🦄 One Person Unicorn
Submit Your Company →Submit

playbook · Julien de Waal · 8/12/2026 · 6 min read

Access Control for AI Agents: The $2M ARR Gap Nobody Has Closed Yet

The problem with identity when the user never logs out

Every corporate IAM system — Okta, Azure AD, CyberArk — was designed around the same assumption: a human sits down, authenticates, does something, and logs off. Sessions are bounded. Permissions are attached to people.

AI agents don't work that way.

An agent runs continuously, often across multiple systems, impersonating users or service accounts to get things done. It doesn't have a lunch break. It doesn't time out. It makes thousands of API calls where a human would make ten. And when it gets compromised — or simply misbehaves — there's no clean audit trail that maps to a single authenticated session.

This is not a theoretical gap. It's the gap that every security and platform engineering team at a mid-market SaaS company is quietly staring at right now.

Why existing IAM tools fail agents

The technical mismatch runs deeper than "agents don't have passwords."

Session-based auth assumes a defined start and end. Agents are stateless in some contexts, persistent in others — often both within the same workflow.

Role-based access control (RBAC) assigns permissions to humans in defined roles. An agent that handles customer onboarding, pulls CRM data, sends emails, and updates billing records doesn't map cleanly to any single role. It needs scoped, context-aware permissions that can be audited at the action level, not the session level.

Audit logging in most enterprise tools captures who logged in and what they clicked. Agent actions are programmatic, high-frequency, and often triggered by other agents. The log volume alone breaks most existing SIEM pipelines.

OAuth and service accounts are the current workaround — and they're a mess. Security teams hand agents long-lived tokens with broad permissions because scoping them properly is too painful. This is exactly how you get a compromised agent with keys to the kingdom.

The opportunity: $250K–$2M ARR for the team that solves the wedge

The market sizing here isn't coming from analyst reports — it's coming from the actual buyer pain. Security teams at companies running agent infrastructure are already spending budget on IAM. The question is whether access control for AI agents becomes a line item they pay for separately, or gets absorbed into an existing vendor.

Right now, no major IAM vendor has shipped a focused product for agent identity. Okta has hints of machine identity work. But nothing purpose-built for the agent-action-audit loop that security leads actually need.

That makes this a wedge play: build a focused first version that solves the most urgent slice — say, scoped credential management and action-level audit logs for agents running on top of internal tools — and land it with the security or platform engineering lead at one company that's already deploying agents at scale.

The ARR ceiling of $250K–$2M is realistic for a solo or two-person team that stays focused. Enterprise IAM deals run $50K–$200K annually at companies with 200–2,000 employees. You need five to twenty customers to hit that range. That's not a moonshot. That's a focused GTM.

Who builds this

This is not a general-audience product. The founder who wins here has direct access to a security architect or platform engineering lead — not through a cold email, but through a prior working relationship or deep community presence in DevSecOps or platform engineering circles.

The technical bar is real: you need to understand OAuth flows, service account patterns, policy engines (OPA, Cedar), and how agents authenticate to APIs in practice. But the actual build for a v1 is narrower than it sounds. A focused credential vault with agent-scoped tokens, a lightweight policy layer, and structured audit logs is buildable by a single technical founder in a quarter.

This is the kind of infrastructure company that fits the one-person-unicorn model precisely because the wedge is narrow, the buyer is identifiable, and the product doesn't need a sales team to close its first ten deals — it needs founder-led discovery with the right five security leads.

The founder fit score: 6/10 — and what that means

The idea navigator that surfaced this opportunity scores founder fit at 6/10. That's not a red flag — it's a calibration signal.

The 6 reflects the fact that most founders will not have the specific buyer relationships needed to validate and close fast. But for the founder who does — someone who spent time in DevSecOps, who ran platform teams, who has a Slack DM open with a CISO right now — the score flips. Buyer access is the moat.

The revenue model is also straightforward for AI-native startups optimizing revenue per employee: annual contracts, usage-based expansion tied to number of agents or API calls audited, and a natural upsell path to policy management and compliance reporting (SOC 2, ISO 27001 teams will pay for agent audit trails).

What a v1 actually looks like

Forget the full IAM replacement. The v1 that closes the first deal probably does three things:

1. Scoped token issuance — generate short-lived, action-scoped credentials for agents instead of handing them a service account with admin rights 2. Action-level audit log — every API call an agent makes, structured and queryable, mapped to the workflow that triggered it 3. Policy rules — simple allow/deny rules based on agent identity, target system, and action type, with a UI that a security engineer can configure without writing code

That's it. No dashboard redesign. No SSO integration suite. One workflow, done well, sold to a buyer who is already in pain.

Building a one-person startup with AI means the entire policy engine, logging pipeline, and token management layer can be scaffolded with AI coding tools in weeks — but the design decisions still require someone who understands how agents misbehave in production.

The window is narrow

Okta, HashiCorp, and AWS will get here. The question is when — and whether they'll get there with a focused product or bolt it onto an existing offering that doesn't quite fit.

The solo founder who ships a tight v1 to two or three design partners in the next six months owns the category narrative before the incumbents even publish a blog post about it. That's the actual opportunity.

Julien de Waal, who spent 16 years managing growth, product, and marketing teams across crypto, fintech, and SaaS before building the AI-native systems that replaced those departments, has noted that the fastest-moving infrastructure plays in the AI stack right now aren't the ones with the biggest TAMs — they're the ones where a specific buyer is in active pain and no vendor has called them back yet. Agent identity is that play.

---

Is your company eligible? Submit to the leaderboard → onepersonunicorn.co/submit

Read the full AI-native companies guide.

Is your company eligible? Submit to the leaderboard →

Submit Your Company

More on AI Agents for Founders: The Complete 2026 Guide

AI Agents Listing Is the First Directory to Index Agents, MCP Servers, and Skills TogetherAI Agents Listing Is the First Directory to Index Agents, MCP Servers, and Skills TogetherAI Agents Listing Is the First Directory to Index Agents, MCP Servers, and Agent Skills Together

Related companies on the leaderboard

Sonscape

Undisclosed ARR ·

Polsia

$1M ARR · $1M/person

Swan

$1M ARR · $333k/person