Who Controls AI Agents When Software Starts Acting Alone With Oasis Security
AI at WorkSeptember 27, 2026
53
00:30:2427.85 MB

Who Controls AI Agents When Software Starts Acting Alone With Oasis Security

What happens when software can reason like a person, move at machine speed, and use every permission it receives?

In this episode of AI at Work, I speak with Adam Ochayon, VP of Product Strategy at Oasis Security, about why autonomous AI agents create a different identity and access problem from the software businesses have secured for decades.

Adam explains that traditional software is fast but generally deterministic, while people can reason but usually act slowly enough for organizations to intervene. AI agents combine reasoning with machine speed. They are goal-seeking, capable of choosing different routes to complete a task, and likely to use any access available to them. Permissions that might remain unused by an employee can become active risk almost immediately when assigned to an agent.

We discuss why static roles are poorly suited to this behavior. An agent may need different permissions from one session or task to the next, depending on the person directing it, the data involved, its recent behavior and the action it is attempting. Adam argues for contextual authorization that can grant narrowly defined access at the right moment, monitor behavior continuously and provide a kill switch when an agent begins operating outside its approved purpose.

Ownership presents another problem. Employees can create, modify and reuse agents across several business systems. Some agents act on behalf of a person, while others receive their own autonomous access. In both cases, companies need to know who remains accountable, which credentials the agent holds, what happens when its owner leaves and how its permissions are retired.

Adam connects these questions with the wider problem of nonhuman identities, including service accounts, API keys and secrets. Companies that have not brought those identities under control may find AI adoption magnifying weaknesses that already exist. Security teams also face a delicate balance. Excessive friction encourages employees to bypass approved systems, while unrestricted access creates unacceptable exposure. Adam believes identity teams can become advisers to the business by creating controls that permit faster adoption with clearer boundaries.

We also discuss Cyera’s announced $1 billion deal to acquire Oasis Security and what the combination of data security and access governance may signal about the direction of enterprise AI security. Adam closes with a practical sequence for leaders: discover which agents exist, understand their access, assign ownership, define policies, monitor activity and enforce controls across cloud and on-premises systems.

Who owns your AI agents, and would your organization know when one moves beyond its approved purpose? Share your thoughts with me.

Useful Links

[00:00:00] [SPEAKER_00] AI agents are only as strong as the data that they're given. When provided with an outdated data set, your agents could end up doing more harm than good. But not with Denodo. With an AI data layer built within your platform, your agents are provided with real-time data changes. So with Denodo, your agents can finally make the right business decisions. Simply visit denodo.com to learn more.

[00:00:33] [SPEAKER_00] What happens when software can reason like a person, but act at machine speed, and immediately use every permission that it receives, all at the same time? Now today on AI at Work, I'm joined by the VP of Product Strategy at Oasis Security. And together we're going to examine why traditional identity controls will struggle with autonomous agents.

[00:01:02] [SPEAKER_00] And he will explain why AI agents are goal-seeking, unpredictable actors that combine human-like decision-making with the speed of software. So I want to dig a little bit deeper on dynamic authorisation, agent ownership, kill switches, and the growing problem of non-human identities across cloud and enterprise systems. It's a pretty big year for the company too.

[00:01:28] [SPEAKER_00] Sayara recently announced a $1 billion deal to acquire Oasis Security, and I want to talk about that. Well, it signals about the demand for AI agent governance, and so much more. So if your business wants AI autonomy without handing every agent the digital master keys to your organisation, I think this conversation offers a timely starting point. But enough from

[00:01:55] [SPEAKER_00] me, let me introduce you to my guest now. So thank you for joining me on the show today. Can you tell everyone listening a little about who you are and what you do?

[00:02:07] [SPEAKER_01] Absolutely. So thanks for having me, Neil. My name is Adam O'Chayon. I'm VP of Product Strategy at Oasis Security. We're a non-human identity management and agentic access company. A bit about myself, I was born in the States, grew up most of my life in Israel, and moved back to the States almost a decade ago. And I like to say I'm in the intersection of our field and our go-to-market

[00:02:34] [SPEAKER_01] and our product and our tech, right? So really what I do day to day is make sure that I have a good pulse on the market on one hand and on our field, and also understand what we're working on developing and building, making sure that there's a very tight fit, good feedback loop from what the market needs and from what our product can deliver on. Yeah.

