World Congress 2026 North America
September 25, 2026 · 11:40–12:10
Stage 6
Codifying Trade-offs: Security, Cost, and Compliance as Agent Guardrails
Suzanne Daniels
Chief Developer Advisor at Microsoft
World Congress 2026 North America
Every agent demo runs with a god-token. Then it ships, and someone has to explain why the helpful AI just rm -rf’d the staging database “to clean up.”
I run platform infrastructure at a frontier lab, and for the last year my job has partly been: let coding agents do real work against real systems, without ever having to write the postmortem. This talk is the permission model that fell out of that - not RBAC-with-extra-steps, but primitives designed for an actor that’s smart, fast, tireless, and occasionally confidently wrong.
The four primitives:
quarantine but not delete, retry but not approve, propose but not merge. The verb list is the security boundary. Stop thinking in resources, start thinking in reversible vs. irreversible actions.I’ll show the ~200-line policy layer that implements all four, the failure modes each one exists to catch, and the one design I shipped that turned out to be security theater. Tool-agnostic - works whether your agent is touching CI, a database, a cloud account, or your users’ files.
If you’re shipping an agent that does anything more than read, you’ll leave with a threat model and a starting policy you can paste into your repo on the flight home.
World Congress 2026 North America
September 25, 2026 · 11:40–12:10
Stage 6
Suzanne Daniels
Chief Developer Advisor at Microsoft
World Congress 2026 North America
September 25, 2026 · 16:50–17:20
Stage 3
Tejas Pravinbhai Patel
IEEE Award-Winning Researcher | Best Keynote Speaker | Sr. Software Engineer at Amazon | AI Systems & Agent Architect
World Congress 2026 North America
September 24, 2026 · 11:40–12:10
Mainstage
Darko Mesaros
Distinguished Developer Advocate at AWS
World Congress 2026 North America
September 24, 2026 · 09:45–10:15
Mainstage
Mark Cavage, Michael Irwin, Hervé Bizira