
Agentic Access Control and Intent-Based Activity Monitoring give security teams a policy layer for agents and a live check on their behavior, matched against intent instead of static permissions
LAS VEGAS, Aug. 4, 2026 /PRNewswire/ -- BigID, the leader in data security and AI governance, today announced Agentic Access Control and Intent-Based Activity Monitoring. The two capabilities answer the question dominating hallway conversations at Black Hat this year: once an agent has access to your data, what actually stops it from doing something you never approved?

Permissions were built for people. Agents don't act like people.
Role-based access control assumes a human is behind every request: someone who logs in, clicks around, and occasionally asks for more access. Agents don't work that way. They act at machine speed, chain tasks across systems on their own, and can drift from their original purpose long before anyone notices.
That leaves two blind spots most security teams haven't closed:
Govern the access. Then watch the behavior.
BigID's new capabilities close both gaps, together.
Agentic Access Control is a policy layer purpose-built for AI agents:
Intent-Based Activity Monitoring watches what happens after access is granted:
Together, they form what BigID calls an authority layer: one system of record for what an agent is allowed to do, what it says it's trying to do, and what it's actually doing, all grounded in the data.
Why security teams need this now
Agent adoption has outrun the tooling meant to govern it. Static permissions can't keep pace with agents acting on their own, and activity logs alone can't tell you whether an action was expected or a warning sign. BigID ties both problems back to the one thing that doesn't shift underneath you: the data.
Quick answers
What is agentic access control? A policy framework that governs what an AI agent can access, based on data sensitivity and task scope, rather than static roles or standing credentials.
What is intent-based activity monitoring? A way of checking what an AI agent actually does against what it was authorized and expected to do, flagging deviations even when the action falls within permitted access.
How is this different from traditional access control? Traditional access control checks permissions once, at the point of entry. BigID checks continuously, against both data sensitivity and the agent's declared intent, and adjusts as the task evolves.
Who needs this? Any organization giving AI agents standing access to sensitive data: customer records, source code, financial systems, regulated data of any kind.
What sets BigID apart
Executive quote
"Every agent you deploy inherits a level of trust. The real question is whether you can verify that trust is earned continuously, not just granted once at setup." - Nimrod Vax, Co-Founder & Head of Product, BigID.
About BigID
BigID is the only AI-native platform built to secure data and govern AI across the enterprise. BigID helps organizations discover, classify, protect, and manage sensitive data at scale, from cloud storage and databases to SaaS applications, code repositories, and AI systems. BigID has been recognized for innovation as a World Economic Forum Technology Pioneer; by Forrester as a Leader in Sensitive Data Discovery and Classification; named to the Forbes Cloud 100; the Inc 5000 for 5 consecutive years; the Deloitte 500 for 5 consecutive years; Market Leader in Data Security Posture Management (DSPM); and an RSA Innovation Sandbox winner.
View original content to download multimedia:https://www.prnewswire.com/news-releases/bigid-defines-the-missing-governance-layer-for-autonomous-ai-agents-302842899.html
SOURCE BigID