Follow access all the way to the data.
Connect the people and devices behind an agent to its permissions, data and policy outcome.

Scroll the image to inspect the details.
Access an agent was given, against access it uses.
Grants that outlive the session.
OpenClaw Gateway holds 16 persistent grants across four installations, including file write, a terminal on the gateway host, the browser and messaging. Each grant shows how often it was used.
More on Workforce AI
Scroll the image to inspect the details.
One customer’s invoice reconciler was entitled to 12 systems. Across 4,112 recorded actions, it had touched 3.
Least privilege, measured.
- Every credential an agent holds
- OAuth grants and tokens on laptops, scopes in each platform, IAM roles and API keys in your cloud accounts, by person and device.
- Issued against used
- Each grant beside how often the agent used it, so the unused ones are plain to see.
- Remove what it does not need
- Revoke a scope through the platform’s admin API, or hand the change to the owner, with your approval.
- Confirm the change
- The next scan shows the grant is gone, and the change stays on the agent’s record.
Common questions
Which credentials does Guard0 read?
OAuth grants and tokens on laptops, scopes in Copilot Studio, Agentforce, ServiceNow and many more, and IAM roles and API keys in your cloud accounts.
Will removing an unused scope break the agent?
A scope the agent has never used is the safest one to remove. Guard0 shows the usage history first, and the owner approves the change.
How is this different from an identity provider?
An identity provider knows what was issued to an account. Guard0 ties it to the agent that uses it, records what the agent did with it, and names the person who answers for it.
Start with one agent’s access.
Connect a platform or a cloud account and see what each agent holds and uses.