World Congress 2026 North America

When Agents Became Users: Rearchitecting Identity and Permissions for AI at Scale

September 24, 2026 14:50 – 15:20 · 30 min Stage 7

World Congress 2026 North America

September 23–25, 2026 · San José, CA

Attend in person

Get tickets

Watch remotely

Watch live with Pro

Pro

Can’t make it to San José? Watch this session live with Pro. You also get:

  • All full videos, bookmarks, and playlists
  • World Congress livestreams
See pricing

What this session covers

Most platforms add AI agents as apps: the agent runs with the permissions of whoever invokes it. Simplest thing to ship. Across hundreds of thousands of teams, serving enterprises that audit every access, that model fell apart. This is how we rebuilt agents as first-class users, with their own identity, permissions, and audit trail. The first architecture was the obvious one: an agent could do only what both it and the invoking user were allowed to do. Simple to build, it broke at scale. The agent’s access changed with every invoker, so no one could say what it could actually reach. Actions were attributed to the human, leaving no per-agent audit. And a shared agent became a leak risk, exposing its invoker’s data to everyone allowed to run it. Fixing this meant making a non-human a first-class user inside a system built for humans: its own identity, scoped least-privilege permissions, admin-managed provisioning, and a place in the workspace where it can be assigned work and audited. The payoff was counterintuitive. Once an agent is a user, 20 years of enterprise identity infrastructure (SSO, RBAC, provisioning, audit logs) works for it for free, instead of a separate control plane for AI. One enterprise built 25 agents, each needing different access. Before, any agent could read what its invoker could read and pass it to the whole team. Now each is shared across the team and never touches data it was not explicitly granted. The permission models, the tradeoffs we got wrong first, and what it takes at scale. From the applied AI perspective, why agent identity is the central design problem for AI at work. Expect real systems and real failure modes.

Related talks at this congress

Open session

World Congress 2026 North America

September 24, 2026 · 17:30–18:00

Stage 5

Securing AI Agent Infrastructure: Identity, Attestation, and Trust at Scale

Abdel Fane

Founder of OpenA2A

Abdel Fane
Open session

World Congress 2026 North America

September 24, 2026 · 11:40–12:10

Mainstage

I Don't Trust AI Agents (And Neither Should You): Building Production-Ready Architectures

Darko Mesaros

Distinguished Developer Advocate at AWS

Darko Mesaros
Open session

World Congress 2026 North America

September 24, 2026 · 09:45–10:15

Mainstage

Manufacturing trust: speed and safety in the age of agents

Mark Cavage

Mark Cavage President and COO of Docker

Mark Cavage
Open session

World Congress 2026 North America

September 25, 2026 · 09:00–09:30

Stage 7

AI Agents are Only as Smart as their Context: Building a Real-Time Context Engine at Intuit

Bharat Patel

Lead Software Engineer at Intuit

Bharat Patel
All sessions at this congress