# Unified Access

Published articles for Unified Access.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## 5 ways to optimize AI costs and reduce wasted AI spend

DevFeed: [5 ways to optimize AI costs and reduce wasted AI spend](<https://devfeed.tech/articles/5-ways-to-optimize-ai-costs-and-reduce-wasted-ai-spend-1889.md>)

Original publisher: [Read original article](<https://1password.com/blog/5-ways-to-optimize-ai-costs>)

Author: info@1password.com (Rachel Sudbeck)

Published: 2026-09-03T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [cursor](<https://devfeed.tech/topics/cursor.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [ai-models](<https://devfeed.tech/tags/ai-models.md>), [cost](<https://devfeed.tech/tags/cost.md>), [cursor](<https://devfeed.tech/tags/cursor.md>), [saas-management](<https://devfeed.tech/tags/saas-management.md>), [shadow-ai](<https://devfeed.tech/tags/shadow-ai.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>)

### AI overview

The article outlines ways businesses can reduce AI spending, including choosing less expensive models, overseeing AI agents, and identifying shadow AI.

### Source excerpt

The tokenmaxxing era has left companies grappling with an uncomfortable reality. Now that AI vendors have switched to usage-based billing models, businesses are facing sky-high bills, and IT and finance teams are under pressure to rein in spending without slowing down innovation. The logical first step is to locate areas where that spend is going to waste, but even getting visibility into usage can be overwhelming when it's spread across departments, users, models, vendors, and agents. If you're trying to track down wasted AI spend and find opportunities to optimize your tokens, it helps to start with some of the primary reasons why AI bills may balloon past your company's budget. Top ways to optimize your company's AI costs So IT and Finance teams can know where to focus their efforts, here are five of the most common sources of unexpected AI spend. 1. Stop defaulting to the most expensive model For businesses to optimize spend, they need a way of overseeing and enforcing which models are being used for what tasks. Different AI models can vary wildly both in their abilities and their cost, and many users default to flagship AI models without realizing that there are more affordable options that can accomplish their goals at a fraction of the cost. For instance, in a recent experiment run by Cursor, building a web browser from scratch cost $10,565 when using a top-tier flagship model, and $1,339 when using a mix of models, even though the end results were comparable in terms of quality. 2. Stop letting agents run without oversight As the Stanford Digital Economy Lab reported, AI agents are "uniquely expensive, consuming 1000x more tokens than code reasoning and code chat." Meanwhile, data from OpenRouter shows that the majority of tokens spent overall are being used by agents. Here's a scenario that's becoming familiar to many AI developers and builders: An agent is instructed to perform a certain task, but it fails. So it tries again, and fails. With each loop, it

## 1Password signs OpenAI open letter calling for collective action on cyber defense

DevFeed: [1Password signs OpenAI open letter calling for collective action on cyber defense](<https://devfeed.tech/articles/1password-signs-openai-open-letter-calling-for-collective-action-on-cyber-defense-1944.md>)

Original publisher: [Read original article](<https://1password.com/blog/openai-open-letter-cyber-defense>)

Author: info@1password.com (1Password)

Published: 2026-08-28T00:00:00Z

Content type: opinion

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [AI Bots](<https://devfeed.tech/topics/ai-bots.md>), [AI, ML & Data Engineering](<https://devfeed.tech/topics/ai-ml-data-engineering.md>), [cursor](<https://devfeed.tech/topics/cursor.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [audit-trail](<https://devfeed.tech/tags/audit-trail.md>), [aws](<https://devfeed.tech/tags/aws.md>), [cloud-infrastructure](<https://devfeed.tech/tags/cloud-infrastructure.md>), [codex](<https://devfeed.tech/tags/codex.md>), [collective](<https://devfeed.tech/tags/collective.md>), [cursor](<https://devfeed.tech/tags/cursor.md>), [identity](<https://devfeed.tech/tags/identity.md>), [openai](<https://devfeed.tech/tags/openai.md>), [security](<https://devfeed.tech/tags/security.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>)

### AI overview

1Password supports OpenAI's call for collective cyber defense, arguing that AI agents need least-privilege access, traceable identities, clear boundaries, and audit trails.

### Source excerpt

As AI moves from answering questions to taking actions, the ecosystem around it will determine whether organizations can use it safely and with confidence. OpenAI's open letter on collective cyber defense warns that defenders have a limited window to strengthen security. It urges organizations to fix their highest-risk weaknesses, build least privilege and strong access controls, verify fixes, and make agentic identities traceable and accountable. The real work is building the ecosystem that lets them act safely and earn trust in production. That is why we continue working with OpenAI on trusted access for people and their agents. 1Password integrations with OpenAI, Codex, Anthropic Claude Code, Cursor, Kiro, Perplexity, and AWS Secrets Manager extend trusted access across development and cloud workflows. People should give agents access to key systems without exposing underlying credentials to the AI model. Cyber defense is a leadership responsibility. AI changes who and what can act inside the most sensitive systems, so identity security can no longer stop at human login. OpenAI is right to call for urgency, coordination, and fixes that organizations can verify without disrupting essential services. The standard is simple: every agent needs an identity, a boundary, and an audit trail." -Nancy Wang, Chief Technology Officer, 1Password Status quo security won't be enough Every security organization balances known weaknesses, technical debt, and limited time. The challenge for CISOs is deciding where to focus first and finding controls that reduce risk across the environment where AI is changing who and what can act inside an organization. Agents that work across browsers, repositories, terminals, cloud infrastructure, and production systems create a security challenge that begins before they take action. Standing access gives an agent more authority than a specific task requires and keeps it available after the task ends. If the agent is compromised or follows untru

## When AI adoption outpaces IT visibility

DevFeed: [When AI adoption outpaces IT visibility](<https://devfeed.tech/articles/when-ai-adoption-outpaces-it-visibility-1973.md>)

Original publisher: [Read original article](<https://1password.com/blog/when-ai-adoption-outpaces-it-visibility>)

Author: info@1password.com (Stephanie Torto)

Published: 2026-08-27T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Responsibility & Safety](<https://devfeed.tech/topics/responsibility-safety.md>), [dashboards](<https://devfeed.tech/topics/dashboards.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-adoption](<https://devfeed.tech/tags/ai-adoption.md>), [ai-governance](<https://devfeed.tech/tags/ai-governance.md>), [cost](<https://devfeed.tech/tags/cost.md>), [dashboards](<https://devfeed.tech/tags/dashboards.md>), [models](<https://devfeed.tech/tags/models.md>), [saas](<https://devfeed.tech/tags/saas.md>), [saas-management](<https://devfeed.tech/tags/saas-management.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>)

### AI overview

1Password describes how fragmented vendor dashboards and consumption-based AI pricing made it difficult for IT to understand AI spending. It argues that IT should provide visibility and context for business and engineering leaders making budget and model decisions.

