AI Agents Need Identities Too: Securing Agentic AI Access | Joshua Moses | Cybertrace Foundation
Joshua Moses | Cybertrace Foundation
0:00 / 0:00
AI Agents Need Identities Too: Securing Agentic AI Access | Joshua Moses | Cybertrace Foundation
4 просмотра · 5 дней назад
Joshua Moses | Cybertrace Foundation
96 подписчиков
4 просмотра · 5 дней назад
An AI agent is not a service account. It acts for others, behaves non-deterministically, and its scope grows with the task.
This video treats agents as first-class identities and prompt injection as an authorization problem.
Joshua Moses | Cybertrace Foundation
Autonomous Compute Fabric Series, Video 27 of 32: Agentic AI as a First-Class Identity
IN THIS VIDEO
• Why agents break the service account model
• Registering agents and attesting the model and its configuration
• Task-bound permissions plus resource, spend and time limits
• The over-permissioned agent reused for jobs it was never scoped for
• Controlling tool and connector calls through the fabric, not the agent
• Prompt injection as an identity and authorization problem
• Monitoring intent vs action, anomaly detection and kill switches
• Ownership, approval and accountability for agent actions
YOUR TAKEAWAY
An agent onboarding and authorization checklist with a permission scoping worksheet. Use it as a working template for
your own environment.
WHO THIS IS FOR
IAM architects, security engineers, PAM and identity governance teams, cloud and platform engineers, auditors, and
security leaders who have to make identity work across more than one domain.
ABOUT THE SERIES
The Autonomous Compute Fabric series is a 32-part course on running identity and access management as one
autonomous system across Active Directory, multiple clouds, Kubernetes, SaaS, OT and AI agents. Every video follows the
same fictional multinational and ends with a practical artifact you can use.
Previous: Video 26, Non-Human Identity at Scale
Next: Video 28, Delegation, Intent, and Chained Authority
ABOUT JOSHUA MOSES
Joshua Moses has spent more than 30 years in cybersecurity, working across privileged access management, identity and
access management, Active Directory, penetration testing, red teaming and GRC.
Subscribe to Cybertrace Foundation and turn on notifications so you don't miss the next video in the series.
#AgenticAI #AISecurity #IAM