Urgent.News

What's breaking now, across thousands of outlets.

AI

Podcast: Securing AI Agents: Identity, Authorization, and the DPACT Framework

In this episode, Sahil Agarwal talks about the critical challenges of identity, authorisation, and security in the age of AI agents. Sahil introduces the DPACT framework (Delegation, Policy, Auditability, Context, and Time) as a blueprint for building responsible, guardrailed agentic systems, moving away from simple token-based access toward bounded, delegated authority. By Sahil Agarwal

InfoQ Podcast: Securing AI Agents - Identity, Authorization, and the DPACT Framework

Olimpiu Pop: Hello, everyone. I am Olimpiu Pop, an InfoQ editor. Today, we are discussing a critical topic about AI and agents acting in our name or they should act in our name. We have the pleasure of talking with Sahil Agarwal, an area engineering leader at a leading cloud collaboration and content platform company. He is responsible for the identity and authorization stack, which directly relates to building agents for individuals or enterprises.

Sahil Agarwal: Thank you for having me, Olimpiu. My name is Sahil Agarwal, and I lead the identity and authorization stack at a leading cloud collaboration and content platform. The focus of our discussion today is on how to separate human identities from agents, the challenges they present, and how to build responsible agentic systems.

Olimpiu Pop: Based on our initial conversation, we touched upon how AI is transforming our world. Earlier this year, people were discussing how AI will not replace individuals, but people who use AI will do. Most coders were focusing on using AI without tokens in platforms like Claude. The conversation moved from pricing per user or seat in software as a service tools, as the tools we use are primarily in the cloud. We started discussing the problem of token-based access and how it needs to be addressed.

Sahil Agarwal: My perspective is that we are shifting the value from raw coding skills to who wields agents and how they use them. The shift is from writing good code to working effectively with agentic systems. The metered and token-based access concentration is a concern, but the shift is towards being the software orchestrator who uses agents to help build applications.

Olimpiu Pop: Sahil, you mention a significant problem that organizations are facing. The challenge lies in the fact that teams rush to capabilities without considering identity, accountability, and trust. Instead of carefully designing delegation, scopes, and policies before using agents, they are prone to risking sensitive data and unauthorized actions.

Sahil Agarwal: That's right, Olimpiu. We cannot simply hand kids knives and expect them to use them responsibly. Similarly, as AI agents have access to sensitive data and can perform various tasks, we must ensure that teams understand how to use them properly, in a safe environment, to prevent harm to themselves and others.

Written by urgent.news from InfoQ's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at infoq.com →

More in AI

Your Finance Agent Needs an Evaluation Harness, Not Just a Prompt

Your Finance Agent Needs an Evaluation Harness, Not Just a Prompt A finance agent can produce a convincing answer and still be wrong in the one way that matters: it can make a decision without enough…

  • Implement evaluation harness for finance agents, not just prompt improvements.
  • Define decision-making scope with desired action, confidence level, evidence IDs, and rationale.
  • Create dataset with transaction types and expected behavior for regression testing.

More from Monday 21 September →