At its init() conference in San Francisco on 7 October 2026, WorkOS ran live previews of three products: Airlock, which decides what agents may do; Atlas, a platform for internal AI apps; and Passport, which signs people in on the Mac. WorkOS's recap says all three "are previews rolling out over the coming weeks and months." It gives no pricing and no general availability dates. The Airlock and Passport product pages each invite teams to request early access. In the Airlock demo, policy held outside the agent decided every call the agent made.

Airlock: Policy Decides Each Call

WorkOS's Michael Grinich described agent permissions today as two bad options: approve every action by hand, or tire of approving and switch the prompts off. WorkOS calls Airlock a governed access layer for local and background agents. It weighs who is asking, what they want to accomplish, and which system and action they want against company policy written in natural language. It then approves, denies or escalates to a human, and audits every decision. WorkOS first showed Airlock at its Agent Night in August, and its September guide described it as available in early access.

On stage, an agent in Cursor investigated a customer's invoice across Linear, Snowflake, Stripe and Gmail, all connected through WorkOS Pipes. The agent requested an intent token describing what it planned to do and presented it on every call, so Airlock could judge each call against policy. It found that the demo customer had paid $1,200 for 40 seats when Snowflake showed 30, a $300 overcharge. Three decisions followed:

  • A $1,200 refund was denied because it exceeded the policy's $500 cap.
  • A $300 refund fell under the cap but crossed the threshold for human approval. A finance approver saw the agent's reasoning, signed off, and the refund went through.
  • An email to the customer was blocked because the body contained financial data. The approved refund did not carry over to the email, which was checked on its own.

Airlock uses two kinds of rule. Enforce rules handle deterministic checks such as an endpoint, a method or a value in the request body. Runtime rules go to a governing agent, an LLM inside Airlock that reads the policy's instructions. For the refund, it checked Linear for a linked issue with valid reasoning. Grinich's point afterward was that with one governed permission surface, neither the agent harness nor any single model has to guarantee security, and the agent never sees the actual tokens.

Atlas: A Home For Internal AI Apps

Atlas is a platform for building and using internal software with AI, aimed at a company's own staff rather than its customers. Under the app it handles authentication, data connectors and credentials, a database, an AI gateway, permissions, versioned deploys and analytics. In the demo, a vibe-coded customer app went live with data from Snowflake, a database for its notes and shared sign-in. When an admin limited a second app to the sales group, which Atlas reads from the identity provider, a user outside that group was locked out on her next refresh and the activity tab recorded the denial. Building an app directly from Slack was described but not shown.

Passport: App Sign-In And Agent Access Are Separate

Passport starts by enrolling a Mac once with the organization, which an IT admin can do. In the demo, Notion then opened already signed in. When the presenter asked Claude which Airlock integrations he could reach through Passport, Claude listed GitHub, Linear, Slack, Datadog, incident.io and Snowflake, and reported that Notion was not connected. The recap describes app sign-in and agent access as separate states: Notion the app had signed him in, while Notion as an Airlock integration for his agent had not been set up. Grinich said the MCP connections behind Airlock show up on the device automatically.

The Same Idea On The Panel

In a panel on who owns the agent, Jean-Denis Greze of Town said users approved everything no matter how fine-grained the controls were. Town now has a separate agent judge each tool call: safe calls go through, and dangerous or uncertain ones still go to a person. Dex Horthy of HumanLayer argued that an agent working for several people should get only the access they all share, with its actions audited to each of them.

What Operators Should Change

  • Route agent tool calls through one point that holds the provider credentials and the policy. WorkOS's Airlock guide warns that a second, direct route to a provider would let the agent bypass the policy checks.
  • Put hard limits, such as a refund cap, in deterministic rules, and send judgment calls, such as whether a refund has a valid linked issue, to a separate check or a person.
  • Check each action on its own. An approval for one action should not clear the next.
  • Track a person's app sign-in and their agent's access to the same app as separate grants.

What The Recap Does Not Show

  • All three products are previews. The recap gives no pricing, general availability date or customer numbers.
  • WorkOS staff ran the demos on fictional companies. Aaron Tainter of WorkOS said a rule typed in plain English gets translated into policy, but he did not write one on stage.
  • The Atlas and Passport results come from staged demos, not customer deployments.

Related: Our earlier note on Airlock gating agent actions by intent covers the August demo. The permission outside the agent playbook sets out the same pattern, and Meta's Muse is another example.