Full-Time
Updated on 9/4/2026
Cloud-native CPAM with just-in-time access
$170k - $190k/yr
Remote in USA
Remote
Remote within the United States.
See people who can refer or advise you
Britive provides a cloud-native privileged access management platform that secures identities and permissions across multi-cloud and hybrid environments. Its patented just-in-time (JIT) access replaces standing privileges with time-bound permissions to achieve Zero Standing Privileges. The agent-less, proxy-less platform manages human, non-human, and AI identities across AWS, Azure, Google Cloud, and SaaS apps like Salesforce and Snowflake, with features such as Access Builder, secrets management, and PyBritive for DevOps integration. It targets security-focused enterprises with a subscription SaaS model and helps automate compliance with SOC 2, PCI, and NYDFS through auditable logs and centralized visibility.
Company Size
51-200
Company Stage
Series B
Total Funding
$35.9M
Headquarters
Glendale, California
Founded
2018
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Health Insurance
Dental Insurance
Vision Insurance
Paid Parental Leave
401k (U.S.)
Flexible + Unlimited PTO
Home Office Stipend
Phone/Internet Stipend
Remote Work Options
Career development opportunities and paths
Britive gives AI agents temporary privilege - and can revoke it mid-task. Britive's August 24, 2026 launch release introduced ARC as an immediately available part of its platform. The runtime-access model is designed to give AI agents temporary, task-scoped privilege, control supported actions while work proceeds and remove access when the task ends or conditions change. The product targets agents that can act inside enterprise databases, cloud infrastructure, servers, SaaS applications and APIs. A contemporaneous Dealroom report also records the launch and current availability, but identifies PR Newswire as its source; it corroborates the event rather than independently testing the controls. One agent action passes through the full control lifecycle. The ARC product specification organizes each agent action around verify, assess, authorize, observe and revoke. Authentication is resolved for every request, the proposed action is evaluated in context, denial is the default, activity remains subject to enforcement and privilege is ultimately removed. Consider a hypothetical infrastructure agent asked to inspect a production database and correct a configuration problem. Verification establishes which agent is requesting access and, where delegated authority applies, the identity on whose behalf it is acting. Assessment can include the requested tool, its arguments, the target, surrounding conditions and any intent supplied with the call. Authorization is attached to the requested task instead of a permanently assigned privileged role. For supported targets, ARC can create permission within the target system without issuing a privileged credential for the agent to retain. Systems that still require credentials can receive credentials created and injected at runtime, with revocation after use. Observation keeps the decision open after access is granted. In the documented database scenario, an agent authorized to read can still have a destructive SQL operation stopped before it reaches the resource. Access ends when the task completes, its time limit expires or a qualifying live signal triggers earlier revocation. Mid-task revocation depends on the enforcement path. ARC's observe stage is what supports the headline's mid-task consequence. Signals delivered through the Shared Signals Framework - including Continuous Access Evaluation Profile and Risk Incident Sharing and Coordination events - can trigger stronger enforcement, require human involvement or withdraw active access while work remains underway. When ARC is configured in the connection path, enforcement can reach individual SSH commands and SQL statements. Tool calls routed through the Britive MCP Gateway are evaluated against centralized policy before an unauthorized action reaches a downstream system. That is more granular than issuing a short-lived credential and simply waiting for it to expire. The qualification matters: mid-task revocation is a documented product capability, not evidence that ARC can intercept every action in every application. Coverage depends on the target system, integration path, policy configuration and available signals. An operation outside an ARC-controlled route does not automatically gain equivalent command-level enforcement. The available package spans more than temporary credentials. ARC's documented availability covers agent discovery and governance, runtime authorization for tool calls, temporary elevation, access enforcement, delegated authority and signal-driven revocation. This was presented as a current platform offering rather than a preview or future roadmap item. For delegated work, policy can keep an agent's authority at or below that of the person it represents, then narrow it for a particular agent, task, resource or content type. The agent and delegating identity remain correlated in the transaction record, providing a route from an automated action back to the source of its authority. The same policy model is intended to cover agentic, human and other non-human