← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Varonis Introduces Agent IBAC for AI Agent Security in Atlas Platform

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Varonis released Agent IBAC in its Atlas platform.
  • Agent IBAC controls AI agent access to enterprise data.
  • It compares agent instructions to actions, blocking misalignments.
  • The system can quarantine identities and block subsequent actions.

Varonis Atlas Enhances AI Security with Agent IBAC

Varonis has announced Agent Intent-Based Access Control (IBAC), a new feature integrated into its Varonis Atlas platform. This capability aims to secure AI agents by ensuring they operate within their intended boundaries when interacting with enterprise data. The introduction of Agent IBAC comes in response to concerns about AI agents potentially misusing access, such as exposing sensitive data or performing destructive actions.

Real-time Enforcement and Anomaly Detection

Agent IBAC functions by comparing an AI agent's received instructions with its reasoning and the tools or data it attempts to access. If a discrepancy is detected, the system can respond in real time by alerting administrators or blocking the action. For significant deviations, Atlas can quarantine the AI agent's identity and block subsequent actions for a specified period.

Granular Control Based on Impact

The system allows for configurable responses based on the potential impact of an agent's deviation. For instance, a clear mismatch between an instruction (e.g., checking weather) and an action (e.g., invoking a migration tool) would result in automatic blocking. In cases where an agent's action drifts but poses no data risk (e.g., setting a reminder instead of a one-time answer), Agent IBAC can simply log the deviation without interrupting the process.

Addressing Limitations of Traditional Access Control

Traditional role-based access control systems were not designed to evaluate the contextual actions of non-human identities like AI agents. These static controls can be circumvented by agents that elevate privileges or access data outside their intended scope. Agent IBAC addresses this by enforcing permissions at runtime, focusing on whether an agent should be allowed to act on specific data within a given context, rather than just whether it has general access.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Varonis has launched Agent Intent-Based Access Control (IBAC) within its Atlas platform, designed to prevent AI agents from performing unauthorized or out-of-policy actions when accessing enterprise data. This new capability addresses the security risks associated with AI agents needing broad data access by enforcing permissions at runtime and responding to deviations in real time.