World Congress 2026 North America

When Agents Became Users: Rearchitecting Identity and Permissions for AI at Scale

September 23–25, 2026

World Congress 2026 North America

September 23–25, 2026 · San José, CA

Attend in person

Get tickets

Watch remotely

Watch live with Pro

Pro

Can’t make it to San José? Watch this session live with Pro. You also get:

  • All full videos, bookmarks, and playlists
  • World Congress livestreams
See pricing

What this session covers

Most platforms add AI agents as apps: the agent runs with the permissions of whoever invokes it. Simplest thing to ship. At 250,000 teams, serving enterprises that audit every access, that model fell apart. This is how monday’s R&D org rebuilt agents as first-class users, with their own identity, permissions, and audit trail. The first architecture was the obvious one: an agent could do only what both it and the invoking user were allowed to do. Simple to build, it broke at scale. The agent’s access changed with every invoker, so no one could say what it could actually reach. Actions were attributed to the human, leaving no per-agent audit. And a shared agent became a leak risk, exposing its invoker’s data to everyone allowed to run it. Fixing this meant making a non-human a first-class user inside a system built for humans: its own identity, scoped least-privilege permissions, admin-managed provisioning, and a place in the workspace where it can be assigned work and audited. The payoff was counterintuitive. Once an agent is a user, 20 years of enterprise identity infrastructure (SSO, RBAC, provisioning, audit logs) works for it for free, instead of a separate control plane for AI. One enterprise built 25 agents, each needing different access. Before, any agent could read what its invoker could read and pass it to the whole team. Now each is shared across the team and never touches data it was not explicitly granted. The permission models, the tradeoffs we got wrong first, and what it takes at scale. From the applied AI perspective, Why agent identity is the central design problem for AI at work. Expect real systems and real failure modes.

Related talks at this congress

Open session

World Congress 2026 North America

Securing AI Agent Infrastructure: Identity, Attestation, and Trust at Scale

Abdel Fane

Founder of OpenA2A

Abdel Fane
Open session

World Congress 2026 North America

AI Agents are Only as Smart as their Context: Building a Real-Time Context Engine at Intuit

Bharat Patel

Lead Software Engineer at Intuit

Bharat Patel
Open session

World Congress 2026 North America

Closing the Visibility Gap: Lessons from Safety Critical Agentic Systems

Vivek Pandit

Principal Engineer at Cadence

Vivek Pandit
Open session

World Congress 2026 North America

Give the Agent a Budget, Not a Token

Sachin Malhotra

MTS @Anthropic

Sachin Malhotra
All sessions at this congress