Oso

1.3K posts

Oso banner
Oso

Oso

@osoHQ

Visibility, controls, alerting, and auditing for Claude Code, Cursor, Codex, and the next agent your engineers try

New York City شامل ہوئے Ocak 2019
257 فالونگ1.2K فالوورز
Oso
Oso@osoHQ·
Oso and @cyera_io studied 2.4 million workers and found 96% of permissions go completely unused. Redditors in r/cybersecurity said it best: this is the "security debt nobody's talking about loudly enough" Full conversation: reddit.com/r/cybersecurit…
Oso tweet media
English
0
0
3
62
Oso
Oso@osoHQ·
To our knowledge, this is the first research examining how permissions are actually exercised in production. Most discussions focus on policy — how access should be structured. Far less is known about how access is actually used in practice.
English
0
0
0
18
Oso
Oso@osoHQ·
In summary, as an industry we are vastly over-permissioned. The principle of least privilege is widely discussed, but rarely practiced. In an agentic world, getting closer to it becomes much more important.
English
1
0
0
31
Oso
Oso@osoHQ·
Our research found 31% of workers hold modify/delete permissions and 13% have export capabilities, creating significant exposure when agents inherit human access.
English
0
0
0
20
Oso
Oso@osoHQ·
Delete, modify, and export permissions are intended for limited operational use, yet they remain broadly distributed across enterprise environments. Humans exercise these capabilities infrequently, but agents can invoke them instantly.
English
1
0
0
35
Oso ری ٹویٹ کیا
Techstrong TV
Techstrong TV@TechstrongTV·
🤖 AI coding agents move fast, but overpermissioned environments make them dangerous. 🎙️ Alan Shimel speaks with Oso CEO Graham Neray about why authorization is becoming a critical C-suite issue in the agentic era. Watch full interview here:techstrong.tv/videos/intervi…
English
0
1
1
243
Oso
Oso@osoHQ·
Our CTO, Nick, on sensitive data exposure.
English
0
0
0
45
Oso
Oso@osoHQ·
Many employees retain access to sensitive information even if they rarely use it. In many environments, those permissions remain permanently available once granted. 91% of users never interact with the sensitive data they have access to — but it’s still reachable. When agents inherit those permissions, they can access it in seconds. 13 out of 100 corporate workers have access to regulated data. When agents inherit those accounts, they inherit that access as well. Our CTO, Nick, explains another key finding from our research: how sensitive data exposure persists inside enterprise permission models and why agents change the risk profile.
English
0
0
0
51
Oso
Oso@osoHQ·
Only 4% of permissions are exercised. The other 96% go unused over a 90-day window — and most companies have agents inherit human permissions by default. Even among active users, ~80% of available permissions still sit unused. Our CTO, Nick, walks through the first finding from our research: the massive gap between permissions granted and permissions actually used — and why agents make that gap dangerous.
English
0
0
1
76
David P
David P@Lat3ntG3nius·
@osoHQ This is one of the most underrated risks in enterprise AI. Agents inherit the credential footprint of whoever provisioned them, not the footprint they actually need. Least-privilege for agents is a solved problem nobody has bothered to implement yet.
English
1
0
1
11
Oso
Oso@osoHQ·
96% of enterprise permissions go unused. New research analyzing 2.4 million workers and 3.6 billion permissions, reveals a massive gap between granted access and real usage. Once AI agents inherit these permissions, the dormant exposure becomes active — at machine speed. Hear from our CTO, Nick, on the reasoning behind this research and how to think about permissions in an agentic world.
English
1
0
1
60
Oso
Oso@osoHQ·
The biggest mistake companies make with AI agents: assuming yesterday's identity model will hold. Nancy Wang of @1Password says it even better than we could 👇 And our new research with Cyera puts numbers behind that: osohq.com/research #rsac2026
Oso tweet media
English
1
0
2
71
Oso
Oso@osoHQ·
“Make sure that observability of agents extends into tool use: what data sources they access, and how they interact with APIs,” says @grahamneray co-founder and CEO, Oso. “You should not only be monitoring the actions agents are taking, but also categorizing risk levels of different actions and alerting on any anomalies in agentic actions.”
InfoWorld@InfoWorld

7 safeguards for observable AI agents spr.ly/6015B6bZa5

English
0
0
1
81
Oso
Oso@osoHQ·
As engineers, you sit on the arc of technological progress. Right now that arc is bending faster than ever. Getting to be part of it — and contributing to it — is pretty cool.
English
1
0
0
52
Oso
Oso@osoHQ·
The Oso team is at #RSAC2026 this week
Oso tweet media
English
1
0
2
68