All right. I think more of AI agents and security and what goes on in that space. I'm going to touch upon some of the nuances and the governance issues that we see with AI agents coming into play in an environment and then talk about a solution architecture in terms of how to think about it and then what one can consider in terms of a roadmap and what to look at in that.
So I'm sure everybody here has seen some variation of this representation infographic which talks about the dramatic rise in what we are seeing in the industry in terms of the proliferation of these non-human entities and what happens with those identities within the environment and we expect this explosion to happen and not something that is going to prevent people from taking this innovative model to run their business operations and organizational activities. So what does it mean in terms of reality today, right?
Many organizations probably have a version of software that is already using AI agents and they probably don't know. It might not have been advertised, represented in the system or they might know and they might not have done anything with respect to that. So this rapid adoption of these capabilities across pretty much everything that touches the business operations from engineering, finance, HR operations and every function of an organization, right?
These agents not just do some minimalistic pieces as what they were set out to do over a period of time, they started to do more complex activities. Some of them are pretty much in the realm of non-deterministic flows, that's where the complexity increases and it essentially brings in this problem where there is no mechanism to detect what is happening in terms of the activities that are being performed and kind of gives room for these gaps in terms of the governance itself that one needs to look at.
So what we are seeing in the industry today is most of the governance models that people have is centered around not just humans but we are also talking about primarily access governance. What we are looking at here is more of execution governance, that's the fundamental shift in terms of the focus, right? Looking at what does it mean to control and have the necessary guardrails and pieces in place for your execution governance and how do you bring in a maturity roadmap into that piece. So what truly are the things that we see in terms of governance gap, let's take a look at that.
The traditional systems are largely focusing on humans and focused on who can do what and what are some of the rules that they're given, focused primarily on that. On the other hand, the PAM solutions kind of came subsequently, they talked about certain capabilities given to service accounts and things around that and tracking some of the activities performed by those systems and fundamentally what has happened is neither of those systems are readily something that you can map it to what we have in terms of the agent situation.
So if you just look at a very high level, what does it mean to map these into where things stand? Fundamentally, you are looking at pieces around inventory and discovery and you'll find that it's fairly matured on the human side but fairly fragmented on the agent side because they're all over the place, there is no representation and human identities have fairly good representation in terms of the accountability and ownership.
Same holds true in terms of lifecycle governance, there are a good amount of standardized models to support that and then things surrounding access reviews and policy informant, you know, give or take and auditable give or take, we have good coverage in terms of how that, you know, governance, you know, looks like and significant gap that you see of varying degree when it comes to agents, right.
So if you look at what is it that the areas you really feel that, you know, should be covered, you know, and it is not covered is, you know, there is no inventory, nobody knows where, you know, the agents are, there is no single repository, it's not like you have a pre-established directory or, you know, a registry that everybody is talking about this availability or it's something that, you know, we'll have to go and there is no platform or engagement that talks about where is the delegation that's happening because you go from a human delegating some work to an agent and agent subsequently potentially delegating that work to another agent, you know, is something that chain needs to be monitored and, you know, tracked as well and there are no runtime controls because once you see series of activities, you know, the traditional model of fixed set of logical steps, you know, talking about workflow, they're all fixed set of sequenced activities deterministic and you kind of knew what was happening in this model, you know, you really need to see with every step which path it will take subsequently, so you need to establish a fair amount of runtime controls, you know, as you do this and then you start with what triggered this agent and how the activities are happening, the intent must be well understood and the intent should be well understood to a point where you shouldn't have a drift in terms of what you started with and where you end up with and what tools you execute and where you go there.
And last but not least, who is the owner? How did this agent get triggered? And it's important to take a look at it. So fundamentally, you're looking at five elements from which there are gaps, you know, in terms of the governance itself. So now let's shift to see what it means to have some core elements that one should look at when it comes to governance, right? First and foremost is visibility. And you really need to know what is it that's running in your environment, right?
Because you're not just talking about application, you're talking about your employees using third party services, you are looking at things that are shadow activities that are happening, you know, through your, you know, scheduled business processes and all that. So we really need to know what are the processes that are supported and aided by this, you know, build some sort of visibility into that, right?
And then really establishing that, you know, the trace of activities, and we'll see an example of what the trace looks like, you know, the gentleman before this call, this presentation also gives a couple of examples, you know, similar to that, essentially, you need to see where we ended up with and why we ended up, you know, there, it's important. And then the controls are some things that happen during the process, it's not something that you can do after the fact. So fair amount of risk assessment, and dynamic risk scoring needs to happen as you go through this process.
It's not something that you compute risk after the execution gets completed, it might be too late by the time you do that. So you really need to have policies that help you ensure that the guardrails are there. And as you are working through your policies, make sure that the risk is well understood and managed. Right. So bottom line is, is that the tracing, risk profiling, and ownership, visibility, and then we're talking about auditability, extremely important, because if somebody asks, why did this account get created? Or why did this transaction get processed?
Or why was this account debited? Whatever the system in which this operation is happening, you really need to know what, how we got there. So which brings the question with AI, fundamentally, one of the things you're looking at is explainability, you absolutely need to cover explainability in this process, as you go from, you know, your starting point to where you ended up, you know, in the system. So let's dig a little bit deeper into the visibility aspect itself, right.
And then, there is always a struggle with regards to how much visibility do you want to, you know, spend your time on? And how do you want to do this? So you don't want to make this complicated in terms of architecture.
And, but at the same time, you have these signals that are coming in, make sure you understand those signals, to the extent that is relevant for the transaction and the process you're looking at. And then fair amount of telemetry on a continuous basis should be looked at to see what are the trends that are happening?
