WorkOS Airlock: Intent-Based Access Control for AI Agents | Michael Grinich, Agent Night Keynote @WorkOS
WorkOS Airlock: Intent-Based Access Control for AI Agents | Michael Grinich, Agent Night Keynote  @WorkOS
Uploaded August 2026 | Updated September 2026, 1 day ago
WorkOS introduces Airlock at Agent Night. Airlock is a new authorization system designed specifically for AI agents. It's aimed at developers and technical founders building agentic software who need a principled way to handle permissions beyond the current extremes of manual approval or unrestricted access.

The talk opens with a framing of how agents have shifted from single-player copilots to team-wide orchestration tools, and why the 'manager of infinite minds' model demands a rethink of how permissions work. The core argument: neither role-based access control (RBAC) nor fine-grained authorization (FGA) fits agentic systems, because agents discover what they need at runtime rather than at compile time — making the principle of least privilege effectively unenforceable with static rules.

WorkOS's answer is Intent-Based Access Control (IBAC), implemented in a product called Airlock. Airlock sits between an agent and its connected services (via WorkOS Pipes), evaluating each action against both deterministic policies and non-deterministic AI-evaluated rules derived from the agent's stated intent. The live demo shows Airlock blocking an email containing financial data, routing a bulk-send to a distribution list through a human approval flow in Slack, and logging all agent activity for audit.

The session also covers Atlas, WorkOS's internal Slack-native AI teammate built on Pipes, Relay, and Vault, which is now publicly available. Airlock integrates with Atlas, MCP gateways, and coding agents like Claude Code, Codex, and OpenCode.

Chapters:
0:00 Welcome & Agenda
1:17 How Agents Have Changed Work
2:51 We're All Managers Now
5:19 Why Software Engineering Led Agentic Adoption
6:35 What Enterprise Agents Actually Need
8:22 WorkOS Stack: Vault, Pipes, Relay & Atlas
11:33 The Agent Permissions Problem
13:07 Why RBAC and FGA Don't Work for Agents
15:58 Introducing WorkOS Airlock & IBAC
20:39 Live Demo: Airlock in Action
28:06 What Airlock Enables & Wrap-Up
WorkOS Airlock: Intent-Based Access Control for AI Agents | Michael Grinich, Agent Night Keynote95% of Your Documentation Is Invisible to AIWhy Self-Driving Production Is the Future — Eric Schwartz, Traversal | AI Engineer Worlds Fair 2026How Vercel deploys internal agents at scale — Andrew Qu, Vercel | re:Invent 2025Why Your CI/CD Pipeline Isnt Ready for AI — Kyle Galbraith, Depot | re:Invent 2025The evolution of AI: From chat to code #ai #coding #techAgent Night Live: Introducing Intent-Based Access ControlDaytona AI Builders - NYC, September 9, 2026Bring Your Own Cloud: Deploy SaaS in Customer AWS — Jon Morehouse, Nuon | Enterprise Ready Conf 2025Why Trust Is the Bottleneck for Agents — Jean-Denis Greze, Town | AI Engineer Worlds Fair 2026The story behind why developers chose this over everything else #coding #techCI Pipeline Validation Just Got Easier #coding #devops
WorkOS |

WorkOS Airlock: Intent-Based Access Control for AI Agents | Michael Grinich, Agent Night Keynote

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER