●  Built for the age of AI agents

Traditional tools protect people and services.
Bastion governs your AI.

Privileged access no longer stops at people. Humans, service accounts, devices, and critical assets all need control — and so do AI agents that hold credentials, make decisions, and act on their own. Bastion makes every one of them a fully governed identity: with a clear owner, the right level of access, built-in data protection, and continuous risk monitoring.

Every screen here is a real Bastion capability, playing live.
Privileged access, governed

Bastion guards
every door.

Who connects The protector What they reach
Humans
Applications
AI harnesses
Service accounts
Bastion
Protects every
connection
Databases
AI models
Servers
Network Devices
Every identity
Humans, service accounts, and AI agents — one governed lifecycle from day one to decommission
Just-in-time
Privileged access scoped to the moment — no standing rights for people or agents
Data-safe
Secrets and sensitive data stopped before they leave sessions, agents, or LLM calls
Live risk
Continuous behavioral scoring that contains off-rails agents and privileged abuse
01 / AGENT IDENTITY

Every agent is a governed identity with a real owner.

Onboard an AI agent the same way you'd welcome a new team member. You set what it can use, how much it can spend, and a named person who's accountable for it. No agent ever runs unattended or anonymously.

  • A clear lifecycle for every agent: onboarded → active → paused → retired.
  • A named owner who's accountable, with safe ownership hand-offs.
  • Its own secure access keys and spending limits, kept under lock and key.
  • Automatic pause if an owner ever leaves, so nothing is left running on its own.
bastion · agents · payments-copilot
payments-copilot Cloud AI model
Autonomous finance assistant · data access: Restricted
owner: agent.owners@cymmetri.com·budget: $200/mo·status: active
Lifecycle
Onboarded Active Paused Retired Archived
bastion · access

What this agent can do

sensitivity decides who approves
CapabilitySensitivityApprovalAuto-expires
When one agent asks another to help

An agent can hand work to a helper — but can never give away more than it has itself. Watch:

orchestrator
can: read records, send email
report-helper
asks for: read records
02 / RIGHT ACCESS, RIGHT TIME

Just the access each agent needs — and only when it needs it.

Give agents capabilities the way you'd grant permissions to staff. Everyday, low-risk actions are approved instantly; sensitive ones ask a person first. Every grant is temporary and expires on its own, so access never piles up.

  • Capabilities sorted by sensitivity, with the right approval for each.
  • Access that's granted on demand and expires automatically — no lingering permissions.
  • When agents collaborate, a helper can never gain more than its requester has.
  • Smart suggestions for the right capabilities, based on what your agents actually do.
03 / BUILT-IN DATA PROTECTION

Catch a secret before it ever leaves.

Every request an agent sends to an AI model passes through Bastion first. We inspect it for secrets, personal data, and manipulation attempts before it reaches the model — and stop anything risky in its tracks. Try it below: type something sensitive and watch it get blocked.

bastion · data protection
🤖 Agent
payments-copilot
🛡 Bastion
checking the request
☁ AI Model
the model
Pick an example above or edit the message.
0
Blocked
0
Cleaned
0
Allowed
0
Checked
04 / CONTINUOUS RISK MONITORING

Spot a compromised agent and contain it automatically.

Bastion learns what normal looks like for each agent and watches for the warning signs: manipulation attempts, unusual spikes in activity, or access from somewhere it shouldn't be. When risk climbs too high, the agent is paused automatically — its very next request is denied.

  • A single, easy-to-read risk score from low to critical.
  • Watches for manipulation, activity spikes, and unusual locations.
  • Pauses risky agents on its own — no waiting for a human to react.
  • Bringing an agent back requires a second person to sign off.
bastion · risk · data-scraper-07
Risk score
8
Status
● active
normalauto-pause at 80
Everything looks normal
Agent paused automatically. Its next request is denied. Bringing it back needs a second person's approval.
More ways Bastion protects you

The same care, applied to your toughest access problems.

Four more capabilities that other tools make painful, or skip entirely. Each one is built right into Bastion.

05 / EMERGENCY ACCESS

Emergency access that no single person can abuse.

Your most powerful master password is split into pieces and shared among several trusted people. Unlocking it takes a set number of them together, so one rogue insider or one stolen laptop can never open it alone. It even works offline — a true "break glass in case of emergency" path that's always there when you need it.

  • You choose how many key-holders are required (for example, 3 of 5).
  • No single person ever sees the full secret.
  • Works even if everything else is down, and every step is fully recorded.
  • The password automatically locks itself again after a short window.
bastion · emergency access · core-db root
3-of-5 required password: root@core-db locked

An outage just triggered an emergency request. Collect approvals from the key-holders:

1A. Rao
Security
2J. Lee
Platform
3M. Diaz
Incident lead
4K. Singh
Security chief
5P. Novak
Database admin
approvals: 0 / 3 required
unlocked password
•••••••••••••••••••
Click key-holders to approve. It stays locked until the third.
bastion · connections · dc-west
🛡 Bastion
your control center
your firewall
⤢ Connector
offline
🗄 core-db
private system
🖥 app-07
private system
☸ k8s-prod
private system
firewall ports opened: 0
06 / SIMPLE, SECURE CONNECTIVITY

Reach private systems without opening your firewall.

A lightweight connector sits inside your network and reaches out to Bastion — so there's nothing to expose, no holes to poke in your firewall, and no VPN to manage. Bastion then routes every session to the right system automatically, whether it's a server, desktop, or database.

  • Nothing exposed on your network — the connector reaches out, not in.
  • One connector can serve many private systems across your environment.
  • Sessions are routed to the right place automatically, every time.
  • If the connection ever drops, sessions safely stop rather than hang open.
07 / PASSWORD DRIFT ALERTS

Know the instant a managed password is changed behind your back.

Someone changes a managed account's password directly on a system — maybe a rushed admin, a stray script, or an attacker trying to dig in. Bastion notices the moment the password no longer matches, rates how serious it is, and emails the owner (plus anyone else you choose) before it turns into an outage or an incident.

  • Catches password changes made outside of Bastion, automatically.
  • Rates how serious each change is and tracks how often it happens.
  • Emails the owner and any extra people you choose, the moment it's detected.
  • One click to fix it and bring the account back under control.
bastion · password drift
🔑
svc_backup@core-db
managed · last checked 6m ago · in sync
● managed
⚠ Password changed unexpectedly high
The managed password no longer works on the system. It was changed outside of Bastion.
found by: routine check account: svc_backup system: core-db times seen: 1
08 / ONBOARD ANYTHING

Onboard any device — no waiting on a vendor.

Other tools make you file a request and wait months for support for a new kind of device. With Bastion you simply describe how a device changes and checks its password, and it becomes a fully supported connection in seconds. No coding, no upgrade, no waiting.

bastion · onboard a device
Try an example:
📄 server-mgmt-card.platform.yaml · validates against custom-platform.schema.json
Edit the steps or load an example, then publish.
Other tools
File a request → wait for vendor support → upgrade → re-test. Weeks to months.
Bastion
Describe it, check it, publish. The new device type is ready to use on your accounts right away.
See it on your own agents

Your AI agents are already powerful.
Start governing them.

Bring one agent and we'll show you the rest: we'll give it an identity, set its access, run its requests through data protection, and watch a secret get blocked — all in minutes.