And what, what is it that, you know, the data is telling you, because those internally will tell you if, you know, there are any patterns for good behaviour or behaviour that needs somebody's attention, right. And make sure this can scale, you know, sometimes this can be so burdening that people might end up, you know, overengineering the visibility and lose the benefit, because then it becomes complex.
Suddenly, everything will end up becoming, you know, human in the loop kind of activity.
The second important thing to understand is, even though we have evolved in terms of architecture itself, where we started with humans, non human identities, now we have agents, I think it's important to go back and find a model where you can represent these pieces with one representation, even though there are some semantic differences between these elements, it's important to collate and build them into one place so that for operational efficiencies and for operational explainability, having a uniform representation of identity becomes important.
So therefore, do not look at something that can be that ends up becoming just a bolt on to an existing architecture, because the bolt on will mean that there is a completely different path of identity, you know, this one set of processes and, you know, capabilities for human and other for non human and then agent, you know, that will complicate your organisational, you know, objectives and goals you want to achieve. And then very important to see where this is going to take us right in terms of the sequencing itself.
The human starts with something and then it results in a bunch of actions, you know, a simple action could be just a simple update somewhere or, you know, pushing some content into some folder or something of that nature or generating a report for that matter, or even approving some request. But as things get more complex, you know, you really need to understand was this agent which was authorised by a human, is that authorised to perform invocation of the next agent? And if yes, what policy provided that capability, right?
You know, it has to be driven by policy and it has to be driven by what is the current state, what is the policy that facilitates that and also the risk that would come into play if that execution occurred. So keeping that, you know, in line and tracking that becomes important. So the execution governance is more of a sequential activity. So fundamentally, it's kind of different from access governance, which is kind of looking at can this person get an account or a role and, you know, you left answering the question yes or no with, you know, minimal explanation.
But here, the series of activities, you know, complicates the matters and that's why the chain of delegation and tracking that, you know, is important. So here is an example that, you know, you can think of. So it's important to, you know, bring back the fact that, you know, I talked about a graph because graph truly represents the nature of the activities here, right?
You know, this is truly relationships that you go into and you want to track that. And you can, as you can see in the illustration, it takes you from the human all the way to whatever got executed and whatever, you know, the end activity was. Sometimes we might start with something and then we would end up with something, you know, different, but you want to be able to answer these questions.
So, and you really want an ability to ask these questions in interactive way as well. So the explainability is one thing, but some of the questions that you might want to ask in the execution must also be aided through AI to understand, you know, how they say, because some of those questions, you really can't build a user interface or, you know, make those things, you know, functional, right? So what is the approach you want to take?
Once you build in these architectural pieces that I talked about, you know, delegation chaining, identity graph and, you know, explainability and visibility in place.
So the first and foremost is, you know, make sure you have a mechanism to discover what's out there and understand, you know, what the patterns are and, you know, where things, and make sure you have a mechanism to register these, right, with some ownership and ensuring that there is enough information that talks about the agents themselves as well, and have a mechanism where there is an ability to intercept what's happening between the agent and the system or the agent and another agent or the user and the agent.
So there are different layers of interaction, and you make sure that you have ability to intercept those invocations, very important that you don't miss that. And then evaluate at every step, you evaluate the policy, compute the risk score and understand if you need to do something. So if you find a policy, it meets the criteria, you might want to enforce that. And then at the end of the day, you absolutely need the ability to audit, you know, what's happened in that exercise. Right. So I won't go into all of the details into the platform that we have to support that.
So essentially, this kind of encompasses the objective of what needs to be there in terms of agent governance in a solution for your environment. Some of these are there in the human side of things, but this has more exhaustive elements in terms of what needs to be done.
We'll see, you know, what actually you will do when you start thinking about executing this, you know, in a phased manner. So there are a few scenarios here, I wouldn't necessarily go through. But suffice to say, you know, simple use cases of, you know, things that are operationally that somebody will, you know, put together. But the what this means is the class of agents themselves that, you know, and you get handled. Right. So sometimes you might have an agent for which there is no owner. Sometime you might see an agent that is doing more than what it should. Right.
And then some cases you'll find that certain things are bypassed. So you need to be aware of the different class of agents and how they would operate. So in terms of the adoption journey itself, you can project your organizational needs as a longer term, what you want to see, you know, first and make sure you want to understand what's in your environment. You really need to know what systems are doing, what appraisal happening and where the elements are coming into place, whether it's the applications or the user base, and then understand the risk. Right.
What are the systems that they are doing, what operationally what they do and what's the impact of the business. So have a good handle on that and then make sure that you qualify the high risk cases and pay higher attention to those and then put a story around the agents and the fact that agents evolve over a period of time. And it's important for you to, you know, look at a scale of this. So build something in a way that it helps you scale. So I know this is looking like a lot of things for people to do.
You don't have to jump in and take this, you know, approach necessarily, but you can start something smaller. So I thought it'd be good to put in a slide that will help you take, you know, baby steps in the process. Essentially, it talks about just do the discovery sprint, right? The first sprint is just get that in place. Identify your high risk systems and, you know, have policies in place and how you want to do this and make sure there is ownership. Every agent, every system has a business owner and a technical owner, you know, to manage, you know, these things.
So lastly, to, you know, summarize, we understand the problem. Enterprises are scaling at a fast pace. Agents are, you know, taking over a lot of the human activities, more so in certain domains than others. And it comes with its own security and, you know, governance issues that we deal with. But make sure you understand this is an execution time problem and governance requires a different, you know, reference and visibility to how you do this and not look at this problem post-facto, right? Look at it as we things grow. And this industry has evolved.
We bring in technology, but I think once some of the operational maturities happen with these AI agents, we'll see better governance and, you know, security with respect to that. That's it from my side. Is there any questions?
No, we're going to stop. Thank you very much, Sanjay. That was really thoughtful and thought-provoking.
So please, a round of applause for our speaker.