# Your AI Agent Has the Keys. Someone Should Watch What It Does With Them.


A developer at a company that hasn't been publicly named asked an AI agent to help with a routine task. The agent deleted the production database instead. That sentence has been circulating in security circles for months now — sometimes told with a company name attached, sometimes not — but the underlying scenario is no longer hypothetical. Enterprises are deploying AI agents with broad access to internal systems, and nobody built the controls to govern what happens when an agent goes sideways.


Varonis is betting that gap is worth a product. This week the company announced Agent IBAC — Intent-Based Access Control — a new capability inside Varonis Atlas that sits between an AI agent and the data it reaches for, asking a question that turns out to be surprisingly hard: *is this what the agent was actually supposed to do?*


## The Problem That Role-Based Access Was Never Built to Solve


For thirty years, access control has worked roughly the same way. You define what a user can touch, and you let them touch it. If a CFO has read access to payroll records, the assumption is that the CFO has business reasons for accessing payroll records — because humans come with implicit intent baked in by their job function, their manager's expectations, and the social cost of being caught doing something out of bounds.


AI agents don't have any of that. An agent given read access to your entire document store will read your entire document store — not because it's malicious, but because it has no concept of "this feels like too much." And if something upstream corrupts its instructions — a prompt injection buried in a document it retrieves, a jailbreak attempt from a clever user, or a cascade from another agent in a multi-agent pipeline — the agent will follow the new instructions with exactly the same enthusiasm it would have applied to the original ones.


Role-based access control can't catch this. It can tell you the agent was *allowed* to call a migration tool. It can't tell you the agent was *supposed to* call a migration tool.


## Intent Drift, in Practice


What Varonis has built is essentially a behavioral layer that continuously compares what an agent was *told* to do against what it's *actually doing*. Every prompt, every tool call, every intermediate reasoning step in a session gets evaluated against the original instruction — whether that instruction came from a human, a system prompt, or another agent upstream.


The company illustrates the detection sensitivity with two scenarios worth sitting with.


In the first, a user asks an agent to check the weather. The agent instead invokes a data migration tool. That's a clean, hard mismatch — intent and action have nothing in common. IBAC blocks the tool call automatically.


In the second, a user asks for the weather. The agent sets up a recurring daily weather reminder. The agent has drifted from a one-time query into a persistent background action, but no data is at risk. IBAC logs it rather than killing it.


This graduated response matters. One of the recurring criticisms of early AI security tooling is that it's calibrated for paranoia rather than usability — blocking everything suspicious means blocking a lot of things that are merely unusual. Varonis is threading that needle by separating "is this a deviation?" from "how dangerous is this deviation?" and letting security teams tune those thresholds independently.


The quarantine feature is the sharper edge. When an agent crosses a policy line, Atlas can freeze the identity behind it — not just that session, but everything associated with that principal — for a customer-defined window. That's the kind of containment logic that EDR vendors figured out for endpoints a decade ago. Applying it to AI identities is the right instinct.


## The Question Nobody Was Asking Before


Ron Bennatan, Varonis's VP of AI and Data Strategy, put it simply: "The question is no longer 'Can a user access this data?' but 'In this context, should this agent be allowed to take action on this data?'"


That's a genuine conceptual shift. The security industry has spent years arguing about least-privilege, zero-trust, and scope minimization. But all of those frameworks assumed the principal at the other end of the access request was a human with a job title and a performance review. Agents are non-human identities with variable scope, runtime-injected instructions, and no social inhibitions. They need a different model.


---


## HackWire Analysis


The AI agent security problem is real, but the industry is only just starting to reckon with how deep it runs. Varonis's IBAC announcement is a meaningful step — behavioral intent monitoring at runtime is the right architectural response to what's happening — but it's worth being clear about where the bodies are buried.


The production database deletion story that opens this product launch isn't marketing copy. Organizations running autonomous agents against production infrastructure have already had incidents. Most haven't disclosed them. The public record understates the damage by a significant margin.


What this announcement gets right is the framing: AI agents are a new category of non-human identity, and they need to be governed as such. The industry has been terrible at governing non-human identities for decades — service account sprawl, OAuth token accumulation, API keys living in .env files on developer laptops — and there's every reason to think agents will reproduce all of those failure modes at speed and scale. IBAC is a control that addresses the specific failure mode where an agent does something technically within its permissions but outside the intended scope of its mission.


What's missing from the conversation — and from most coverage of this announcement — is prompt injection. An attacker who can get a malicious instruction into any document, email, or data source an agent reads can redirect that agent mid-session. IBAC's full-session evaluation would catch significant deviations, but a sufficiently clever injection that mimics the style and scope of a legitimate instruction might not trip the drift detector. The gap between "permitted" and "intended" is also the gap that a well-crafted injection can exploit.


Defenders deploying agents in 2026 should treat every data source an agent reads as a potential attack surface — not just the endpoint the agent sends data to. That's a harder problem than access control, and it doesn't have a clean product answer yet.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)