Apollo previews field-level controls for AI agents using enterprise APIs
CEO and co-founder Matt DeBergalis is extending Apollo's API-orchestration platform to agent access, with Intuit piloting the service in private preview.
By RuntimeWire Staff · Published
Primary source: PR Newswire
Why it matters
Apollo is extending API orchestration into agent identity and access control, positioning its graph as a governance layer for enterprise AI. Intuit's pilot is an early use case, while private-preview availability and unverified performance claims leave adoption and results to prove.

Apollo GraphQL CEO and co-founder Matt DeBergalis is extending Apollo's platform to a new layer of enterprise AI: deciding what an agent can retrieve and do through existing APIs. Apollo announced GraphOS Agent Services on October 7th, putting identity, policy and audit controls between agents and the systems they use. Intuit is piloting the service in private preview.
The move extends the infrastructure Apollo has spent years building for developers. Its GraphOS platform connects and orchestrates APIs, while GraphOS Agent Services is designed to apply access rules to agents that query those systems. Apollo says the controls can be enforced field by field without asking an AI model to make the authorization decision. That distinction addresses a practical risk: an existing API may return billing details or internal notes alongside the customer information an agent was asked to find.

DeBergalis has built his career around infrastructure that other developers can use. Before Apollo, he co-founded Meteor Development Group with Geoff Schmidt and Nick Martin. The team initially set out to make a travel-recommendation app, then shifted to its underlying application framework after seeing other startup teams struggle with the same development work. A 2014 WIRED profile of Meteor's founders also notes DeBergalis's earlier co-founding of online fundraising platform ActBlue. Apollo's current leadership page lists him as CEO and co-founder; Apollo announced that he became CEO in July 2025, succeeding Schmidt.
That history fits the product bet. Apollo's original pitch was to simplify the plumbing developers needed to build applications. Agent Services applies that same infrastructure-first approach to a newer problem: allowing autonomous software to use company systems without treating every agent like a trusted human developer.
Governance moves into the API layer
The service groups its stated capabilities into four areas: search to help agents find data and tools, identity for agents acting on their own or on behalf of a person, policy to control what each can see or do, and audit to record activity. Apollo says requests are translated into API calls and credentials are brokered for those requests, with access decisions enforced outside the model's judgment loop.

Apollo's documentation makes the current stage explicit: Agent Services is in private preview, and onboarding requires help from an Apollo employee. The docs describe classifying fields with tags, then setting rules that allow, mask or deny access for specified people, groups or clients. For a denied field, administrators can configure whether it is hidden, returns an error, or can be requested. Those are useful operational details; Apollo's announcement does not provide pricing, general availability timing or the terms of Intuit's pilot.
Intuit is already using GraphOS and is piloting Agent Services for an AI marketing workflow. Chris Miller, Intuit's head of AI Marketing Futures, said in Apollo's announcement that the agents can analyze campaign spending against results and propose changes in real time, with access limited to necessary data and an audit trail. His example gives the product a concrete business use: shortening the feedback loop between marketing spend and campaign adjustments. It does not establish how long the pilot has run or what measurable results it has produced.
The control point Apollo wants
The launch also broadens Apollo's agent tooling for developers. The GraphOS MCP Server gives AI assistants access to Apollo documentation and graph-building capabilities; authenticated users can also connect it to graphs their accounts are permitted to access. The new Agent Services pitch reaches beyond helping developers work with GraphOS: it aims to govern agents as they use enterprise APIs and data.
Apollo is positioning its existing graph as the place to centralize that governance. Apollo says GraphOS orchestrates more than 2 trillion operations a month, a company-reported measure of platform activity rather than an independently verified customer or revenue figure. If businesses already map their services and data through GraphOS, Apollo's argument is that agent permissions can be managed alongside the API infrastructure those agents need to use.
That approach has a clear appeal for companies trying to keep agents from pulling unnecessary sensitive data into prompts, logs or other systems. It also makes the graph a more consequential layer in an enterprise's AI stack. The test is whether customers can apply consistent rules across the services agents actually touch, and whether they trust Apollo to be the control point for those decisions. The private-preview status and the single named pilot leave those questions open.
The announcement also included GraphOS Router 3.0 in preview. Apollo claims it cuts typical query-planning time by 95% compared with Router 2.0, with larger gains on complex graphs and lower memory use. Those are Apollo's benchmarks, not independent measurements. For DeBergalis, the central product move is clearer: Apollo is extending its API orchestration business from connecting services for applications to controlling how AI agents use them.