1Password’s acquisition of Apono and the launch of Credential Broker move the company from storing credentials toward governing what identities do with them at runtime. The premise is right but 1Password needs to move quickly.
Most security incidents do not begin at the login screen. They begin much later, when an identity has authenticated once and keeps its access long after the reason for it has disappeared. Standing access is the liability almost no one measures. Employees keep permissions from projects that ended years ago. Service accounts reach systems no one remembers connecting. API keys sit in config files, valid until someone notices, which is usually never.
For the longest time, this was still manageable. People log in a few times a day, act at human speed, and usually leave a trail someone can reconstruct later. Software acting on our behalf changes the equation. An Artificial Intelligence (AI) agent can operate continuously, across systems, through credentials scattered across code, pipelines, vaults, and SaaS tools.
Authentication tells you who the agent claims to be but does not tell you what the agent should be allowed to touch, why, or for how long. That is the problem 1Password has now decided to address, with an acquisition reportedly valued well above $200 million.
What 1Password did
When 1Password introduced Unified Access in March 2026, the strategic direction was already clear: access, not authentication, was becoming the control point for humans, machines, and agents. What was less clear was how much runtime enforcement the platform could actually provide.
The more recent announcements answer that question only partially, but they make the missing piece visible. 1Password acquired Apono, a cloud-native just-in-time (JIT) access governance platform, and launched Credential Broker into private beta. These two announcements are closely related, but they are not interchangeable. They address different layers of the same access problem.
Credential Broker covers credential delivery: where secrets live, how they are retrieved, how they are injected into workflows, and how organizations can stop hardcoding them into automation, scripts, repositories, pipelines, and local developer environments. Its first private beta use case, GitHub Actions, is still quite narrow but shows the direction of future development. CI/CD workflows are exactly where long-lived secrets, excessive permissions, and developer convenience tend to reinforce each other.
Apono addresses runtime authorization. Once an identity has received access, what can it actually do, under which conditions, with whose approval, and for how long? This is where JIT access, zero standing privilege (ZSP), approval workflows, session controls, and auditability become central. Apono is less about protecting the credential itself and more about governing the entitlement that credential enables.
Credential Broker helps prevent credentials from being scattered, copied, embedded, and forgotten. Apono helps prevent access from becoming broad, persistent, and detached from business need. One is about delivering secrets safely while the other makes access conditional, temporary, and observable at runtime.
The vault is still the company’s original foundation, but 1Password’s ambition is no longer simply to store credentials securely. It is to decide when credentials should be released, what access they should enable, what the identity may do with that access, and when the permission should disappear again.
Credential security and access governance have been treated as separate disciplines for too long. In an agentic environment, that separation becomes a liability. An AI agent does not care whether the risk came from a leaked token, an overprivileged service account, or an approval workflow that granted too much access for too long. It only needs enough authority to wreak havoc at machine speed.
Credential Broker and Apono are therefore not just two product additions. They are the two sides of the runtime access layer the Unified Access narrative was missing in March.
Why access, not login, is the control point
For most of its history, enterprise identity centered on authentication: create the account, verify the login, provision access, deprovision on exit. The workflow was built around the moment of entry, because for human users that was where the interesting decisions usually happened.
Agents work differently: they act after entry, continuously and at machine speed. They chain actions together, cross system boundaries, and use delegated authority in ways no one fully anticipated when the session opened. A permission that looked reasonable at login can become excessive a minute later, when the agent reaches into a system it was never meant to touch. Point-in-time authorization cannot see that happen, let alone stop it.
“Who is allowed in” is no longer the right question to ask. We need to know what identity is allowed to do once inside, whether the permission still makes sense, and whether it should still exist a second later.
This is the shift from Zero Trust as a slogan to Zero Trust as an operating model, where enforcement follows the identity into every action. The agentic version is even sharper because agents act through APIs, with delegated authority, at a volume conventional controls were never built to police. This is the broader argument I make in Leadership Compass Zero Trust Platforms and No API Security, No AI Security. 1Password is making the right call: runtime access, not the login event, is becoming the control point for agentic work.
From vault to access platform
As a company that already holds credentials, secrets, and developer workflows, 1Password has a strong starting point for broader identity security. The vault is not enough to make it an enterprise access platform, but it is a powerful foundation from which to try. Its strength has always been usability, and that matters more than enterprise identity vendors sometimes like to admit. A security control no one wants to use is usually something people quietly work around.
