Thank you, Kay. Thank you very much. And I'm really happy and proud to be here also as the Women in Identity Ambassador for DACH. And I can only say, join us at the networking event. I think it's in B04. But today I would like to talk about Agent-Aware Identity and Access Management. What does it mean?
This is, I'm presenting a joint work, which I had done together with my former colleague, Hari Haya-Krivan. And he is unfortunately not able to be here. And we had done some work over the last couple of months. And the presentation is grounded on two papers we have published, one in February and one just last week. And I would like to introduce what it means from our perspective to have Agent-Aware Identity and Access Management.
Some introduction, but I think, as you had been heard in the last two days, a lot about AI, agentic AI and identity and access management, that the world has changed, but IAM has not over the last years. So I won't get into that, into detail.
As I said, the last two days were really, really looking really deep into this topic, especially who had been attending the discussion on Tuesday with Martin Kuppinger, Matthias Weinbart and his colleagues, where they presented the most, for them, the most pressing things which had to be solved over the next years. But no one has answers yet for these questions.
This is, so I think this was one of the really best introductions into that topic. And they had also talked about these things that in the end, IAM had not been designed for that. It had been designed for humans. It had been designed for relatively static non-human identities. And this is something which really doesn't fit for managing autonomous agents, which we call autonomous non-human identities. So it's just an abbreviation. For those who doesn't know it, but I'm a mathematician by education and mathematicians are lazy. And they like abbreviations.
They like shortening notations through just a little bit. It looks like a formula, but in fact it isn't. So with that said, I would like briefly go into what makes ANHIs different. We have heard that also in the last days, so just briefly. But this difference, this brings us to the point that there are a lot of IAM assumptions are broken with this specific class of identities. They are autonomous. So a human is not always in the loop.
The scale, that also it is born dynamically in large numbers and with unpredictable lifespans to some time. And so it is not like what we know for 25 years, something like that. That it is provisioned deliberately, human initiated.
No, this is often not the case. And it has a dynamic context. This means very different actions in different situations. So behavior is not really predictable. And this is what we were doing with like role-based. We have yesterday heard about policy-based rules.
Okay, that's also fine. But this shows that there are some things which we cannot deal with our current and by our current approaches. And any framework we have that does not address all these three topics will have an issue and will leave gaps. So in our first paper, we had been talking about the agent-aware IAM framework. We had differentiated between four identity models for these autonomous agents. This with two main components. The first is the identity model. The other component is the governance and IAM capabilities which we see need to be put into practice at some point.
So we differentiate between persistent, long-lived, and stable agent identities, which might be the case, similar to like non-static, non-human identities, but with a behavior which is more human-like, I would say. Then short-lived ones.
Of course, you have them popping up, popping down, hierarchical, orchestrator, really chains, multi-agents, sub-agent chains, and forked. So one agent spawning for different tasks than other agents, sub-agents. And we have heard from a governance perspective, also in last days, it was always the ownership is a point. You need to look into that one, the provenance, and you need to have a lifecycle management. A little bit similar to like joiner, mover, leaver, we all know for, and now for agents. And also authentication, adaptive contexts aware, the cross-agent trust mechanisms which you need.
Also a lot of discussions in the last days on that one, and authorization. So the classical ones also don't work. This gives us, or had given us, the structural foundation on how to address this challenge, I would say. But when Harry and I, when we dug deeper, we found that this was not sufficient, of course. And this leads us to the next slide. And by the way, on the last slide, I give you the links and also to the paper. So you can then see this in more detail. So we have said, OK, we have governance with ownership and everything around it.
But it doesn't usually not tell you why an agent is doing something. So at a given moment, and what is it trying to achieve? And what we had found in the current industries literature in our research, but also in the research literature, is that purpose and intent are often used simultaneously. And this is not just a little bit floppiness in terminology. It leads to governance gaps, if you use that interchangeable. And this is something we thought it is worth really to clarify. So what we define now is purpose is the thing at provisioning time. It is stable. It is lifecycle management.
And why was this agent provisioned? It is a little bit to a job description for an agent.
You can, in your world. And the intent is now, no, sorry. This must be runtime.
Sorry, there is a mistake in the presentation. It must be runtime.
Runtime, dynamic session scope, and what is the agent want to achieve, is trying to achieve right now. And why do we say is it very important that you differentiate between these two dimensions of purpose intent? Because if you don't do that, you will run into something in a failure mode, which is called semantic privilege escalation. This means an agent has the right permissions, correct permissions to do something, but with an intent which was never authorized for that. In our paper, we also bring some examples.
Yesterday, I don't know who had been in the NHI discussion. We had an example of an HR person who has authorized an agent to do some analyzing some applicants for a role or for a new job. And then the other one, the access rights would be OK. But the purpose is that one. But the intent, the agent might go into it and do some sort of salary analyzation. And this was not in the purpose. The intent is now then different from the original purpose, although the access rights were given to the agent. And this is something what you need to recognize.
