Building Infrastructure That Can Govern AI Agents With Broadcom
Tech Talks DailyAugust 27, 2026
3700
25:5719.59 MB

Building Infrastructure That Can Govern AI Agents With Broadcom

What happens when an organization writes careful AI governance policies but its infrastructure cannot enforce any of them?

In this episode of Tech Talks Daily, I speak with Sabina Anja, Chief Technologist at Broadcom within the VMware Cloud Foundation division, about the infrastructure controls required as AI agents move from generating answers to accessing data, calling APIs, modifying systems, and triggering work.

Sabina brings experience from both sides of enterprise technology. She remembers cabling networks, dealing with unstable infrastructure, and receiving those weekend calls when downtime had already upset the business. That background informs her belief that ambitious AI programs cannot succeed without stable, observable, and enforceable infrastructure beneath them.

Many organizations are repeating a familiar pattern. Business teams adopt AI services before IT has established visibility, ownership, or control. The terminology may have changed from shadow IT to shadow AI, but the management problem remains. Sabina argues that CIOs first need an inventory of agents, nonhuman identities, data access, processes, and accountable owners.

The risk becomes greater because agents behave differently from people. They operate across multiple systems at machine speed and can perform repeated actions without appreciating the wider business outcome. An agent does not need malicious intent to cause disruption. Excessive permissions, flat networks, inconsistent access rules, and years of deferred infrastructure work can give it plenty of opportunities.

Sabina recommends brokered access rather than direct access, alongside dedicated virtual machines or namespaces, microsegmentation, lateral security, east-west policy controls, and tamper-evident logging. Organizations also need to define which data an agent can view, modify, or move, especially when sovereignty and regulatory requirements apply.

One of Sabina's most memorable ideas is to treat an AI agent like a superhuman contractor. It should have a defined purpose, a named manager, a clear access specification, an activity record, and an end date. Additional permissions should be earned through evidence of reliable behavior rather than granted on the first day.

She also warns about agent debt. AI systems are developing rapidly, so an agent created today may become outdated within months. Sabina recommends assuming that many agents will expire after six to nine months rather than allowing forgotten systems and permissions to accumulate indefinitely.

For CIOs wanting an immediate test, her advice is straightforward. Create an inventory of nonhuman identities with production access. Then select one agent and examine every part of the infrastructure it attempted to reach. The question is not simply whether the application produced the expected result. Leaders should ask whether the agent entered systems, networks, or data stores that nobody expected it to access.

We also challenge the familiar claim that AI agents will take everybody's jobs. Sabina sees an opportunity to remove repetitive tasks and give technology professionals new skills, although she warns that agents may behave like teenagers armed with infrastructure permissions. They may not take your job, but they could become remarkably good at testing your patience.

I'd love to hear your thoughts. Does your organization know how many AI agents have production access and who is accountable for each one?

Useful Links

[00:00:03] - [Speaker 0]
What happens when an AI policy says one thing, but the infrastructure allows an agent to do almost anything? That is the moment where governance stops being a document and becomes an operational test. And my guest today is Sabina Anja. She's chief technologist at Broadcom within the VMware Cloud Foundation division. And she started out in data centers, cabling networks, and answering the kind of Sunday afternoon calls that leave a permanent emotional scar.

[00:00:36] - [Speaker 0]
Trust me. I've been there. But today, she helps customers think through brokered access, isolation, micro segmentation, tamper evident logging, and the growing problem of agent and technical debt. So today, we will discuss why agents should be treated like a superhuman contractor, why their permissions should expand only after evidence of good behavior, almost like a teenager, and why every agent might need an owner and an expiration date. So if your AI ambitions are moving faster than your infrastructure controls, this conversation is for you.

[00:01:15] - [Speaker 0]
So let me introduce you to her right now. So thank you for joining me on the show today. Can you tell everyone listening a little about who you are and what you do?

[00:01:25] - [Speaker 1]
Neil, I know you love a long resume, I'll keep it short. I've spent a bunch of time in IT. I used to be the person, you know, in the back of the data center cabling networks and dealing with things like NIC flapping and so on. I've since moved from a very inconsistent working schedule on many weekends, Working at VMware as a chief technologist, I've been here for about seven years. My job sits in between customers and product today.

