
Let your agents run. (safely)
Opal Zero inventories every agent, maps to an owner, decides every request it makes, and enforces that decision in the MCP gateway you already run.
0
1
The problem
You want your agents to run. But you need to give them the appropriate access.
0
2
Unlike humans, agents lack inhibition.
Humans
Deliberate about what they request and what they use.
Agents
Inherit broad access, use it, and multiply faster than human judgment can scale.
agent and NHI growth
more entitled than a person
never reviewed
0
3
It's a million-to-one decision problem.
Not a hundred-to-one identities problem.
The CISO's mandate
Written policy
Request context
Approved in 90s
invoices.write only
Expires in 4h
Reasoning recorded

Can you approve this, the invoice run is blocked...
Absolutely, feel free to proceed!
The whole decision
Approved in 30s
Full Stripe admin
No expiry
No record
0
4
What the industry is saying
“Opal Zero gets that agentic accountability isn’t a compliance checkbox, it’s an architecture problem, and they are building the plumbing for it.”
Mrityunjay Gautam · CISO, Instacart
instacart
See every agent
Okta
Entra
Anthropic
OpenAI
Bedrock AgentCore
CURSOR
One inventory of every agent across the identity providers and AI platforms you already run.
Surface the risk
Off-purpose
Unowned
Standing access
Inline fix
What's off-purpose, unowned, or standing, explained by the product and routed to the owner with the fix inline.
Fix the cause
Policy change
waiting time
unused access
One policy change beats a thousand one-off remediations. Prices waiting time and unused access in hours and dollars.
Decide every request
Least-privileged path
Owner boundary
Shown reasoning
Reads each request the way your best security engineer would, and shows its reasoning.
Enforce the decision
Unity Gateway
AgentCore Gateway
Scoped
Time-bound
Writes the decision as scoped, time-bound policy into the MCP gateway you already run. No rip and replace, no second control plane.
0
standing permissions
human toil
friction
0
6
Launch offer, through 30 Dec
Three Zero for the first year.
Every agent inventoried, every request decided, every decision enforced. No agent cap, no procurement cycle before you can see it working.
THE TERMS
Agent control is uncapped
Full Opal Zero platform. Inventory, Risk Center, Policy Insights, Paladin and Gateway Enforcement.
Per human identity, billed annually
Opal Zero is priced based on your headcount, not on agent count. Agent growth doesn't cost you more decisions.
Good through this year
$30k for a one year term, offer available until December 30th. Organizations must be under 3,000 employees to qualify, organizations above 3,000 please inquire for the enterprise package.
0
Pricing promo
From our design partners
“Agent adoption moves faster than governance usually does. Opal Zero helps close that gap.”
Mallory Rudolph · IT IAM Engineer, Faire
"Unity Gateway gives us a single place to see and control what every one of them is touching. Opal Zero helps sharpen how we express that access in policy."
Jack Zaldivar Jr. · Staff Systems Engineer, Databricks
“Opal Zero moves beyond inventory to real-time, policy-driven access decisions.”
Den Potapenko · Head of Corporate IT and Security, Superhuman
“We’re interested in how Opal Zero could support access governance for AI agents: clear owners, standard access reviews, and just-in-time access.”
Jean-Sebastien Caron · Sr. Manager, InfoSec Security Architecture, Elastic
Partnerships and integrations
Opal Zero launches with the platforms your agents already run on.

INFERENCE AND INVENTORY
The Anthropic connector brings every Claude deployment, API key, and managed agent into the access graph.
ENFORCEMENT
Access decisions are written into Unity Gateway as scoped, time-bound policy. No second control plane.

CROSS APP ACCESS
Agent-to-app connections are governed on the same terms as people, with Opal deciding what each connection is allowed to do.



