Aembit now secures Meta Muse, giving security teams a purpose-built way to control how Muse authenticates to enterprise resources, enforce least-privilege access policies, and maintain a complete audit trail of every access event.
If Muse is showing up in your organization, and with its adoption curve, it will be, this is the piece of the security stack that’s been missing.
Personal AI agents are a newer class of software built to take action for people, not just answer questions. That also means they are starting to cross into the workplace. An employee can bring one in much the way earlier generations brought personal devices and cloud apps, then connect it to the systems they already use for work. Once that happens, the question is no longer just what the agent can do. It is what the agent can access, under whose authority, and how the business can control that access.
What Is Meta Muse?
Meta launched Muse on Sept. 8 as a personal AI agent for the U.S. and Canada. It isn’t a chatbot that answers questions. It’s an agent that carries out tasks on your behalf: shopping, booking travel, scheduling, and taking actions on your computer through a dedicated secure cloud VM, powered by what Meta calls Muse Spark.
It shot to the top of the App Store’s free chart within days of launch, and Meta has since extended it with business connectors and support for custom connectors to services Meta doesn’t offer natively. With millions of users delegating real tasks, the question of how Muse authenticates to enterprise resources stopped being theoretical fast.
Why Existing IAM Doesn’t Fully Cover Meta Muse
Muse wants to connect to external servers as soon as you create your account. It connects to email, calendars, and third-party services through connectors, including custom connectors to services Meta doesn’t offer natively, such as the Aembit MCP Identity Gateway.
The security cost of that ease is that Muse reaches further, faster, than the access model keeping up with it. When Muse needs to reach an enterprise resource, it needs a credential to do it. The default approach, OAuth that lets the user grant the agent access, works well enough to get the agent running. It doesn’t work well enough to satisfy a compliance audit, defend against credential exposure, or give a security team meaningful visibility into what the agent accessed and why.
The core issue is that Muse isn’t a deterministic workload. It doesn’t follow a fixed access path and makes runtime decisions about which tools to call and which resources to reach. A static credential scoped for one expected behavior ends up held by an entity whose behavior can’t be predicted. There’s a fundamental mismatch between how existing human IAM tooling works and how AI agents behave, and it persists across agent platforms. Aembit was built to close that gap.
How Aembit Secures Meta Muse Access
Aembit sits between Muse and the enterprise resources it needs to reach. The MCP Identity Gateway terminates the agent connection, and the MCP Authorization Server acts as the policy decision point. When Muse needs a credential at runtime, Aembit evaluates the request against your access policies, checking the agent’s identity, the resource being requested, and the conditions of the request, and issues a short-lived, scoped credential if the request is authorized. When the task is done, the credential expires. No persistent access. Nothing for the agent to store, leak, or reuse.
In practice, this means:
- No standing access. Muse never holds persistent credentials. Every credential is issued for a specific task and expires automatically when that task is complete.
- Least-privilege enforcement. Access is scoped to exactly what the agent needs for the specific interaction, not what it might conceivably need across all possible interactions.
- A real audit trail. Every credential issuance, access event, and policy decision is logged with enough context to answer compliance questions cleanly: which agent acted, for whom, and what policy authorized it.
- Centralized policy management. Access policies for Muse are defined and enforced in one place, alongside policies for your other agent platforms.
How Meta Muse Connects to the Aembit MCP Identity Gateway
This integration didn’t start in an admin console. It started in a chat window: “connect my Aembit MCP gateway.” Muse registered itself as an OAuth client against the Aembit authorization server using Dynamic Client Registration, with no app to create and no client ID or secret to copy and paste.
When the authorization flow stalled, we diagnosed it with Aembit’s own documentation and MCP Authorization Tracing. The authorization service required the request to name the gateway as its target audience, which we fixed by requesting the gateway URL as a scope, exactly what the gateway advertises in its protected-resource metadata.
Once connected, Muse generated a skill file so it can list and invoke tools through the gateway going forward (tenant details redacted):
# ~/workspace/skills/aembit-mcp-gateway/bin/mcp.py
CREDENTIAL_NAME = "custom.aembit-mcp-gateway"
MCP_URL = "https://<tenant>.mcpgateway.aembit.io/mcp"
ALLOWED_HOSTS = ["<tenant>.mcpgateway.aembit.io", "<tenant>.id.useast2.aembit.io"]
def _initialize():
# MCP handshake: initialize -> notifications/initialized
...
def cmd_tools_list():
session = _initialize()
return _rpc("tools/list", session) # what can I call?
def cmd_tools_call(name, arguments):
session = _initialize()
return _rpc("tools/call", session, # call it
{"name": name, "arguments": arguments})
We verified the whole thing with a live tools/list call against the gateway: 49 tools returned for GitHub, working on the first attempt after the fix. The entire integration was configured conversationally, debugged against our docs, and codified as a reusable skill. That may be what agent onboarding increasingly looks like.
What Other AI Agent Platforms Does Aembit Support?
The Muse integration is the latest in a series of platform-specific integrations we’re releasing this year. Aembit already secures Microsoft Copilot Studio agents, Claude, ChatGPT, Gemini, and custom LLM-based agents under the same policy model, and we’ll have more to announce in upcoming launches. If there’s a specific agent platform your organization is deploying and you want to talk through the access model, reach out.
The agents are already in your environment. Aembit is here to help deploy them securely.
How to Get Started Securing Meta Muse
If your organization is deploying AI agents, Muse included, start with the access questions every security team should answer before agents go live. We’ve built an interactive checklist for exactly that: the Agentic AI Deployment Checklist. It covers Muse alongside Copilot Studio, Claude, ChatGPT, and Gemini because the underlying access problem is the same regardless of which agent is running. Work through it with your team. It’s a useful way to find where your current agent deployments have gaps and what to prioritize.
Or skip the checklist and talk to an engineer about putting Muse behind Aembit’s MCP Identity Gateway. We’ll work through the specifics of your deployment, whether you’re in the early stages of evaluating agent security or already have agents running in production without a clear access model.
< VIDEO >
Talk to an Engineer · Take the Agentic AI Deployment Checklist