1Password will grant AI agents access only for a single task and require proof of correct completion before any next step, chief technology officer Nancy Wang said at Okta's Oktane event. The approach treats agents as a hybrid identity with traits of both human and machine users. Credentials under this model never sit inside the model itself. The statement matters because agents now log in, hold credentials and act on behalf of employees, which complicates attribution in audit logs.
Task-scoped access instead of standing rights
Wang spoke with theCUBE Research's Krista Case and co-host Rebecca Knight during an exclusive broadcast on theCUBE, SiliconANGLE Media's livestreaming studio. She said 1Password rejects standing privilege for humans, machines and agents alike. Access is granted just in time and checked against the reason it is needed. The company has turned that principle into a privileged access product scoped to a single task. Like an intern who must show finished work before taking a new assignment, an agent must show it used the right permissions and acted correctly before it proceeds.
The technical core is separation between authorization and exposure. 1Password's Credential Broker releases a secret only at the moment it is needed, without exposing it to the agent or the underlying model. Separately, 1Password and Okta support shared identity standards so a verified agent identity and its authorization context can move across both systems. That lets the check on who the agent acts for travel with the request instead of being recreated in each tool. The result is task-based control rather than broad credentials stored where the model could retain them.
The background is a shift in how software acts. Agents log in, carry credentials and operate on someone's behalf, so an audit log can show the employee even when software took the action. Wang described the correct answer to whether an agent is human or machine as probably both, which makes it more important to record which identity the agent used. She also pointed to a move toward thin-client applications with most code written in remote sandboxes. In that setup, secure access has to happen in the cloud rather than on the device.
What this means for companies using agents
For businesses deploying agents in sales, support or back-office workflows, the change is about scope of trust. A task-scoped model limits what a compromised or mistaken agent can do with finance systems, customer records or internal tools. Small firms gain a clearer way to let an agent handle bookings, inbox triage or data entry without handing over standing logins. Larger organizations with many systems and service accounts get a path to tie each agent action to a specific job, which simplifies reviews of who did what and under which approval.
The model still leaves operational questions for buyers to verify. Teams need to define what counts as one task, how completion is proven, and who approves the next step when work spans several systems. Logging must distinguish the employee from the agent acting for that employee, or incident review will stay ambiguous. Before adoption, it is worth asking how Credential Broker integrates with existing Okta policies, which standards carry the identity context, and where secrets briefly appear during execution. The announcement by itself does not remove the need for tight permission design and regular access reviews.
A concrete marker to track is whether task-scoped controls and cross-system identity context appear in production deployments from 1Password and Okta, rather than in event-stage descriptions. Adoption by regulated teams that must explain each privileged action would signal that hybrid agent identity is becoming standard practice. If audit tools start showing agent and principal separately, the approach will have moved from principle to control.