[00:02:54] [SPEAKER_00] Awesome. Well, it's a pleasure to have you join me today. It's a lot I want to talk about because every tech conference I go to this year, predictably, is all about agentic AI and AI agents. And there's a lot of noise, a lot of hype. But one of the things that attracted me to you and what you're doing at Oasis Security is that you've argued that AI agents behave very differently from the software enterprises that, enterprises that, do that again, differently

[00:03:22] [SPEAKER_00] from the software enterprises have spent decades securing. So for everybody listening here, what is it that changes when software can reason, choose tools across, access multiple systems and take actions independently? And why does all that force us to rethink identity?

[00:03:40] [SPEAKER_01] Yes. Excellent question. So I think really the interesting thing here is AI agents, they kind of loan different attributes from the two sides that we're familiar with that have historically been pretty separate and now we're colliding, right? So there's humans and how human behave, right? Of course, humans, you know, have their ability to reason, right? That's what makes

[00:04:05] [SPEAKER_01] us what we are, allows us to make decisions to figure out the right path to do something. But also, on the other hand, generally speaking, humans are slow to act, right? On the one hand, and also generally, generally speaking, a human will do things within specific confines. And if not, we can hold humans accountable, which is another really important part.

[00:04:30] [SPEAKER_01] Then on the other side of the field, so to speak, is what we've always known around software, around automation, around scripts, around workloads, where, again, on the one hand, they move incredibly quickly, incredibly fast. On the other hand, usually pretty consistent, pretty deterministic, right? In the end of the day, programs are built to work in a specific way. And they always work in that way. Of course, sometimes there are bugs, sometimes there are issues. But generally speaking,

[00:05:00] [SPEAKER_01] the logic is imbued in the software. And so now these two worlds collide, because we have non-deterministic reasoning actors that can change what they do, what they act, based on different inputs, based on different contexts. But they also work at machine speed, right? So a lot of how we've been governing human access, for example, doesn't really fit anymore. Because if we give a human

[00:05:29] [SPEAKER_01] too much access, that's like a theoretical problem. Like, okay, maybe some at some point, this human will use this additional access, but we'll know, we'll know to find it because it'll be slow enough, and we'll know who's accountable for it. You give an agent too much access, it almost by definition is going to use it immediately. Because that's how the system operates, right? Agents are, they're goal seeking, they aim to please, they're greedy, right? They search those boundaries. And so that problem

[00:05:58] [SPEAKER_01] moves from hypothetical to real very quickly. So again, a lot of the concepts that we were familiar with on the human side of how we manage access to a human, you know, putting them within roles, defining it pretty statically, things not changing too often, a lot of that really shatters when you're talking about, about agents, which I think is what's making identity for AI for agents,

[00:06:22] [SPEAKER_00] an incredibly tough and interesting topic today. Yeah, I completely agree with you. And I want to spare a thought for security teams at the moment that seem to be caught in an almost impossible position. They cannot simply block AI because employees and business units will find a way around them, but they also cannot ever justify and approve unrestricted access. So what does a workable middle ground look like there? We're going back to reasoning here again, but what does that look like?

[00:06:52] [SPEAKER_01] Yeah. And the interesting thing on that is this is not new for identity teams. This is the problem that identity teams at its core have been facing forever. If you think of the concept of privileged access, it really is pretty similar, right? You have this access that we deem is incredibly sensitive and we want to be able to measure and control who and when can have that access, right? We're familiar with this

[00:07:18] [SPEAKER_01] concept from the human side, of course. And again, the similar kind of, you know, rock in a hard place, so to speak, that organizations are caught of. It exists in the privileged access space where, right, where on the one hand, if you add too much friction to the process, everyone's just going to bypass you. And then you're even worse where you started. But on the other hand, you want to let the business operate, right? So you want to find that sweet spot between

[00:07:43] [SPEAKER_01] no friction at all. And I have no idea what's happening or too much friction. And then people are going to bypass me. Right. But again, with AI, the pace, the speed of change, and I think the complexity of the non-determinism really makes this explode in terms of the gap, right? So organizations today are, on the one hand, being pushed by their business to adopt quickly and

[00:08:07] [SPEAKER_01] rapidly integrate AI into their systems because the value is immense and undeniable. But on the other hand, they sacrifice governance when they do that, right? So the question now is for these teams, how do they find the sweet spot of not only securing, but also enabling the business? And I think that's, you know, the smart organizations will find that the best way to do that is not by just adding, locking things up, adding a ton of friction, because again, then people are just

[00:08:36] [SPEAKER_01] going to bypass you as they always do. It's finding a way to work with the business, work with security, building in the right guardrails that let the business operate, but provide governance and trust

[00:08:50] [SPEAKER_00] layers around it. And it does feel like we've spent years talking about least privilege for employees, but of course now we're throwing AI agents into the mix and they might need different permissions from one task to the next. So does authentic AI requires to move from relatively static access rights that seldom change to toward a more dynamic and maybe contextual authorization model?

