Varonis yesterday introduced Agent Intent-Based Access Control (Agent IBAC), a capability in Varonis Atlas designed to keep software agents operating only within their intended boundaries. The announcement frames the feature as a real‑time safety layer for agent workflows after a series of high‑visibility incidents—agents have "gone rogue," exposed sensitive company data and, in one reported case, deleted an entire production database—that highlighted the limits of static access controls.
How Agent IBAC detects intent drift
Agent IBAC uses an LLM evaluator to compare the instruction that started an agent with the agent's reasoning, the tools it calls, and the data it reaches for. The evaluator asks whether the steps the agent takes align with the original request. Sensitivity is tunable across three settings—lenient, balanced (the default), and strict—so teams can choose whether to flag only clear mismatches, allow some improvisation, or require close alignment for agents that touch regulated or high‑value data.
Varonis offers two concrete examples to illustrate intent drift: a clear mismatch where a user asks an agent to check the weather but the agent invokes a migration tool (Agent IBAC can automatically block the tool call), and a low‑risk drift where a user asks for a one‑time weather answer but the agent sets a recurring reminder (Agent IBAC can simply log the deviation without interrupting productivity).
Full‑session evaluation and multi‑turn detections
Rather than judging single actions in isolation, Agent IBAC evaluates every prompt, response, and tool call across a session. Sessions are tracked by the conversation ID assigned by the AI tool, enabling a single evaluation to span from the first prompt to the last. Varonis says this full‑session view is crucial for detecting gradual drift and multi‑turn attacks, including jailbreak attempts assembled from several benign‑looking prompts.
Teams can write session policies in plain language and set how many events must accumulate before an evaluation runs, giving administrators control over when and how session‑level checks activate.

Built by Nubivance.
OSINTSights' secure edge-first architecture, AI content pipeline, and serverless ops are designed by Nubivance. We do this for clients too.
Talk to us →Runtime guardrails, quarantine, and the audit trail
Agent IBAC pairs detection with runtime guardrails that act in real time. Possible responses include alerting, blocking, modifying (for example, redacting sensitive data), logging activity, or routing an action to a human for approval. For scope creep—such as an agent pulling a larger set of customer records than requested—Agent IBAC can flag the action for human‑in‑the‑loop approval before it proceeds.
When a violation warrants more than stopping a single action, Atlas can quarantine the identity behind the session. Quarantines block every prompt that follows for a customer‑defined window—from a couple of minutes up to a full day—while administrators can lift, extend, or make a quarantine permanent. Atlas also records every prompt, response and tool execution alongside the action Atlas took, presenting both a conversation view (what the user experienced) and an execution view (the underlying tool calls most likely to carry risk).
Where Agent IBAC sits in the stack and its availability
Varonis stresses that Atlas sits inline between the agent and the model driving it: every prompt, model response, and tool call flows through Atlas before reaching its destination. That inline position is the mechanism Varonis cites for enforcing guardrails in real time rather than relying on after‑the‑fact logs. Agent IBAC is presented as one component of Atlas’s broader approach to securing agentic systems, alongside capabilities Varonis names as AI‑SPM, AI Red Teaming, and AI Detection & Response.
Varonis states that Agent IBAC is available today to Varonis Atlas customers. The company also links demonstrable learning exercises and training: the announcement points readers to a quick three‑minute demo and to a free online exercise called Breach at the Beach for red teams, blue teams, and professionals seeking continuing professional education credits (https://breachatthebeach.com).
What this means for security teams, red/blue teams, and enterprise leaders
- Security teams and technologists: Agent IBAC gives security operators a runtime control that can be tuned by sensitivity and policy, plus an execution‑level audit trail for investigation and compliance.
- Red teams and blue teams: Varonis points defenders and testers to Breach at the Beach as a hands‑on learning tool; the full‑session detection and jailbreak awareness features are aimed at catching multi‑turn attack techniques that traditional controls can miss.
- Enterprise and procurement leaders: Agent IBAC is sold as a way to let organizations "say 'yes' to agents"—enabling agent productivity while constraining dangerous or out‑of‑policy actions—and is available now to existing Atlas customers.
Varonis frames intent‑based enforcement as a shift from static access controls to contextual runtime decisions. The company argues that trust—measured by how safely agents act, not by how many agents are deployed—is the ultimate metric of agentic success. Whether that runtime layer becomes a standard fixture for organizations deploying agents will depend on how widely customers adopt Atlas’s inline model and how effectively teams tune sensitivity, quarantine rules and human‑in‑the‑loop gates.
Original story: https://www.bleepingcomputer.com/news/security/varonis-agent-ibac-keeps-ai-agents-within-their-intended-boundaries/




