Delegated Authority, Trust & Accountability
Combined Session
Tuesday, October 06, 2026 14:40—16:00
Tuesday, October 06, 2026 14:40—16:00
Autonomous AI agents are rapidly becoming a new class of enterprise identity. Unlike traditional non-human identities, AI agents can make decisions, invoke tools, access enterprise systems, delegate work to other agents, and act on behalf of users. As organizations deploy agentic AI at scale, existing identity, governance, and security models struggle to answer fundamental questions: Which agents exist? What can they access? Under whose authority are they acting? And how can their decisions be explained after the fact?
This session introduces two emerging capability areas: Agent Visibility and Observability Platforms (AVOP) and Agent Threat Detection and Response (ATDR). The session will also explain how these emerging disciplines complement existing IAM, NHI, ITDR, PAM, and Identity Fabric architectures. Attendees will gain a practical framework for understanding why AI agents represent a fundamentally different identity challenge and what organizations should do today to prepare for the next generation of autonomous digital identities.
Almost every agent-identity product now ties an AI agent to a human, and most tie it to the wrong one. "The agent inherits the identity of its user" has become the default, yet it quietly collapses two different people into one: the principal whose authority the agent borrows for a given action, and the owner who is accountable for the agent existing at all.
The two carry opposite rules. When an agent acts for a principal, it must not exceed that user's rights, or it becomes a confused deputy that a single injected instruction can turn against them. Under an owner, the same agent can and often must hold access the owner personally lacks, exactly as a CFO is accountable for finance-team access she does not have herself. Confuse the two, and you get privilege escalation on one side and unaccountable autonomy on the other.
This session separates the two relationships cleanly and derives the rule that reconciles them. When an agent acts on someone's behalf, its effective authority is bounded by the intersection of its own entitlements and that user's, never the union. From there the talk asks a sharper question: what would it mean to govern an agent by what it is for, rather than by whose identity it wears? That same confusion extends to the tools: most platforms still bind agents to a human identity rather than to a task, and we will look honestly at what their "purpose" and "intent" features actually deliver.
Every agent log answers what happened and none answer who allowed it. This talk closes that gap with live forensics on a staged incident.
Sooner or later an AI agent at your company will do something consequential: spend, sign, delete, or disclose. The first question from your auditor, regulator, or counsel will not be about the model. It will be about the mandate: who authorized this action, exactly what did they authorize, and can you prove it? For most NHI estates the honest answer today is a shrug. The action traces back to a service account holding a bearer token that fifty workloads share, and the authorizing human exists only in a Slack thread, if at all.
This session shows what a defensible answer looks like. Your identity fabric already does the first half well: Okta can prove, authoritatively, which human authenticated and when. KYA-OS extends that evidence chain past the login to every agent acting in that human's name: every agent bound to a verified principal, every mandate a signed, scoped, revocable credential, every action leaving a verifiable receipt. We will run live forensics on a staged incident, starting from one suspicious agent action and walking the cryptographic chain back to the human who authorized it, the exact scope they granted, and the moment that authority was revoked. The demo uses KYA-OS, the open agent-identity stack built on Decentralized Identity Foundation standards and implemented by Vouched.
Built for CISOs, IAM leaders, and GRC teams who would rather build the audit trail now than reconstruct it under subpoena.
Treating an AI agent like a workload identity misses what makes it dangerous: it behaves less like a system calling an API and more like a privileged human who never sleeps, never asks twice, and can act on someone else's authority. This panel challenges the instinct to bolt agent governance onto machine-identity tooling built for a different problem.