PlainID is the identity leader built for the AI era. It is the only runtime authorization platform that controls what every human, non-human, and AI agent can access, do, and expose in real time. By enforcing Zero Standing Privileges, PlainID ensures access is granted only when needed and dynamically adapts as context changes, securing applications, APIs, data, and agentic AI workflows at scale.
Agentic AI promises massive efficiency gains by autonomously executing complex business workflows. Yet as autonomy increases, so does risk. Without enforceable boundaries, AI agents can overreach, accessing sensitive data, triggering unauthorized actions, or disrupting critical systems at machine speed.
Establishing secure agentic AI requires intent-aware, policy-based controls embedded across the entire agentic flow. Modern authorization architectures enable dynamic, context-aware decisions that govern what agents can access, when, and under which conditions, aligning autonomy with enterprise security, compliance, and operational resilience.
John Tolbert, Lead Analyst at KuppingerCole will frame the discussion within the broader identity and authorization landscape, examine emerging patterns in agentic AI security, highlight architectural control points, and provide independent guidance on aligning AI autonomy with Zero Trust and policy-based access strategies.
Gal Helemski, CPO & Co-founder at PlainID will explore real-world agentic AI risks, explain how policy-based authorization enforces intent and scope, demonstrate layers of control across agents and humans, and share practical approaches to preventing data leakage while enabling scalable AI-driven innovation.
As AI-driven systems become central to business operations, controlling access to their data, models, and actions has become mission-critical. With decisions increasingly automated, unauthorized or unchecked access can lead to compliance violations, data breaches, and ethical pitfalls.
Modern approaches to access control—such as policy-based authorization, zero-trust architectures, and dynamic access enforcement—are redefining how AI pipelines should be secured. Fine-grained controls tailored to AI workflows offer organizations a way to enforce accountability, transparency, and resilience.
Alexei Balaganski, Lead Analyst & CTO at KuppingerCole will explore the broader landscape of AI-based architectures, including current risks in AI model exposure, evolving regulatory expectations, and the intersection of IAM and AI ethics. He will discuss aligning identity, access, and policy layers to secure intelligent systems properly.
Gal Helemski, Co-founder & CPO at PlainID will demonstrate how policy-based access control enables organizations to manage AI agent permissions dynamically. Drawing from real-world implementations, she will share insights into securing datasets, APIs, and decision points while ensuring compliance and business agility.
Join security experts from KuppingerCole Analysts and PlainID as they discuss identity management in the digital era, the limitations of ABAC and RBAC, and the benefits of policy-based access control (PBAC)
Martin Kuppinger, Principal Analyst at KuppingerCole Analysts, will talk about the latent potential for using PBAC for legacy use cases, modern authentication, and fraud prevention, and building modern digital services. He will also look at why organizations need to create a unified strategy and approach on PBAC across all areas.
Gal Helemski, PlainID co-founder and CPO, will explain how to navigate the path to modernized authorization and how to kickstart your PBAC program from initial assessment to implementation. She will be joined by Allan Foster, a long time expert and leader in Identity.
Now is the time to implement the Zero Trust security model because the traditional model of enforcing security at the network perimeter is no longer effective with users, devices and workloads moving outside the corporate network, but success depends on understanding the essential components of a Zero Trust Architecture.
In the digital age, collaboration is becoming more dynamic and integrated than ever before. External partners often require specific information, and therefore need access to internal systems. Providing efficient processes to manage partners is key to building a strong partner network.
The evolution of cybersecurity protection demands a more nuanced response to providing access to a company’s sensitive resources. Policy-based access control (PBAC) combines identity attributes and context variables to enable sophisticated granting of access to corporate systems and protected resources based on centrally managed policies that ensure consistent access control decisions across the enterprise. Advancement in both business requirements and technology (such as growing use of micro-services), require a better way to control access. In a way that is consistent across all silos, dynamic enough to react to change in risk, and provides better control for the application business owners.
PBAC facilitates the application of consistent policy across all applications that use the PBAC authorization service. Furthermore, policies are evaluated in real-time against current attributes rather than having to wait for a nightly update of identity attributes before access control policy is correctly applied. PBAC also facilitates a risk management approach to access decisions. If access outside business hours represents a greater risk the authorization service could prompt for an additional authentication factor before access is granted.
In this session PlainID will discuss how organizations can rethink, redesign and modernize their Identity and Access Management (IAM) architecture by implementing PBAC (Policy Based Access Control). This service should be a central service supporting not only one specific set of applications but rather act as a focal point (or a “brain” if you like) for different IAM technologies. This new architecture pattern has evolved to better support more applications and more advanced use cases.
Mastering authorization is critical for modern organizations with multiple user constituencies, applications, and data types. Authorization has become a crucial part of security infrastructures and can no longer be considered just another feature of existing IAM solutions. Instead, authorization control infrastructures have developed their own segment in the security market. There is a need for more than just one technology to meet different needs of the market, especially in the areas of administration and governance - both dictate the need for an authorization solution. Furthermore, customers face challenges in several areas – the main one is having no insight into what data and functionalities users are able to access. And while there is a constant need for businesses to continuously modify, extend, and modernize their processes and business models, there is a lack of adequate and agile data access control and management functionality.
RBAC (Role Based Access Control) has proven handy for adding manageability and assurance to coarse- or medium-grained authorization but break down in the face of dynamic environments or complex access policies. Attribute-based access control (ABAC) has gained adherents but is in fact just another piece of the puzzle. Policy-based Access Control (PBAC) is an emerging model that seeks to help enterprises address the need to implement actionable access control schemes based on corporate policy and governance requirements. In general, PBAC can be considered the harmonization and standardization of the ABAC and RBAC models at an enterprise level in support of specific governance objectives.
See All Locations
See All Locations