### Source excerpt

At 1Password, we started expanding our use of AI with a familiar IT playbook. We identified the problems we wanted to solve and the tools that could help us achieve those goals. The plan was straightforward: enable teams, move quickly, learn what worked, and build the visibility needed to manage the cost. Then the operating model changed. AI vendors introduced consumption-based pricing faster than our processes could keep up, leaving us with a distributed system of vendor-specific dashboards to track and manage our AI use. For IT, that created a new kind of chaos when it came to understanding how much we were spending on AI and where that budget was being used throughout the company. We had data spread across systems, but we didn't yet have a clear, shared answer. How IT teams can govern AI use IT teams are close to the tools and access patterns that shape AI usage. That gives IT an important role in AI spend decisions, and is no small part of why AI governance can become framed as an IT mandate. Budget and model decisions belong with the leaders who set business and engineering priorities, while IT's role is to provide the context those leaders need. In the face of the changing nature of AI governance, IT teams should focus on finding ways to make AI spend explainable, to give the company a more useful basis for making decisions. Visibility changes the conversation Previously, 1Password's IT team could see activity in individual vendor consoles, but each view covered only part of the picture. We spent too much time moving between systems and interpreting different definitions. By the time we exported data from one tool and combined it with another, the result was already out of date. When we started using AI Spend and Consumption Management in 1Password SaaS Manager, it felt like a breath of fresh air. We now had a shared view of AI usage and spend across vendors and teams, with detailed insights on users and models, meaning that we could better understand our budg

## 451 Research report: How agentic AI is redefining identity security

DevFeed: [451 Research report: How agentic AI is redefining identity security](<https://devfeed.tech/articles/451-research-report-how-agentic-ai-is-redefining-identity-security-1927.md>)

Original publisher: [Read original article](<https://1password.com/blog/how-agentic-ai-is-redefining-identity-security>)

Author: info@1password.com (1Password)

Published: 2026-08-20T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>)

Tags: [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [developers](<https://devfeed.tech/tags/developers.md>), [identity](<https://devfeed.tech/tags/identity.md>), [news](<https://devfeed.tech/tags/news.md>), [security](<https://devfeed.tech/tags/security.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>)

### AI overview

A 1Password article summarizes a 451 Research report on how agentic AI is changing enterprise identity and access security. It highlights the need to discover AI agents and non-human identities, deliver credentials just in time, guide developer remediation, and provide auditable attribution for actions.

### Source excerpt

In the short time that AI agents have been a part of the enterprise, they have upended many of our bedrock assumptions about the nature of identity, access, development, and work itself. At 1Password, we've been in the trenches of the agentic revolution; we've seen its positive impact on productivity, and the serious concerns it raises about security. We've worked to build solutions that both harness AI's potential and rein in its risks, and watched customers and colleagues grapple with the same issues. In order to better understand how the industry at large is facing the agentic moment, 1Password commissioned a Vanguard Report from 451 Research, titled A new access model for the agentic enterprise. The report describes how agentic AI is redefining access and identity, and lays out what C-level leaders can do to ensure a smooth transition to this new paradigm. Its core recommendations include: Start with discovery and visibility of AI agents and poorly governed non-human identities (NHIs). Move to just-in-time credential delivery, rather than static credentials and standing privileges. Implement guided remediation for developers so they can address NHI and agentic risk without interrupting their workflows. Ensure full auditability and clear attribution that ties every action to a specific human or agent identity and authorization context. Read on to explore the report's findings, or download the full report here. An expanding identity perimeter, with agents already inside A new access model for the agentic enterprise begins by establishing that agentic AI is already deeply embedded in the enterprise. 69% of enterprises they surveyed have deployed AI agents, and 90% plan to do so within the next two years (these findings align with 1Password's own research on agentic adoption). But while agents became ubiquitous almost overnight, the tools and strategies to secure them have not kept pace. This on its own isn't unusual; the report reminds readers that this "pattern ha

## Developer secrets management that keeps delivery moving

DevFeed: [Developer secrets management that keeps delivery moving](<https://devfeed.tech/articles/developer-secrets-management-that-keeps-delivery-moving-1915.md>)

Original publisher: [Read original article](<https://1password.com/blog/developer-secrets-management-that-keeps-delivery-moving>)

Author: info@1password.com (Robert Imeson)

Published: 2026-08-17T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [Software Engineering](<https://devfeed.tech/topics/software-engineering.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [Database](<https://devfeed.tech/topics/database.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [api-keys](<https://devfeed.tech/tags/api-keys.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [code](<https://devfeed.tech/tags/code.md>), [developer](<https://devfeed.tech/tags/developer.md>), [developers](<https://devfeed.tech/tags/developers.md>), [development](<https://devfeed.tech/tags/development.md>), [github](<https://devfeed.tech/tags/github.md>), [incident](<https://devfeed.tech/tags/incident.md>), [logs](<https://devfeed.tech/tags/logs.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [software](<https://devfeed.tech/tags/software.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [tokens](<https://devfeed.tech/tags/tokens.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>)

### AI overview

The article examines how unmanaged developer credentials--such as API keys, cloud credentials, SSH keys, and tokens--can remain outside approved security controls. It argues that secrets management must reduce workflow friction and address credentials at the point where developers create and use them, while enabling rotation, revocation, auditing, and reporting.

### Source excerpt

In March 2025, attackers compromised a GitHub Action used in the development pipelines of more than 23,000 repositories. The malicious code exposed API keys, cloud credentials, SSH keys, and other tokens in workflow logs. Affected teams were advised to review their workflow runs and rotate any credentials the logs exposed. Affected organizations had to determine which credentials had been exposed, what those credentials could reach, and how to replace every one of them without halting development. Many could not confidently answer the first question alone. The incident illustrates the problem those responsible for a team's credentials face today: the credentials that carry the most risk are often the ones nobody is tracking. Security tools cannot govern credentials they never see Unmanaged credentials are simply a byproduct of the modern software development environment, where developers are under pressure to constantly ship code. A developer standing up an application needs a database password or an API key immediately, and the fastest way to supply one is a .env file on the local machine, an SSH key in a home directory, or a token pasted into a pipeline variable. Each choice keeps work moving, and each one creates a working credential that exists outside any approved system, where no one responsible for keeping projects, credentials, and access safe can rotate, revoke, or audit it. Traditional secrets management can leave this gap open because it starts on the wrong side of it. Conventional tools provide a secure destination but depend on developers to bring credentials to it, so governance begins only after migration. When a security process adds friction, teams find workarounds. 1Password's research found that 43% of developers don't use a dedicated secrets manager or vault at all, managing secrets through a mix of secure and unsecure means instead. As a result, credentials remain outside the controls, reporting, and rotation processes intended to protect them.

## Remove standing access before AI agents exploit it

DevFeed: [Remove standing access before AI agents exploit it](<https://devfeed.tech/articles/remove-standing-access-before-ai-agents-exploit-it-1950.md>)

Original publisher: [Read original article](<https://1password.com/blog/remove-standing-access-before-ai-agents-exploit-it>)

Author: info@1password.com (Sanjay Ramnath)

Published: 2026-08-06T00:00:00Z

Content type: opinion

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [OAuth](<https://devfeed.tech/topics/oauth.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [incident](<https://devfeed.tech/topics/incident.md>), [coding](<https://devfeed.tech/topics/coding.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [api-keys](<https://devfeed.tech/tags/api-keys.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>)

### AI overview

The article argues that AI-driven autonomous systems can rapidly discover and exploit standing credentials after gaining access to enterprise environments. It recommends removing unnecessary access, vaulting plaintext secrets, and reducing the blast radius of credential-based attacks.

