When an Agent Acts on Your Behalf, Who Holds the Keys? - Mariusz Sabath & Maia Iyer, IBM Research
About this talk
This talk addresses the complex challenges of security in enterprise environments when agents act on behalf of users. The speakers, Mariusz Sabath and Maia Iyer from IBM Research, explore how traditional static API keys fall short in capturing the context behind actions taken by these agents. They present an architecture that cryptographically binds agent identity with delegated user identity, utilizing SPIRE’s workload attestation to create verifiable agent identities. Furthermore, they introduce Keycloak as an OAuth 2.0 server for managing delegated user identity and discuss an open-source MCP Gateway for enforcing policy and audit controls, ensuring that all actions are traceable back to the approving user and the executed code.
More from this event
See all 436 talks →
Best of KubeCon + CloudNativeCon Amsterdam 2026
2:17
The Quiet Work of Forever: Sustaining Open Source Communities - O. Hope Amaechi-Okorie, JSON Schema
26:24
Evolving KServe: The Unified Model Inference Platform for Both Predictive and... F. Spolti & J. Lee
32:40
Preventing S3 Cost Storms: Applying Cortex’s Efficiency Lessons to I/O-Heav... A. Fishman-Lichterman
5:32