[00:01:52] - [Speaker 1]
We work a lot with what features make the most amount of sense, how our customers are adopting them. So it's really, it's getting both sides, sometimes both the love and the hate. And the whole idea is how do you make the most of what you have?

[00:02:06] - [Speaker 0]
Oh, man. I was getting flashbacks when you were talking about weekend cover and everything there. I've been there myself, but it it never leaves you. Right? Even though you've kinda moved on and you've got a more senior role now, it's that that technical side doesn't leave you.

[00:02:18] - [Speaker 0]
Right?

[00:02:19] - [Speaker 1]
No. It's it's it's definitely what's keeping me grounded because the discussions with customers become a lot more real when you remember exactly how it felt to have that, you know, 2PM on a Sunday afternoon cab or steering committee that's mad at you for you know, you've done downtime. What are you gonna do? How quickly you're gonna solve it? And you have that clear understanding of stable infrastructure is key, but you also now see it from the executive side.

[00:02:43] - [Speaker 1]
Right? You talk about the impact on finances. You talk about the impact on productivity and so on. So it's it's really being able to bring both sides of the story, and I'm very grateful for the background that I've been given and earned.

[00:02:55] - [Speaker 0]
Yeah. It sounds like we've both got a few scars from those days. And, of course, fast forward to present day, organizations now are writing policies for what AI agents should and shouldn't be doing. But I was reading before you joined me today that you argue that policy means very little if the infrastructure itself cannot enforce it. Music to my ears.

[00:03:17] - [Speaker 0]
But what is the the biggest gap between AI governance on paper, and what actually happens in production? What are you seeing here?

[00:03:24] - [Speaker 1]
Yeah. I think we both know how this works, especially coming from this infrastructure background. Right? The ambition is always to have the an ideal version of your infrastructure, and then reality kicks in. And I'm gonna touch on that word that we all love called tech debt, which means I've set this up in, you know, 2,005, and you can't touch it because there's an application on it that goes like, no.

[00:03:45] - [Speaker 1]
No. It works as it is. Please do not migrate. Do not upgrade. Don't don't do anything.

[00:03:50] - [Speaker 1]
And then but then you have all of this new stuff that's coming in. You have to upgrade. You have to migrate. You have to move into, you know, let's call it the AI era. And you have all of these new things that are coming at you, but you somehow somehow have to figure out this marriage between what I have, what I need to put on, and have a consistent policy.

[00:04:09] - [Speaker 1]
And, you know, in all honesty, the way we used to do things is not particularly compatible with the agentic era, whether it's security, whether it's policy, whether it's how we protect our own data. So, you know, just as an expose, there's a lot going on. Nobody's at

[00:04:23] - [Speaker 0]
the bleeding edge at every point in time, so catching up is not a fun job. Yeah. It's so true. And we're also seeing with quick scroll down our news feeds that AI adoption is moving faster than governance, while business units are increasingly adopting AI without involving IT. And once that happens, though, how does a CIO regain visibility and control without becoming that department of blockers that always says no rather than being business enablers?

[00:04:53] - [Speaker 0]
We've kinda been here many times before with BYOD, shadow AI, or shadow IT. Now shadow IT. We've been here many times before, but what's the secret here to avoiding this?

[00:05:06] - [Speaker 1]
Let me start with there there's a point before that we should make. Right? It because IT feels like sometimes it's not in control anymore of everything that's coming. Right? You have to your point.

[00:05:15] - [Speaker 1]
You mentioned ShadowAI and, you know, the breaches as a result of ShadowAI are already, like, half a million, close to a million. Like, I know IBM put out a a recent study on that, and the numbers are already staggering. And you get a lot of unsanctioned AI deployments in a lot of organizations. And I've seen customers do both things. I've seen customers or at least the IT department say, you wanna do IT?