### Source excerpt

AI has changed the calculus of a credential attack. Before, finding and exploiting credentials in an enterprise environment required time, patience, and human judgment. An attacker had to decide which accounts were worth testing and which systems were worth reaching. Many credentials never made the list. By contrast, an autonomous system that gains a foothold in a victim's systems has no need to be picky. It can sweep an environment in moments, scooping up API keys, service account tokens, OAuth tokens, cloud credentials, and plaintext secrets on developer devices. It authenticates with whatever it finds and moves laterally as far as standing access allows, one credential opening the next, at machine speed. An attacker with AI doesn't need to choose targets. Everything accessible is worth exploiting. Recent high-profile incidents with experimental AI models have shown that pattern in action. Entry points differed: software exploits in two cases, weak passwords in a third. But what followed was the same in each incident: automated systems swept for whatever credentials the environment offered and moved as far as standing access would carry them. In one documented case, that meant more than 17,000 recorded attacker events over a single weekend. These stories are just early indicators of what defenders will soon be facing as these experimental models become commonly available services. As autonomous systems become more capable and more widely deployed, credential sweeps after breaches will become faster, more thorough, and harder to detect. Any enterprise running AI workloads, AI coding tools, or developer workflows on shared infrastructure has accumulated the same kind of exposure that made these headline-grabbing attacks successful: service accounts whose permissions grew beyond their original purpose, API keys that were never rotated, and secrets left in plaintext on developer devices because they were easier to use that way. In the face of what is coming, strengthe

## Productiv shutdown: Switch to 1Password for durable AI and SaaS Management

DevFeed: [Productiv shutdown: Switch to 1Password for durable AI and SaaS Management](<https://devfeed.tech/articles/productiv-shutdown-switch-to-1password-for-durable-ai-and-saas-management-1947.md>)

Original publisher: [Read original article](<https://1password.com/blog/productiv-shutdown-switch-to-1password-for-durable-ai-and-saas-management>)

Author: info@1password.com (Evan Sandhu)

Published: 2026-08-05T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [SaaS Management](<https://devfeed.tech/topics/saas-management.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [shadow AI](<https://devfeed.tech/topics/shadow-ai.md>), [Unified Access](<https://devfeed.tech/topics/unified-access.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [Extension](<https://devfeed.tech/topics/extension.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [automation](<https://devfeed.tech/tags/automation.md>), [browser](<https://devfeed.tech/tags/browser.md>), [extensions](<https://devfeed.tech/tags/extensions.md>), [policy](<https://devfeed.tech/tags/policy.md>), [saas](<https://devfeed.tech/tags/saas.md>), [saas-management](<https://devfeed.tech/tags/saas-management.md>), [shadow-ai](<https://devfeed.tech/tags/shadow-ai.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>)

### AI overview

Productiv is shutting down its SaaS management platform, prompting customers to move app inventory, spend, and usage data. The article presents 1Password SaaS Manager as an alternative with AI spend and consumption tracking, SaaS discovery beyond SSO, access governance, and lifecycle automation.

### Source excerpt

On August 2, 2026, Productiv told customers its SaaS management platform was shutting down on August 6, with account data deleted once access ended. Four days is not much time to pull years of app inventory, spend, and usage data out of a system you've come to depend on, especially with AI tools now adding a fast-moving new layer of spend and access to track on top of everything else. If you're facing that deadline, or just taking stock of what you'd do if your own platform disappeared tomorrow, here's why 1Password SaaS Manager is the strongest place to land. A Leader you can build on 1Password SaaS Manager is a Leader in the 2026 Gartner® Magic Quadrant™ for SaaS Management Platforms, for both Completeness of Vision and Ability to Execute. That recognition reflects work we've been doing deliberately since acquiring Trelica in 2025. We've brought AI and SaaS discovery into our broader Unified Access platform, alongside the credentials, identities, and access controls that secure every application in a portfolio. Built for how AI and SaaS actually get used today We recently launched AI Spend and Consumption Management inside SaaS Manager, giving IT and finance teams a normalized view of AI token usage by vendor, team, and model, with burn-rate alerts before prepaid budgets run out. AI is quickly becoming the least governed, fastest-growing corner of the software portfolio, and we built that governance directly into SaaS Manager rather than bolting it on as a separate tool. It's one of several capabilities that set SaaS Manager apart: Discovery that goes beyond SSO: SaaS Manager continuously discovers apps across identity providers, SSO logs, finance systems, browser extensions, and 1Password Enterprise Password Manager vaults, surfacing the unmanaged SaaS and shadow AI tools that SSO-only discovery misses. Governance you can act on: Discovery is anchored to credentials and sign-ins, so IT can revoke access and enforce strong authentication even for apps outside SSO,

## 1Password Credential Broker is now in public preview

DevFeed: [1Password Credential Broker is now in public preview](<https://devfeed.tech/articles/1password-credential-broker-is-now-in-public-preview-1881.md>)

Original publisher: [Read original article](<https://1password.com/blog/1password-credential-broker-public-preview>)

Author: info@1password.com (Jeff Malnick)

Published: 2026-07-28T00:00:00Z

Content type: release

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [JSON Web Tokens](<https://devfeed.tech/topics/jwt.md>)

Tags: [audit-trail](<https://devfeed.tech/tags/audit-trail.md>), [aws](<https://devfeed.tech/tags/aws.md>), [azure](<https://devfeed.tech/tags/azure.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [developers](<https://devfeed.tech/tags/developers.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [identity](<https://devfeed.tech/tags/identity.md>), [incident](<https://devfeed.tech/tags/incident.md>), [news](<https://devfeed.tech/tags/news.md>), [policy](<https://devfeed.tech/tags/policy.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>), [workflow](<https://devfeed.tech/tags/workflow.md>)

### AI overview

1Password Credential Broker is moving from closed beta to public preview. It uses workload identity federation and GitHub Actions OIDC tokens to give each workload scoped, temporary credential access with detailed issuance attribution and audit logging.

### Source excerpt

Every security team has tried to trace a credential access event back to a specific workload, and received nothing but a "service account." That service account probably had access to an entire vault, and its audit trail doesn't tell you which repo triggered the request, which specific credential was accessed, or whether the workflow still has access. When an auditor asks, or an incident occurs, that's not a good place to be. The credentials feeding those workloads are usually created for convenience: scoped broadly to avoid last-minute permission errors, stored in plaintext .env files, placed directly in CI/CD pipelines, and rarely rotated because doing it manually is slow and error-prone. 1Password Credential Broker was built to close that gap: give every workload or agent its own identity and scope its access. Every issuance event gets logged with attribution clear enough to hold up in an incident review. Today, we're moving Credential Broker from closed beta to public preview, available for all Enterprise Password Manager Business customers to start using right now. How 1Password Credential Broker works The foundation of our Credential Broker is Workload Identity Federation, a standards-based approach that GitHub, Google Cloud, AWS, and Azure have all adopted. When a GitHub Actions workflow runs, GitHub automatically generates a signed token that identifies exactly which repo, branch, and workflow is executing. Think of it like a digital badge: here's what this job is and where it came from. Our Credential Broker validates that badge against a trust policy you configure, then delivers only the specific credentials that job is approved to retrieve. The workload can retrieve only the approved credential during the authorized job, without receiving standing access to the vault. We log every issuance with full attribution: the repo, branch, workflow, environment, and commit that triggered the request. Your audit log no longer reads "a service account accessed this i

## Secure developer secrets with 1Password

DevFeed: [Secure developer secrets with 1Password](<https://devfeed.tech/articles/secure-developer-secrets-with-1password-1957.md>)

Original publisher: [Read original article](<https://1password.com/blog/secure-developer-secrets-with-1password>)

Author: info@1password.com (Allie Dusome)

Published: 2026-07-28T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Code](<https://devfeed.tech/topics/code.md>), [App](<https://devfeed.tech/topics/app.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [ai-adoption](<https://devfeed.tech/tags/ai-adoption.md>), [breach](<https://devfeed.tech/tags/breach.md>), [code](<https://devfeed.tech/tags/code.md>), [developer](<https://devfeed.tech/tags/developer.md>), [developers](<https://devfeed.tech/tags/developers.md>), [github](<https://devfeed.tech/tags/github.md>), [local](<https://devfeed.tech/tags/local.md>), [news](<https://devfeed.tech/tags/news.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [tools](<https://devfeed.tech/tags/tools.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

This article introduces 1Password Environments and Developer Watchtower, two capabilities designed to reduce developer secret sprawl. Developer Watchtower detects plaintext credentials on local devices and guides users to import them into 1Password, while Environments provides a secure place to store, share, and use secrets for apps, services, automations, and AI-assisted workflows.

