Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Delegated authority, running locally: Give an agent on your machine an identity you can trust

Part 3 of our agent-identity series: a reference architecture showing how a locally running AI agent, like the coding assistant in your editor or the copilot in your browser, can borrow a human's authority in a scoped, short-lived, auditable way, anchored in an app the user already trusts.

The tokenmaxxing bill is due: Take control of AI spend with SaaS Manager

A nasty shock is hitting finance leaders across every industry right now: AI token bills that run ten, twenty, even a hundred times over what they forecasted, blowing holes straight through quarterly budgets. These leaders are all asking the same questions: How could this happen if they didn't approve it? Why didn't any of their systems alert them to the spike? And most importantly, what can they do now?

Don't bring exposed developer credentials to Black Hat

Black Hat is where the security industry gathers to compare notes on what works. In recent years, supply chain attacks have been a recurring topic, and the 2026 Verizon Data Breach Investigations Report shows security teams are struggling to find a solution. According to the report, third-party involvement increased by 60% over the last year and now accounts for 48% of all breaches.

How IT can reduce credential risk across every department

Credential sprawl has long been an issue IT and security teams have had to grapple with, and solutions like single-sign-on (SSO) have never been able to contain it completely. Now, AI is accelerating the problem. AI agents need access to credentials at an unprecedented scale, leaving IT and security teams struggling even more to ensure that every credential, across every department, is secure.

Braintrust's Ankur Goyal: Code review doesn't cover prompts

Zero-Shot Learning is a podcast about how AI gets built, secured, and deployed. Hosted by Nancy Wang, 1Password CTO, and Dev Tagare, Senior Director of Engineering at Google, it’s a builder’s view of the architecture and the decisions it takes to ship with AI.

Scaling security reviews at 1Password: Building an AI-powered pipeline

The developers and engineers here at 1Password are always working to improve our products. With all the active development to introduce features, fix bugs, and enhance the overall user experience, numerous code changes go into every release. We strive to ensure each iteration is better than the last and that new code doesn’t introduce vulnerabilities. A key part of this process is our Product Security (ProdSec) team’s review of all code changes that may have security implications.