[00:05:39] - [Speaker 1]
Give me the right amount of budget so I can manage this properly. Otherwise, it's just not my problem because I don't want to be responsible for this. And then you have CIOs that go into it, and I'm like, I want to own all of it, and I really mean all of it. It. I want to understand our data protection.

[00:05:55] - [Speaker 1]
I want to understand how we're storing it. I need to have a clear inventory of our agents, of our processes, of who's touching this data. So it it's it's really you have to figure out what your battles are. Is your leadership ready to hear the story of this is gonna cost us a lot of money so it doesn't cost us even more money when we do it poorly? If not, do you wanna put it together, you know, with tape and figure out whether it works like that?

[00:06:23] - [Speaker 1]
If you're in the lucky box of I can do it properly, if you're that CIO, again, start at the beginning. Don't start with what you did in the human operated era because agents are very, very different. If you're in the cobbling it together, my luck to you. Good luck, and that's it.

[00:06:40] - [Speaker 0]
Yeah. It's so true. I mean, when an AI agent moves from just generating an answer to accessing data, calling APIs, changing systems, or even triggering workflows, governance can become a operational problem and very quickly. So a big question, almost a podcast episode on its own here, but what infrastructure controls should be in place before an a enterprise thinks about giving agents the lev that kind of level of autonomy and handing the keys?

[00:07:08] - [Speaker 1]
Well, I think that's a really good question, and it's something that we've been focusing quite a bit with VMware Cloud Foundation because some of the things that you want to do in your infrastructure are, what is your brokered access policy? Right? Like, we used to kinda live in this, environment of, yeah. You know, we're gonna just give just the right amount of access. Nothing was particularly well locked down because you're counting on kind of people and responsibilities.

[00:07:33] - [Speaker 1]
But if an agent, for example, inherits a scientist credentials or, you know, IT admins credentials, and they can do any number of things, oh, boy, can an agent do a lot more than you think at the end of the day. And they spawn ideas. They spawn multiple new steps that they start impacting on your infrastructure. So brokered access, not direct access. Figure out how to do it best.

[00:07:58] - [Speaker 1]
You need to figure out the policy enforcement very early on because once it's loose, it's loose. It's very hard to reel it back in. This isn't your firewall any any rule that you've been having on your firewall for like fifteen years, and you just got lucky that nobody abused it yet. These agents are designed to literally test the limits from the moment you deploy them. Right?

[00:08:17] - [Speaker 1]
So that comes to the next thing. You need to figure out your blast radius containment. Like, figure out your dedicated VMs or your namespaces. Figure out your micro segmentation. There's never been a better time for proper lateral security.

[00:08:31] - [Speaker 1]
Distributed firewalling, proper East West policy control based on this is ideal. But also, like, how do you want your data to be handled? So we go back to the fundamental part. Right? Because we're doing this because we're trying to work with data.

[00:08:45] - [Speaker 1]
Should an agent touch this data? Should this be handled a certain way? What is exactly is the agent allowed to do on this data? Can it modify the financial record? Can it move it around?

[00:08:56] - [Speaker 1]
Can it move it in a zone that's not as protected or, let's say, sovereign if you're if we're talking even to that level of rules? So you have a lot of things that you need to figure out, and you need to be able to have tamper evidence logging. This is your in case it still doesn't behave the way you want it to do, go get the logs, go understand how the behavior is actually evolving in your infrastructure to be able to roll it back, curtail it, close it, shut it down. So that's a lot. You know, it's a lot in thirty seconds or forty five, but yeah.

[00:09:27] - [Speaker 0]
Yeah. Well, you covered a lot there. And a few moments ago before that, you were talking about how AI is exposing infrastructure technical debt that many organizations have accumulated for many years. And I would say every organization, every industry has got a tale to tell there. But what kind of weaknesses are agents revealing from what you're seeing?

[00:09:47] - [Speaker 0]
And and what are the warning signs that a teletek leader listening that their infrastructure might not be as ready as they thought it was for AgenTik AI?

