Bottom line: Varonis positions Agent IBAC as a complement to classic access control to detect and stop so-called intent drift in AI agents in real time.
Varonis has introduced Agent IBAC (Intent-Based Access Control), an approach designed to keep AI agents within their actual scope of tasks despite having far-reaching permissions. The approach addresses a gap in classic access models, which can check whether an access is permitted, but not whether an action actually matches the user’s intent.
To be useful at all, AI agents generally require broad access rights to systems, data and applications for their tasks. Traditional access control models such as RBAC or ABAC, however, only check whether an identity is fundamentally authorized to perform a particular action. They cannot assess whether a specific action still matches what the user actually requested in terms of content. With Agent IBAC, Varonis describes a mechanism designed to close exactly this gap by detecting when an agent deviates from its original intent — a phenomenon referred to as intent drift.
This is relevant for CISOs because autonomous AI agents are increasingly being equipped with far-reaching permissions, for example to search emails, edit files, or execute actions in third-party systems. An agent that is technically authorized can nevertheless carry out actions that fall outside its originally intended purpose, for instance due to misinterpretation of a task, prompt injection, or chain reactions when using multiple tools. Classic static permission models offer no protection here, since they only classify actions in binary terms as permitted or forbidden, without taking into account the context of the original user intent.
According to Varonis, Agent IBAC relies on real-time guardrails that compare the intent behind an action with the action actually performed, and intervene in the event of deviations before an agent leaves its intended scope of action. For security leaders, this means an additional control point specifically for agentic AI workloads, intended to operate alongside existing identity and access management structures rather than replace them. Organizations planning to deploy AI agents with access to sensitive data should examine how intent-based controls can be integrated into existing IAM and data protection architectures.