March 2026 Summaries
4 posts from Oso
Filter
Month:
Year:
Post Summaries
Back to Blog
A recent study by Oso and Cyera revealed that 96% of enterprise application permissions granted to employees remain unused, highlighting a significant operational risk as AI agents gain prominence in managing these permissions. Unlike human workers, who often overlook or ignore these permissions, AI agents utilize them to their full extent, potentially causing security vulnerabilities. This issue, which has persisted under layers of accumulated roles, is now receiving attention due to the rapid adoption of AI technologies. Various media outlets such as InfoWorld, Puck News, and Techstrong TV have covered this study, emphasizing the need for improved identity and authentication tools to address the dormant attack surfaces created by unused permissions. Oso CEO Graham Neray discussed with Alan Shimel on Techstrong TV how the authorization, traditionally a low-priority area, is becoming a focus for executives aiming to safely deploy AI agents. The primary concern is not malicious agents but well-intentioned ones inadvertently accessing systems beyond their intended scope due to unchecked permissions.
Mar 30, 2026
398 words in the original blog post.
An analysis conducted by Oso and Cyera on 2.4 million workers and 3.6 billion permissions reveals that 96% of permissions are unused by employees, highlighting a significant overpermission issue in SaaS systems. This problem becomes critical with the introduction of autonomous agents, which inherit these unused permissions, potentially leading to security breaches due to their lack of judgment and constant operational capacity. Incidents have already occurred where agents, unlike humans who are limited by judgment and time, have caused significant disruptions, such as a prolonged AWS outage and an attack on global targets by a Chinese state-sponsored group. To mitigate risks, it is recommended to audit and separate human and agent permissions, limit agent access to what is necessary, and maintain thorough logs of all actions. Oso is developing infrastructure solutions to address these challenges, emphasizing the urgency of managing agent permissions effectively while the majority are still in pilot phases.
Mar 19, 2026
1,032 words in the original blog post.
A joint research study by Oso and Cyera reveals that 96% of enterprise application permissions granted to employees remain unused, posing a significant security risk when such permissions are assigned to AI agents. These agents, unlike human employees, operate continuously and fully utilize available access, increasing the potential for data breaches and unauthorized actions. The research highlights that a large proportion of sensitive data remains untouched by humans, yet AI agents, which lack human constraints like sleep and accountability, could exploit these dormant permissions. As AI agent deployment accelerates, with predictions of substantial growth in AI-enabled applications, the study underscores the need for robust access control and permission management to mitigate risks associated with over-provisioning and static permission profiles. It calls for identity systems that align agent actions with human intent to prevent expanding the attack surface when agents are integrated into enterprise workflows.
Mar 18, 2026
865 words in the original blog post.
The deployment of coding agents in organizations is hindered by a tradeoff similar to Brewer's CAP theorem, where teams must choose between capability, autonomy, and permissions, often resulting in compromised security. Unlike the inherent limitations of distributed systems, this tradeoff is an infrastructure issue that can be addressed by implementing automated least privilege frameworks. Traditional permissions systems, designed for human users, fail to adequately secure non-human agents that operate at machine speed and are susceptible to trickery. Overpermissioning remains a critical vulnerability, with many organizations still applying human-centric access controls to AI agents, which exponentially increases risk. To mitigate these risks, organizations must shift to real-time, dynamic permission management and continuous monitoring to ensure that agents only access what is necessary for their tasks, thereby reducing the potential for breaches. The advancement of AI provides the tools needed to continuously analyze and adjust permissions, making it possible to resolve the tradeoff and securely deploy agents. As models improve and the demand for agent deployment grows, addressing the permissions problem becomes increasingly urgent for organizations to avoid security incidents and leverage the full potential of AI agents.
Mar 02, 2026
1,776 words in the original blog post.