Introducing Agent Intent-Based Access Control
Varonis launches Agent Intent-Based Access Control (IBAC) to detect intent drift, enforce runtime guardrails, and stop rogue AI agents before damage occurs.
Varonis has unveiled Agent Intent-Based Access Control (IBAC), a novel feature within its Atlas platform. This innovation enables businesses to integrate AI agents with their corporate data while implementing security measures that thwart improper or harmful actions. The core functionality of Agent IBAC lies in its comparison of an agent's instructions to its reasoning process, as well as the tools and data it utilizes.
In real-time, Agent IBAC intervenes when the actions deviate from the original intent, issuing alerts or blocking the actions entirely.
In cases of significant deviation, Atlas can isolate the identity behind the agent and halt all subsequent actions for a predetermined period. The level of response can be customized based on the potential impact of the breach. For instance, if an agent's action poses a clear risk to data integrity - such as an AI agent instructed to check the weather but instead invokes a migration tool - Agent IBAC can automatically halt the execution of the migration tool.
On the other hand, if an agent's action, though slightly off course, does not pose any risk to the data (like the same agent checking the weather and instead setting up a recurring daily reminder), Agent IBAC can log this deviation instead of interrupting the agent. This approach ensures that productivity is not unnecessarily hampered.
With Agent IBAC, Varonis Atlas provides enterprises with the assurance that their agents are operating within the intended parameters, without unnecessarily slowing down productivity. This feature is critical to agentic security and forms a core part of Atlas's comprehensive strategy for AI security. Varonis is committed to creating a security layer that allows enterprises to embrace AI agents, emphasizing the need for such controls in today's data-driven world.
As Ron Bennatan, Varonis' Vice President of AI & Data Strategy, states, "Agents don't wait for permission. Agents need broad access to data and tools to be useful, which is precisely what makes them risky. Traditional role-based access control is insufficient to judge what a non-human identity does with the access it has. Static controls cannot prevent an agent from finding ways to bypass them, such as by escalating its privileges, calling tools, and acting on data it was never meant to handle. Enforcement must occur at runtime."
The focus shifts from "Can a user access this data?" to "In this context, should this agent be allowed to take action on this data?". This is where Agent IBAC comes into play – closing the gap between what an agent is permitted to do and what it is designed to do. It evaluates every action an agent undertakes during a session, assessing it against the original instruction that initiated the agent's activity.
This evaluation takes into account the full context surrounding the action, rather than relying on blanket restrictions.
Furthermore, Agent IBAC allows for sensitivity to be adjusted according to the potential impact of the detected drift. The evaluation encompasses every prompt, response, and tool call within a session, enabling the detection of drift that develops gradually over multiple turns, including multi-turn jailbreak attempts. Teams also have the capability to create their own session policies in plain language.
A key aspect of Agent IBAC is its role as a runtime guardrail. It sits inline between the agent and the model that controls it, evaluating every prompt, response, and tool call before it reaches its destination. This real-time enforcement is what makes Agent IBAC possible. Unlike log analysis after the fact, Agent IBAC is positioned in the path of the interaction, capable of halting actions before they are executed.
The intent drift detection mechanism uses an LLM evaluator, similar to the engine powering Atlas's other guardrails. This evaluator assesses whether the agent's action logically follows from the instruction given. It scrutinizes the reasoning the agent generates, the tools it selects, and the parameters it provides. The evaluator then asks the question, "Do these steps align with the request?"
The sensitivity of this detection is adjustable, offering lenient, balanced, and strict settings. Lenient allows for some flexibility and flags only clear mismatches, balanced is the default setting, while strict demands a very close alignment between the request and the action, making it ideal for agents handling sensitive or high-value data.
The full-session evaluation capability of Agent IBAC is crucial. It assesses the agent's actions across the entire session, from the initial prompt to the final response. This allows Agent IBAC to catch drift that unfolds gradually, where no single action appears alarming but the cumulative path leads somewhere unintended by the user.
This is particularly important in scenarios where agents can carry context forward from earlier turns, a factor to be considered when assembling malicious requests, such as multi-turn jailbreak attempts.
In summary, Agent IBAC provides a robust, real-time security mechanism that aligns AI agents with the intended data usage, mitigating the inherent risk associated with deploying AI in enterprise environments.
Written by urgent.news from HackerNoon's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.