### Source excerpt

No developer wants to be responsible for causing a catastrophic breach. But security best practices are often incompatible with the expectation that developers constantly write and ship code, and that velocity is massively accelerating thanks to AI adoption. Developers trying to work fast need convenience, but the easiest place to put a developer secret can sometimes be the riskiest place to leave it. For many developers, that place is a local .env file: fast, familiar, and supported by the tools they already use, but often stored in plaintext on disk. Even when developers are given discrete tools for managing secrets, they can be complex, time-consuming, and disconnected from their workflows. So when someone needs to get an app up and running, the fastest path can be the familiar path: put a credential in a plaintext file on your local disk. These habits create a visibility gap for IT and security leaders and contribute to secret sprawl. GitGuardian's 2026 State of Secrets Sprawl report found 28.65 million new secrets in public GitHub commits in 2025, up 34% from the previous year. The same report found the number of leaked secrets for AI services had grown by 81% in a single year. When credentials are stored in plaintext on a local device, IT and security teams may not know they exist, which means they cannot monitor them, revoke them, rotate them, or understand what else depends on them. That is the gap 1Password is closing with the launch of 1Password Environments and Developer Watchtower: helping teams find improperly stored developer credentials, secure them in the place employees already trust, and let developers keep using them without slowing down the work. Developer Watchtower identifies plaintext developer credentials on local devices and guides users to import them into 1Password. Developer credential visibility for admins provides a clearer view of credential risk across their organization, with reporting and remediation workflows to help employees secu

## Your business runs on credentials IT did not provision

DevFeed: [Your business runs on credentials IT did not provision](<https://devfeed.tech/articles/your-business-runs-on-credentials-it-did-not-provision-1978.md>)

Original publisher: [Read original article](<https://1password.com/blog/your-business-runs-on-credentials-it-did-not-provision>)

Author: info@1password.com (Jairo Camacho)

Published: 2026-07-28T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [passwords](<https://devfeed.tech/topics/passwords.md>), [Security](<https://devfeed.tech/topics/security.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>)

Tags: [business](<https://devfeed.tech/tags/business.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [security](<https://devfeed.tech/tags/security.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>), [web-applications](<https://devfeed.tech/tags/web-applications.md>)

### AI overview

The article describes how unmanaged credentials created outside IT systems can become invisible, unrotated, and risky access points for businesses. It presents Credential Governance in 1Password Enterprise Password Manager as a workflow for discovering company-owned credentials, reclaiming them as company-managed items, and governing access over time.

### Source excerpt

Right now, in one of your employee's personal vaults, there's a login for a vendor portal your team has been using for three years. Whoever set it up no longer works at the company. The password has never been rotated. And until today, you didn't know it existed. That credential was created outside your systems, became essential to a business workflow, and went invisible. Every organization has hundreds like it: break-glass accounts copied into multiple vaults as a precaution, contractor logins that outlasted the contract, apps that don't support SAML so someone signed up and shared the password in Slack. Nobody in IT provisioned any of them, and all of them grant access to real systems. These are your highest-risk credentials: unrotated, unaccountable, and largely invisible. Attackers go after exactly these accounts: the ones with no rotation schedule, no owner, and no audit history. And credentials are the way in: 88% of attacks against web applications involve stolen credentials, according to Verizon's Data Breach Investigations Report (2025). Every unmanaged credential expands your organization's attack surface. These credentials persist because the alternatives are hard. The SSO tax makes federation too costly for some apps. Others simply don't support SAML or OIDC. So the credentials keep accumulating, untracked and unrotated, while auditors ask for evidence you can't produce. Credential Governance gives admins a repeatable way to find those accounts, take ownership of them, and govern access over time, all inside 1Password Enterprise Password Manager. How Credential Governance works Credential Governance gives IT and security admins a repeatable workflow to discover unmanaged credentials, reclaim them as company-managed credentials, and govern access over time. Discover: Build a complete inventory of unmanaged credentials. 1Password finds Login items across all employee and shared vaults and filters by domain to surface company-owned accounts. With every comp

## Introducing 1Password Privileged Access: Zero standing privileges for every identity

DevFeed: [Introducing 1Password Privileged Access: Zero standing privileges for every identity](<https://devfeed.tech/articles/introducing-1password-privileged-access-zero-standing-privileges-for-every-identity-1933.md>)

Original publisher: [Read original article](<https://1password.com/blog/introducing-1password-privileged-access>)

Author: info@1password.com (Rom Carmel)

Published: 2026-07-28T00:00:00Z

Content type: release

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Unified Access](<https://devfeed.tech/topics/unified-access.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [AWS IAM](<https://devfeed.tech/topics/aws-iam.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [Databases](<https://devfeed.tech/topics/databases.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [aws](<https://devfeed.tech/tags/aws.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-infrastructure](<https://devfeed.tech/tags/cloud-infrastructure.md>), [databases](<https://devfeed.tech/tags/databases.md>), [iam](<https://devfeed.tech/tags/iam.md>), [identity](<https://devfeed.tech/tags/identity.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [news](<https://devfeed.tech/tags/news.md>), [security](<https://devfeed.tech/tags/security.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>)

### AI overview

1Password Privileged Access introduces just-in-time access for human and agent identities across cloud and hybrid environments, databases, and Kubernetes. It aims to eliminate standing privileges by granting task-scoped access when needed and automatically removing it when work is complete.

### Source excerpt

Here's a moment that comes up in nearly every compliance review: a security engineer pulls a list of IAM roles in the AWS environment. The list is long. Some roles were created for a migration project that closed two quarters ago, a few belong to contractors who haven't worked there in over a year, and others are attached to agentic identities without any way to see which human they were acting on behalf of. There's no ticket to clean them up, no alert when the access outlived its purpose, and no record of who approved it in the first place. That's standing access in practice; that long list of overprovisioned IAM roles is simply the product of how access has always been provisioned. Admins create it when the work starts, then rely on someone else to clean it up when it's done. But the cleanup rarely happens. The gap between the access granted and the access that's actually needed becomes the gap that shows up in audit findings, and that attackers learn to exploit. That problem has grown harder to manage as AI agents have joined human engineers in operating on production infrastructure. Agents don't request access through a ticket queue. They act continuously, respond to changing inputs, and can be steered in ways that static standing permissions were never designed to contain. Governing agents with the same legacy PAM tools built for human logins carries the risk forward instead of containing it. That's why we're introducing 1Password Privileged Access. It brings Apono's proven just-in-time access engine into the 1Password Unified Access platform, eliminating standing privileges for both human and agent identities across cloud and hybrid environments, databases, and Kubernetes. Access is created at the moment of the request, scoped to the task, and deprovisioned automatically when the work is done. Standing access became the default, and the cost kept growing Cloud infrastructure can change by the hour. New services get spun up, roles get reshuffled, and permission

## The data platform 1Password needed didn't exist. So we built it.

DevFeed: [The data platform 1Password needed didn't exist. So we built it.](<https://devfeed.tech/articles/the-data-platform-1password-needed-didn-t-exist-so-we-built-it-1969.md>)

Original publisher: [Read original article](<https://1password.com/blog/we-built-the-data-platform-1password-needed>)

Author: info@1password.com (Wayne Duso; Mandy Gu; and Amie Bright)

Published: 2026-07-22T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [data](<https://devfeed.tech/topics/data.md>), [Data Infrastructure](<https://devfeed.tech/topics/data-infrastructure.md>), [data-governance](<https://devfeed.tech/topics/data-governance.md>), [real-time](<https://devfeed.tech/topics/real-time.md>), [Unified Access](<https://devfeed.tech/topics/unified-access.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [building-1password](<https://devfeed.tech/tags/building-1password.md>), [data](<https://devfeed.tech/tags/data.md>), [data-governance](<https://devfeed.tech/tags/data-governance.md>), [data-infrastructure](<https://devfeed.tech/tags/data-infrastructure.md>), [developers](<https://devfeed.tech/tags/developers.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [sql](<https://devfeed.tech/tags/sql.md>), [systems](<https://devfeed.tech/tags/systems.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

1Password describes building an internal data platform to make business data accessible, trustworthy, and available in real time across product, finance, engineering, analytics, SQL, APIs, dashboards, and AI workflows. The effort addresses bottlenecks caused by a centralized data lake, bespoke pipelines, and tightly coupled storage, governance, and compute.

