Coffee With Developers • Apr 27, 2026

Building Agents Securely at Scale - Alfonso Graziano

Alfonso Graziano

Alfonso Graziano warns that deploying AI agents blindly is a security nightmare. Stop relying on simplistic tutorials. Learn to implement hard guardrails and continuous evaluations for production-ready LLMs.

Pause
Mute Enter Fullscreen
#1 about 2 min

Building client-facing AI agents for engineering teams

Practical implementations of AI agents focus primarily on serving internal engineering teams and end customers.

#2 about 3 min

Moving beyond simple prompts to reliable agentic systems

Constructing robust AI agents requires recognizing that natural language interfaces must handle unpredictable user queries effectively.

#3 about 2 min

Why simplistic AI agent tutorials fail in production

Most introductory guides ignore critical components like automated evaluations, golden datasets, and continuous user feedback loops.

#4 about 3 min

Implementing security guardrails and OWASP principles for agents

Applying appropriate access controls and addressing new vulnerabilities like indirect prompt injection protects non-deterministic applications.

#5 about 2 min

Essential resources for understanding agentic design and evaluation

Foundational knowledge of large language models and structured frameworks aids in building easily testable AI systems.

#6 about 4 min

Evolving developer roles into tech leads for AI agents

Software engineers must review generated outputs and confidently guide parallel agent workflows instead of blindly trusting automated code.

#7 about 4 min

Risks of granting AI agents complete system permissions

Running experimental agents on personal machines exposes sensitive credentials and local files to unexpected behaviors.

#8 about 3 min

Mitigating hallucinations and sycophancy in tool-calling agents

Restricting tool access and applying framework-level guardrails helps prevent deployed agents from inventing fictitious functions.

#9 about 6 min

Building golden datasets and feedback loops for reliability

Gathering real user interactions and expert annotations forms the foundation for continuously evaluating and improving agent performance.

#10 about 2 min

Refining system prompts to eliminate specific failure modes

Adjusting domain-specific instructions within the prompt configuration significantly boosts evaluation scores and inherently prevents common errors.

#11 about 3 min

Practical enterprise use cases for automating complex workflows

Deploying intelligent agents for complex data search and reproducing repetitive development tasks safely accelerates team productivity.

#12 about 5 min

Learning resources and community engagement for AI engineers

Specialized courses, upcoming literature, and developer conferences offer structured approaches for mastering advanced software integration capabilities.

Matching moments

8:54 min

Preserving engineering fundamentals in agentic development

Chris Heilmann Chris Heilmann +1 · LIVE

2:06 min

Rethinking team structures around AI agent capabilities

Mike Mike · World Congress 2025

4:15 min

Security integration and AI skepticism in developer tooling

Chris Heilmann Chris Heilmann +2 · LIVE

1:10 min

Identifying emerging security vulnerabilities in generative AI agents

Alejandro Saucedo Alejandro Saucedo · World Congress 2025

3:45 min

Fusing developer experience and platform engineering for agentic SDLC

Julia Kordick Julia Kordick · World Congress 2026 Europe

2:52 min

Designing agentic AI solutions for the enterprise

Damir Dobric · Coffee With Developers