[00:09:56] - [Speaker 1]
The best way to think about it is and the way agents expose technical debt is think about all the inconsistencies you have now in human operator purely human operated environments. Again, I'm let's take my example of the any any rule. Imagine how quickly an agent can abuse that. Imagine your flat networks. Imagine when you haven't done your segmentation properly across your different VMs.

[00:10:20] - [Speaker 1]
How again, how will an agent immediately take advantage of that? And for how long you've had that project called infrastructure security that's been put on a back burner because, you know, it hasn't yet gone bad. So do we do that this year? So on average, it's how do you manage all of this? How do you manage all the things that were already a little bit creaky and kinda old world architecture?

[00:10:43] - [Speaker 1]
This is just gonna go up in a multiplier. It's gonna be three x, five x worse just because of this. So, you're managing a a pure vSphere environment or you're already on VCF, look at how many Snowflakes VM you have. Look at how you're you're not managing through policies and governance and automation, and you're still doing manual steps. Wonder how many times you have more access to a VM because, again, Snowflake, it needs a special access.

[00:11:12] - [Speaker 1]
It needs to do special things. Why? I don't know. All of these are now targets for agents going rogue and doing something you won't even know till long after it happened.

[00:11:22] - [Speaker 0]
Yeah. And I think it's worth highlighting that many of the traditional security models were largely designed around humans, applications, and relatively predictable workloads. And I've got to ask you, what is it that breaks when autonomous agents become another actor inside enterprise infrastructure? And possibly the scariest thing is that they're operating at machine speed across multiple systems. I gave you possibly got a few scars here and a few war stories along the way.

[00:11:51] - [Speaker 1]
Well, I mean, I think these things have happened since the early days. I think Yeah. When you you end up with an agent doesn't have to be malicious. It's just it's also not benevolent. It it does it it has a series of thoughts that it needs to complete.

[00:12:05] - [Speaker 1]
And depending on how you design that agent and what you tell it to do, it might find you know, it there's nothing like a creative agent that finds all sorts of way to interact with your data, with your environment, and so on. So, it's an autonomous agent is not a human. It doesn't operate towards the best possible outcome for what you had in mind, but for what it's once it's been programmed. And that sounds a little bit like a philosophical answer. It really isn't because you have the same problems of authorization.

[00:12:35] - [Speaker 1]
What did you actually allow this agent to do? You told her that it has full access to those VMs and containers? Oh, interesting. You allow them to, for example, DRS for you at any point in time at high peak. Oh, maybe there's an error.

[00:12:49] - [Speaker 1]
It tries to now fix it. Oh, it's shutting it down in production. Oh, your wasn't set up properly, and you didn't tell it to do that. You have downtime. Your your machine is offline.

[00:12:59] - [Speaker 1]
You're dealing with this because you told an agent do your best to keep this online. I'm exaggerating a little bit. Yeah. But, you're you're authorized you're usually designing the agent and it's a mistake that will happen for a while with more more access and more ability to do things. So reel it back in as the first thing.

[00:13:17] - [Speaker 1]
Second, remember when I said you have to have a proper audit trail? Detect what the thing is actually doing. We're we're designing these agents based on our access and what we want to do. But, again, I've just hinted at the fact that agents can do a lot more. Make sure you understand how this is working so that, again, you can come back, you can reel it in, you can see when it's doing well.

[00:13:37] - [Speaker 1]
And third thing, when in case an agent is being turned into a malicious actor, that you have the ability to see, like, okay, at one point, they started deviating in behavior. How? Why? What is it going? What is it doing?

[00:13:51] - [Speaker 1]
So the the failure of an agent is not the same as human failure. We have a few things at which it's really, really different. It's attribution. It's speed of detection and behavioral analysis in general, and that key thing authorization. Keep things simple and incredibly contained.

[00:14:10] - [Speaker 0]
Your agentic AI might not be secure even with real time data and proper guardrails, but Denodo make sure your business has every avenue covered. By placing all your data platforms under one AI data layer, your business can reach semantic consistency safely and securely. So get your agents on the same page by visiting denodo.com, and you can learn more about how to start trusting your agents to make business decisions. But now back to today's guest. So this is the part of the show where I'm gonna pull out my virtual crystal ball here and ask you to try and imagine a look at our immediate future, I mean, where an enterprise eventually has hundreds or even thousands of agents operating across multiple different teams.

