Cross-system authorization for enterprise AI.
Lattuss knows who can see what across every system at once. Keeps every agent inside its scope, and bound by the human behind it. Every decision is on the record.
Access accumulates faster than anyone reviews it.
People change teams, projects end, an acquisition lands. Each of those adds access, and the review that would have caught it runs on a cycle measured in months.
So the honest answer to what your estate looks like today is the answer from the last review, plus everything since.
- CollaborationSites, folders and files
- CRMAccounts and contacts
- WarehouseTables and views
- SupportQueues and tickets
- What the person has opened
- What they are entitled to open, and what an agent searches to answer one question
- Where the last review signed off
You can't fix what you can't see.
Before you let agents loose on your data, get the visibility nobody has ever had.
- See what an agent would inherit before you deploy one.
- Find the access nobody remembers granting.
- Give security an answer instead of a hunch.
Our scan is like a penetration test for your permissions. Every person, every system, and the gaps identified before an agent goes anywhere near them.
Agent Readiness Scan
- One map, every system
- Who can reach what, reconciled across all of them at once.
- Findings, worst first
- What to close before an agent goes anywhere near it.
- Paths between systems
- Access that exists only because two systems are connected, and the drift since the last review.
The risk is how deep an agent digs.
Data spread across many systems is what a working company looks like, and none of it is the problem.
A person stops when they have found what they came for. An agent goes as far as each grant allows, in every system it can call, for one question.
Each of those calls is permitted, and each system is right to answer it. The assembly happens outside all of them, so the result is a level of access no single grant describes and no owner ever approved.
Depth is the exposure, and depth is a permissions question.
“What do we know about the customer in ticket 4471?”
- CRMAllowed by a sharing rulePermitted
- BillingAllowed by a role grantPermitted
- SupportAllowed by queue membershipPermitted
One answer, assembled outside all three.
A level of access no one granted, from three grants that were each correct.
The verdict from day one, enforced when you say so.
Watchdog
Checks every call against the person the agent is acting for: this identity, this system, this answer, allowed or not.
The verdict is written down and the call goes through, so nothing is blocked and nothing breaks.
Enforcer
Applies that verdict instead of recording it. One system at a time, in the order you choose, widening as your confidence does.
What comes back is scoped to the person behind the agent, and every withholding is logged with the reason it was withheld.
Your stack is not wrong. It is missing a layer.
Nothing to replace, nothing to reconfigure, nothing to migrate. Each part does its job correctly and stops where its own remit ends, and one question from an agent reaches all of them at once.
Identity guards who comes in. Posture guards data at rest. Lattuss sits in the query path, where the question passes between them.
Incidents, dated and sourced.
See the global incident feed- Sep 2026
SalesBleed (Salesforce Agentforce)
Instructions hidden in a lead submitted through a public Web-to-Lead form made Agentforce query account records, including deal sizes, with the asking employee’s own permissions. The agent then sent them out through a web address its URL filter missed, or through Slack’s link previews, with no click needed. A third flaw let the agent post unattributed Slack messages without confirmation. Reported June 2026, all three patched by 21 September.
Zenity Labs
- Jun 2026
SearchLeak, CVE-2026-42824 (M365 Copilot Enterprise)
A chain of three weaknesses turned enterprise search into an exfiltration path. One click on a genuine Microsoft link made Copilot search the victim’s own mailbox and files, then send the results out through an image URL. CVSS 9.1. Patched server-side.
CVE-2026-42824
The research, reviewed.
Read the blog- Note
SalesBleed, and the agent that already had the permissions
Someone typed instructions into a Salesforce web form. When an employee asked the company’s AI agent about new leads, it followed them and sent account data to a stranger. It never needed more access than the employee already had.
- Note
Fine-grained authorization, and why your systems still run on roles
A model that decides per object and per relationship is tighter than one that decides per job title. The ideas are decades old and the production designs are published, yet the systems holding your data still decide by role. The reason is not that the idea is wrong.