Session

Controls All the Way Down: The Anatomy of Loops

The model wars are becoming less interesting than the loops we build around them. Most teams are no longer asking whether a model can write code, call tools, or inspect a repo. They are asking a more uncomfortable question: what exactly is allowed to happen while the agent is doing that?

Today, many organizations treat AI control as a checkpoint at the end of the workflow: review the pull request, approve the deployment, inspect the output. That misses the real risk. An agent can leak secrets, mutate state, burn tokens, call the wrong API, or destroy a workspace long before a human sees the final result.

This talk breaks down agentic systems as nested control loops: model, tool, environment, workflow, and organization. For each loop, we’ll map the risks, the controls that actually work there, and the controls that only create a comforting illusion. Environment isolation, tool permissions, audit trails, cost policies, human approval, and sandboxing all matter, but they matter at different layers.

The goal is to give engineering leaders and platform teams a shared language for agent governance. Instead of asking “is this agent safe?”, we’ll ask better questions: which loop owns this risk, where is the enforcement point, what happens when the agent ignores the happy path, and how quickly can we recover?

Attendees will leave with a practical taxonomy for evaluating their own agent systems and a map of where their current controls sit versus where the actual risk lives.

Oleg Šelajev

AI and Developer relations at Docker.

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top