Access has outgrown human scale: more requests, more reviews, more identities, and now agents. This release goes after that directly.
Three products are now generally available, plus MCP updates for agents and new integrations, all running on one platform and one access graph across employees, service accounts, and AI agents.
Paladin: AI in every access decision
Reviewers face a bad tradeoff: slow approvals or rubber stamps. Paladin reviews each request the way a senior security engineer would: it collects the context and reasons through the decision. Now GA for all cloud customers.
Reads each request and gathers context from the tools you already run on
Reasons against your policy and shows its work on every decision
You set the dial: advisor on the clear cases, or handling the routine ones and escalating the rest
Opt-in, scoped to the role you grant it, and every decision is logged
Read the deep dive, Paladin: AI that applies your policy to every request, or try it in the docs.
Access Campaigns: reviews that shrink your attack surface
43.5 percent of granted access goes unused, and every unused grant is standing risk. Campaigns cuts the drag at both ends: scope in a sentence, assign with filters and grouping, and reviewers finish in one table, so the access that should go actually goes. A ground-up refresh of Opal’s access reviews, not a new product. Now GA.
Scope with natural language or a query builder, with a preview before launch
Assign reviewers fast with filtering, sorting, and grouping
Track every pending review in one filterable table
Keep campaigns moving with reassignment, custom start messages, and bulk reminders
Available now for cloud, with self-hosted right behind. If you are on legacy Access Reviews, existing reviews keep running as normal. See more in the docs.
OpalScript: your access policy, as code
Policy applied by hand drifts: the same request can get different answers depending on who reviews it and when. OpalScript turns your policies into code, so the same rules run on every request. Now GA.
Catch separation of duties violations before they happen
Enforce duration limits and auto-approve when your criteria are met
Reach external systems through the built-in HTTP library
Version-controlled and testable, so policy ships like the rest of your code
See more in the docs.
Governing agents, not just people
Agents authenticate through the same identities as your employees and act at machine speed. Opal is built for that: API-first, with Terraform, a REST API, and MCP, agents request access the same way developers do. New on that front:
Opal MCP servers: self-hosted, scoped, and approval-ready
OAuth for Opal MCP: give agents scoped, expiring access instead of a standing key
New integrations
Available now:
Docusign: manage users, groups, and permission profiles directly in Opal.
Okta OAuth 2.0: stronger auth support for enforcing least privilege.
Tableau: native user and group management.
Lark: interactive Opal notifications for requestors and reviewers.
Also new
Available now:
Access Comparison: spot access drift between users and fix it in a few clicks
Get started
Opal is the access control plane for every identity.
See any of this in your own environment: book a demo or start in the docs.





