1Password Enhances Security with New Access Management Features
1Password has introduced 1Password Privileged Access, expanding its Unified Access platform with privileged access management (PAM) capabilities.
Addressing Persistent Access Risks
Organizations often maintain excessive access rights that go unnoticed, creating vulnerabilities that attackers can exploit. This hidden access becomes increasingly dangerous as AI agents perform tasks on behalf of users, necessitating temporary, task-specific permissions that are revoked once the work is complete.
Persistent access accumulates over time through routine operations, with credentials and privileges remaining active long after their initial purpose. AI agents amplify this risk by inheriting or retaining access rights from their creators, potentially expanding the attack surface.
1Password Privileged Access Solution
1Password Privileged Access addresses this by dynamically provisioning access when requested, limiting it to the exact requirements of the task, and automatically revoking it upon completion. Built on Apono’s technology, acquired by 1Password in June 2026, the solution integrates directly with target systems’ native policies across cloud environments, databases, and developer infrastructure.
Key Features of 1Password Privileged Access
- Identifying overprivileged access by mapping identities and permissions across cloud, database, and Kubernetes environments to reclaim or adjust excessive rights.
- Enabling just-in-time access through temporary accounts or privileges that expire automatically after each session.
- Maintaining compliance records without manual log reviews by tracking all access requests, approvals, and usage.
- Implementing risk-based approvals that streamline workflows, with low-risk requests auto-approved and high-risk ones routed to reviewers via integrated tools.
Secure Credential Delivery for AI Workflows
1Password Credential Broker, now in public preview for GitHub Actions, issues credentials tailored to individual workflow runs, preventing long-lived secrets from being embedded in pipeline configurations. Before granting access, the system verifies the requesting identity, restricts the credential to the specific request, and logs all deliveries.
Combined with 1Password Privileged Access, these tools create an auditable framework for managing credentials throughout the AI ecosystem. Infrastructure access is configured within the target system’s native policies, while credentials are delivered at runtime to verified identities.
Developer Security Challenges and Solutions
Securing CI/CD pipelines has become more complex due to evolving software supply chain threats. 1Password’s Enterprise Password Manager now offers three capabilities to address credential visibility gaps in developer environments:
- Developer Watchtower identifies exposed credentials in local .env files and guides developers to store them securely in 1Password, while providing administrators with insights into credential risks.
- 1Password Environments allows developers to import existing .env files into the vault, accessing secrets through the MCP Server to keep credentials off disk and out of model contexts.
- Credential Governance provides centralized oversight of company-owned credentials, enabling administrators to claim ownership, track access, and manage permissions over time.
These features address security blind spots where credential risks often originate, offering governance at the earliest stages of development.
