Runtime Authorization

Every AI agent needs boundaries.
We enforce them.

1stProtect defines what autonomous software can access, execute, modify, and communicate with - then enforces those permissions at runtime.

See How It Works

Start in Audit Mode. Designed to work alongside your existing security stack.

Policy editor with targeting, templates, and runtime protection modes.

Autonomous software changes the security model.

AI agents can execute commands, use credentials, modify files, invoke tools, interact with cloud infrastructure, and make production changes. The risk is no longer limited to malicious software. A legitimate agent can perform an action your organization never intended to authorize.

An agent does not need to be malware to create a security incident.

Execution chain

Human

Agent
├─ Shell
├─ MCP
├─ API
└─ Browser
   ↓
Credentials / Data / Production

One policy layer across desktop, laptop, server, cloud, and any agent.

Protection points animate across every connected runtime surface, so you can see where policy is enforced before an unauthorized action is allowed to execute.

Coverage + protection points

Desktop

1stProtect icon1stProtect engine
local policy
Agent read repo -> allow

Laptop

1stProtect icon1stProtect engine
local policy
Agent read SSH key -> block

Server

1stProtect icon1stProtect engine
local policy
Agent run kubectl get -> allow

Cloud workload

1stProtect icon1stProtect engine
local policy
Agent delete prod namespace -> block

No centralized enforcement path. Policy decision stays local to each endpoint.

Every endpoint enforces its own runtime policy boundary. Agents can run anywhere, but authorization is evaluated locally at each protected surface.

Detection is not authorization.

EDR / XDR

Is this malicious?

  • Threat detection
  • Behavioral analytics
  • Malware prevention
  • Incident response

1stProtect

Is this action allowed?

  • Actor attribution
  • Action-level policy
  • Resource boundaries
  • Runtime enforcement

Legitimate user.
Legitimate software.
Legitimate credentials.
Unauthorized action.

Your agent should not automatically inherit everything you can do.

Same identity. Different actor. Different authority.

Access Surface
Human - Alice
Autonomous - Claude Code
SOURCE
ALLOW
ALLOW
TESTS
ALLOW
ALLOW
SSH
ALLOW
BLOCK
CLOUD CREDS
ALLOW
BLOCK
PRODUCTION
GOVERNED
BLOCK

See what happened. See what was stopped.

Runtime decisions become operational security evidence.

Risk inventory with prevented versus detected outcomes, mapped to protection engines and endpoint context.

Define the boundary.

Define enforcement once. Apply it across the workloads and devices in scope.

Policy target • template • engines • detect / prevent

Policy template and runtime engines configured against selected endpoint groups.

Security teams need operations, not another feed.

Track posture, risk drivers, severity, trends, and remediation from the same control plane.

Operational dashboard for onboarding progress, posture summaries, and security trend monitoring.
Risk event stream with response status, severity, and assigned protection engine.
Role-based access governance and section permissions from the same control plane.

Keep your EDR. Add runtime authorization.

CrowdStrike and Microsoft Defender provide mature threat detection and prevention workflows. 1stProtect addresses a different control problem: what should an autonomous actor be permitted to do?

Compare the control models
Local policy evaluationWindowsmacOSLinuxEnterprise RBAC

Don't compare claims. Test the boundary.

Deploy without blocking. Observe how autonomous workloads behave. Define the actions that should never occur. Then test those boundaries in your own environment.

Continue to the Runtime Authorization Pilot form to validate these boundaries in your environment.

AUDIT
OBSERVE
DEFINE
TEST
ENFORCE

Runtime Authorization Pilot

Test whether your existing security controls enforce the autonomous-action boundaries your organization requires.

Start in Audit Mode, observe real behavior, define the boundaries that matter, and test enforcement against agreed scenarios.

Want to talk through your environment first?Talk to Security Engineering