VYPR
advisoryPublished Jul 29, 2026· 1 source

1Password Launches Privileged Access Management to Combat Standing Privileges

1Password introduces its Privileged Access Management solution, aiming to eliminate standing access and enforce just-in-time, least-privilege principles across critical infrastructure.

1Password has expanded its Unified Access platform with the introduction of 1Password Privileged Access, a new solution designed to manage privileged access to critical infrastructure. This launch addresses the pervasive issue of "standing access" – persistent permissions that accumulate over time and create significant security exposure. The company also previewed Credential Broker for GitHub Actions and enhanced its Enterprise Password Manager capabilities, focusing on developer and AI security.

"Most organizations have more standing access in their environments than they can see or justify," stated David Faugno, CEO of 1Password. He highlighted that this invisible access is often discovered by attackers before the organization itself. With the rise of AI agents acting on behalf of employees, the need for temporary, task-specific, and automatically revoked access becomes even more critical to mitigate the expanded blast radius these agents can create.

Standing access, a long-standing security challenge, grows organically as employees and service accounts retain permissions long after tasks are completed. The increasing use of AI agents exacerbates this problem, as they can inherit or retain the privileges of the users who deploy them. A recent 1Password study revealed that 40% of developers grant AI agents persistent access, underscoring the ease with which access can outlast its intended purpose and operate at machine speed across more identities and systems.

1Password Privileged Access aims to solve this by provisioning access precisely when requested, scoping it to the specific task, and automatically deprovisioning it upon completion. Built upon the technology acquired from Apono, this new solution integrates directly into the target system's native policy layer across cloud environments, databases, and developer infrastructure, avoiding the need to replace existing tools or directly expose credentials.

The new Privileged Access solution offers several key benefits for organizations. It enables the discovery of overprivileged access by tracking identities and permissions across various environments, allowing for reclamation or right-sizing of excessive permissions. It facilitates the provisioning of just-in-time access, creating temporary accounts or privileges that are automatically revoked post-session. Furthermore, it simplifies compliance by logging every access event with full attribution, supporting standards like SOC 2, HIPAA, and GDPR, and allows for risk-based access governance with automated approvals for low-risk requests and routed approvals for higher-risk ones.

Complementing the Privileged Access launch, 1Password Credential Broker for GitHub Actions is now in public preview. This feature securely delivers credentials scoped to individual workflow runs, eliminating the need for long-lived static secrets in CI/CD pipelines. It verifies requesting identities, scopes credentials to the specific request, and logs all deliveries, thereby reducing the risk of credential theft. Ben De St. Paer-Gotch from GitHub noted that this helps engineering teams secure pipelines against credential theft while providing necessary access for building and shipping software.

To address credential security in developer tools and local machines, 1Password Enterprise Password Manager now includes three generally available capabilities. Developer Watchtower identifies exposed credentials in local .env files and guides remediation, providing administrators with visibility into credential risk. 1Password Environments allows developers to import .env files into vaults and access secrets via a secure server, keeping credentials off disk and out of AI model context windows. Credential Governance offers administrators a centralized view of company-owned credentials, enabling identification, ownership, and control over access over time, bringing much-needed governance to the point where credential risk often originates.

These new offerings collectively aim to enhance security across the entire runtime access lifecycle, from infrastructure provisioning to credential delivery for AI agents and workloads. By integrating with native policy layers and providing secure, just-in-time credential access, 1Password is positioning itself to help organizations manage the complexities of modern IT environments and the growing threat landscape driven by AI.

Synthesized by Vypr AI