### Source excerpt

Consider a few tasks that take place across every business, every day: A product team ships a feature and wants to know if customers are using it successfully. A finance team needs customer and account information for planning. An analyst needs definitions to create a report. An AI assistant needs operational context to answer a business question. Those sound like different workflows, but they all rely on the same underlying data. And each one of these actors, across each of these teams, needs that data to be both accessible and trustworthy. At 1Password, trust is at the center of everything we build. Millions of people and businesses rely on us to protect the credentials, secrets, and access workflows that power modern work. The same principle applies to our own internal data. As our products, systems, and use of AI evolved, data became a shared dependency across the business. It powers everything from Unified Access andsecure agentic access patterns for customers, to the workflows used by product, finance, and engineering teams. As those systems grew, so did the number of people and applications that depended on our internal data. But our data infrastructure did not respond well to this. We had built a centralized data lake supported by a growing collection of bespoke data pipelines and one-off solutions. Each new use case required another integration or transformation. Over time, the data platform became a bottleneck: teams turned to CSVs to move faster, and data engineers spent more time maintaining pipelines than enabling new capabilities. What we learned was that manually moving data was no longer enough. Data needs to be available in real time, accessible wherever it's needed, and trusted through the forms our customers need, whether that is through SQL, APIs, dashboards or AI workflows. Privacy and governance need to be built into data the moment it's created so every downstream use remains secure and unambiguous by design. This is the foundation we're build

## Welcoming Apono to 1Password

DevFeed: [Welcoming Apono to 1Password](<https://devfeed.tech/articles/welcoming-apono-to-1password-1879.md>)

Original publisher: [Read original article](<https://1password.com/blog/1password-acquires-apono>)

Author: info@1password.com (David Faugno)

Published: 2026-06-15T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Unified Access](<https://devfeed.tech/topics/unified-access.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [Device Trust](<https://devfeed.tech/topics/device-trust.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [identity](<https://devfeed.tech/tags/identity.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [news](<https://devfeed.tech/tags/news.md>), [saas](<https://devfeed.tech/tags/saas.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>)

### AI overview

1Password announces its acquisition of Apono to expand 1Password Unified Access with just-in-time privileged access governance. The article explains that growing numbers of machine identities and AI agents require continuously verified, consistently governed access across enterprise environments.

### Source excerpt

Over the past two decades, 1Password has earned the trust of millions of people, more than one million developers, and over 180,000 businesses by helping them secure one of the most fundamental elements of digital life: identity. Today, I'm thrilled to share that 1Password has acquired Apono, and I want to explain why this matters so much to us. Identity is changing. For years, the model was straightforward. Humans logged in, systems responded. Credentials verified who you were, and access controls determined what you could reach. That world is changing quickly. Software is now acting on our behalf. Machine identities far outnumber human identities. AI agents are beginning to retrieve data, execute workflows, provision resources, and make decisions across enterprise environments. The number of actors inside organizations is growing fast, and the systems governing identity and access were not built for this new reality. This is what we hear from customers every day. Businesses of all sizes and their security teams are struggling to get the full leverage of their AI investments while managing the risks brought about by non-deterministic agents accessing critical systems. Organizations want to move faster with AI, but they need confidence that every identity, whether it belongs to a person, a machine, or an agent, is continuously verified and governed consistently. They need to know not only who is requesting access, but what that identity should be allowed to do, under what conditions, and for how long. That challenge is exactly where Apono fits. 1Password has long been the vault that enterprises and their users relied upon to keep their secrets safe. With Apono, we become the access layer. For 1Password Unified Access, this is an important step forward. We already help organizations secure credentials, manage access to SaaS applications, strengthen device trust, and broker credentials at the moment they are needed. Apono's just-in-time privileged access governance co

## Introducing 1Password Credential Broker

DevFeed: [Introducing 1Password Credential Broker](<https://devfeed.tech/articles/introducing-1password-credential-broker-1932.md>)

Original publisher: [Read original article](<https://1password.com/blog/introducing-1password-credential-broker>)

Author: info@1password.com (Jeff Malnick)

Published: 2026-06-15T00:00:00Z

Content type: release

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [developers](<https://devfeed.tech/tags/developers.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [identity](<https://devfeed.tech/tags/identity.md>), [policy](<https://devfeed.tech/tags/policy.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [tokens](<https://devfeed.tech/tags/tokens.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>)

### AI overview

1Password introduces Credential Broker, a runtime credential-brokering service for machine workloads and AI agents. Its initial beta targets GitHub Actions, using workload identity, policy controls, and audit tools to provide credentials only when needed and revoke access afterward.

### Source excerpt

Right now, somewhere in your organization, a service account token is sitting in a CI/CD environment variable with access to your entire cloud environment. The job it was created for got deleted three sprints ago, and nobody knows it's still there. Unfortunately, that's not just a worst case scenario. For many teams it's a byproduct of how they manage credentials today. Someone in your organization creates a token, scopes it broadly to avoid any last-minute permission errors, drops it into a config file or a pipeline environment variable. They assume someone else will track it down to revoke it when the work is done. That assumption is almost always wrong, and the tokens and overprovisioned access accumulate. Machine identities now vastly outnumber human identities across most enterprises, and AI agents are growing faster and are governed less than almost anything else in the stack. The attack surface keeps expanding, and most teams are still managing credentials and access with the same approach they used five years ago. 1Password has spent more than a decade building what we believe is the best credential vault for humans. More than 180,000 businesses trust us to protect their most sensitive credentials and secrets. Now we're extending that same foundation to the machine workloads and AI agents. Introducing 1Password Credential Broker Our new 1Password Credential Broker extends what you can do with 1Password, from storing credentials and secrets to brokering them at runtime: delivering the right credential to the right workload at the moment work actually needs to happen. A machine workload or AI agent shouldn't hold credentials it doesn't currently need. It should prove who it is, get exactly what policy allows, and lose that access when its job is done. 1Password Credential Broker does exactly that, using the same 1Password vault, policy controls, and audit tools your team already relies on. Our initial beta focuses on GitHub Actions, which handles more than 6 b

## Our takeaways from the Gartner® Hype Cycle for Agentic AI report

DevFeed: [Our takeaways from the Gartner® Hype Cycle for Agentic AI report](<https://devfeed.tech/articles/our-takeaways-from-the-gartner-hype-cycle-for-agentic-ai-report-1920.md>)

Original publisher: [Read original article](<https://1password.com/blog/gartner-agentic-ai-governance>)

Author: info@1password.com (Sanjay Ramnath)

Published: 2026-06-05T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [AI Bots](<https://devfeed.tech/topics/ai-bots.md>)

Tags: [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [gartner](<https://devfeed.tech/tags/gartner.md>), [security](<https://devfeed.tech/tags/security.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>)

### AI overview

1Password discusses Gartner's view that enterprise AI-agent deployments need human oversight and stronger security governance as adoption accelerates.

