Your AI Agent Is a Privileged Identity: Securing MCP, Tool Use, and Autonomous Workflows

About this session

AI agents aren't just chatbots anymore. They're actively calling APIs, reading sensitive data, and executing tasks across your enterprise systems. This basically turns every agent into a highly privileged user, which is a huge risk because traditional app security simply wasn't built to handle it.

In this session, we'll walk through a vendor-neutral approach to securing autonomous workflows and tool connections. We'll break down the new attack surface, covering everything from prompt injection and tool poisoning to lateral movement. Then, we'll show you how to actually protect your systems. You'll learn exactly how to reduce your exposure using smart identity boundaries, least-privilege access, policy gates, and human-in-the-loop approvals.

You'll walk away with exactly what you need to safely launch. We'll give you a practical threat model, an architecture checklist, and a red-team plan to stress-test your AI agents before they ever hit production.

Speaker

Key takeaways

  • Build a practical threat model covering the model, context, identity, data, tools, APIs, and runtime environment surrounding an AI agent.
  • Apply least-privilege access, trusted-tool controls, policy gates, monitoring, and human approval without removing the speed and usefulness of agentic workflows.
  • Create a pre-production red-team plan that tests prompt injection, tool poisoning, permission abuse, unsafe actions, lateral movement, and failure containment.

Related sessions