Session
Who Is Your Agent, Really? Fixing the Identity Anti-Patterns That Break Production Agentic AI
Most teams building agentic AI get identity dangerously wrong: one static service role, long-lived credentials shared across every agent, and an agent running as an all-powerful super-user — until it touches data it shouldn't, or a security review stops the project cold. In production, identity is where agentic AI quietly breaks.
This session dissects the most common identity anti-patterns in real agentic systems — the shared "god-mode" role, over-scoped credentials, no separation between agent and user identity, missing delegation boundaries, and audit trails that can't say which agent did what, on whose behalf. Then we show how modern agent identity platforms fix them: distinct workload identities, a secure credential vault enforcing least privilege, and identity-aware authorization that lets an agent act on behalf of an authenticated user with full context and auditability.
You'll leave with a clear model for agent identity and a checklist of anti-patterns to eliminate before they become incidents.
Level: Intermediate. Audience: Engineers, architects, and security/platform teams building or operating agentic AI. Prerequisites: Familiarity with AI agents and basic OAuth 2.0 / OIDC. Format: Technical session with architecture walkthroughs and demos. Views are the speaker's own; practices and standards are evolving.
Juan Pablo Garcia Gonzalez
Solution Architect @ AWS Startups
Boston, Massachusetts, United States
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top