And the further concept, we have developed several concepts. And one of them, which I want to mention here, is also the so-called purpose path. And this means the audit trail for changes in purpose, audit trail for changes in purpose. And this is very important, for example, to show compliance to several articles in the EU AI Act. This is something, and it is a governed thing, like role changes in the classical IAM. And this is what we have developed also. And then we had also worked on a two-layer governance architecture. Where we say, OK, this layer, and it is a very, how should I say it?
It is not a detailed picture here, but this layer shows, OK, if I differentiate or if I can differentiate between purpose and intent and I do that, then I have two layers. One, at provisioning time, this is stable. This is relatively audible, audible, auditable, which you also can change purpose, but it has a trail in it. And the permission compatibility tells you, is the purpose in line with the labels of the data which will be accessed? This is something what we had 20 years ago when the discussions were coming up around GDPRR.
There, you had to define purpose, but purpose was then a label for the data. And this is really, I would say, borrowing from that one. So you can initially look into that with the purpose. It's a purpose so that it is allowed to access a specific data, which is a label. Talk about the HR pieces. You have PII into that one, and then you have that. So this is the very first check at provisioning time. And if the purpose is not compatible with the data labels, then you cannot continue with it.
OK, let's say the purpose is compatible with the data labels, then what I said before, we had the intent then at the runtime. And what you need to measure is the intent at the runtime. This is not easy, and this is something what we had also looked into. And you will find a separate section on that one in the paper. But you need to measure the intent. And what you need to guarantee is the intent in the boundaries of the purpose.
Otherwise, you would have a purpose and intent drift. And so you can also recognize a drift in intent. And this we call the containment constraint. And then you can recognize whether the intent is out of scope of the purpose or not. And this would be the next point where you say stop, not further. And this is, I think, or we think this is an approach which brings it from the static to the runtime and provides you really with a comprehensive, I would say, view of that one.
But, and here's my but, at the moment, it is a model. We have a lot of open questions put together based on this clarification also in our paper. But I think, or we think, that this is at least some sort of clarification which is necessary to deal with these problems. And so what needs to happen?
Of course, the classical one. So what we say, what you can do now, establish the autonomous NHIs really as a governed identity class as first ownership and provenance. We have heard that. And see it as an instrument really for, you need instruments for purpose and intent as different governance dimensions. And engage cross-functionality. And this is non-technical, but really, really important. Work across, especially with the AI teams, with the IM teams, with the security teams. And it is not easy. I have done these discussions with AI teams to discuss that with them.
They have a totally different view on how to secure agents. But anyway, and you know that there are some regular agency, urgency around that. So the clock is running to August, something like that. With that said, I would like to close my presentation. And I'm open for questions. But I will also be around the conference at least until this evening. And whenever you have any questions, you can come to me. Thank you very much. Questions in the chair? So I have one, or actually I have two. But it feels like the cross-functionality is going to be the big problem.
I mean, in theory, the identity management function should have been, and probably has been trying to be cross-functional for 20 years. Sometimes winning, sometimes not. You mentioned that you talked with your AI colleagues. What was their objection to essentially the model that you just laid out? Let's say talking about purpose, they said purpose is static. And I said, no, purpose is not static. Because even with the prompt, you might change the purpose. Even if it is not a bad actor, but you might change the purpose.
And then the answer was, yeah, then we decommissioned the agent and set up a new one. This is unrealistic. Cool stuff. And this discussion I had with them, to convince them that purpose needs to be governed.
Of course, we don't have anything yet how to do that. But really to understand that it needs to be governed. This was a lot of, I don't know if I have even convinced that guy. But anyway. How is their, are they OK with the idea that the governance comes from an external function? Like even having a security and identity team? At that client, yes. Because this is a large program at that client.
So yeah, they come to that. But the discussion had shown that there are totally different worlds. And we need to come together. It's not unusual that the development world and the security world are totally different worlds. And a final question from me before we go on to the next one is, it feels like purpose is trying to set the guardrails for using So if you can sufficiently define purpose, sufficient to find if the intent exits the guardrail, you can do it. Yes. Can you sufficiently define purpose such that any intent leaving the guardrail? Yes and no. This is one of the open questions.
There are also measuring intent. At the moment, three approaches on the market, I would say, and also tools. But each of them, one is, for example, analyzing the prompt. But natural language can be vague. So this is one thing. The other one is to really look into an agent and what the agent is doing. So which API it is using or something like that. But this is retrospective. So something has happened. This is also not what we would like to have on that one. And the third one is to have a cryptographical signature on an agent. So then you can say it doesn't have changed over this lifetime.
But what you haven't is the intent in the boundaries of the purpose, because you do not have a governance construct for that. Excellent.
Well, thank you very much. On to the next session. Thank you.