Session
Six Questions Before You Ship an Agent
Every agent has an authority boundary, whether the team designs it deliberately or discovers it during an incident. A support agent that can reset a password becomes a different risk when it can also change the account email. Useful permissions accumulate one at a time, and recovery can disappear before anyone asks how much autonomy the system should have.
This session turns the Cloud Security Alliance's autonomy levels into six questions a team can ask before an agent ships. We work those questions against the real account-takeover case, deciding which actions need approval, which boundaries belong in code, what must be reversible, and how the system should fail when no reviewer responds. Then we apply the same reasoning to prompt injection and untrusted content, where a carefully limited authority boundary can contain the damage even when a bad instruction gets through. If you build or approve agentic systems, you'll leave with one assessment you can take into a design review and clearer language for saying how far an agent may act on its own.
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top