Platform

Customers

Resources

Platform

Customers

Resources

Paladin: AI that applies your policy to every request

Andrew Graviet

0

1

Security runs on thousands of judgment calls a day. Paladin brings the context and the reasoning to the ones your team can't make one by one. That matters more every day, as agents multiply.

Approval becomes the default

Security in an enterprise runs on thousands of decisions a day. Someone requests a role, and a person is supposed to weigh who they are, what they already have, whether the request is risky, and whether it even makes sense:

  • Is permanent access to this resource really warranted?

  • Do we know why this service account exists, or what it is being used for?

  • Does this person already have something narrower that would do the job?

Most teams don't have the time, or the context, to answer questions like these manually.

Across half a million access requests on the Opal platform last year:

  • Median approval time stretched to 15 minutes, and latencies at some enterprises ran over 24 hours

  • 43.5 percent of granted access went unused for more than 90 days

It gets sharper with agents. This is the before picture, from our own platform, over the last 12 months:

  • Agent and non-human identities grew 2,300 percent and 90 percent of that access went unreviewed

  • Each agent holds 3x the entitlements of a person

  • Only 3.8 percent carry any description at all

Access is multiplying faster than humans can review it, attached to identities that often don't have clear descriptions or stated manifests.

Meet Paladin

Paladin is an AI reviewer that approaches an access decision the way your best security engineer would, if your best engineer had time to look at every one.

On every request it:

  1. Reads the request and what it is really asking for.

  2. Gathers the relevant context across your connected applications.

  3. Reasons through it against your policy.

  4. Puts forward a decision with its reasoning attached.


That last step is the one that matters. Paladin never hands you a bare yes or no. Every recommendation comes with a plain-language rationale, the signals it weighed and the conclusion it drew, so you can trust it because you can see how it got there.

The context it reasons with

A good access decision is mostly about context, and Paladin brings the context a careful reviewer would gather if they had the time.

What Opal already knows about the request:

  • The requester's existing access

  • What similar people on their team hold

  • How sensitive the resource is

  • How access like this tends to be used once it is granted

Where it reads from

Paladin reasons over the tools your team already runs on.


  • Policy and docs: Notion, Confluence

  • Tickets: Jira, Linear, ServiceNow, Shortcut, Freshservice

  • Incidents and on-call: PagerDuty

  • Device posture: FleetDM

  • Approval conversations: a pinned Slack channel you choose

You curate what it reads. Point one access-approvals channel at one app's requests, or hand Paladin the page that defines who should hold a role, and its recommendations reflect your organization rather than a generic model's best guess.

Automate the routine, escalate the rest

Most requests are routine and have a knowable right answer. The moment a request is risky, unusual, or ambiguous, Paladin does what a careful teammate would and brings in a human.

You decide where the line sits:

  • As an advisor. Paladin recommends on the clear cases, declines the ones that should not go through, and routes anything uncertain to a reviewer, with the person notified either way.

  • With more authority, as you build trust. Widen its scope to handle the routine, policy-conforming cases and escalate the rest.

Either way, its authority is graduated and it stays inside its lane. It only ever acts within the role you grant it, and every recommendation and decision is logged with its reasoning. The routine work stops consuming your reviewers, their attention goes where it actually matters, and you are audit-ready without anyone assembling evidence after the fact.

Where Paladin is going

Access requests are the first decision Paladin takes on, not the last. The same engine applies anywhere people are asked to judge access at a scale they cannot keep up with:

  • Role mining. Instead of hand-curating roles, Paladin learns the access people actually hold and use, and proposes clean roles and cohorts from the real patterns.

  • Policy suggestions. Paladin spots the access everyone in a cohort gets every time and suggests promoting it to auto-approval, while flagging the outliers worth a second look.

Same idea each time: bring full context to a decision people have been making blind, and give the routine cases back their speed without giving up rigor.

The bigger picture

Identity is becoming the place where security is won or lost, and the number of decisions is only going up, especially as agents and non-human identities multiply. Careful review does not scale by adding headcount. Paladin is how access decisions stay thoughtful at a volume people were never going to reach.

See Paladin on your own requests. Book a demo

AI that makes continuous access decisions, with you on the dial.

AI that makes continuous access decisions, with you on the dial.

AI that makes continuous access decisions, with you on the dial.

Everything you need to know about Opal

What is Opal Security and what does it do?

What systems does Opal integrate with?

How is Opal different from traditional IGA and IAM tools?

Can Opal govern AI agents and non-human identities?

Does Opal replace my existing identity stack?

How fast can Opal be deployed?

Who is Opal's leadership?

0

FAQ

Everything you need to know about Opal

What is Opal Security and what does it do?

What systems does Opal integrate with?

How is Opal different from traditional IGA and IAM tools?

Can Opal govern AI agents and non-human identities?

Does Opal replace my existing identity stack?

How fast can Opal be deployed?

Who is Opal's leadership?

0

FAQ

Everything you need to know about Opal

What is Opal Security and what does it do?

What systems does Opal integrate with?

How is Opal different from traditional IGA and IAM tools?

Can Opal govern AI agents and non-human identities?

Does Opal replace my existing identity stack?

How fast can Opal be deployed?

Who is Opal's leadership?

0

FAQ

See. Encode.

Enforce.

© 2026

See. Encode.

Enforce.

© 2026

See.

Enforce.

Encode.

© 2026