[00:09:16] [SPEAKER_01] Yes, 100%. And I think that's really the key part here, because when the question is, how do we apply guardrails? How do we govern? I think your observation is exactly on point. The same agent with the same human driving it on the same task will sometimes need different access, just session by session or task by task. And so the key becomes, okay, how do we understand? Again, this is not groundbreaking in terms of the identity concepts,

[00:09:44] [SPEAKER_01] but it's applied in a completely different way. How do we understand who should have what access at what time and under what policy? This is the crux of identity and always has been. But again, the playing field has completely changed. So now the question becomes, how do we gain the context and also apply the policies to understand what is this agent trying to do? What is the context

[00:10:09] [SPEAKER_01] of how this agent has been or is behaving in the current session, in past sessions? Where's the traffic coming from? Who's driving it, et cetera, right? And importantly, how does this tie to our organizational policies around what sensitive data should this agent have access to? At what point in time? What task is considered sensitive versus unsensitive? How do we ensure that we approve it without adding too much friction to the process, but also have a kill switch so that if something goes

[00:10:38] [SPEAKER_01] wrong, we can shut it down immediately? So yes, I think the tensions have always been there, but now this contextual authorization really becomes paramount because again, an agent given access will use that access. The agent wants to achieve the goal. And so that gap between, okay, we have this proxy estimation of a role that kind of encompasses what a human needs and sometimes gives them a little more

[00:11:07] [SPEAKER_01] than what they need, but usually that's okay because 99% of the time they're not going to use it. That's no longer the world we live in. 100% of the access we should assume will be used immediately. So finding out the mechanism to scope down the agent access to only what they need only at the specific time becomes essential really.

[00:11:32] [SPEAKER_00] Yeah. There's also an ownership question here as well. If I create an agent that, I don't know, connects to five enterprise systems and then one, then another employee modifies it and reuses that same agent. Whose identity and permission should it inherit? I guess is the first question. And who remains ultimately accountable for what it subsequently then goes off and does on a Sunday afternoon?

[00:11:58] [SPEAKER_01] Yeah. Yeah. I think both of those points are really, are really important because on the one hand, I'll start with the second one because I think it's, it's a lot easier to grasp and understand, but accountability is a massive challenge. And in fact, this challenge builds on the challenges enterprises already face with non-human identity and with non-human access. At the end of the day, you have these systems that are built by an engineer and then the engineer moves somewhere else or the system changes hands or whatever it may be. It's really hard to pinpoint and understand,

[00:12:28] [SPEAKER_01] okay, who's in charge of this system that's operating behind the scenes and is requiring access to different places. The same is true with agents. You have now an agent, which is essentially just a more complex, sophisticated piece of software in the end of the day, right? An agent still operates in the speed of software, I'd say, but now with this additional capability of, of reasoning and understanding, exploring different paths. So the point around accountability

[00:12:56] [SPEAKER_01] is even harder than it has been to this point, right? So who is this agent? Who's responsible for this agent and for its actions? Who manages its life cycle? And organizations, I think are waking up to a problem where just like for the past 10, 20 years, they really have no idea what the service account does and who's in charge of it and who's accountable for it. And who do we, who do we talk

[00:13:22] [SPEAKER_01] to when we need to make changes or when something goes wrong? Again, this is now exploding with agents because not, not only developers are building out these, uh, these software systems, like in, in the yesteryear. Now agents are built by any business user. Uh, and so that point of tracking accountability, understanding who in the end of the day is responsible for the actions of this agent

[00:13:48] [SPEAKER_01] is a really hard problem and also incredibly important for the business to be able to function. Now on the point of related to, uh, to the access and whose access, uh, is inherited, there are really kind of two models here and they each have their own interesting gaps. The first model is, uh, the delegated model, the on behalf of model where an agent operates on behalf of a specific human, which is on one hand, great, convenient, you know, as a human,

[00:14:14] [SPEAKER_01] I can say, Hey, I already have access to this. I bestow this access upon my agent to be able to do my work more effectively, which is terrific. But then what happens if I'm an admin in the organization and I have right access to my databases and I just give that access to an agent. And all of a a sudden the database is gone, right? Again, it goes back to accountability. What do we do at this point? Was it the agent fault? Was it my fault? How do we manage that? Right? So again, being able

[00:14:41] [SPEAKER_01] to say, Hey, I have all this access, but the agent needs just this access, just that subset of it. How do we manage that? So that's a very interesting and important challenge. The other model is the autonomous model where essentially we give the agent the access that is not bestowed upon from any human, not delegated. It's access that the agent itself intrinsically has to do a specific task.

