Every time a company hands a task to an AI agent, it is a little like giving a new employee a key card, a set of instructions, and a brownie recipe, then walking away. The agent might be brilliant. It might know exactly how to send a follow-up email, update a customer record, or reorder inventory. But unless every door it opens is the right door, the whole experiment can end in costly mistakes and security violations. That is the problem Temporal, an enterprise infrastructure company based in Bellevue, Washington, is trying to solve. Temporal builds what it calls “durable execution” technology, a way for applications to keep their state and history even when servers crash, networks fail, or tasks time out. It is already the backbone for AI agents used by companies like OpenAI and NVIDIA. On Tuesday, Temporal made a significant move toward making that backbone more secure by bringing in a team from Oso, a New York-based startup that specializes in application authorization. The move is designed to put access controls directly inside the platform, so agents cannot simply do whatever they want. It arrives at a moment of enormous momentum for Temporal, which closed a $550 million funding round last month at a valuation of $12.55 billion. To understand why this matters, consider what happens with modern AI systems. A large language model is essentially a brain. It can process enormous amounts of text and generate responses, but it lives in a cloud somewhere and cannot touch the rest of the world. To be genuinely useful, it needs hands. Those hands come in the form of connections to internal databases, customer records, payment systems, and a long list of external APIs. Once those connections exist, you have a truly autonomous agent, one that can not only say what it thinks but actually do things. That means the boundary between the model and everything else is exactly where the risk lives, and it is why companies like Temporal are spending serious money on the problem.
Oso’s team isn’t coming empty-handed. As part of the arrangement, a holding company called Tiny will take over Oso’s software product and its customer base, while the people who have been working on it will carry their expertise into Temporal. This split, product goes one way, people go another, gives Temporal the talent and the point of view without the burden of maintaining a legacy product. It’s a familiar but increasingly common pattern in the tech industry, and it signals something important. Security can no longer be an afterthought in the AI era. Oso’s entire focus was on application authorization, which sounds like a dry topic until you realize what it means in practice. It means determining, for every single request, whether the person behind that request has permission to do what is being asked. For a human user, that might mean clicking through a permission screen. But for an AI agent, operating at machine speed, it means evaluating every action, remembering who initiated it, and checking it against a policy that might change from moment to moment. The problem is that agents often work asynchronously. A user asks for something, the agent begins working, and by the time the agent finishes, the user’s permissions may have changed. If the agent doesn’t re-check, it can end up doing something that was never allowed. An agent might be asked to update a user’s account, cancel a subscription, or move money between departments. It can do these things dozens of times in a minute, while a human is still reading the first email. Without restrictions, or if permissions are lost during a retry, the result is a serious security gap. With Oso’s framework inside Temporal, every retry of a failed workflow can re-validate the actor’s identity and authorization, so a rejected action does not just repeat until it slips through. That kind of guardrail might seem obvious, but it is surprisingly difficult to get right in distributed systems.
Preeti Somal, Temporal’s VP of product, framed the challenge in stark terms in Tuesday’s announcement: “AI safety doesn’t stop at the model.” Her point is that enterprises have spent a lot of time worrying about whether a language model will say something harmful, but very little time worrying about whether an agent will do something harmful. That is starting to change. Temporal’s technology is known for a concept called durable execution. The phrase sounds technical, but it is easier to understand if you think of it as a memory for software. If a process crashes halfway through a multi-step workflow, a durable execution platform remembers exactly where it was and what it was doing. It saves the state, retries the failed step, and continues from exactly the right place. For AI agents, that kind of memory is essential. In a typical workflow, an agent might have to call a dozen different APIs, each of which can fail, time out, or return an unexpected result. Durable execution makes those workflows reliable. But it also introduces a subtle security risk. If a workflow is retried, the original authorizations might be stale. What if the human who requested the action no longer has permission? What if the agent’s credentials have been revoked? What if a previous step did something that should have invalidated the entire mission? Oso’s technology solves that by making authorization a first-class part of the workflow, not something checked once at the beginning and then forgotten. Somal called the goal practical: to help developers put agents to work with appropriate access and with guardrails their companies control. In practice, that means asking, for each action an agent takes, who it is acting for and what that person is allowed to do, and getting the same answer every time the work is retried. This is a subtle but important shift. It means the platform, not just the model, is enforcing safety. It means a company can decide exactly what an agent can access, what it can change, and what it cannot do, even if no one is watching at the exact moment the agent decides to act.
