Opal Zero is here. Read the news and explore the
AI-native IGA: access decisions for humans, NHIs, and AI agents
AI-native IGA is identity governance built so that every access request, whether it comes from a person, a service account, or an AI agent, is decided against policy and enforced as a time-bound grant in the identity and gateway stack you already run. It’s a different model from adding a chatbot to last quarter’s certification campaign.
Opal delivers this with Paladin, its decision engine, and [Opal Zero](https://www.opal.dev/zero), access governance for AI agents, on top of continuous discovery, policy, and enforcement. Read the Opal Zero launch announcement. Opal is built for engineer-led, cloud-native enterprises governing people, NHIs, and AI agents together.
Related: What is IGA · Access governance · Opal vs SailPoint
AI-native IGA vs AI added to legacy IGA
AI added to legacy IGA
AI-native IGA
Unit of work
Campaigns, roles, periodic certifications
Each request: purpose, scope, owner coverage
Default grant
Standing entitlement until the next review
Time-bound, expires on its own
Identities in scope
Mostly employees, with NHIs and agents as an afterthought
Humans, service accounts, machine identities, and AI agents
What the AI does
Summarizes review queues or suggests roles
Decides routine requests, escalates with a reason, enforces in gateways
Evidence
Assembled for auditors after the fact
Byproduct of grants and logged decisions
Architecture
Often a separate admin plane
Sits on the IdP and MCP gateway you already run
Opal decides every access request against policy for human users, service accounts, NHIs, and AI agents, and enforces it in your existing identity and gateway infrastructure. Policy is versioned logic, and enforcement is continuous.
NHIs, including AI agents, service accounts, and machine identities, get the same least-privilege and just-in-time controls as people. Agents can call Opal for decisions with human oversight, and every action is logged.
Paladin, the decision engine
Paladin is how Opal makes a call on each request. It:
Paladin doesn’t replace security ownership. It replaces the assumption that every grant needs a slow human queue, and that every review needs someone to rubber-stamp low-risk renewals.
Paladin works across Opal’s 250+ integrations, alongside just-in-time access, AI-guided reviews, and agent governance.
Opal Zero, access governance for AI agents
Opal Zero governs AI agents from inventory through enforcement, without adding a second control plane.
What Zero does:
Inventories the agents in your environment
Attaches an owner and a declared purpose to each one
Limits each agent to the access its owner holds. Requests beyond that get escalated.
Decides each agent request with Paladin
Enforces in the MCP gateway you already use. Zero doesn’t replace the MCP gateway or the IdP.
Zero decides every access request against policy, whether it comes from a person, an agent, or a service account, and enforces it in the gateway you already run. JIT is the default, and audit evidence is a byproduct. Zero also handles agent discovery, what happens when an agent’s owner leaves, and SOC 2 evidence.
Launch offer: $30,000 for the first year, through December 30, 2026, for organizations under 3,000 employees. Details on opal.dev/zero.
Continuous enforcement across people, NHIs, and agents
AI-native IGA falls short if the AI only writes better review comments while standing privilege stays in place.
Opal’s enforcement model:
Time-bound grants by default. Privileged access when it’s needed, revoked when the work ends.
Standing access treated as debt. Removed, not only reported.
The same controls for people and non-humans. Service accounts, machine identities, and agents.
Evidence as a byproduct. Logged decisions and expirations, including agent actions.
Your IdP stays. Okta, Entra ID, and others remain in place, and Opal adds the decision and enforcement layer.
This continuous loop connects Paladin, which decides, with Zero, which applies those decisions to agents and enforces them at the gateway. More on Platform, Zero, and in the docs.
Customer results
Result
Customer
88% reduction in standing access
Chronosphere
86,000 time-bound access requests approved
Databricks
150+ apps under governance
Superhuman
78% reduction in privileged access
Palo Alto Networks
1,500+ developers on JIT
Sophos
5 min access requests, down from 3 days
Valon
Opal Security has raised $59M from Greylock and Battery Ventures and works with 100+ enterprise teams, including Databricks, Cloudflare, Coreweave, Notion, Superhuman, and Runway. More on the customers page.
Who AI-native IGA is for
Built for security and engineering teams at cloud-native companies that are deploying AI agents and tooling. These teams need access that’s tied to an owner, scoped to a purpose, and set to expire, and they already run an IdP and often an MCP gateway.
Not the best fit for buyers whose only success metric is SailPoint-class SoD libraries and certification at the scale of the largest enterprises. See Opal vs SailPoint.
FAQ
What is AI-native IGA?
AI-native IGA decides and enforces each access request against policy for humans, NHIs, and AI agents, with time-bound grants and continuous enforcement. It isn’t AI features added onto quarterly certification workflows. On Opal, Paladin handles decisions and Opal Zero handles agent inventory, ownership, and MCP gateway enforcement.
How is AI-native IGA different from IGA with AI features?
AI features added to legacy IGA help reviewers move faster through the same campaign model. AI-native IGA makes the request the unit of work and JIT the default grant. It treats agents as identities with owners and a purpose, then writes decisions into the gateways you already operate.
What is Paladin?
Paladin is Opal’s decision engine. It evaluates purpose, scope, and owner coverage on each access request. It approves when it’s confident and escalates with a stated reason when it isn’t. Paladin powers AI-guided reviews and agent decisions.
What is Opal Zero?
Opal Zero is access governance for AI agents. It inventories agents, assigns an owner and purpose, keeps each agent within its owner’s access, decides requests with Paladin, and enforces in the MCP gateway you already run. It doesn’t replace your IdP or MCP gateway. Launch offer: $30,000 for the first year, through December 30, 2026, for organizations under 3,000 employees, on opal.dev/zero.
Can Opal govern AI agents and non-human identities?
Yes. Agents and other NHIs get the same least-privilege and just-in-time controls as people. Agents can call Opal with human oversight, and every action is logged. Opal Zero adds agent inventory, owner and purpose binding, and gateway enforcement.
Does AI replace human access reviewers?
No. Paladin automates routine decisions and escalates the exceptions that need human judgment. Security still owns policy, ownership, and high-risk calls. The AI shrinks the queue, and people stay accountable.
Can an AI agent get more access than its owner?
No. With Opal Zero, an agent stays within the access its owner holds. Anything beyond that is escalated instead of granted automatically.
Does Opal Zero replace my MCP gateway or IdP?
No. Decisions are enforced in the MCP gateway and identity stack you already run. Zero adds governance on top: inventory, policy, decisions, and evidence.