[00:15:07] [SPEAKER_01] Um, and that also needs to be managed and, and, and modeled in a way that is tenable in the organization that is governable that we can, again, one, find the accountable individuals to map out what the access is actually needed for the specific task. Again, how do we prevent that ballooning of access that suddenly gets out of hand? Um, and I think importantly, it's how do we find the models in which an organization can roll these things out responsibly so that again, they're not

[00:15:36] [SPEAKER_01] slowing down the business, but they're also not putting it at risk at the same time.

[00:15:41] [SPEAKER_00] And all this comes at an incredibly interesting moment because many companies out there and people listening will already be struggling with service accounts, API keys, secrets, and other non-human identities. So does agentiKI simply make an old identity problem bigger or does autonomy maybe introduce fundamentally new risks that existing identity systems weren't designed to handle? It feels like

[00:16:07] [SPEAKER_01] they're caught between a rock and a hard place here. Yes. Yes. I think it's on the one hand, it's a compounding of problems. So a lot of the same issues, again, if we talk about that autonomous agent model, we need to figure out how do we give that autonomous agent the correct access? Again, it's not delegated from a human. So this is just a compounding non-human problem, uh, non-human identity problem specifically. Uh, and so yes, organizations that don't have that in check yet are really going to

[00:16:35] [SPEAKER_01] struggle building the next phase, right? If you're, if your foundations are shaky, uh, you know, the, the, the whole building is going to be toppling over before you, before you know it. Uh, and so being able to come from a strong foundation of, okay, we understand how we manage our non-human access, how do we manage these different accounts, how we govern them properly, how we enforce our policies, how we continuously and contextually verify, you know, what data is sensitive, what access is risky,

[00:17:03] [SPEAKER_01] et cetera, et cetera, becomes even more, um, uh, even more crucial for, for agents. Yeah.

[00:17:10] [SPEAKER_00] And before you join me on the podcast today, I was reading how you've said that some of the organizations that are succeeding with AI the best are, they're the ones that are treating security and governance as enablers rather than placing the brakes on innovation. We have so refreshing to hear that. And very often, I think people think the opposite and it's great to hear that you're, from what you're seeing, that isn't true, but what are they doing differently and how can

[00:17:35] [SPEAKER_00] better identity controls actually allow companies to give agents more autonomy rather than less? It'd be great to bust that myth to them. Yeah, of course. I think in the end of the day,

[00:17:46] [SPEAKER_01] and this is, this is something that's always been true between security and the business and why I think identities place there is very unique because oftentimes, uh, the business and the security side are at odds. Uh, the business is trying to innovate, trying to do things security saying, Hey, Nope, you can't do that. That's dangerous. That's risky. Now identity has always been somewhere in the middle. It's always been very close to the business, but also a very important on, on security

[00:18:13] [SPEAKER_01] because in the end access is everything starts with access. If no one in the business has access to anything, nothing can happen. Uh, so figuring out how that right access gets provisioned in a way that's quick, that's effortless, but also that is compliant. That's always been really relevant. And I think what, what AI is now, uh, evolving businesses into, it's really elevating the position of identity within the business. And the best organizations that we see really driving success

[00:18:42] [SPEAKER_01] here are seeing them, their role as advisors to the business. They're not there to inhibit progress. It's the absolute opposite. They're there to understand how can the business go as fast as needed here. Uh, but also how do we do that without putting everything the business stands for at risk, right? If you have a specific, uh, business that innovates on, um, new and unique

[00:19:09] [SPEAKER_01] inventions or recipes, so to speak. Uh, this is of course, especially through everything that's happening with manufacturing these days. Uh, what's important for that business is understanding, okay, how do they leverage all of that information that they have? How do they give it access to the right individuals, but how do they do that responsibly without that information, which is the core of the business getting into the wrong hands, right? So the, the, the best partners that we've seen on the identity side, again, they see it as a partnership with the business

[00:19:37] [SPEAKER_01] and they work with the business and understanding where can we let go? Where can we loosen up specific constraints? How do we build the guardrails to allow the business to work within them? And, and in the end of the day, reap the benefits of these new systems that are now being introduced.