Oso founder Graham Neray summed up the moment with a sharp observation: “What makes agents valuable is the same thing that makes them dangerous – access to real systems and data.” He pointed out that Temporal already powers agents in applications like Cursor and OpenAI Codex, and that unlocking their full potential requires the right security controls. That message resonates across the industry. Generative AI has moved from demo mode to production mode, and with that transition comes a very real sense of accountability. A demo can fail gracefully. In production, an agent can accidentally email thousands of customers, delete a database row, or approve a refund it shouldn’t have approved. No company wants to be the one whose AI caused a breach. With the memory of past data incidents still fresh, the enterprise software market is hungry for tools that add a layer of control between AI’s reasoning and its actions. Temporal’s move is not just about feature development; it is about telling a larger story. The company wants to be the place where AI agents are built, not just for speed and reliability, but for safety and governance. By absorbing a team that has dedicated years to authorization, Temporal is signaling that it understands the landscape better than many of its competitors. The company also says the Oso team will accelerate security features currently in development, while existing platform operations remain unchanged. That’s important for current customers, who don’t want a change of direction to disrupt their workflows. Instead, the announcement is additive. It is a way of saying that security is not a separate product to be bolted on, but a layer of the foundation itself. The deeper message is that AI agents should be trusted because they are controlled, not because they are smart.
Temporal was co-founded in 2019 by Samar Abbas and Maxim Fateev, two veterans of Amazon and Microsoft who saw a gap in how large organizations handle complex, long-running software workflows. They created an open-source orchestration technology that has since become a favorite for companies that need to keep track of everything from microservices to AI agents. Its customer list reads like a who’s who of the tech world: OpenAI, NVIDIA, Netflix, Snap, and JPMorgan Chase. That kind of trust does not come easily. The company recently surpassed $250 million in annualized revenue run rate, a more than 200% year-over-year increase. That growth rate, combined with the new $550 million financing round, focused on building a backbone for AI agents, explains why Temporal is on such a rapid trajectory. The funding round isn’t just a vote of confidence. It is a bet that the infrastructure layer connecting AI models to the rest of the enterprise will be as important as the models themselves. The valuation of $12.55 billion places Temporal among the most valuable private infrastructure companies in the Pacific Northwest. It is a far cry from its 2019 roots, but the founders have never shied away from ambitious bets. They have been careful, though, not to confuse hype with reality. Their approach is grounded in boring but important technical problems like consistency, retries, and authorization. Those are the kind of problems that don’t get flashy headlines but become massive headaches when ignored. In an industry often obsessed with the next flashy model release, Temporal has bet on the plumbing that makes AI actually usable in the real world.
On a more human level, Temporal remains a company that prizes flexibility. It employed about 570 people before the Oso deal, roughly double its headcount from a year earlier, with 89 of those employees based in the Seattle area. The company is fully remote, which means the Bellevue office, a space previously occupied by OpenAI, is used mainly for meetings and gatherings rather than daily 9-to-5 work. That’s a lifestyle many engineers appreciate, and it’s a signal that Temporal’s culture is built around trust and output rather than location. The company recently rose to the #1 spot on the GeekWire 200, the list of the fastest-growing private tech companies in the Pacific Northwest, a recognition that reflects both its financial momentum and its expanding influence. The Oso acquisition is another chapter in that story. It doesn’t mean Temporal is suddenly in the business of selling authorization software as a standalone product. Instead, the integration of Oso’s team will accelerate what the company is already building, making it easier for developers to create AI agents that have guardrails baked into their DNA. The question is whether that will be enough. The industry is still learning how to build safe autonomous systems, and no single tool can guarantee that a deployed agent will never make a mistake. But by making authorization part of the execution fabric, Temporal is taking a significant step in the right direction. For the people who build and use AI agents, this is a meaningful development. It means companies can trust their agents to do more, not less, because they can control exactly what those agents are allowed to touch. It means an agent working on behalf of a customer service representative will not suddenly become an administrator. It means a retry after a network failure will not inadvertently repeat a sensitive transaction without permission. It is the kind of work that is invisible when done right, and chaos when done wrong. Temporal’s move to bring in Oso’s team is a signal that the next phase of AI infrastructure will be as much about limitation as about capability. The most powerful systems are not the ones that can do everything. They are the ones that can do exactly what they’re supposed to do, and nothing more. That’s a hard lesson for an industry obsessed with capabilities, but it’s the lesson that will ultimately determine whether AI agents become a trusted part of daily life or a liability. For now, at least, Temporal is putting its money, and its team, where its mouth is.