[00:15:02] - [Speaker 0]
What does that operating model look like for knowing who owns each agent, who can access it, what actions it has taken, and when a human needs to intervene? In an ideal world, what should that look like, and what should people be doing now to prepare for that immediate future?

[00:15:19] - [Speaker 1]
Remember when my first piece of advice to CIOs and IT leaders and then so on was inventorize? Yeah. There's a there's a next step after that, which is if you wanna be successful at this, look at agents almost like you're looking at your contractors, but that they're, you know, superhuman contractors. So, what you do if you hire a person for a temporary amount of time for a job, you're usually giving them a clear spec of what they're allowed to do. If this has a record, and it's named, it has a manager, it has somebody that's responsible for it.

[00:15:50] - [Speaker 1]
Think of agents like that. Don't think of agents as VMs that, you know, oh, I can just shut it down anytime and it doesn't do anything on its own. This thing has a mind of its own. Who's responsible for it? What does it have access to?

[00:16:02] - [Speaker 1]
Can it steal my company's secrets and quit and give them to somebody else? Can it be tampered with? And then, you know, from that identity and access and how do you set it up, you already have a far better place to be in. And then you want to have you know, there's this concept of promoting your agents to do more. Right?

[00:16:21] - [Speaker 1]
You evolve them. You give them new skills. Do evidence based promotion, which is what has it done so far? What does it do well, and then tear it up slowly. So rather than giving it all the skills from the beginning and say, go nuts.

[00:16:33] - [Speaker 1]
You're great. Treat it a little bit more as a teenager. I'm gonna give you a little bit and a little bit more. And once I see that I can trust what you do and I have this paper trail and the person responsible for it takes care of it properly, I know it's not gonna set my my house on fire, and it's not gonna cause damage in my infrastructure. Also, agents expire.

[00:16:54] - [Speaker 1]
Make sure that these things actually have a begin date and an end date. And notice that with the rapid evolution of AI, we get into this point that there's new things coming out, you know, every month, every quarter. Assume your agent is gonna expire in about six to nine months. So don't make this an ownership of the next five years. That's how you create agent debt at that stage, which will create more tech debt and so on.

[00:17:17] - [Speaker 1]
Assume these are short lived and keep them, again, very, very well curtailed.

[00:17:23] - [Speaker 0]
And I would imagine there's also a chance of storming into a leadership problem here because responsibility for AI can span the CIO, CTO, and CISO, data teams, legal, and inside individual business units. So when something does go wrong with an autonomous agent, where should that accountability sit, and how can organizations maybe establish that before an incident rather than afterward? Is this something that you've seen as well?

[00:17:52] - [Speaker 1]
You know, that's a really good question because it's come up in a lot of our conversations with customers. The main challenge is there there's different parts of, let's call it, accountability for AgenTeq and whatever comes next. Right? There's the outcome. What do I want this agent to do?

[00:18:10] - [Speaker 1]
And that's, you know, that's exactly what we're designing it to do. It might be a scientist. It might be whatever. Security is not in the problem of that specific scientist. So the CSO needs to have a clear, clean policy.

[00:18:22] - [Speaker 1]
Go back to, you know, the beginning. What am I expecting these agents to do? How far am I allowing them to go? What is your internal policy of this is safe? And, you know, the question that's the CISO needs to ask when something happens, if something happens is, where were my guardrails?

[00:18:37] - [Speaker 1]
Was this tested and properly enforced? That will save their bacon. The platform accountability, and that's where it gets really interesting, is on the CIO slash CTO depending on how those roles fit in your organization. Well, the things like identity isolation. How do you implement it on a platform like VCF, for example, is where the CTO and the CIO really need to get together and figure out, we have all of these things that we want to do.

[00:19:01] - [Speaker 1]
We have these security requirements. It's our substrate. It's our platform that makes that enforcement possible. How do I make the most out of our platform to make sure that all of this happens?

