Перейти к содержимому

Fredrik Warfvinge | Hashicorp IBM | Securing Your Coding Agent | Stockholm Mlops #38

Stockholm MLOps

0:00 / 0:00

Fredrik Warfvinge | Hashicorp IBM | Securing Your Coding Agent | Stockholm Mlops #38

45 просмотров · 12 дней назад
Stockholm MLOps
23 подписчика
45 просмотров · 12 дней назад
Recorded live at Stockholm MLOps Fall Bash #38 August 20, 2026 Speaker: Fredrik Warfvinge — Principal Architect, HashiCorp (an IBM Company) Topics: • Securing autonomous and agentic workflows in the enterprise • Non-deterministic AI behavior vs. legacy IAM architectures • Machine identity explosion and standing privilege elimination • Defense patterns against prompt injection and the "lethal trifecta" • Just-in-time (JIT) dynamic credentials with HashiCorp Vault • Out-of-band human authorization with OAuth 2.0 CIBA and IBM Verify You wouldn't give a new hire unlimited production access on day one—so why do enterprises hand standing root credentials to non-deterministic AI agents? At Stockholm MLOps Fall Bash #38, Fredrik Håstav-Arvinge challenges current security assumptions around agentic systems and details how to implement zero-trust runtime governance across autonomous workflows. His core message: Trust cannot be prompted into existence; security must be deterministically enforced outside the agent. What is relevant Traditional IAM systems were architected for predictable human operators and deterministic services. As machine-to-human identity ratios surge past 45:1, autonomous agents making decisions on the fly completely break legacy perimeter controls. When developers grant broad standing privileges or rely on generic user approvals, agents expose organizations to severe blast radiuses. Attacks exploiting the "lethal trifecta"—private data access, untrusted content, and external communication channels—consistently prove that prompting an LLM to "not touch production" fails. Without out-of-band policy controls, prompt injections and dependency attacks easily compromise enterprise backends. Key insight: Autonomous agents require identity-based, point-of-use enforcement that operates entirely external to the model runtime. Rather than relying on persistent API tokens and trust-based prompts, secure enterprise architectures enforce cryptographic identity per agent, strip standing privileges via ephemeral dynamic credentials, and require explicit out-of-band human verification (CIBA) before any high-privilege state change can execute. What Fredrik covers • The failure modes of legacy IAM when applied to non-deterministic tool-using agents. •Real-world post-mortems of agent compromises, including data exfiltration, supply chain typo-squatting, and repository hijacking. • The five enterprise imperatives: register every agent, strip standing privileges, tie actions to intent, enforce policy at point of use, and produce cryptographically verifiable audit trails. • Architecture patterns for agentic runtimes: • Non-personalized retrieval using dynamic JIT credentials with explicit TTLs. • Personalized workflows using OAuth 2.0 with Rich Authorization Requests (RAR) and delegated ⁠may_act⁠ claims. • High-risk/financial transactions requiring out-of-band verification via Client-Initiated Backchannel Authorization (CIBA). Live demo: "HashiBank"—demonstrating runtime privilege escalation, mobile push approvals, and single-use credential minting using IBM Verify and HashiCorp Vault. Timestamps • 00:00 - The agentic identity explosion and non-deterministic risk • 01:26 - Four critical enterprise risk areas • 02:22 - Real-world agent compromises and the lethal trifecta • 04:06 - Architectural defense patterns against prompt injection • 04:32 - Five imperatives for enterprise agent governance • 06:36 - Ephemeral credentials and JIT secrets with HashiCorp Vault • 07:41 - Personalized context retrieval using OAuth delegation and RAR • 08:41 - High-privilege execution: Out-of-band step-up approval via CIBA • 10:10 - Demo: HashiBank privilege escalation and runtime policy enforcement About Stockholm MLOps: Stockholm MLOps is one of the fastest-growing AI infrastructure and MLOps communities in Europe focused on: • Production AI systems • AI infrastructure • Open-source AI • MLOps • Sovereign AI • Real-world deployment lessons Website: https://www.stockholmmlops.se Meetup: https://www.meetup.com/stockholm-mlop... LinkedIn:   / stockholm-mlops   #MLOps #AIInfrastructure #Inference #OpenSourceAI #SovereignAI