Atul Tulshibagwale,
Senior Director, Continuous Identity Strategy, CrowdStrike
As enterprises race to adopt AI, identity and security practitioners face a familiar set of problems in an unfamiliar context: discovering which agents are running (and preventing "shadow AI"), ensuring only approved agents and LLMs are used, enforcing fine-grained access to specific resources, revoking access when conditions change, and auditing every action across call chains that traverse systems and organizations. The Model Context Protocol (MCP) has emerged as the de facto communications layer connecting agents to enterprise systems, and it supports OAuth, but OAuth may not provide all the answers. While some might be inclined to invent new standards to address these gaps, we propose achieving this using existing standards. The building blocks already exist. In this session, we'll walk through five concrete best practices, each grounded in an existing or emerging open standard, that together tame AI's unpredictability with deterministic controls.
...
Show More
Show Less