is AgileBits Inc., launched on July 28, 2026 as a generally available product. The company said the product provisions access at the moment it is requested, scopes it to the task and removes it automatically when the work ends, for both human and AI identities. It is built on technology from Apono, which joined 1Password in June 2026, and covers cloud environments, databases and Kubernetes.

According to 1Password, low-risk requests can be approved automatically by policy, while higher-risk requests go to a human reviewer. Every request, approval and access event is logged with attribution, and access is revoked at the end of each session, the company said.

The second piece is 1Password Credential Broker, which entered public preview on July 28, 2026 for GitHub Actions and is open to 1Password Enterprise Password Manager Business customers. It checks a signed identity token from the requesting workload before issuing a credential scoped to that request, and logs each delivery. 1Password said custom OpenID Connect (OIDC) workflows, a beta capability it is rolling out gradually, extend the model to other workloads that issue such tokens, including AI agent frameworks, and that it is working on additional controls for AI agents.

Wang also said 1Password and Okta (OKTA) are backing shared identity standards so an agent's verified identity and authorization context can carry across their systems, according to SiliconANGLE. Okta's own Oktane 2026 announcement, published September 23, introduced Cross App Access, an open protocol for agent-to-app connections, and a Blueprint Alliance whose named members include AWS, CrowdStrike, Databricks, Google Cloud, Salesforce and ServiceNow. That Okta page does not mention 1Password.

The numbers

Developers who grant agents persistent access, per 1Password research (methodology not disclosed)
40%
1Password Privileged Access general availability
July 28, 2026
Apono joined 1Password
June 2026

Why CEOs should care

For CISOs, the case for task-scoped access is about limiting damage. An agent holding standing credentials can use everything those credentials allow if it is compromised or misbehaves; one scoped to a single task and revoked afterward exposes far less. 1Password said its own research found 40% of developers grant agents persistent access to systems or credentials. Its release did not disclose the sample size or methodology, so the figure is worth testing against your own environment.

For technology buyers comparing agent platforms, the useful questions are concrete. Can every agent action be traced to both the agent and the human who authorized it? Are secrets ever placed in the model's context or in plaintext configuration files? Is access issued per task and revoked automatically, and who approves high-risk requests? Buyers should also note maturity: Credential Broker launched as a public preview, its custom OIDC workflows for other workloads are in beta, and 1Password described extra AI agent controls as work in progress in July.

For CFOs and boards, just-in-time access produces audit evidence: a record of who requested access, who approved it and when it ended. That can ease compliance reviews, but approval steps can also slow automation. Leaders should ask which agent actions are auto-approved by policy, who owns that policy, and how often it is reviewed.

The bigger picture

Both companies are positioning to secure AI agents. Okta used Oktane 2026 to introduce Agent SSO, built on Cross App Access, along with its blueprint for securing agents, while 1Password is stretching from password management into privileged access. 1Password frames its approach around zero standing privilege, meaning no identity, human or machine, keeps access it is not actively using; Okta says its tools help enterprises find agents, define what they can do and respond when something goes wrong.

Help Net Security's coverage of the July launch quoted 1Password CEO David Faugno saying access must be granted for a specific task and removed when the work is done. Wang's Oktane remarks apply that pitch specifically to agents, which can chain many tasks together without a person checking each step.

What’s next

1Password's July announcement gave no general availability date for Credential Broker or its additional AI agent controls. Watch whether the shared standards work Wang described with Okta turns into published specifications or product integrations, and whether other vendors adopt Cross App Access for agent connections.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

1PasswordOktaNancy WangAI agentsIdentity security

Earlier coverage of Okta

All Okta coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.