[00:19:53] [SPEAKER_00] And also when doing that research, I also came across a pretty big news story, and that was a $1 billion deal to acquire Oasis security, which feels like a striking valuation for a company focused on non-human identity security. So tell me a bit more about that deal. What's it tell us about where the cybersecurity model maybe believes value is moving, especially as AI agents continue to proliferate,

[00:20:19] [SPEAKER_00] not just this year, but next year and beyond it. And why has this area become so strategically

[00:20:24] [SPEAKER_01] important? Do you think? Yeah. Yeah. I think, um, I think there are a couple of, of trends really that have, have driven the excitement in the market and also the, uh, obviously the recent news on Oasis and say, are working to join forces. Um, and I think again, two trends, right? One is the identity market itself is just completely changing to the point where we've spent so long

[00:20:51] [SPEAKER_01] and so much of our focus on, on human identity and access, which is incredibly important, of course, right? For all of us in the workforce. But today in the, in the transformation that's been happening in the past several years through cloud adoption, through business transformation. Now, of course, through AI, non-human actors are depending, you know, depending which number you want to quote, there are different numbers here, but over 90% of the actors in the business are now non-human.

[00:21:19] [SPEAKER_01] So over 90% of access we need to govern is now non-human access. So I think that's one evolution in the identity space. But now of course there's, there's the AI space that really is, is, is, is colliding and merging, uh, different worlds, right? And it's, it's really, it's, it's kind of like an earthquake. Uh, and when an earthquake happens, you have, you have two choices. Uh, one is, uh, you know, you, you wait for the earthquake to subside and you, you rebuild what

[00:21:45] [SPEAKER_01] you had before. Um, and the other option is you envision what a new city looks like and you build it from the ground up with new foundations. And I think that's, that's, what's really interesting with, with, with Siren Oasis, right? To, to be able to, to manage this, this earthquake, this revolution that is agentic AI, uh, you really need to understand what agents can see and what agents can do very, very simply. And that means you need to understand the access

[00:22:12] [SPEAKER_01] and you need to understand the data. Uh, and I think the, the, the unique proposition here is that no company has really treated those two problems, uh, as closely as Siren Oasis are now, are now able to treat them, building the strong foundations that each company has on the one side on, on data, uh, and classifying it, understanding its sensitivity, both at rest in motion, but then

[00:22:37] [SPEAKER_01] also access, understanding access to that data, uh, overlaying those two allows us to build policies, allowed us to build context and intelligence that is really, uh, able to drive organizations to adopt this AI eyes wide open, understanding what's at risk, what's exposed, how do we do it safely? How do we, uh, drive this, uh, innovation forward? So I think that's, that's really the, the, the big, uh, change that's happening in the market. Obviously all of us are very, very excited,

[00:23:06] [SPEAKER_01] uh, to be at the forefront of what this new revolution looks like, you know, this merger between access and data, uh, in, in one place, uh, to secure AI.

[00:23:19] [SPEAKER_00] Exciting times ahead. It sounds like there. And I always try and give people listening a, a valuable takeaway. So if we have a business leader listening who maybe wants employees using AI agents today, rather than waiting around for security architecture to catch up, what kind of questions should they be asking about every AI agents identity, ownership, permissions, credentials, and activity before they allow it to go out there and perform that meaningful work? What kind of

[00:23:49] [SPEAKER_00] starting point or tips and advice would you offer there? Yeah, of course. And I think this is as,

[00:23:55] [SPEAKER_01] as with most processes, there's going to be a crawl, walk, run here and we all want to run as quick as we can, but if we do that, we're going to topple over. Right? So it's, it's important for us to build the foundations. The foundations are, you need to first understand what even exists. If you don't know what exists, you're not going to be able to apply any control, any governance, uh, on it. Right? So you need to understand what agents exist, what access they have. Then you need to start tying business context to it. Who's responsible for it? Who approves it? What are the policies that we're

[00:24:23] [SPEAKER_01] defining around it? What is, and is sensitive, isn't sensitive, right? Once you start building what's important is to start building the continuous controls that allow you to, again, see what's actually happening, tie that to what the organization, um, considers in policy, out of policy and understand how you can actually take, uh, ideally as automated as, as you can, uh, but take these actions that actually make sure everything is, is staying on track,

