Yesterday, Varonis announced Agent Intent-Based Access Control (IBAC), a new capability in Varonis Atlas that lets businesses connect AI agents to their enterprise data with safeguards that stop dangerous or out-of-policy behavior.
Agents are making headlines for going rogue, exposing sensitive company data and, in one case, deleting an entire production database.
Agent IBAC compares the instruction an agent received to its reasoning and the tools and data it reaches for, then responds in real time to actions that don't align, including alerting or blocking.
When an agent crosses the line, Atlas can quarantine the identity behind it and block everything that follows for a defined window.
Agent IBAC can be tuned to take appropriate action based on the potential impact. For example:
Clear deviation puts data at risk: A user asks an agent to check the weather. Instead, it invokes a migration tool. This is a clean mismatch between intent and action. Agent IBAC can automatically block the tool call.
A user asks an agent to check the weather. Instead, it invokes a migration tool. This is a clean mismatch between intent and action. Agent IBAC can automatically block the tool call. Drift but nothing at stake: A user asks an agent to check the weather. The agent sets up a recurring daily reminder instead of providing a one-time answer. The agent's action has drifted, but no data is at risk. Agent IBAC can simply log the deviation rather than interrupt an over-eager attempt to help.
With Agent IBAC, Varonis Atlas gives enterprises confidence that their agents are acting within the intended scope, without unnecessarily slowing productivity. Agent IBAC is a critical component of agentic security and a core part of Atlas's end-to-end approach to AI security.
At Varonis, we are building the security layer that lets enterprises say 'yes' to agents. Watch this quick 3-minute demo to see Agent IBAC in action.
Agents don't wait for permission
... continue reading