Every agent log answers what happened and none answer who allowed it. This talk closes that gap with live forensics on a staged incident.
Sooner or later an AI agent at your company will do something consequential: spend, sign, delete, or disclose. The first question from your auditor, regulator, or counsel will not be about the model. It will be about the mandate: who authorized this action, exactly what did they authorize, and can you prove it? For most NHI estates the honest answer today is a shrug. The action traces back to a service account holding a bearer token that fifty workloads share, and the authorizing human exists only in a Slack thread, if at all.
This session shows what a defensible answer looks like. Your identity fabric already does the first half well: Okta can prove, authoritatively, which human authenticated and when. KYA-OS extends that evidence chain past the login to every agent acting in that human's name: every agent bound to a verified principal, every mandate a signed, scoped, revocable credential, every action leaving a verifiable receipt. We will run live forensics on a staged incident, starting from one suspicious agent action and walking the cryptographic chain back to the human who authorized it, the exact scope they granted, and the moment that authority was revoked. The demo uses KYA-OS, the open agent-identity stack built on Decentralized Identity Foundation standards and implemented by Vouched.
Built for CISOs, IAM leaders, and GRC teams who would rather build the audit trail now than reconstruct it under subpoena.