Session

When Agents Get the Keys: Securing AI Assistants That Read Email and Take Action

Discover how to secure the next generation of AI agents: assistants that can read email, understand intent, call tools, update systems, and trigger workflows.

Copilot Studio and other low-code agent platforms make it possible for business users to create powerful automations without deep technical knowledge. That creates huge productivity potential, but it also changes the security model. An agent that can access a mailbox and take action in another system is no longer just answering questions. It is operating with real permissions, real data, and real consequences.

In this session, we will explore the practical risks of user-created agents, including over-permissioned access, prompt injection, data leakage, unsafe connectors, unintended actions, unclear ownership, and missing audit trails. Using realistic examples, we will look at how an innocent-looking email assistant can become a security and compliance problem if it is not designed with the right guardrails.

You will learn practical ways to reduce risk without blocking innovation: identity and permission design, connector governance, Data Loss Prevention policies, human approval for sensitive actions, environment strategy, monitoring, auditing, and lifecycle management. Microsoft Copilot Studio and Microsoft 365 will be used as concrete examples, but the principles apply to any platform where end users can build agents that access data and use tools.

The session will include a hands-on threat-modelling walkthrough of an agent that reads email and takes action. Together, we will identify what can go wrong and map those risks to controls that IT, security, and platform teams can actually implement.

The goal is to help organisations say yes to useful agents safely: with clear ownership, least privilege, visible actions, approval points, and enough monitoring to know what agents are doing after they are published.


After this session, participants will be able to:
1 Understand how action-taking agents change the security model compared to traditional chatbots and workflow automations.
2 Identify the main risks of agents that can read email, use connectors, access enterprise data, and perform actions on behalf of users.
3 Apply practical guardrails for agent safety, including least privilege, identity design, connector governance, environment strategy, Data Loss Prevention policies, and action approval.

Level 200-300
45 mins + questions

Mika Vilpo

IT geek building clouds, MVP

Turku, Finland

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top