Skip to content
Identity and access

The connection between tools becomes a policy decision.

Cross App Access is an OAuth extension that lets an application request access to another on a user's behalf, with the identity provider evaluating the request against enterprise policy and issuing a token if it passes. Our work is replacing ad-hoc integration consent with policy the identity provider enforces.

Cross App Access replaces per-user consent prompts with a policy the identity provider evaluates. It is how an assistant reaching another application becomes something an administrator can see and control.

What it is

Cross App Access is an OAuth extension that lets an application request access to another on a user's behalf, with the identity provider evaluating the request against enterprise policy and issuing a token if it passes.

It is for organizations where assistants and tools are already connecting to each other through consent prompts that individual users clicked, and where nobody can produce a list of what is connected.

request review approve change record who decides, and on what evidence the gate is defined before anything is automated L1 L2 L3 L4

What it does

Policy instead of consent prompts

Access between applications is evaluated centrally rather than approved by whoever saw the dialog.

Administrators can see what connects

A list exists, which is the prerequisite for governing anything.

It is an open protocol

Adoption across vendors is what decides whether this becomes the norm or a single vendor's feature.

Where it fits

L1, identity and access, controlling behavior that shows up at L4. Tool-to-tool connections are the fastest growing category of unmanaged access. Moving them from user consent to enforced policy is what makes them reviewable at all.

Where it earns its place

An organization with assistants already in use

Teams connected tools themselves. The question is what those connections can reach, and it has no answer today.

A regulated estate facing a vendor review

An integration approved by a user in a dialog is difficult to defend as a control.

An estate consolidating shadow integrations

Replacing bespoke tokens with a policy-evaluated path removes credentials nobody owns.

Proof

25+

Early adopters of the protocol at announcement, including Anthropic, Zoom, and Slack.

Okta newsroom, Cross App Access partner announcement, 2026.

AI Innovator Finalist, 2026

AI Innovator Finalist, 2026

Atlassian Partner Awards, 2026

Questions we get

Is this only for agents?
No. It applies to any application-to-application access. Agents made it urgent because they multiply the number of connections.
What does it replace?
Per-user consent prompts and hand-rolled integration credentials, which are the two things nobody can inventory later.

Find out who can reach what.

Fixed scope. The assessment starts at the identity layer: human and non-human access, the accounts nobody owns, and what has to be true before an agent gets one. You get the findings, the ownership gaps, and the order to close them in.