### Source excerpt

In our view, The Gartner® Hype Cycle™ for Agentic AI, published in April 2026, contains a passage that we at 1Password feel should be a wakeup call for any organization building an agent program. Gartner states, "In practice, fully autonomous agents are not ready for most enterprise use cases, and human oversight remains essential. Semiautonomous deployments, where there is some human supervision of the work of AI agents, are what enterprises must plan for." That is a clear directive for organizations, and the gap between what it requires and what most current deployments provide should be driving every enterprise AI architecture conversation right now. The Hype Cycle for Agentic AI report states that "Interest in AI agents is significant and accelerating. According to Gartner's 2026 CIO and Technology Executive Survey, only 17% of organizations have deployed AI agents so far, but 42% expect to do so in the next 12 months, and another 22% within the following year. This is the most aggressive adoption curve among all emerging technologies in the survey." Later in the report, Gartner also states: "However, the supporting infrastructure and processes are still maturing. Integration, reliability, security, governance, and financial management for agents are all evolving, and organizations should be prepared for gaps and growing pains." Many of the organizations accelerating the AI agent adoption curve may be doing so without adequate governance in place. The question is how businesses can begin to build that infrastructure, and where they should put their focus when considering agent security governance. Not all agents carry the same security risks Agentic AI is not a monolithic category; distinct agentic innovations sit at different maturity stages with different architectural properties, and with distinct risks. We'll focus on three commonly known agentic use-cases from the 2026 Hype Cycle, as representative examples to explore 1Password's insights into some of the s

## Credential management for AI agents

DevFeed: [Credential management for AI agents](<https://devfeed.tech/articles/credential-management-for-ai-agents-1910.md>)

Original publisher: [Read original article](<https://1password.com/blog/credential-management-for-ai-agents>)

Author: info@1password.com (Rachel Sudbeck)

Published: 2026-05-07T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [AI Bots](<https://devfeed.tech/topics/ai-bots.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [MFA](<https://devfeed.tech/topics/mfa.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [api-keys](<https://devfeed.tech/tags/api-keys.md>), [developer](<https://devfeed.tech/tags/developer.md>), [identity](<https://devfeed.tech/tags/identity.md>), [management](<https://devfeed.tech/tags/management.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [saas](<https://devfeed.tech/tags/saas.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>)

### AI overview

The article examines how AI agents intensify credential sprawl by creating, using, and replicating non-human credentials at machine scale. It highlights risks from overprivileged, long-lived, and poorly audited API keys and service accounts, alongside gaps in traditional identity controls.

### Source excerpt

This blog has been adapted from an excerpted section of 1Password's ebook: Credential sprawl: How AI increases the risks. To read the complete ebook and learn more about the evolving challenges of credential sprawl, click here. The proliferation of credentials outside centralized visibility and control is known as "credential sprawl," and attackers are eager to take advantage of it. Unfortunately, credential management is a broad problem that only grows in complexity as organizations add new tools, employees, and partners. Today's companies have to manage an ever-growing number of credentials that go well beyond traditional passwords, such as developer secrets, passkeys, shared logins, API keys, SSH keys, service accounts, and SSO access tokens. Each of these, if exposed in an attack or breach, can have severe consequences, and developer secrets pose particular, systemic risk. Addressing credential sprawl has become especially urgent due to the rise of AI-based tools and agents. AI agents are a primary driver of credential sprawl because they create, use, and replicate credentials at machine scale. They have unique access needs and can behave both autonomously and unpredictably. Companies that want to integrate AI-based tools must carefully consider how to mitigate these risks to avoid an exponential rise in unmanaged and vulnerable credentials. How do AI agents increase credential risk? AI agents increase credential security risks through their reliance on non-human identities like API keys and service accounts, which are frequently overprivileged, long-lived, and poorly audited. Agents create and use these credentials at machine scale, beyond centralized oversight, leading to rapidly expanding credential sprawl with limited oversight for security teams. And while AI tools and agents pose new and distinct risks, they're also expanding on credential problems that have existed for years, stemming from SaaS sprawl, shadow IT, and unsafe developer practices. Traditiona

## 1Password and Perplexity expand partnership to secure access for Perplexity Computer

DevFeed: [1Password and Perplexity expand partnership to secure access for Perplexity Computer](<https://devfeed.tech/articles/1password-and-perplexity-expand-partnership-to-secure-access-for-perplexity-computer-1880.md>)

Original publisher: [Read original article](<https://1password.com/blog/1password-and-perplexity-expand-partnership>)

Author: info@1password.com (John Torrey)

Published: 2026-04-30T00:00:00Z

Content type: news

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Orchestration](<https://devfeed.tech/topics/orchestration.md>), [systems](<https://devfeed.tech/topics/systems.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agentic](<https://devfeed.tech/tags/agentic.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [news](<https://devfeed.tech/tags/news.md>), [orchestration](<https://devfeed.tech/tags/orchestration.md>), [partnership](<https://devfeed.tech/tags/partnership.md>), [systems](<https://devfeed.tech/tags/systems.md>), [tools](<https://devfeed.tech/tags/tools.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>), [workflow](<https://devfeed.tech/tags/workflow.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

1Password and Perplexity are expanding a partnership to integrate secure credential access with Perplexity Computer, enabling AI agents to carry out multi-step enterprise workflows without exposing credentials to the model.

### Source excerpt

AI has gotten very good at generating answers. The bigger opportunity now is helping people take action. That shift is already underway, and AI is moving from chat into real workflows: researching, navigating applications, and completing multi-step processes across systems. But the moment AI moves from answering questions to getting things done, one problem becomes impossible to ignore: secure access. Secure access, in this context, means ensuring the right human or AI agent can reach the right application or credential at the exact moment an action is taken without exposing sensitive data or stopping the workflow to ask someone to log in manually. Every meaningful agentic workflow depends on this, but most existing access protocols weren't designed for it. That's why we're expanding our partnership with Perplexity, by making 1Password's secure access capabilities seamlessly integrate with Perplexity Computer. AI agents are a new kind of actor in enterprise systems Perplexity is building an orchestration platform that coordinates models, tools, and connectors to automate complex work. As Perplexity Computer operates across enterprise environments, access stops being a convenience question and becomes a trust question. Consider what this looks like in practice: It's mid-March at a twelve-person CPA firm, and twenty new clients have dropped off boxes of files. In past years, the junior staff would spend ten days logging into Chase, Fidelity, Coinbase, and a dozen other portals one client at a time. This year, the senior CPA hands the intake list to Perplexity Computer. The agent asks 1Password for each credential, pulls the 1099s, logs into the IRS practitioner portal, files the extensions, and drops everything into UltraTax. The credentials never touch the model; the CPA spends her fourteen hours reviewing returns instead of typing them, and the firm takes on six more clients than last year because the bottleneck moved. That's what Perplexity Computer does. And 1Pass

## How to protect against OAuth-based supply chain breaches and credential sprawl

DevFeed: [How to protect against OAuth-based supply chain breaches and credential sprawl](<https://devfeed.tech/articles/how-to-protect-against-oauth-based-supply-chain-breaches-and-credential-sprawl-1949.md>)

Original publisher: [Read original article](<https://1password.com/blog/protect-against-oauth-supply-chain-breaches>)

Author: info@1password.com (Sanjay Ramnath)

Published: 2026-04-23T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Authorization](<https://devfeed.tech/topics/authorization.md>), [Google](<https://devfeed.tech/topics/google.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [breach](<https://devfeed.tech/tags/breach.md>), [google](<https://devfeed.tech/tags/google.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [saas-management](<https://devfeed.tech/tags/saas-management.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>)

### AI overview

The article explains how credential sprawl and overpermissioned OAuth connections can create supply-chain risk. It outlines an attack chain in which a compromised third-party service exposes a valid OAuth token that an attacker can use to access internal systems, then calls for visibility into connections, just-in-time access, and usage records.

