> Markdown version of [/events/world-congress-2026-north-america/sessions/1713-when-agents-became](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1713-when-agents-became). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # When Agents Became Users: Rearchitecting Identity and Permissions for AI at Scale - **Event:** World Congress 2026 North America ## Description Most platforms add AI agents as apps: the agent runs with the permissions of whoever invokes it. Simplest thing to ship. At 250,000 teams, serving enterprises that audit every access, that model fell apart. This is how monday's R&D org rebuilt agents as first-class users, with their own identity, permissions, and audit trail. The first architecture was the obvious one: an agent could do only what both it and the invoking user were allowed to do. Simple to build, it broke at scale. The agent's access changed with every invoker, so no one could say what it could actually reach. Actions were attributed to the human, leaving no per-agent audit. And a shared agent became a leak risk, exposing its invoker's data to everyone allowed to run it. Fixing this meant making a non-human a first-class user inside a system built for humans: its own identity, scoped least-privilege permissions, admin-managed provisioning, and a place in the workspace where it can be assigned work and audited. The payoff was counterintuitive. Once an agent is a user, 20 years of enterprise identity infrastructure (SSO, RBAC, provisioning, audit logs) works for it for free, instead of a separate control plane for AI. One enterprise built 25 agents, each needing different access. Before, any agent could read what its invoker could read and pass it to the whole team. Now each is shared across the team and never touches data it was not explicitly granted. The permission models, the tradeoffs we got wrong first, and what it takes at scale. From the applied AI perspective, Why agent identity is the central design problem for AI at work. Expect real systems and real failure modes. ## Speakers ### [Yoav Gal](https://www.wearedevelopers.com/@yoav-gal) Product Lead at monday.com ### [Dor Cohen](https://www.wearedevelopers.com/@dor-cohen-2) Director of Engineering @ monday.com ## Related talks at this congress - [Securing AI Agent Infrastructure: Identity, Attestation, and Trust at Scale](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1432-securing-ai-agent) — Abdel Fane - [AI Agents are Only as Smart as their Context: Building a Real-Time Context Engine at Intuit](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1736-ai-agents-are-only) — Bharat Patel - [Closing the Visibility Gap: Lessons from Safety Critical Agentic Systems](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1408-closing-the) — Vivek Pandit - [Give the Agent a Budget, Not a Token](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1695-give-the-agent-a) — Sachin Malhotra ## Watch remotely Can’t make it to San José? Watch this session live with Pro. You also get: - All full videos, bookmarks, and playlists - World Congress livestreams [See pricing](https://www.wearedevelopers.com/pricing) ## Links - [Get tickets](https://www.wearedevelopers.com/world-congress-north-america/tickets)