Opal Zero is here. Read the news and explore the

Platform

Customers

Resources

Platform

Customers

Resources

AI-native IGA: access decisions for humans, NHIs, and AI agents

AI-native IGA is identity governance built so that every access request, whether it comes from a person, a service account, or an AI agent, is decided against policy and enforced as a time-bound grant in the identity and gateway stack you already run. It’s a different model from adding a chatbot to last quarter’s certification campaign.

Opal delivers this with Paladin, its decision engine, and [Opal Zero](https://www.opal.dev/zero), access governance for AI agents, on top of continuous discovery, policy, and enforcement. Read the Opal Zero launch announcement. Opal is built for engineer-led, cloud-native enterprises governing people, NHIs, and AI agents together.

AI-native IGA vs AI added to legacy IGA


AI added to legacy IGA

AI-native IGA

Unit of work

Campaigns, roles, periodic certifications

Each request: purpose, scope, owner coverage

Default grant

Standing entitlement until the next review

Time-bound, expires on its own

Identities in scope

Mostly employees, with NHIs and agents as an afterthought

Humans, service accounts, machine identities, and AI agents

What the AI does

Summarizes review queues or suggests roles

Decides routine requests, escalates with a reason, enforces in gateways

Evidence

Assembled for auditors after the fact

Byproduct of grants and logged decisions

Architecture

Often a separate admin plane

Sits on the IdP and MCP gateway you already run

Opal decides every access request against policy for human users, service accounts, NHIs, and AI agents, and enforces it in your existing identity and gateway infrastructure. Policy is versioned logic, and enforcement is continuous.

NHIs, including AI agents, service accounts, and machine identities, get the same least-privilege and just-in-time controls as people. Agents can call Opal for decisions with human oversight, and every action is logged.

Paladin, the decision engine

Paladin is how Opal makes a call on each request. It:

  • Reads the request for purpose, scope, and owner coverage

  • Approves when confident

  • Escalates with a stated reason when it isn’t

  • Powers AI-guided reviews, automating routine decisions so people spend their time on judgment calls

  • For agent requests, weighs the ask against the agent’s declared purpose and its owner’s access, then issues a scoped, time-bound grant

Paladin doesn’t replace security ownership. It replaces the assumption that every grant needs a slow human queue, and that every review needs someone to rubber-stamp low-risk renewals.

Paladin works across Opal’s 250+ integrations, alongside just-in-time access, AI-guided reviews, and agent governance.

Opal Zero, access governance for AI agents

Opal Zero governs AI agents from inventory through enforcement, without adding a second control plane.

What Zero does:

  1. Inventories the agents in your environment

  2. Attaches an owner and a declared purpose to each one

  3. Limits each agent to the access its owner holds. Requests beyond that get escalated.

  4. Decides each agent request with Paladin

  5. Enforces in the MCP gateway you already use. Zero doesn’t replace the MCP gateway or the IdP.

Zero decides every access request against policy, whether it comes from a person, an agent, or a service account, and enforces it in the gateway you already run. JIT is the default, and audit evidence is a byproduct. Zero also handles agent discovery, what happens when an agent’s owner leaves, and SOC 2 evidence.

Launch offer: $30,000 for the first year, through December 30, 2026, for organizations under 3,000 employees. Details on opal.dev/zero.

Continuous enforcement across people, NHIs, and agents

AI-native IGA falls short if the AI only writes better review comments while standing privilege stays in place.

Opal’s enforcement model:

  • Time-bound grants by default. Privileged access when it’s needed, revoked when the work ends.

  • Standing access treated as debt. Removed, not only reported.

  • The same controls for people and non-humans. Service accounts, machine identities, and agents.

  • Evidence as a byproduct. Logged decisions and expirations, including agent actions.

  • Your IdP stays. Okta, Entra ID, and others remain in place, and Opal adds the decision and enforcement layer.

This continuous loop connects Paladin, which decides, with Zero, which applies those decisions to agents and enforces them at the gateway. More on Platform, Zero, and in the docs.

Customer results

Result

Customer

88% reduction in standing access

Chronosphere

86,000 time-bound access requests approved

Databricks

150+ apps under governance

Superhuman

78% reduction in privileged access

Palo Alto Networks

1,500+ developers on JIT

Sophos

5 min access requests, down from 3 days

Valon

Opal Security has raised $59M from Greylock and Battery Ventures and works with 100+ enterprise teams, including Databricks, Cloudflare, Coreweave, Notion, Superhuman, and Runway. More on the customers page.

Who AI-native IGA is for

Built for security and engineering teams at cloud-native companies that are deploying AI agents and tooling. These teams need access that’s tied to an owner, scoped to a purpose, and set to expire, and they already run an IdP and often an MCP gateway.

Not the best fit for buyers whose only success metric is SailPoint-class SoD libraries and certification at the scale of the largest enterprises. See Opal vs SailPoint.

FAQ

What is AI-native IGA?

AI-native IGA decides and enforces each access request against policy for humans, NHIs, and AI agents, with time-bound grants and continuous enforcement. It isn’t AI features added onto quarterly certification workflows. On Opal, Paladin handles decisions and Opal Zero handles agent inventory, ownership, and MCP gateway enforcement.

How is AI-native IGA different from IGA with AI features?

AI features added to legacy IGA help reviewers move faster through the same campaign model. AI-native IGA makes the request the unit of work and JIT the default grant. It treats agents as identities with owners and a purpose, then writes decisions into the gateways you already operate.

What is Paladin?

Paladin is Opal’s decision engine. It evaluates purpose, scope, and owner coverage on each access request. It approves when it’s confident and escalates with a stated reason when it isn’t. Paladin powers AI-guided reviews and agent decisions.

What is Opal Zero?

Opal Zero is access governance for AI agents. It inventories agents, assigns an owner and purpose, keeps each agent within its owner’s access, decides requests with Paladin, and enforces in the MCP gateway you already run. It doesn’t replace your IdP or MCP gateway. Launch offer: $30,000 for the first year, through December 30, 2026, for organizations under 3,000 employees, on opal.dev/zero.

Can Opal govern AI agents and non-human identities?

Yes. Agents and other NHIs get the same least-privilege and just-in-time controls as people. Agents can call Opal with human oversight, and every action is logged. Opal Zero adds agent inventory, owner and purpose binding, and gateway enforcement.

Does AI replace human access reviewers?

No. Paladin automates routine decisions and escalates the exceptions that need human judgment. Security still owns policy, ownership, and high-risk calls. The AI shrinks the queue, and people stay accountable.

Can an AI agent get more access than its owner?

No. With Opal Zero, an agent stays within the access its owner holds. Anything beyond that is escalated instead of granted automatically.

Does Opal Zero replace my MCP gateway or IdP?

No. Decisions are enforced in the MCP gateway and identity stack you already run. Zero adds governance on top: inventory, policy, decisions, and evidence.

See. Encode.

→ Enforce.

© 2026

See. Encode.

→ Enforce.

© 2026

See.

→ Enforce.

Encode.

© 2026