### Source excerpt

For security teams, credential sprawl is like dust; you don't notice it until it has accumulated. Over time, access spreads across SaaS apps, developer tools, automation workflows, and now AI agents. People sign up for tools to get work done and connect accounts using OAuth because it is fast and familiar. Credentials get reused across scripts, stored in environment variables, or passed between systems that were never meant to share a common control layer. The problem only becomes visible when you zoom out and realize that all these individual decisions have created a network of external dependencies that now sit on top of your internal access model. That is where credential sprawl turns into a supply chain risk. Add enough overpermissioned OAuth connections and suddenly, access to your internal systems is at the mercy of the security posture of every third-party service that has been granted access along the way. What is the attack chain for an OAuth-based supply chain brief? Recent incidents have shown how this access pattern can turn into a breach. Here's how it has played out: An employee connects a third-party tool using Google Workspace OAuth. The permissions are granted through a standard consent flow. At some point later, that third-party service is compromised. The attacker obtains the token and uses it to access internal systems. There is no need for the attacker to bypass authentication, because the token is valid. There is also no need to escalate privileges, because the permissions are already in place. What makes this type of attack so insidious is that, from the perspective of most security systems, the hacker's activity does not appear anomalous. The requests are authenticated, the client is recognized, and there are no failed login attempts or obvious indicators of abuse. The attacker is operating within the boundaries that have already been approved. The issue here is that trusted access has been extended into an environment that sits outside of di

## What we learned using AI agents to refactor a monolith

DevFeed: [What we learned using AI agents to refactor a monolith](<https://devfeed.tech/articles/what-we-learned-using-ai-agents-to-refactor-a-monolith-1971.md>)

Original publisher: [Read original article](<https://1password.com/blog/what-we-learned-using-ai-agents-to-refactor-a-monolith>)

Author: info@1password.com (Nancy Wang; Wayne Duso; K.J. Valencik)

Published: 2026-04-20T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Refactoring](<https://devfeed.tech/topics/refactoring.md>), [Code](<https://devfeed.tech/topics/code.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [systems](<https://devfeed.tech/topics/systems.md>), [toolchain](<https://devfeed.tech/topics/toolchain.md>), [Security](<https://devfeed.tech/topics/security.md>), [Unified Access](<https://devfeed.tech/topics/unified-access.md>), [Parser](<https://devfeed.tech/topics/parser.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [code](<https://devfeed.tech/tags/code.md>), [developers](<https://devfeed.tech/tags/developers.md>), [go](<https://devfeed.tech/tags/go.md>), [performance](<https://devfeed.tech/tags/performance.md>), [refactoring](<https://devfeed.tech/tags/refactoring.md>), [security](<https://devfeed.tech/tags/security.md>), [sql](<https://devfeed.tech/tags/sql.md>), [toolchain](<https://devfeed.tech/tags/toolchain.md>), [tooling](<https://devfeed.tech/tags/tooling.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>)

### AI overview

1Password describes using AI agents and an agentic toolchain to analyze, plan, and execute refactoring of its multi-million-line Go monolith. The article focuses on dependency mapping, system decomposition, extraction sequencing, and lessons from applying the approach to live production systems while preserving reliability, performance, privacy, and security.

### Source excerpt

AI agents are increasingly used to refactor large codebases, but many teams lack a clear understanding of where they succeed and where they fail. At 1Password, we applied agentic tooling to a multi-million-line Go monolith, and in this blog we'll share what worked, what broke, and what it means for teams adopting AI in production systems. Here's the situation: 1Password runs a large Go monolith called B5. It has been the foundation of our product for years and continues to perform well in production, both in terms of reliability and scale. Now, Unified Access is designed to support both human and agent-driven workflows at high request rates and low latency. As we continue adding and enhancing its capabilities, we need clearer service boundaries and more independent scaling characteristics. Over time, that means evolving parts of the system in a way that preserves the privacy, performance, reliability, and security properties we have already established. Coming up with an actionable plan for tackling this problem sounded like a good job for agents. In our case, this meant applying agentic refactoring: using AI agents to analyze, plan, and execute changes across a codebase, from dependency mapping to system decomposition. There's a version of this story where agentic tooling analyzes a large codebase, produces a clean extraction plan, and service decomposition follows a predictable path from there. Parts of that story did play out as expected. We built an agentic toolchain that analyzed millions of lines of code and gave us a clear, defensible extraction order, and that work has meaningfully improved how we think about decomposing the system. What ended up being more valuable, though, was what we learned once we applied those tools to real changes in a live production environment. That is the part that tends to get glossed over, and it is the part that actually determines whether this approach works. Building the analysis layer The first question we had to answer was

## RSA 2026: Leading the way to secure agentic AI

DevFeed: [RSA 2026: Leading the way to secure agentic AI](<https://devfeed.tech/articles/rsa-2026-leading-the-way-to-secure-agentic-ai-1951.md>)

Original publisher: [Read original article](<https://1password.com/blog/rsa-2026-leading-the-way-to-secure-agentic-ai>)

Author: info@1password.com (Elaine Atwell)

Published: 2026-03-27T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [Unified Access](<https://devfeed.tech/topics/unified-access.md>), [releases](<https://devfeed.tech/topics/releases.md>), [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [agentic-security](<https://devfeed.tech/tags/agentic-security.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [conference](<https://devfeed.tech/tags/conference.md>), [incident](<https://devfeed.tech/tags/incident.md>), [life-at-1password](<https://devfeed.tech/tags/life-at-1password.md>), [releases](<https://devfeed.tech/tags/releases.md>), [security](<https://devfeed.tech/tags/security.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>)

### AI overview

1Password's RSA 2026 recap focuses on securing agentic AI as organizations adopt AI agents faster than governance can keep up. It highlights 1Password Unified Access, a platform for discovering, securing, and auditing access across humans, agents, and machine identities, along with conference discussions about AI safety, security safeguards, breaches, and incident response.

### Source excerpt

Every year, security and tech leaders come to the RSA conference in San Francisco to take the industry's pulse, and every RSAC tends to be dominated by a single, overarching theme. Last year, the theme was: "AI agents are coming, and governance isn't ready." And sure enough, the theme of RSAC 2026 was: "AI agents are here, and governance needs to catch up." Throughout the conference, security practitioners, vendors, and analysts were all asking the same questions: How can we enable a culture of agentic AI builders, without compromising on bedrock security principles? How can we mitigate the potential for AI agents to behave unsafely, either via malicious compromise or their own nondeterministic nature? What are the most impactful safeguards every organization should be putting into place to secure AI and automation in the next year? 1Password provided answers to those urgent questions at RSA. Prior to the event, we announced the release of 1Password® Unified Access, a new platform that helps teams discover, secure, and audit access across humans, agents, and machine identities, so organizations can adopt AI confidently and securely. At RSA, 1Password leaders spoke on panels, met with customers, discussed what's next in agentic security with industry analysts and press, and demoed our products for booth visitors. Here's a look at the highlights. Day 1 of RSA: Booth conversations and customer appreciation The 1Password booth was buzzing with RSAC attendees eager to learn about how our latest product releases could address their security needs. They experimented with interactive demos of our products, which you can check out for yourself: 1Password Unified Access 1Password Enterprise Password Manager 1Password SaaS Manager Monday night, 1Password leaders hosted a customer appreciation happy hour, where everyone enjoyed the chance to unwind, swap stories, and discuss the shared future for 1Password and our customers. Day 2 of RSA: Security lessons from before and after

## The next layer of AI security

DevFeed: [The next layer of AI security](<https://devfeed.tech/articles/the-next-layer-of-ai-security-1901.md>)

Original publisher: [Read original article](<https://1password.com/blog/ai-security-runtime-controls>)

Author: info@1password.com (Jacob DePriest; Nancy Wang; Jeff Malnick)

Published: 2026-03-19T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [AI Bots](<https://devfeed.tech/topics/ai-bots.md>), [AI Chat](<https://devfeed.tech/topics/ai-chat.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [developers](<https://devfeed.tech/tags/developers.md>), [microsoft-365-copilot](<https://devfeed.tech/tags/microsoft-365-copilot.md>), [security](<https://devfeed.tech/tags/security.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article examines prompt injection risks in AI agents that act with user-level permissions. Using the EchoLeak vulnerability in Microsoft 365 Copilot as an example, it argues that correct authentication and authorization do not prevent unsafe actions after access has been granted.

