Opal Zero is here. Read the news and explore the
Opal Zero is the end-to-end access governance platform for AI agents, announced today. Chief Product Officer Sameer Mehta on what it is, which design partners shaped it, and why the goal is reducing standing access to zero.
What is Opal Zero?
Opal Zero is just-in-time access governance for AI agents. Opal is the access control plane for every identity, and with Opal Zero that now covers agents on the same terms as humans and NHIs. In practice, least privilege for agents means three things: grants that expire, an owner for every agent, and a decision at the point of access.
It works in five parts. Inventory sees every agent, its owner and its access. Risk Center revokes risky agent access at the source. Paladin, the reasoning model inside Opal Zero, decides every request by policy and context the moment it’s made. Policy Insights sharpens policy from real agent behavior. Gateway Sync enforces each decision in the gateway already in place.
Why build it now?
Because this is already happening. Agents are multiplying far faster than headcount, so the number of access decisions is multiplying with them, and humans can’t keep up.
Opal Labs found that more than 96% of non-human identities have no recorded purpose, and only 10% of their access has been reviewed in the past year. If nobody can say what an agent is for, nobody can say whether its access is appropriate.
How is that different from what’s already out there?
The first generation of tools stops at inventory and discovery. Others put a proxy of their own in the path and then enforce a permanent grant, which is the thing we’re supposed to be getting away from.
Opal Zero decides each request the moment it’s made, against policy and context, then enforces it as scoped permissions in the gateway already in place.
Which design partners shaped the product, and how?
When I joined Opal, one of the key reasons was to co-build with best-in-class companies. Databricks, Elastic, Faire, Superhuman. All of them pushing the boundary on how agents get access to resources.
The needs were genuinely different. For some it’s automation, because granting agent access has been manual and they want that loop closed faster. For others it’s visibility, because the agents they worry about are the ones they don’t know exist. The platform is sanctioned, but nobody can say what the agent is reaching.
What does the problem look like in practice?
Today, for an agent to get access to any resource, someone files a support ticket. Everything in the manifest has to be documented there. What it needs access to, through which interface, how long the credential stays active. Extremely manual, because the security person on the other end has no idea what these agents actually do.
So we helped one customer define a policy. Reading logs from a database, Paladin auto-approves. Any update or critical action, modify, write, delete, always has a human in the loop.
That was the key insight. Building the right policy for agents, with real segregation of duty, matters as much as anything else. Without it you either increase risk or add time to every ticket.
What are the capabilities, and which are the most differentiated?
Inventory is the foundation: see every agent, its owner and its access. It ingests agents from Okta, Entra, Anthropic, AWS Bedrock AgentCore, OpenAI, Cursor and more, and maps each one to an owner, a purpose and what it can reach, with people and agents held to the same record. Ownership and purpose have to be understood before any decision gets made. Beyond that, four things differentiate us.
Risk Center revokes risky agent access at the source: unowned and dormant agents, standing privileges, access that reaches beyond an agent's purpose, access to sensitive resources. It explains why each risk matters and routes the fix to the owner. The outcome isn't another dashboard. It's less risky access.
Policy Insights sharpens access policy from real agent behavior. Fundamentally this is what all of IGA is about: who has access to what and why. We score the policy itself, on access hygiene, approval efficiency, right-sizing and time to access, so you fix the policy that produced the risk rather than the ticket that surfaced it.
Paladin decides every request by policy and context, the moment it's made. AI approving AI.
And open architecture, which Opal has always been on the frontier of. Opal Zero is an open platform across identity providers, model providers, agent platforms and gateways, so Gateway Sync enforces each decision in the gateway already in place. We become the intelligence rather than another thing in the path.
What does Paladin use to make an accurate, real-time judgment?
The gap between what an agent says it's for and what it can actually reach.
It evaluates each request against your policy and everything Opal knows about that agent: its owner, its declared purpose, what it can reach today, its blast radius, whether it's carrying a long-lived credential, and what its activity says it actually does. It also pulls from the systems the work happens in, like Slack, Jira and PagerDuty, so a privileged request during an active incident reads differently than the same ask on a normal Tuesday.
So if the manifest says this agent is just for testing but it has access to an HR system and therefore to stock compensation plans, that doesn't match the purpose. Paladin escalates and a human gets involved. The agent files the request itself through Opal's MCP server, and Paladin shows its reasoning and leaves a full audit trail.
And then enforcement?
We integrate with the best MCP gateways out there, and that’s a strategy call: a gateway sees all the traffic, human and agent. Databricks Unity Gateway, AWS AgentCore. Customers use infrastructure they’ve already provisioned rather than adding more.
We become the intelligence. Gateway Sync writes each decision in as scoped, time-bound policy and the gateway enforces it. Other vendors only let you act on their recommendations inside their own gateway. We’re not that.
Opal Zero launches with integrations across the agent stack. What's the logic there?
Agents don't live in one vendor's world, so the integrations follow where they actually run.
With Claude, we're bringing deployments, API keys and agents into the same access graph as the workforce, so they're owned by policy and revoked when the owner leaves or the purpose ends. With Databricks Unity Gateway, we sharpen how access is expressed in policy and hand it to the gateway to enforce. With Okta Cross App Access, every agent-to-app connection Okta authorizes arrives with an owner, a purpose and a time bound, reviewed on the same terms as human access.
Where is the industry going from here?
A lot of SaaS companies are becoming AI platform companies. That means our customers will be building agents on more and more platforms, and we’ll have to support that, which starts with inventorying agents across many different sources.
And this launch is a starting point. The whole goal is to reduce standing access to zero. That’s why we named it Opal Zero. From here it’s task-based permissions and scopes for each agent, in line with its purpose and its MCP tool call chain, and redacting anything outside that. The brand should match exactly what the product does.
Launch offer: Opal Zero is available at $30,000 per year through December 30. Visit opal.dev/zero for details and to schedule a demo.




