Orchestrating Non-Human Identity (Workloads, Devices, Agents) II
Combined Session
Wednesday, May 20, 2026 15:35—16:35
Location: A 05-06
Log in to download presentations
Wednesday, May 20, 2026 15:35—16:35
Location: A 05-06
Watch the video
By mid-2026, the ratio of non-human to human identities will reach a critical tipping point. The rise of Agentic AI - autonomous systems capable of orchestrating workflows and accessing sensitive data without a human in the loop - renders traditional IAM models obsolete. We are no longer securing tools. We are governing digital employees.
This session offers a comprehensive view on integrating autonomous agents into a modern Identity Fabric. We move beyond static authorizations and over-privileged service accounts toward a model of Continuous Adaptive Trust, where every identity, human or machine, earns access through context, intent, and policy.
Participants will explore a blueprint for:
- Identity Attribution: Establishing a framework that ties every agentic action back to a human principal and a specific intent, ensuring full traceability across the identity graph.
- Policy-Based Access: Transitioning from static roles to dynamic, policy-based access for autonomous workloads, aligned with least privilege and Zero Standing Privileges.
- IAM and GRC Convergence: Treating the fusion of identity governance and compliance as the accelerator for a truly governed and audit-ready enterprise identity ecosystem.
Watch the video
Digital transformation has accelerated the growth of identities - and with it the expansion of the enterprise attack surface. Today’s organisations rely on an increasingly diverse set of human and non-human identities originating from many sources: Entra ID for SaaS, federated domains created through mergers and acquisitions, partner and supplier ecosystems, service accounts, API integrations, IoT devices, workloads, automation tools, and increasingly autonomous AI agents operating across cloud and on-prem environments. Every optimisation or digitalisation initiative introduces additional actors that must be consistently authenticated and authorised.
But identity proliferation doesn’t just introduce complexity. When applications directly rely on external identity providers - whether from SaaS platforms, multi‑cloud setups, partner ecosystems, or post‑merger domains - trust begins to spread far beyond its intended boundary. This increases blast radius whenever a credential is compromised or a provider is misconfigured.
In this session, I demonstrate how OAuth Token Exchange offers a standards‑based pattern to decouple identity origin from trust enforcement. By issuing context‑aware, boundary‑scoped tokens, organisations can enforce identity consistently and reduce risk across internal domains - regardless of where the identity was created.
Key Message
The architectural approach applies equally to on‑prem systems, multi‑cloud deployments, and federated organisations.
Call to Action
We cannot control where identities are created — but we can control how, where, and under what conditions trust is applied.
If identity enforcement still lives inside your applications, you are scaling complexity and risk. Let’s talk about how to centralise trust - not vulnerabilities.
Watch the video
As AI agents grow more autonomous - booking travel, executing transactions, acting on our behalf across digital systems - a fundamental question emerges: do we treat them as quasi-human entities deserving of trust, identity, and even rights, or as sophisticated programs to be controlled, audited, and constrained? The answer is far from academic. How we frame AI agents shapes the security models we build, the identity architectures we deploy, the liability frameworks we establish, and the attack surfaces we expose. This panel explores the tension between these two worldviews, interrogating the assumptions behind our current approaches and asking what is truly at stake as agents become more capable, more embedded, and harder to distinguish from the humans they represent.