Home / Companies / WorkOS / Blog / Post Details
Content Deep Dive

Agent Night recap: Airlock and intent-based access control

Blog post from WorkOS

Post Details
Company
Date Published
Author
Zack Proser
Word Count
1,898
Company Posts That Month
89
Language
English
Hacker News Points
-
Post removed?
No
Summary

At WorkOS Agent Night in San Francisco, founder Michael Grinich introduced Airlock, an intent-based access control system designed to manage the evolving permissions needed by AI agents working across enterprise tools. Grinich argued that while software engineering agents benefit from established environments such as codebases, tests, CI systems, and version control, other business functions lack equivalent infrastructure for shared context, safe system access, and human collaboration. WorkOS has built supporting components including Vault for encrypted data, Pipes for integrations, Relay for credential-free agent access, and Atlas, a Slack-based agent with memory and action capabilities. Airlock aims to address the limitations of role-based, fine-grained, and least-privilege authorization by evaluating an agent’s stated intent at runtime, then approving, denying, escalating, or requesting more information based on deterministic rules and AI-assisted policies. In a demonstration, Airlock governed a Gmail-connected agent by allowing routine messages, blocking an email containing financial token-spend data, and requiring IT approval before messaging an unfamiliar company-wide distribution list. The system brokers credentials so agents do not directly receive broad access tokens, logs actions for auditing, supports approval workflows through Slack, and can operate with WorkOS Pipes, MCP gateways, coding environments, and Atlas.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 4 1,985 445 125 -23%
MCP 2 8,107 809 199 -26%
AI Agents 1 5,422 1,164 237 -21%
LLM 1 4,718 960 222 -38%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.