~ / directory / oso
OS
Mixed · Identity & AppSec · reviewed 2026-04

Oso

Agent security and authorisation platform — visibility and controls to secure AI coding agents. Scopes permissions, monitors agent behaviour, enforces least-privilege. Used by Verizon, Duolingo, Wayfair, Webflow.

Visit osohq.com
01

What it does

Agent security and authorisation platform that provides visibility and controls for AI coding agents. Three-phase approach: Scope (map permission posture, identify over-privileged identities, recommend what to reduce before agents inherit them), Monitor (real-time visibility into agent actions with risk-classified alerts), and Enforce (policy-driven controls that block unsafe agent behaviour). Maintains a Rogue Agents Registry documenting real-world AI agent incidents. Customers include Verizon, Visa, Duolingo, Wayfair, Webflow, PagerDuty, Brex, Intercom, and Honeycomb. Research shows employees ignore 96% of their permissions — agents won't.

02

Security relevance

Addresses the fundamental problem that AI agents inherit human permissions but use all of them, unlike humans who self-limit. Maps the permission posture across the organisation, classifies risk, and recommends scoping down before agents are deployed. Runtime monitoring detects anomalous agent behaviour and policy violations. The authorisation engine integrates with existing identity providers to enforce least-privilege dynamically.

03

When to use it

Use when rolling out coding agents (Cursor, Claude Code, Copilot) and need to answer: what can these agents access, and should they? Particularly valuable for organisations where developers have accumulated broad permissions over time. Enterprise platform — customers include multiple Fortune 500 companies.

04

OWASP coverage

Risks addressed — mapped to both OWASP Top 10 standards. 1 in LLM, 4 in Agentic.

LLM Top 10 · 2025 · 1/10 covered
01
02
03
04
05
06
07
08
09
10
05

The raw record

What Yuntona stores. Single source of truth — fork it on GitHub.

name: Oso
slug: oso
type: Mixed
category: Identity & AppSec
url: https://osohq.com

reviewed:   2026-04
added:      2026-04
updated:    2026-04

risks:
  llm:  [LLM06]
  asi:  [ASI01, ASI02, ASI04, ASI08]

complexity:    Plug & Play
pricing:       —
audience:      AppSec · CISO
lifecycle:     [deploy]

tags: [Agent Security, Authorization, Commercial, Least Privilege, Observability]