Beta

Automated Least Privilege for Agents

Authorization, monitoring, alerting, and access throttling.

A screenshot of Oso's Agent Monitor dashboard
A screenshot of Oso's Agent Monitor Security Alerts tab
A screenshot of Oso's Agent Monitor policy recommendation

Permissions for LLMs and Agents

ai-robot-icon

LLM Authorization

Define permissions in one place and enforce them for human and LLM users alike

LLM Authorization diagram
ai-brain-icon

RAG Apps

Build Retrieval-Augmented Generation that adds context without leaking data

Diagram for RAG apps
mcp-icon

Agents

Monitor agents’ actions and scope permissions down to least privilege

Agents venn diagram

Built for the critical path

Scalability
Scales horizontally to
1M+
requests/sec
Performance
Delivers
<10ms
p90 latency
Built in Rust
rustacean-flat-white-logo-mark

Case Studies

Replaced the legacy system with Oso Cloud and built dashboards and APIs on top of Polar, enabling business self-service and eliminating manual code changes.

Unified RBAC, ReBAC, and ABAC into a single, maintainable framework using Oso’s declarative policy language—enabling reusable, consistent access logic across services—while Oso Cloud delivered fast, compliant authorization checks close to local HR data.

Adopted Oso as a centralized authorization platform, enabling faster delivery of secure, agentic AI applications.

Centralized complex permission logic without syncing sensitive data, simplifying development and debugging.

Delivered centralized, versioned policies that streamlined complex access control across services, with enterprise-grade audit logs and dashboards enabling transparent reporting to meet stringent compliance requirements.

Eliminated infrastructure overhead, standardized global access, and enabled fine-grained RBAC and ABAC via Polar—giving engineers the tools to model real-world access while ensuring low-latency, resilient authorization with geo-replicated environments.

Featured in
Foundry-Logo

Developer Love

Duolingo-logo-markclose-quote-icon
Oso is a compelling fit because of their singular focus on authz, plus the flexibility of their Polar rule definitions. In twenty minutes we’d managed to define a custom Polar definition to handle our current use case.
Evan Ziebart
Engineer, Duolingo
Productboard-logo-markclose-quote-icon
We reviewed multiple solutions – Oso came out on top for its devex, scalable and consistent performance, and the flexibility to match all our needs.
Jiří Brunclík
VP Engineering, Productboard
Intercom-logo-markclose-quote-icon
Oso is A+. As we moved upmarket, being able to implement authz consistently and accurately helped us move faster and resolved a never-ending source of bugs.
Brian Scanlan
Engineer, Intercom
Oyster-logo-markclose-quote-icon
It used to take us months to add new roles. With Oso we cut that time 10x. The Oso team has also been very helpful, making our migration super smooth.
Derick Matamoros
Lead Engineer, Oyster HR

Are you looking for Application Authorization?