The challenge is that enterprise identity security is not just a usability problem. It is also an architecture problem, an integration problem, but most of all an organizational problem. Identity, security, DevOps, and engineering teams all look at access from different angles. A vault gives 1Password a strong point of entry, but the enterprise narrative must extend beyond secure storage into policy, enforcement, audit, governance, and operational fit.
That was the open question in March. Unified Access pointed in the right direction, but the runtime layer was still more implied than delivered. Apono gives 1Password a credible answer to what happens after a credential is released and after an identity enters a system. Whether that answer becomes an integrated enterprise platform is still a separate question.
Unified is still a claim about the future
The word doing the heavy lifting in “Unified Access” is unified. It is also the part still coming together, since customers cannot yet buy the pieces as one integrated platform.
The pieces sit at very different stages. Enterprise Password Manager is established. SaaS Manager is real and growing. Device Trust has been in the portfolio since 2024. Credential Broker is in private beta and starts with GitHub Actions. Apono has only just arrived inside the company, with deeper integration still ahead. The two building blocks carrying most of the agentic runtime story are also the least mature pieces inside the 1Password platform.
The harder part is that credential delivery and runtime authorization have to converge in practice. Credential Broker cannot remain only a safer way to retrieve secrets, and Apono cannot remain only a JIT access layer beside the vault. The value of Unified Access depends on making both layers part of the same policy decision: who is asking for access, which credential is being requested, what task it supports, what the identity can do once inside, when access expires, and what evidence is produced afterward. A portfolio can contain a vault, a broker, a SaaS visibility tool, device trust, and JIT access. A platform has to make those components behave like one control plane.
Read generously, 1Password saw a gap in its own roadmap and moved decisively. Read skeptically, a core capability is now being positioned as central to the strategy just weeks after arriving through acquisition. Both readings can be true. That is what makes the move interesting.
The most crowded corner in identity
1Password is entering one of the most crowded market segments of identity security, and it has arrived at the same conclusion at almost the same moment as its competitors.
CrowdStrike is talking about Continuous Identity for AI Agents, real-time authorization, removal of standing privileges, and delegation chains. SailPoint is positioning Agentic Fabric around agent ownership and ZSP models. Delinea bought StrongDM for a similar reason.
Even the vocabulary is converging: zero standing privilege, just-in-time access, unified control plane, humans, machines, agents. When every vendor uses the same labels in the same quarter, the labels stop carrying information. The only useful question is what sits underneath them.
1Password’s advantage is the vault, the developer footprint, and the everyday usability that many enterprise incumbents still struggle to match. It starts close to where credentials are created, stored, shared, and quietly misused. That gives it a credible path from human access to delegated agent access, especially in developer workflows where agents, automation, and secrets already collide.
What it does not have is uniqueness. Several competitors now have defensible foundations of their own, whether they start from privileged access management, identity governance and administration, endpoint security, identity threat detection and response, or continuous authorization. 1Password is not the only vendor building this, but it may have one of the strongest starting points where developers and agents already work.
Where the pitch gets ahead of the product
Apono’s intent-based access model asks an agent to state, in natural language, why it needs access, then compares that declared intent against what the agent actually does. If the behavior diverges, access can be narrowed or revoked.
Conceptually, this is where agent governance has to go. In practice, it depends on reliably characterizing the intent of a non-deterministic system and detecting drift without a lot of false positives. That is an exceptionally hard problem, and no vendor has cracked it reliably at scale yet.
Tying an agent’s access to the human who authorized it, scoped to a task, is the delegated identity model the industry is rapidly converging on. It is also easier to describe than to implement. It raises uncomfortable operational questions. What happens when the delegating human’s own access changes mid-task? What happens when an agent calls another agent? Where is the chain anchored, how is it verified, and who can revoke it?
Both claims run into the credential and protocol layer where agents connect to tools, the surface examined in Model Context Protocol, and both sit on top of the non-human identity problem charted in From Machine Identity to Agentic AI. These are not objections to the model. They are the conditions under which the model becomes real.
The work that starts after the deal
Access, not authentication, is becoming the control point for agentic work. 1Password has identified that shift correctly, and with Apono it has bought the runtime access layer it was missing.
However, the market will not wait while 1Password turns multiple products into one platform. Larger and better-resourced competitors are assembling versions of the same model, often with deeper roots in privileged access, identity governance, endpoint security, or continuous authorization. 1Password’s advantage is real but narrow enough to erode if integration stalls.
The move from storing credentials to governing access is the right one. Whether 1Password can turn it into a defensible enterprise position depends on making the vault, Credential Broker, Apono, SaaS Manager, and Device Trust behave like one system before the market decides that someone else already solved the problem.