[00:24:53] [SPEAKER_01] staying in the right place, that the agent intent isn't suddenly drifting into some other area where it's, it's, the agent is now doing something it wasn't really supposed to do. Right. Or when, uh, if a specific credential or token that's required for access finds its hands in the wrong place, you know, maybe it's committed to code, maybe it's leaked somewhere, but you know who to talk to and you know what action needs to be taken as soon as possible. Right. Um, and so that

[00:25:21] [SPEAKER_01] you can clean up maybe access that is no longer needed, right? These are all, uh, bits and pieces of the problems that we see, uh, every day. But I think again, it has to start with the foundations. It needs to start with understanding across all your different platforms, your cloud services, your on-prem systems on your end point, right? In your managed services and SASs. Um, you need to really understand that surface area, uh, rationalize it, tie it back to what the business

[00:25:48] [SPEAKER_01] knows to understand, uh, establish your policies around it and understand the mechanisms and the enforcement points, uh, to control them properly. And this is going to be a team effort, right? There isn't going to be, uh, one, uh, point where we're going to be able to say, Hey, all our defenses are going to go at the gateway layer or at an end point layer or whatever it is, right? There are going to be different layers here as we've always had in security defense in depth, et cetera, remains

[00:26:16] [SPEAKER_01] important. Uh, there are going to be different enforcement points, different layers. The question becomes, how are you able to see it in one place, control it from one plane, have unified policy, uh, across all these different areas. So that again, in the end of the day, you can control what agency and do so you can trust what's actually happening in the enterprise. Uh, that's, that's, that's really the goal in the end of the day.

[00:26:40] [SPEAKER_00] Wow. That's incredibly cool moment to end on. And we've started there with a few little starting points for people listening for anyone wanting to dig a little bit deeper and talk with you or your team. Where can they find out more information about you, uh, Oasis security and anything we discussed today? Where, where can I point people?

[00:26:58] [SPEAKER_01] Yeah, absolutely. So you can point people to Oasis dot security, pretty, pretty catchy. Uh, and obviously there you'll find more resources that in general allow you to learn about the space. One of the things I'm actually really excited about our team contributing to is we have, uh, public open courses about non-human identity and about agentic access that anyone can take, uh, from a neutral point of view. So I think those are incredibly exciting. And of course we offer a

[00:27:26] [SPEAKER_01] product that helps organizations, uh, govern this access from those foundations of even understanding what exists to the point where how understanding how it ties to the business all the way to understanding how you can actually manage it. Uh, you know, from fine grained authorization for agents to automatic governance, uh, for non-human identities, uh, all in one platform, right? So Oasis dot security is the place to go to learn more, talk to our team, um, and really, uh, upskill in this exciting times.

[00:27:56] [SPEAKER_00] Well, I'm seeing a, an increasing demand for tools that govern AI agents. It's all everybody's talking about at the moment. And when, before implementing, they've got to want that security to go with it. So I urge anyone listening to check out the links, um, that you've just mentioned that I will post everything in the show notes. So please go and have a look and, and also please share your stories with me. What's working, what isn't working and how you're dealing with the security issue around AI

[00:28:25] [SPEAKER_00] agents. Love to hear from you, but, uh, more than anything, just a big thank you to you, Adam, for starting this story, increasing awareness and sharing your success as well. Thank you. Thank you so much, Neil. Thanks for having me. I think Adam's advice begins with a deceptively simple question for a complex world. Do you know which agents exist inside your business? From there as a leader, you need to establish ownership, identify credentials, map permissions,

[00:28:54] [SPEAKER_00] define sensitive actions, and most importantly, continuously watch for behavior that might drift from its original purpose. It's not a case of just set and forget need constant monitoring. And I think the goal here is to give AI agents enough access to create value without leaving every door open. And as I said at the beginning, Sierra's $1 billion deal to acquire Oasis security. I think

[00:29:22] [SPEAKER_00] this shows just how valuable that control layer is becoming, especially as access and data security begin to converge. So a big thank you to Adam for joining me. Remember, you can find him and his team and free educational courses, et cetera, at Oasis dot security. But over to you, who owns your AI agents when the decisions move beyond the task that you originally approved six months ago? Love to

[00:29:50] [SPEAKER_00] hear your experiences on this tech talks, network.com. Remember we have an eight podcasts, there 4,000 interviews. You can leave me a voice message. You can work with me or meet me at a tech conference near you. Everything you need will be over at that site, but that is it for today. So I'll be back again real soon with another guest. Thanks for listening. Bye for now.