Cross-system authorization for enterprise AI.

Lattuss knows who can see what across every system at once. Keeps every agent inside its scope, and bound by the human behind it. Every decision is on the record.

Access accumulates faster than anyone reviews it.

People change teams, projects end, an acquisition lands. Each of those adds access, and the review that would have caught it runs on a cycle measured in months.

So the honest answer to what your estate looks like today is the answer from the last review, plus everything since.

  • CollaborationSites, folders and files
  • CRMAccounts and contacts
  • WarehouseTables and views
  • SupportQueues and tickets
  • What the person has opened
  • What they are entitled to open, and what an agent searches to answer one question
  • Where the last review signed off
Nobody uses all the access they have. Your agent does.

You can't fix what you can't see.

Before you let agents loose on your data, get the visibility nobody has ever had.

  • See what an agent would inherit before you deploy one.
  • Find the access nobody remembers granting.
  • Give security an answer instead of a hunch.

Our scan is like a penetration test for your permissions. Every person, every system, and the gaps identified before an agent goes anywhere near them.

Agent Readiness Scan

One map, every system
Who can reach what, reconciled across all of them at once.
Findings, worst first
What to close before an agent goes anywhere near it.
Paths between systems
Access that exists only because two systems are connected, and the drift since the last review.

The risk is how deep an agent digs.

Data spread across many systems is what a working company looks like, and none of it is the problem.

A person stops when they have found what they came for. An agent goes as far as each grant allows, in every system it can call, for one question.

Each of those calls is permitted, and each system is right to answer it. The assembly happens outside all of them, so the result is a level of access no single grant describes and no owner ever approved.

Depth is the exposure, and depth is a permissions question.

Someone asks

“What do we know about the customer in ticket 4471?”

The agent asks each system in turn
  • CRMAllowed by a sharing rulePermitted
  • BillingAllowed by a role grantPermitted
  • SupportAllowed by queue membershipPermitted
The agent joins them

One answer, assembled outside all three.

A level of access no one granted, from three grants that were each correct.

The verdict from day one, enforced when you say so.

Watchdog

Checks every call against the person the agent is acting for: this identity, this system, this answer, allowed or not.

The verdict is written down and the call goes through, so nothing is blocked and nothing breaks.

Learn more about Watchdog

Enforcer

Applies that verdict instead of recording it. One system at a time, in the order you choose, widening as your confidence does.

What comes back is scoped to the person behind the agent, and every withholding is logged with the reason it was withheld.

Learn more about Enforcer

Your stack is not wrong. It is missing a layer.

Nothing to replace, nothing to reconfigure, nothing to migrate. Each part does its job correctly and stops where its own remit ends, and one question from an agent reaches all of them at once.

Identity guards who comes in. Posture guards data at rest. Lattuss sits in the query path, where the question passes between them.

Agent platformsRun the agent and trust the caller. That is what a platform is for.
IdentityEstablish who is signing in, and with what factor.
LattussIn the query path
Checks every call against the person behind the agent, decides what comes back, and keeps the record of both.
Data platformsEnforce their own grants, for whichever identity was presented.
Data postureClassify data where it sits, and flag the sensitive material.

Incidents, dated and sourced.

See the global incident feed
  • Sep 2026

    SalesBleed (Salesforce Agentforce)

    Instructions hidden in a lead submitted through a public Web-to-Lead form made Agentforce query account records, including deal sizes, with the asking employee’s own permissions. The agent then sent them out through a web address its URL filter missed, or through Slack’s link previews, with no click needed. A third flaw let the agent post unattributed Slack messages without confirmation. Reported June 2026, all three patched by 21 September.

    Zenity Labs

  • Jun 2026

    SearchLeak, CVE-2026-42824 (M365 Copilot Enterprise)

    A chain of three weaknesses turned enterprise search into an exfiltration path. One click on a genuine Microsoft link made Copilot search the victim’s own mailbox and files, then send the results out through an image URL. CVSS 9.1. Patched server-side.

    CVE-2026-42824

Start with what your agents can reach, then decide what they should.

Contact sales

Fill out the form and we will be in touch.

Start with a scan

Ready to find out what your agents can reach before somebody else does?

Tell us a bit about your setup and we will be in touch.