C1 scopes every AI agent to the tools its job needs, governs every tool call against policy, and ties each action to a governed identity you can audit.
SAN FRANCISCO — July 29, 2026 — C1 today launched intent-based access control for AI agents, which scopes each agent to the tools its job requires, governs every tool call against policy, and ties each action to a governed identity. An AI agent's power is the tools it can reach, and once connected it can read a record, run a query, push code, or send data outside at machine speed without human intervention.
Intent-based access control governs agents by what they exist to do—not by broad, standing access. Every tool call flows through an identity-aware AI gateway that registers an organization's MCP servers and discovers the tools they expose. C1 grants each agent access only to the tools it needs, enforcing the same policies that govern every human and machine identity. Every action is fully auditable, with each request tied to the agent, its owner, and the policy that authorized it.
A tool call looks the same whether it is routine or an attack. "Read this record" looks identical whether the data goes into a quarterly report or an outsider's inbox. What differs is the task and its context, and most controls never see that layer. Identity tools check who an agent is and which tools it may reach, then hand over a credential and step back. Prompt filters inspect the model's words. Neither one governs what the call actually does, which is where an over-permissioned agent turns a hidden instruction into a breach.
C1 scores every call against the "lethal trifecta" (named by researcher Simon Willison): private data in reach, untrusted content in play, and a path to send data outside. Based on the risk, C1 blocks the call, holds it for approval, or redacts sensitive data from the response. The controls fail closed—if a guardrail check cannot run or a content judge is unavailable, C1 becomes more restrictive, not less. For example, if a support agent encounters a hidden instruction to retrieve customer records and send them to an external address, C1 detects the risk, blocks the action, and records an audit trail tied to both the agent and its owner.
"Managing credentials for agents is a start, but by itself, is insufficient," said Alex Bovee, CEO and co-founder of C1. "Agents are fundamentally non-deterministic. We ask them to do things, and they can take various paths to accomplish the goal. This means agents also have to be governed at runtime. They need guardrails and run-time enforcement of what data they can access and what they can do with the data."
C1 customers are using agent runtime governance today. For more information or to request a demo, visit c1.ai.
About C1#
C1 is the control plane for the agentic enterprise, empowering companies to adopt AI fearlessly. Our platform secures human and non-human identities, automates access, and accelerates AI adoption. With C1, the fastest path to AI adoption at scale is the governed path—giving organizations visibility and control without sacrificing security or slowing innovation. Companies such as Ramp, Zscaler, Instacart, and Brex trust C1 to power their agentic transformation.

