Opal Security Launches Opal Zero to Make Least Privilege a Reality for Enterprise AI Agents
Opal Security Launches Opal Zero to Make Least Privilege a Reality for Enterprise AI Agents
Opal Zero brings dynamic AI-based decisioning to enable frictionless just-in-time access governance to AI agents across Claude, OpenAI, Cursor, and other platforms
SAN FRANCISCO--(BUSINESS WIRE)--Enterprises are moving fast on AI agents, and the controls have to adapt just as fast. Access policy is where those controls get encoded: what each agent may reach, for how long, and on whose authority. Opal Labs found that more than 96% of non-human identities have no recorded purpose, and only 10% of their access has been reviewed in the past year. Least privilege for agents means grants that expire, an owner for every agent, and a decision at the point of access.
Opal Security today launched Opal Zero to bring least privilege to AI agents across the enterprise. The first generation of agent governance tools stops at inventory and discovery, or puts a proxy of their own in the path and typically enforces a permanent grant. Opal Zero decides each agent request the moment it's made, against the security team's policy and organizational context, then enforces it as carefully scoped permissions in the gateway already in place.
Opal Zero was built with design partners Faire, Databricks, Elastic, and Superhuman, and in close collaboration with security industry leaders. It launches with integrations across the agent stack, including Claude, Databricks Unity Gateway, and Okta Cross App Access.
“Long standing credentials for AI agents are basically full compromise with a delay timer. Static auth was never built for entities that spin up, act non-deterministically, and disappear in milliseconds. Opal Zero gets that agentic accountability isn't a compliance checkbox, it's an architecture problem, and they are building the plumbing for it. Excited to see the evolution of Opal Zero, now providing JIT access control at agentic speed in production and enterprise environments,” said Mrityunjay Gautam, Chief Information Security Officer at Instacart.
“Agent adoption moves faster than governance usually does. Closing that gap means seeing every agent and non-human identity, knowing who owns it, and using AI to match policy to purpose in real time. As a design partner, we have been part of these conversations from early on and are excited about what Opal Zero does for the agentic world,” said Mallory Rudolph, IT IAM Engineer at Faire.
Opal Zero drives efficiency and reduces risk across your entire agent lifecycle.
See every agent, its owner and its access. Inventory ingests agents from Okta, Entra, Anthropic, AWS Bedrock AgentCore, OpenAI, Cursor, and more, and maps each to an owner, a purpose and what it can reach, with people and agents held to the same record. That context gives Opal Zero the foundation to make better access decisions, ensuring ownership and purpose are understood before a decision is made.
Revoke risky agent access at the source. Risk Center identifies risky agent access: unowned or dormant agents, standing privileges, access beyond an agent's purpose, and access to sensitive resources. It combines ownership, purpose, access and activity signals to explain why each risk matters and routes the fix to the owner, who can assign ownership, revoke unnecessary access, or deactivate the agent. When ownership or purpose changes, Opal Zero surfaces the agent for review.
Decide every request by policy and context, the moment it's made. Paladin, the reasoning model inside Opal Zero, reads each agent request the way a security engineer would: against written policy and the context around the request, including who owns the agent, what it was built for, and whether the ask reaches past what its owner holds. The agent files that request itself, through Opal's MCP server, and Paladin shows its reasoning and leaves a full audit trail.
Sharpen access policy from real agent behavior. Policy Insights scores each policy on access hygiene, approval efficiency, right-sizing and time to access, with people and agents measured on the same terms. It prices what the current policy costs in waiting time and unused access, and proposes the change with its confidence attached, so the security team fixes the policy that produced the risk rather than the ticket that surfaced it.
Enforce each decision in the gateway already in place. Opal Zero works with the MCP gateway the enterprise already runs, whichever it is. Gateway Sync writes each decision into that gateway as scoped, time-bound policy: what the agent may reach, for how long, on whose approval, and when it ends. The gateway enforces the full decision, and no second proxy is added to the path. Gateway Sync supports any MCP gateway, including Databricks Unity Gateway and AWS AgentCore Gateway at launch.
Opal Zero is an open platform across identity providers, model providers, agent platforms and gateways, and it launches with integrations across the full agent ecosystem. Among them:
Claude. Opal Zero is integrating with the Claude Compliance API, admin controls for Claude Code, and Enterprise-Managed Authorization for MCP connectors to bring Claude deployments, API keys, and agents into the same access graph as the workforce. They’re owned by policy, reviewed in Access Campaigns, and revoked when their owner leaves or purpose ends.
Databricks Unity Gateway. Unity Gateway gives Databricks customers a single place to see and control what every agent is touching, from model calls to MCP tools to the underlying data. Opal Zero sharpens how that access is expressed in policy: each agent request is decided by policy and context, then handed to Unity Gateway as scoped, time-bound policy to enforce.
Okta Cross App Access. Opal Zero works with Okta Cross App Access (XAA), the open standard through which Okta authorizes agent-to-app connections, bringing every connection authorized through Okta into Opal's access graph with an owner, a purpose and a time bound, reviewed and revoked on the same terms as human access.
“Agent identities are multiplying fast, and we want our controls to scale with that curve rather than just keep pace. Unity Gateway gives us a single place to see and control what every one of them is touching, from model calls to MCP tools to the underlying data. Opal Zero helps sharpen how we express that access in policy. Together it means we can expand what agents reach and stay confident in how they reach it,” said Jack Zaldivar Jr., Staff Systems Engineer at Databricks.
“AI agents are quickly becoming first-class identities across the AI platforms enterprises rely on. The challenge isn't simply discovering them, it's continuously governing what they can access, knowing who owns them, and ensuring they only receive the minimum permissions required for the task at hand. Opal Zero moves beyond inventory by helping organizations make real-time, policy-driven access decisions throughout an agent's lifecycle,” said Den Potapenko, Head of Corporate IT and Security at Superhuman.
“We use Opal for workforce access today, so we're interested in how Opal Zero could support access governance for AI agents. Directionally, we want agents to have clear owners, be included in standard access reviews, and leverage just-in-time access rather than standing credentials,” said Jean-Sebastien Caron, Senior Manager, InfoSec Security Architecture, at Elastic.
Opal Zero is generally available at the end of September.
Launch offer: Opal Zero is available at $30,000 for 12 months, offer available through December 30. Visit opal.dev/zero for details and to schedule a demo.
About Opal
Opal is the access control plane for every identity, across humans, NHIs, and AI agents, giving security teams real-time visibility, policy-as-code and direct control. Opal has raised $59 million from Greylock Partners, Battery Ventures, Box Group, SVCI and Cambium Capital, and was named to Notable Capital's Rising in Cyber 2026 list.
Contacts
Media contact: Christine Ooley. christine@opal.dev
