C1 / Identity, after the login✦2026 / Autonomous Worker and agent runtime controls✦From access reviews to AI access✦C1 / Identity, after the login✦2026 / Autonomous Worker and agent runtime controls✦From access reviews to AI access✦

01 / Company profile Identity security

The Permission Slip That Learned to Move

C1 began with a familiar office absurdity: people waited for access they needed and kept access they did not. Now its software is being asked to govern the far less patient workforce of AI agents.

An engineer leaves a company. A year later, the old GitHub account still works. Somewhere else, a new hire spends days waiting for permission to use the tools of the new job. The two stories look like opposites, but they are twins: the organization cannot reliably say who needs what, for how long, or who ought to decide. Alex Bovee used the departed engineer in a 2021 founding note for ConductorOne, the company now called C1. It was an unusually good origin story because almost every office has a version of it.

The short version / 04
  • C1 maps identities and permissions across enterprise software, then automates requests, reviews, and revocation.
  • Its customers include Instacart, Brex, Zscaler, Ramp, and DigitalOcean.
  • The 2026 product expansion gives AI agents identities, owners, scoped access, and checks on tool calls.
  • Pricing is quoted: choose a scoped platform plan or usage-based Flex billing.

Bovee and co-founder Paul Querna had worked at Okta, where the business of knowing who someone is was already mature. Their new question was what happens after a successful login. A single sign-on button cannot tell whether a finance analyst should still have production access, or whether a machine account created for a weekend project should live forever. C1 entered through that neglected doorway.

Alex Bovee, C1 co-founder and CEO
Alex BoveeCo-founder & CEO
Paul Querna, C1 co-founder and CTO
Paul QuernaCo-founder & CTO

The spreadsheet was the first opponent

The founders started work in 2020. Seed funding of $5 million arrived in 2021; the first generally available product, automated access reviews, followed in 2022. Security and compliance teams had been stitching together app exports, help desk tickets, screenshots, and quarterly certification spreadsheets. C1 connected to the applications, gathered the underlying permission data, and gave reviewers a place to approve or remove access with an audit trail. The original job was gloriously unromantic: make the review someone was already obliged to do less painful and more accurate.

Connections mattered as much as the screen. C1 released Baton, an open-source connector toolkit, in 2022. An identity system that can see only the tidy applications is like a fire inspector allowed into the lobby. Baton lets developers extract and manage permissions from cloud tools and custom systems, including those that never fitted an off-the-shelf identity diagram. C1 later built that connector fabric into requests, lifecycle changes, temporary privileges, and compliance work.

C1 team members gathered outdoors
FIG. 01The C1rew, as the company calls itself. Permission slips are serious business; team photos apparently are not.

This is a business-to-business software company, sold to the people who get blamed when access is too slow and when it is too broad: IT, security, identity, and governance teams. Its buyers are large enough to have many apps, infrastructure permissions, contractors, and auditors. C1 names Instacart, Brex, Zscaler, Qualtrics, Ramp, and DigitalOcean among customers. It says the platform manages millions of identities, though it does not publish a customer count. Its reported $79 million Series B in October 2025 brought its announced funding rounds to $111 million.

50,000Brex access requests processed through C1
400Brex entitlements added in two days
60%Zscaler reduction in help desk provisioning tickets

What changed a buyer's mind

Instacart's account is more revealing than a slogan. Its security team wanted privileged access that appeared when needed and expired afterward. A legacy identity governance platform was already under contract, but had not been successfully implemented. Matthew Sullivan, the infrastructure security leader, judged it too inflexible for the work and switched to C1. The attraction was a policy engine that could express detailed conditions and a Terraform provider that made those rules maintainable as code.

Instacart says it moved privileged access to automated, policy-based, just-in-time grants. Its engineers used close to 100 production policies, some with roughly 30 conditions, across AWS, Google Cloud, Snowflake, and internal systems. The point is not that everyone must write 30-line policies. It is that an approval can use the same context a careful human would ask for, yet arrive before that human finishes coffee. Sensitive exceptions still need judgment. Instacart built its own bot, Gadjit, on C1 data to assess some of those requests; the customer describes that system as its own work, not a boxed C1 feature.

“Everyone should have the access they need to do their job, but no one should have more than that.”Mark Hillick, Brex CISO

Brex offers a second angle. It says 50,000 access requests have passed through C1, and that its team used Terraform to add 400 entitlements in two days. The old cost of identity was not merely software; it was the labor of turning a request into a decision, an entitlement, an expiration date, and audit evidence. C1's published pricing page offers two models: a predictable Platform plan based on scope, identities, and modules, or Flex, which bills monthly for events using C1 Tokens. It does not display a universal dollar figure. The price of doing nothing, meanwhile, often hides in tickets and stale privileges.

Then the requester stopped being human

The company changed its public name from ConductorOne to C1 in April 2026. The shorter name carried a much larger ambition. An AI agent may call several tools, borrow a person's authority, create work for another agent, and vanish before a quarterly review comes around. C1's answer is to attach an identity and accountable owner to the agent, constrain the credentials and tools it can use, evaluate each action against policy, and record the result. In March it announced AI Access Management. June brought the C1 Autonomous Worker, an agent that can handle identity administration tasks such as finding stale grants or assembling review evidence. July brought runtime governance for agent tool calls.

A permission's new itinerary

01 / DiscoverFind the human or agent
02 / AssignName its owner and scope
03 / DecideApply policy at the action
04 / RecordExpire and audit access

The workflow is the product: visibility, context, a decision, and proof that the decision happened.

Here lies C1's competitive claim. Established identity governance and privileged access suppliers such as SailPoint, Saviynt, CyberArk, and Microsoft Entra each cover parts of the problem; internal scripts and ticketing systems cover others. C1 argues for a common graph, connector layer, policy engine, and audit trail spanning people, service accounts, and agents. The company also joined the Wiz Integration Network so a cloud risk finding can prompt an access review or revocation. That is an integration rather than a magical detector: the signal still has to reach a system authorized to act on it.

The approach has conditions. Connectors must surface reliable entitlement data. Someone must own the agent and write policy that matches real work. Employees need a fast way to request exceptions, or they will find one outside the process. Runtime checks only govern calls routed through the relevant gateway. C1 itself has written about discovering agents that enter through API keys and delegated tokens; an inventory that misses them is only a better-looking spreadsheet. These are implementation questions, not reasons to return to permanent administrator rights.

The rule worth stealing

A smaller team need not buy C1 to copy its clearest idea. Start with one sensitive permission. Identify its owner, record who holds it, define the conditions for receiving it, give it an expiration, and make the revocation observable. Then repeat. It is a modest recipe, which is part of its charm: security improves when the permission slip has a clock and a witness.

C1 is now making that recipe travel farther. Its September 2026 European deployment keeps tenant data in the EU, opening another procurement door. Its agent products try to move the decision from the quarterly meeting to the instant a tool is called. Whether every buyer needs that entire architecture remains an open commercial question. The departed engineer's GitHub account, however, remains a persuasive reminder of the old system's problem: a permission is easy to grant, and remarkably easy to forget.