Skip to content
Octo Inc. — Access Control Unit
Octoberus ACCESS

MODULE IN DEVELOPMENT — WAITLIST

Access control for AI agents and non-human identities

This module is in development. We are publishing the design and opening a waitlist for critical operators who want to co-design it. The problem it targets already exists: an agent that queries a historian, opens a ticket or asks an operations system for data usually does so with a person’s credential. With no identity of its own, no bounded permissions and no log that can be told apart from its creator’s, nobody can tell which actions were the agent’s and which were the person’s.

Why it matters and what we are building

Non-human identities are already the majority. The controls are not.

01

109 machine identities per human one

According to the Identity Security Landscape 2026 report, there are 109 machine identities for every human identity. Each one is a key someone created and almost nobody reviews (source: helpnetsecurity.com, May 2026).

02

Only 34 % apply the same controls

According to Okta’s AI Agents at Work 2026 report, only 34 % of organisations apply to AI agents the same identity controls they apply to people. The other two thirds treat them as scripts (source: okta.com, 2026).

03

Identity abuse is already a top 10 risk

The OWASP Top 10 for Agentic Applications 2026 lists ASI03, Identity & Privilege Abuse. The CSA Agentic Trust Framework (February 2026) and the CISA-and-partners guidance on agentic AI in critical infrastructure (2026) point to the same control: identity and privilege per agent (source: genai.owasp.org, cloudsecurityalliance.org, industrialcyber.co).

04

An identity per agent, with a human owner

We are designing an identity type for agents and services: name, purpose, the system that runs it and a responsible person, just like a contractor credential. ISO/IEC 27001:2022 A.5.16 and A.8.5 already cover identity management and secure authentication without asking whether a person is behind it.

05

Bounded permissions: least agency

The plan is for each agent to receive permissions per asset, per action and per time window, instead of inheriting the master key of whoever created it. It is least privilege, extended to the ability to act. NIST CSF 2.0 explicitly names “users, services, and hardware” in PR.AA-01 and PR.AA-03.

06

The same file as the doors

Every action by an agent will be logged where the door openings already live: what it requested, under which identity, under which permit and what happened. One file to show the cybersecurity delegate, the CIP officer and the DPO.

WAITLIST — AI AGENTS

Join the waitlist

The non-human identity module is in development. Leave us your details and we’ll get in touch once there’s something to test, not before.

Frequently asked questions

Is it available today? +

No. It is a module in development. We publish the design and open a waitlist; we do not sell it, do not charge for it and do not include it in any proposal as if it existed. When there is something to test, the people on the list hear first.

What is the waitlist for? +

To co-design it. We want to understand which agents are already running inside critical operators, with which credentials and against which systems, before settling the permission model. Whoever joins takes part in those conversations and gets priority in the pilot.

And in the meantime? +

Octoberus physical and digital access control is already in production: doors, zones, expiring permits, immediate revocation and exportable evidence. If you have agents or services reaching your systems today, the first step is to inventory them and give each one a human owner. That does not require waiting for any module.

Do you know what your AI agent can open?
Let us talk.

Talk to us →