### Source excerpt

Identity establishes trust. The next problem is how that trust is used. In June 2025, Microsoft patched EchoLeak (CVE-2025-32711), a zero-click vulnerability in Microsoft 365 Copilot that allowed an attacker to exfiltrate sensitive enterprise data, including API keys, confidential documents, and internal conversation snippets, without human intervention. The attack was deceptively simple. An attacker sent a normal-looking email with hidden instructions embedded in it. A human would not notice them, but the model could interpret them. The email remained dormant until Copilot later pulled it into context for another task. At that point, the instructions triggered, and the agent used the victim's existing permissions to retrieve and disclose sensitive information. The specific vulnerability matters, but the broader lesson matters more. A system can authenticate correctly, authorize correctly, and still produce the wrong outcome. Microsoft patched EchoLeak before it was publicly disclosed. Since then, researchers have identified similar patterns across AI-assisted workflows, including additional Copilot-related vulnerabilities in 2026. These are not isolated issues. They point to a broader, repeatable pattern. When AI systems process untrusted content and act with user-level permissions, prompt injection and unintended data access become systemic risks rather than edge cases. This is not a failure of authentication or authorization. It is what happens after both succeed. Systems are behaving exactly as designed, and still producing the wrong outcomes. Prompt injection breaks the execution model Prompt injection isn't just a model issue. It's a signal that something is breaking between how systems reason and how they act. The industry sees the same thing. OWASP Top 10 for LLM applications ranks prompt injection as a primary attack vector, and research from OpenAI and others shows that models cannot reliably distinguish between legitimate instructions and malicious ones e

## Introducing 1Password® Unified Access: Identity Security for Humans and Their AI Agents

DevFeed: [Introducing 1Password® Unified Access: Identity Security for Humans and Their AI Agents](<https://devfeed.tech/articles/introducing-1password-unified-access-identity-security-for-humans-and-their-ai-agents-1934.md>)

Original publisher: [Read original article](<https://1password.com/blog/introducing-1password-unified-access>)

Author: info@1password.com (Nancy Wang and Jeff Malnick)

Published: 2026-03-17T00:00:00Z

Content type: release

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [AI Bots](<https://devfeed.tech/topics/ai-bots.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [api](<https://devfeed.tech/tags/api.md>), [automation](<https://devfeed.tech/tags/automation.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [identity](<https://devfeed.tech/tags/identity.md>), [local-ai](<https://devfeed.tech/tags/local-ai.md>), [news](<https://devfeed.tech/tags/news.md>), [security](<https://devfeed.tech/tags/security.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>)

### AI overview

1Password introduces Unified Access Pro, an identity-security offering intended to discover, secure, and audit access involving people, AI agents, and machine identities. The article argues that credentials used by local agents, automation, and development tooling require access to be confirmed when a credential or secret is used.

### Source excerpt

Agentic AI is changing how work gets done inside organizations. It's embedded in IDEs and automation tools, and it's showing up in browsers, internal workflows, and everyday productivity apps. Developers are using AI agents to accelerate engineering work, while knowledge workers are vibe coding apps without training on developer security practices, all of which create untenable risks for organizations. That shift has real implications for identity and access control. For years, identity security centered on login: authenticating the user, establishing a session, applying policy, and assuming authority for the duration of that session. That model worked for human access, but it breaks down when credentials are used by local AI agents, automation scripts, CI/CD pipelines, and AI-native tooling. In this new reality, authority shouldn't be decided once at login and then trusted all day. It should be confirmed right when access is requested, every time a credential or secret is used. That's why we're introducing Unified Access Pro, available today. It helps teams discover, secure, and audit access across humans, agents, and machine identities, so organizations can adopt AI confidently and securely. To learn more about 1Password® Unified Access, head here:https://1password.com/platform Discover risk where traditional identity security systems can't As work shifts to AI agents and automation, more credentials are used outside the identity systems that security teams rely on. It happens on employee devices, inside local development environments, and across browser-based AI tools. Security teams often have little insight into what's happening on employee devices and in the tools they use every day, where credentials are created, stored, and first used. That gap matters. Exposed SSH keys, plaintext .env files, long-lived API tokens, and locally installed agents rarely appear in traditional SaaS logs or federated identity systems. Yet these credentials can grant direct access

## Enterprise-ready Trino at Bloomberg: One Giant Leap Toward Data Mesh!

DevFeed: [Enterprise-ready Trino at Bloomberg: One Giant Leap Toward Data Mesh!](<https://devfeed.tech/articles/enterprise-ready-trino-at-bloomberg-one-giant-leap-toward-data-mesh-8695.md>)

Original publisher: [Read original article](<https://trino.io/blog/2022/11/30/trino-summit-2022-bloomberg-recap.html>)

Author: Vishal Jadhav, Pablo Arteaga, Cole Bowden

Published: 2022-11-30T00:00:00Z

Content type: article

Language: en

Sources: [Trino Blog](<https://devfeed.tech/sources/trino-blog.md>)

Topics: [data](<https://devfeed.tech/topics/data.md>), [Availability](<https://devfeed.tech/topics/availability.md>), [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Unified Access](<https://devfeed.tech/topics/unified-access.md>)

Tags: [availability](<https://devfeed.tech/tags/availability.md>), [clusters](<https://devfeed.tech/tags/clusters.md>), [data](<https://devfeed.tech/tags/data.md>), [fork](<https://devfeed.tech/tags/fork.md>), [high-availability](<https://devfeed.tech/tags/high-availability.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [latency](<https://devfeed.tech/tags/latency.md>), [load-balancer](<https://devfeed.tech/tags/load-balancer.md>), [low-latency](<https://devfeed.tech/tags/low-latency.md>), [open](<https://devfeed.tech/tags/open.md>), [recap](<https://devfeed.tech/tags/recap.md>), [security](<https://devfeed.tech/tags/security.md>), [series](<https://devfeed.tech/tags/series.md>), [summit](<https://devfeed.tech/tags/summit.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>)

### AI overview

This recap describes Bloomberg's use of Trino to federate diverse financial data and provide unified access. It focuses on the Trino Load Balancer, a privacy-aware fork of presto-gateway that routes workloads across Trino clusters according to resource use and user needs while supporting high availability, performance, and data-access policies.

### Source excerpt

This post continues a larger series of posts on the Trino Summit 2022 sessions. Following the Trino at Apple talk, engineers from Bloomberg shared the latest about their additions to Trino. Bloomberg uses Trino to federate huge amounts of disparate financial data together. When you have many users with different use cases and resource needs, you need something to ensure that the huge workloads don't bully the small ones. Enter the Trino Load Balancer, a privacy-aware solution to help maintain high availability while still treating data security as the first-class citizen that it should be.