identities across cloud, SaaS, database, server and on-premises environments. That describes the breadth of the control model, not uniform enforcement depth across every product in those categories. Buyers still need a target-by-target coverage map. Availability is established; security effectiveness is not. ARC's audit model records identities, requests, authorization decisions, created privileges, actions and outcomes. For agent tool calls, the evidence can include prompts, tools, arguments and stated intent. The published specification also describes correlated sessions, replay at query or keystroke level and export to SIEM and SOAR systems. Those are testable procurement claims, but the public material does not provide comparative evaluations, penetration-test findings, revocation-latency measurements or production incident results. Security and AI-operations teams therefore need evidence for several deployment-specific questions: * Which agent platforms, target systems and connection methods support credential-free elevation? * Does policy run at the tool-call, session, command or statement level for each target? * Which live signals can revoke access, and what happens to an operation already executing? * Do audit records prove that privilege was removed inside the target system, rather than only that a session was closed? * Does a gateway or connector failure deny new access and terminate existing authority, or can a session remain usable? As of August 26, the confirmed story is limited but concrete: ARC is available, its authorization model binds privilege to a task, and supported enforcement paths can block individual actions or revoke access before the task finishes. Whether those controls produce the intended security outcome in a particular production estate remains dependent on integration coverage, failure behavior and audit evidence demonstrated in that environment.
Britive has launched Britive ARC (Agentic Runtime Control), a platform designed to secure AI agents operating in enterprise systems. The system grants AI agents task-specific access only when needed, monitors their activities during runtime, and removes access upon task completion. The platform addresses security concerns as enterprises deploy AI agents capable of querying databases, calling APIs, and modifying infrastructure. Unlike traditional access models built for human users, Britive ARC ties privileges directly to specific tasks rather than maintaining standing access. The system verifies agents and evaluating intent before granting minimal required access. It monitors activities whilst work progresses and captures audit evidence throughout transactions. For systems requiring credentials, Britive creates and injects them at runtime, then revokes them when tasks end. Britive ARC integrates with existing access policies for human and non-human identities across cloud, SaaS, database, and on-premises environments. The platform is available today.
Britive joins Torq AMP Alliance program to accelerate agentic SecOps. Jun 25, 2026, 12:00 ET Torq AMP Drives Agentic AI Innovation Through Deep Integration and Innovation Capabilities, GTM Collaboration, and Disruptive Joint Marketing for Britive's Runtime Privileged Access Management LOS ANGELES, June 25, 2026 /PRNewswire/ - Britive, the cloud-native platform redefining privileged access management (PAM) to secure human, agentic AI, and non-human identities at runtime, today announced it has joined the expanding Torq AMP alliance program, designed to drive agentic AI innovation. Building on a multi-year technology partnership, Britive was selected for its leading just-in-time, runtime privileged access platform that governs human identities, machine identities, and agentic AI workloads, and seamlessly integrates with the Torq AI SOC Platform to empower customers and their SOC/Incident Response teams. The expanded relationship formalizes what joint customers have relied on in production, with automated privilege enforcement tied directly to SOC investigation and response workflows. Torq AMP is unlike any other partner program in the history of cybersecurity. It exists in stark contrast to partner programs stuck in the distant past, built on elitist tiering systems, pay-to-play participation, and excessive bureaucracy. With Torq AMP, partners such as Britive can easily leverage Torq's AI SOC platform and agentic AI capabilities to create unique, high-value solutions that integrate across mutual customers' security stacks and ISV ecosystems. Torq AMP delivers builder-focused, not engineering-focused, integrations that elevate the value of partner offerings and go far beyond the static, pre-defined integrations of typical tech alliances. It's all about driving mutual growth, adoption, and buzz for all participants. Torq AMP provides these exclusive benefits to Britive: * Integrated Solution Creation: Build innovative, joint AI-driven SecOps solutions quickly and easily at scale, without heavy engineering efforts * Deep Torq Sales Engagement: Joint field marketing events, collaborative prospecting, and integrated presence in Torq demo environments * Strategic GTM Collaboration: Collaborative sales enablement, team training, channel packaging, ROI analysis, and reporting * Disruptive Marketing Activation: Integration highlighted within the Torq platform, on Torq's website, in customer and prospect emails, and across social posts, messaging, and custom swag "Britive and Torq have been delivering value together for our joint customers for years, and joining the AMP Alliance is the natural next step as Torq establishes itself as the AI SOC platform of record," said Art Poghosyan, CEO, Britive. "The threat landscape has expanded well beyond human user credentials. Machine identities and agentic AI workloads now represent the fastest-growing and least-governed privilege surface in the enterprise. The joint solution we bring to market with Torq addresses all three planes together. Now our customers get automated, runtime enforcement at the moment of need, regardless of what type of identity is making the access request." "We have seen firsthand how identity-related risk plays out in SOC investigations. Privilege abuse through human accounts, unmanaged machine identities, and now ungoverned agentic AI permissions are consistently the path of least resistance for attackers," said Nauman Mustafa, CSO and VP of Platform and Ecosystem Strategy, Britive. "This renewed partnership with Torq takes the integration we have refined in the field and brings it fully into the agentic AI era. Torq's AI SOC drives investigation and response at machine speed across all three identity planes. Britive ensures that every access decision, whether it originates from a human operator, a machine workload, or an AI agent, is governed, time-bound, and auditable. That combination closes a gap that no other joint solution in the market addresses today." "Torq AMP partners include some of the most prestigious and cutting-edge cybersecurity companies in the world, and we are excited to welcome Britive to the fold," said Eldad Livni, CINO and Co-Founder, Torq. "Britive is an example of an innovative vendor that delivers solutions with maximum impact as we realize the potential of the AI SOC, together. And that means joint offerings that combine cutting-edge threat intelligence drawing from the deepest data pools with blazing fast AI-driven response, remediation, and mitigation. Together, Torq and Britive will protect organizations from the ever-expanding spectrum of threats they're confronted with every second of every day." About Britive Britive is the cloud-native runtime privileged access management platform built for the speed and scale of modern multi-cloud environments. Britive enables enterprises to eliminate standing privilege across cloud infrastructure, SaaS applications, machine identities, and agentic AI workloads through just-in-time access, runtime privilege controls, and continuous governance. Trusted by leading organizations across financial services, healthcare, and technology, Britive reduces identity-based risk across human, machine, and agentic identity planes without slowing down development or operations. Learn more at britive.com. About Torq Torq is the AI SOC platform that combines agentic insights and automation so that enterprises can triage, investigate, and respond to actual risks, faster. Torq streamlines every step from alert through resolution. The platform analyzes your risk context to identify your biggest threats. Global leaders like PepsiCo, Procter & Gamble, Siemens, Telefónica, and Virgin Atlantic trust Torq to power the next generation of Agentic SOC operations. SOURCE Britive
Britive, a privileged access management platform, has become the first comprehensive PAM solution to support the OpenID Shared Signals Framework, including Continuous Access Evaluation Profile and Risk Incident Sharing and Coordination protocols. The integration enables Britive to receive real-time security signals from compatible tools like CrowdStrike, Silverfort and Sailpoint, triggering instant policy-driven responses such as terminating privileged sessions or enforcing step-up authentication when threats are detected. The implementation is bidirectional, allowing Britive to both receive and emit security events. The system extends Britive's existing Zero Standing Privileges and Just-in-Time access capabilities by continuously evaluating security posture throughout active sessions, rather than only at login. All events and responses are recorded in audit logs for compliance and incident investigation purposes.
Britive has launched the Zero Standing Society, a certification programme for presales and sales professionals focused on Zero Standing Privileges (ZSP) for human, machine and agentic AI identities. The programme addresses limitations of legacy vault-based privileged access management systems, which struggle with high-velocity automated workflows. The certification teaches runtime enforcement of privileged access, using dynamic, ephemeral permissions that exist only during task execution, eliminating standing privileges entirely. Britive claims this approach removes the trade-off between security and innovation, particularly for autonomous AI agents performing thousands of actions per minute. Registration is now open to Britive partners. Certified members receive an official Zero Standing Society badge. The Los Angeles-based company provides cloud-native privileged access management for Fortune 500 companies across regulated industries.