Uploaded August 2026 | Updated September 2026, 1 day ago
WorkOS introduces Airlock at Agent Night. Airlock is a new authorization system designed specifically for AI agents. It's aimed at developers and technical founders building agentic software who need a principled way to handle permissions beyond the current extremes of manual approval or unrestricted access.
The talk opens with a framing of how agents have shifted from single-player copilots to team-wide orchestration tools, and why the 'manager of infinite minds' model demands a rethink of how permissions work. The core argument: neither role-based access control (RBAC) nor fine-grained authorization (FGA) fits agentic systems, because agents discover what they need at runtime rather than at compile time — making the principle of least privilege effectively unenforceable with static rules.
WorkOS's answer is Intent-Based Access Control (IBAC), implemented in a product called Airlock. Airlock sits between an agent and its connected services (via WorkOS Pipes), evaluating each action against both deterministic policies and non-deterministic AI-evaluated rules derived from the agent's stated intent. The live demo shows Airlock blocking an email containing financial data, routing a bulk-send to a distribution list through a human approval flow in Slack, and logging all agent activity for audit.
The session also covers Atlas, WorkOS's internal Slack-native AI teammate built on Pipes, Relay, and Vault, which is now publicly available. Airlock integrates with Atlas, MCP gateways, and coding agents like Claude Code, Codex, and OpenCode.
Chapters:
0:00 Welcome & Agenda
1:17 How Agents Have Changed Work
2:51 We're All Managers Now
5:19 Why Software Engineering Led Agentic Adoption
6:35 What Enterprise Agents Actually Need
8:22 WorkOS Stack: Vault, Pipes, Relay & Atlas
11:33 The Agent Permissions Problem
13:07 Why RBAC and FGA Don't Work for Agents
15:58 Introducing WorkOS Airlock & IBAC
20:39 Live Demo: Airlock in Action
28:06 What Airlock Enables & Wrap-Up
WorkOS introduces Airlock at Agent Night. Airlock is a new authorization system designed specifically for AI agents. It's aimed at developers and technical founders building agentic software who need a principled way to handle permissions beyond the current extremes of manual approval or unrestricted access.
The talk opens with a framing of how agents have shifted from single-player copilots to team-wide orchestration tools, and why the 'manager of infinite minds' model demands a rethink of how permissions work. The core argument: neither role-based access control (RBAC) nor fine-grained authorization (FGA) fits agentic systems, because agents discover what they need at runtime rather than at compile time — making the principle of least privilege effectively unenforceable with static rules.
WorkOS's answer is Intent-Based Access Control (IBAC), implemented in a product called Airlock. Airlock sits between an agent and its connected services (via WorkOS Pipes), evaluating each action against both deterministic policies and non-deterministic AI-evaluated rules derived from the agent's stated intent. The live demo shows Airlock blocking an email containing financial data, routing a bulk-send to a distribution list through a human approval flow in Slack, and logging all agent activity for audit.
The session also covers Atlas, WorkOS's internal Slack-native AI teammate built on Pipes, Relay, and Vault, which is now publicly available. Airlock integrates with Atlas, MCP gateways, and coding agents like Claude Code, Codex, and OpenCode.
Chapters:
0:00 Welcome & Agenda
1:17 How Agents Have Changed Work
2:51 We're All Managers Now
5:19 Why Software Engineering Led Agentic Adoption
6:35 What Enterprise Agents Actually Need
8:22 WorkOS Stack: Vault, Pipes, Relay & Atlas
11:33 The Agent Permissions Problem
13:07 Why RBAC and FGA Don't Work for Agents
15:58 Introducing WorkOS Airlock & IBAC
20:39 Live Demo: Airlock in Action
28:06 What Airlock Enables & Wrap-Up










