1Password Aims to Close the Standing-Access Gap Agents Keep Leaving Open

1Password Aims to Close the Standing-Access Gap Agents Keep Leaving Open

IDENTITY SECURITY
1Password is focusing on eliminating standing access rather than adding another management layer. Whether the products close the gap depends on the implementation details.
40%
of developers grant agents persistent, unrevoked access (1Password, 2026)
89%
of American companies require, encourage, or allow AI agents (1Password, 2026)
33%
say they have a secure way to use the agents they are expected to run (1Password, 2026)
67%
of developers report gaps in how their company manages agent security (1Password, 2026)

Privileged Access, Credential Broker, and the Snowflake integration each address standing access from a different direction: infrastructure permissions, runtime credentials, and third-party agent trust. Only the first two are available now. The practical test is whether they remove standing access or create another control plane to administer.

Standing access is the thing every identity audit finds and no one remembers granting. An engineer gets a role for a migration, the migration ends, the role stays. A service account picks up a permission to unblock a deploy, and nobody removes it afterward. 1Password built Privileged Access, Credential Broker's move to public preview, and a pending Snowflake integration around a single mechanism for closing that gap: grant access at the moment of the task, and take it back the moment the task ends.

The company's own AI Agent Governance survey puts a number on the problem the products target. Forty percent of developers grant AI agents persistent access to systems or credentials, meaning access that is never revoked once the task that required it is finished. That statistic is not a marketing flourish. It describes the exact failure mode Privileged Access is engineered to close, and it gives a chief information officer a concrete baseline to measure against once the product is running.

What Privileged Access Changes

1Password Privileged Access extends the company's Unified Access platform into privileged access management, provisioning permissions directly in a target system's native policy layer rather than replacing the tools a security team already runs. It is built on Apono, the just-in-time access startup 1Password acquired in June. Chief Executive Officer David Faugno framed the goal plainly: "access must be granted for a specific task," with permissions revoked automatically once that task ends (1Password, 2026).

How the product works matters more than the positioning. Discovery scans cloud, database, and Kubernetes environments for access that has accumulated and gone unreviewed. Provisioning happens at request time, scoped to the task. Every request, approval, and access event logs with attribution sufficient for SOC 2, HIPAA, PCI-DSS, ISO 27001, and GDPR evidence. Just-in-time access and zero standing privilege are established ideas in privileged access management. The difference here is applying them from the start to identities that are not human, with agents named alongside employees and service accounts in the product's own framing.

Credential Broker Moved to Preview, Not to Production

1Password Credential Broker addresses a narrower but related gap: credentials that get copied into pipelines instead of requested at runtime. It exited private beta and entered public preview for GitHub Actions, issuing credentials scoped to a single workflow run rather than leaving long-lived static secrets sitting in configuration files. GitHub's Ben De St. Paer-Gotch, Director of Product Management, called the goal eliminating secrets from pipeline configurations to reduce the risk of credential theft (1Password, 2026).

Public preview is not general availability.

Teams evaluating the product today can only test what is currently available. Credential Broker supports GitHub Actions and custom OpenID Connect configurations, with the roadmap for machine workloads and AI agents still ahead. A team piloting the product should scope the test to what is shipping, GitHub Actions credential delivery, rather than the fuller cross-agent vision the product name implies.

Most access systems treat agents the way they treat human employees, even though agent behavior matches neither model, and the credentials issued to them tend to outlive the tasks that required them.

1Password VP and Security Strategist Jason Meller states the underlying problem directly: security has spent two decades asking people to slow down, and people have spent two decades saying no. His point is structural. If the secure path is not the fast path, the secure path will not be used.

The Snowflake Integration Is Still a Roadmap Item

The Snowflake integration applies the same access model to a different problem: third-party agents reaching into Snowflake's environment from outside it. 1Password named the integration alongside its own July launch, with general availability scheduled for the second half of 2026. Snowflake's own Black Hat 2026 announcement places the work inside a broader effort called Cortex AI Gateway, where most of the new agent governance controls, including the third-party identity integrations, are listed at private preview rather than general availability (Snowflake, 2026). Snowflake Chief Security and Trust Officer Mayank Upadhyay described the goal as establishing a secure foundation for agent interoperability (1Password, 2026). That direction is necessary as more vendors' agents begin calling into shared data platforms without a common trust layer between them.

Enterprises running both platforms have reason to track that roadmap now. A partnership scheduled for future delivery answers a different evaluation question than a product already provisioning access in production.

Unknowns and Uncertainties

The survey's sample, 500 information technology and security professionals and 500 developers at United States firms with at least 250 employees, is large enough to support its headline figures but says nothing about whether the 40 percent persistent-access finding holds at smaller companies or outside the United States. 1Password has not published a breakdown by company size. Whether Credential Broker's public preview converts to general availability on a fixed timeline, or how quickly the Snowflake integration extends beyond its initial scope, is also not yet disclosed.

CIO/CTO VIABILITY QUESTION

Ask 1Password for the before-and-after standing-access count from a live Privileged Access deployment, not the survey baseline. Showing the actual reduction demonstrates control. Citing only the survey number does not.

Sources

1Password. "1Password Launches Privileged Access to Eliminate Standing Access Across Human and AI Identities." 1Password, 28 July 2026, 1password.com.

1Password. "1Password Joins Snowflake to Tackle AI's Next Security Frontier: Trusted Agent Interoperability." 1Password, 28 July 2026, 1password.com.

Atwell, Elaine. "1Password's Research Finds AI Agent Adoption Is Outpacing Governance." 1Password, 28 July 2026, 1password.com.

Janardanan, Radhika, and Nitika Gupta. "Snowflake Launches Cortex AI Gateway and Advanced AI Security at Black Hat 2026." Snowflake, 28 July 2026, snowflake.com.

Disclaimer: This blog reflects my personal views only. Content does not represent the views of my employer, Info-Tech Research Group. AI tools may have been used for brevity, structure, or research support. Please independently verify any information before relying on it.