Varonis Agent IBAC keeps AI agents within their intended boundaries
Varonis has announced Agent Intent-Based Access Control (IBAC), a new capability in Varonis Atlas that lets businesses connect AI agents to their enterprise data with safeguards that stop dangerous or out-of-policy behavior.
Intelligence analysis by Llama

Varonis Agent IBAC is a new capability in Varonis Atlas that prevents AI agents from taking unintended actions by comparing the instruction an agent received to its reasoning and the tools it calls.
Imagine you ask a robot to get you a glass of water. But instead, it decides to make you a sandwich. Agent IBAC is like a referee that checks if the robot is doing what you asked it to do. If it's not, Agent IBAC stops the robot and says 'no, you can't make a sandwich'.
Analysis
A New Era in AI Security
Varonis Agent IBAC is a game-changer in the world of AI security. By comparing the instruction an agent received to its reasoning and the tools it calls, Agent IBAC prevents AI agents from taking unintended actions. This is a critical component of agentic security and a core part of Atlas's end-to-end approach to AI security.
How Agent IBAC Works
Agent IBAC uses an LLM evaluator, the same engine behind all Atlas guardrails, to judge whether an agent's action follows from the instruction it was given. The evaluator reads the agent loop: the reasoning the agent produces, the tools it selects, and the parameters it passes to them. It then asks a simple question: “Do these steps align with the request?”
The Benefits of Agent IBAC
Agent IBAC provides several benefits, including the ability to detect intent drift, prevent unauthorized access to data, and catch intent drift that unfolds gradually. It also provides a complete audit trail, recording every prompt, response, and tool execution alongside the action Atlas took.
Conclusion
Varonis Agent IBAC is a critical component of agentic security and a core part of Atlas's end-to-end approach to AI security. By preventing AI agents from taking unintended actions, Agent IBAC gives enterprises confidence that their agents are acting within the intended scope.
Key points
- Varonis Agent IBAC prevents AI agents from taking unintended actions
- Agent IBAC compares the instruction an agent received to its reasoning and the tools it calls
- Agent IBAC provides a complete audit trail of every prompt, response, and tool execution
With Agent IBAC, businesses can trust their AI agents to act within their intended scope, without slowing down productivity. This means that companies can focus on innovation and growth, while keeping their data and systems secure.
If Agent IBAC is not implemented correctly, it may not catch all instances of intent drift, leaving businesses vulnerable to security risks. Additionally, the complexity of Agent IBAC may be overwhelming for some organizations, leading to implementation challenges.



