Skip to content
Guard0

Know what every agent can reach.

Guard0 lists the tokens, grants and scopes each AI agent holds, shows which ones it has used, and lets the person who answers for it remove the rest.

Start free

Read-only to start. Changes go through your platforms, with your approval.

Issued permissionsRecorded usageRemove unused access

Follow access all the way to the data.

Connect the people and devices behind an agent to its permissions, data and policy outcome.

OpenClaw Gateway, shadow and critical: 4 people, 146 sessions, 255 background runs, 16 persistent grants, and its execution footprint from people and devices to permissions, data and policy outcome.
Guard0 demo tenant.Open full-size image

Scroll the image to inspect the details.

Access an agent was given, against access it uses.

Grants that outlive the session.

OpenClaw Gateway holds 16 persistent grants across four installations, including file write, a terminal on the gateway host, the browser and messaging. Each grant shows how often it was used.

More on Workforce AI
OpenClaw Gateway permissions: 16 persistent grants across 4 installations, including file write, terminal, browser and messaging.
Guard0 demo tenant.Open full-size image

Scroll the image to inspect the details.

One customer’s invoice reconciler was entitled to 12 systems. Across 4,112 recorded actions, it had touched 3.
A Guard0 customer

Least privilege, measured.

Every credential an agent holds
OAuth grants and tokens on laptops, scopes in each platform, IAM roles and API keys in your cloud accounts, by person and device.
Issued against used
Each grant beside how often the agent used it, so the unused ones are plain to see.
Remove what it does not need
Revoke a scope through the platform’s admin API, or hand the change to the owner, with your approval.
Confirm the change
The next scan shows the grant is gone, and the change stays on the agent’s record.

Common questions

Which credentials does Guard0 read?

OAuth grants and tokens on laptops, scopes in Copilot Studio, Agentforce, ServiceNow and many more, and IAM roles and API keys in your cloud accounts.

Will removing an unused scope break the agent?

A scope the agent has never used is the safest one to remove. Guard0 shows the usage history first, and the owner approves the change.

How is this different from an identity provider?

An identity provider knows what was issued to an account. Guard0 ties it to the agent that uses it, records what the agent did with it, and names the person who answers for it.

Start with one agent’s access.

Connect a platform or a cloud account and see what each agent holds and uses.

Start free