Accelerating AI agent security — Welcome Oso team

AUTHORS
Preeti Somal
PUBLISHED
Oct 06, 2026
CATEGORY
DURATION
4 MIN
  • Durable Execution

Today, I’m pleased to share that the Oso team has joined Temporal to accelerate our work in AI agent security. Temporal is the backbone of agent platforms in enterprise companies. The Oso team has spent years building authorization for enterprise applications, together we accelerate AI agent security built natively into the execution platform.

The tricky thing about AI agents is that exactly what makes them valuable is what also makes them risky. As we’ve gotten deeper into agent platform projects, that tension keeps surfacing in conversations with many of our customers. An agent platform built on Temporal needs identity propagation and policy enforcement that hold up when agents call tools and act on vital data.

We’ve already been focused on the data and control planes, but it’s become clear that we need to extend the scope of that work and move even faster. Now, with the Oso team, we’re making the work even faster and better. That’s why we’re doubling down on our investment here.

Why agents change the authorization problem#

Many companies have tolerated overpermissioning for quite some time because people limit themselves with judgment. Employees ignore most of the access they have. In fact, Oso’s research found that 96% of permissions go unused. Agents don’t show that restraint, and they can’t be allowed to set or expand the limits of their own authority.

Failure makes the problem even more difficult. Crashes, timeouts, and retries are a given in production, so a safeguard that only works when everything goes right isn’t much of a safeguard. If an agent can bypass an approval or replay a rejected action after a retry, the controls are broken. A company’s policies and credentials have to hold up through a failure and keep directing what an agent does.

Where this fits in Temporal#

I’m so proud of the engineering foundation our team has built here. Our product cornerstone, Durable Execution, already preserves application state and execution history, including approvals and rejections, through failures and retries. That gives developers a foundation for guardrails: an approval that was granted stays granted, and a rejection stays rejected, even after a crash or a retry. Visibility into what an agent did and Nexus connectivity across teams and namespaces are part of the platform today as well.

Let’s walk through an example: think about an agent that asks for approval before issuing a refund. If the Worker running it crashes after the approval comes in, Durable Execution picks the Workflow back up with that approval intact, so the agent doesn’t ask again and doesn’t proceed without it.

Most teams handle permissions in application code, with each service checking access in its own way. That gets harder to keep consistent when agents are the callers, because a single agent run can chain many calls across many services, and the identity behind each call matters at every step. The experts we’re welcoming to the team will help us advance more precise authorization within the execution foundation we already have.

AI safety extends far beyond the model#

As we all know, AI safety doesn’t stop at the model. It extends into the applications where agents act, which is where access to systems and crucial data comes into play. Samar made this case in “AI safety doesn’t stop at the model”, and the approach here follows from it.

Our goal is practical: to help developers put agents to work with appropriate access and with guardrails their companies control. In practice, that means asking, for each action an agent takes, who it is acting for and what that person is allowed to do, and getting the same answer every time the work is retried.

For enterprise teams, this is often the difference between piloting an agent and running it in production. Security reviewers want to see that an agent’s authority is bounded and that every action traces back to the identity that allowed it. We want Temporal to be the place where those answers are easier to get, so teams don’t have to assemble them from scratch for each new agent.

What’s available today and what comes next#

Durable Execution and the visibility into what an agent did are core to the platform today, and Temporal Nexus already connects applications across teams and namespaces. Oso joining the team will accelerate authorization work that is already in development, and we’ll share more on this as that work progresses. Nothing in today’s news changes what you can use in the product right now. It speeds up what comes next.

A big welcome to our new colleagues from Oso, and thank you for choosing to build this with us. If you’d like to work on problems like these alongside them, take a look at our open roles.

Temporal Cloud

Ready to see for yourself?

Sign up for Temporal Cloud today and get $150 in free credits.

Build invincible applications

It sounds like magic, we promise it's not.