Session
Who Is the Agent Allowed to Be? Identity, ABAC, and Least-Privilege AI
An enterprise AI agent should never become more powerful than the person or process it represents, yet many agent implementations authenticate once and then give the agent broad access to data and tools. That creates a new class of security and governance risk: the model may be well behaved while the surrounding architecture is overprivileged. This session shows how to design least-privilege agentic systems in which identity, attributes, data entitlements, and tool permissions remain enforceable throughout the workflow. I will walk through patterns for delegated identity, attribute-based access control, row- and column-level data protection, tool authorization, policy checks before actions, approval boundaries, and auditable execution. We will also examine common failure modes such as service-account overreach, permission loss during retrieval, and agents acting outside the user’s business context. Attendees will leave with a practical authorization model, control-point checklist, and reference flow for building enterprise agents that can access sensitive data and take useful actions without bypassing the controls already protecting the business.
Interests
AI Governance, Regulation, & Compliance
AI Infrastructure
AI Application Development
Data Architecture
Job Functions
Architecture/Design
AI Engineer
Security
IT Technology Leader
Mou Rakshit
Avanade, Intelligent Data Platform Data Engineering Thought leadership
Northville, Michigan, United States
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top