[00:19:14] - [Speaker 0]
And I'd love to try and give CIOs listening an actionable takeaway here. So let's say we have a CIO listening. They already have their AI agents moving from pilots into production. They're already several months ahead of many other competitors out there. But what would you ask them to be assessing tomorrow morning to determine whether that infrastructure can actually enforce the governments the governance promises that their organization has made?

[00:19:39] - [Speaker 0]
Any any tips there and something they could do sooner rather than later?

[00:19:44] - [Speaker 1]
Two things. One is a little bit harder than the other. Yeah. The first one is, know, I will repeat this. It's really inventorized.

[00:19:53] - [Speaker 1]
What are you have already AI. Do you have your nonhuman identity things for items that are that have production access? What do they do? Who owns them? That's it.

[00:20:05] - [Speaker 1]
You don't need to go beyond an Excel list. It's already going to trigger a bit of, oh, I actually don't know. Who knows this? And you're gonna realize, oh, no. This is more than I what I thought.

[00:20:14] - [Speaker 1]
There are more agents than I thought. So that's part one. If you're really the lucky one that says I know what everything is doing, great. Then go to the next step. Take one of these agents, where you're hearing them about the first time or not, and look at the log of activities, not based on application impact.

[00:20:31] - [Speaker 1]
Like, hey. It modified this statement or I've done this or it's interacted with a user through a chatbot. Look on the infrastructure and look at all the places it had access. And then ask the question, was this supposed to be there? Did it randomly try?

[00:20:44] - [Speaker 1]
Did we design it to do this? Like, literally do a one agent audit. And if everything there is exactly the way you expect it, you're in a good place. Also, write me an email if that happens. I'd love to have one example of those.

[00:20:57] - [Speaker 0]
Fantastic advice. And I'm curious, as a techie, you must scroll down your LinkedIn newsfeed sometimes and see a lot of myths and misconceptions around AI, around, agents, around anything at all there tech related. I'm curious. Is there anything any myths you want me to bust today that we can maybe lay to rest so we can just stop talking about them or stop reading about them? Anything that annoys you when you're out there?

[00:21:22] - [Speaker 1]
Yeah. The honestly, the whole agents are going to take our jobs and so on. It's just it drives me nuts. It's it's such a great opportunity for all of us, you know, coming from a long career in tech. It's such an opportunity for all of us to get rid of some of the menial tasks that we get used to and clog your days and block your nights and get to a point where you think fast, and you also need to get smarter about things.

[00:21:47] - [Speaker 1]
If you're really keen on infrastructure or anything else, AI is a great place to start playing with it to kinda figure out how can I build better? How can I accelerate this? But, again, you have to be smart about. So it's not so much that it's gonna take over this or that. It's more like, I do need to learn a whole new set of skills.

[00:22:05] - [Speaker 1]
It's kinda everything we talked about in the last twenty minutes. Right? It's foster. It's more uncontrolled. It's an unguided missile.

[00:22:12] - [Speaker 1]
It's your teenager when they slam the door to your, you know, to your office saying, I don't wanna listen to you anymore. It's that in IP form now. So it's not gonna take your job. It's just gonna really, really annoy you all the time.

[00:22:26] - [Speaker 0]
Brilliant. And I know that you're, in the middle of preparing for the big event as well. I don't expect you to reveal any spoilers, but any you can share on what you're working on, what excites you about the space at the moment, and also what you love about the event as well.

[00:22:44] - [Speaker 1]
What I love about I'll start at the end. What I love about it is it it really feels like what was a reasonably quiet space, it's starting to now have a lot of change. I guess it was also desperately necessary. We got to a point of infrastructure at scale to use a buzzword where it was nearly impossible to just use traditional automation for a lot of these. So I'm excited to see how far we can get it, how much better we can build, how we can protect.

[00:23:09] - [Speaker 1]
Obviously, the security aspect of it is making it even more interesting because they're coming at you at that speed as well. But it's exciting. Right? Because there's a lot of change. So that's that's what I love about it.

[00:23:19] - [Speaker 1]
That's what I'm looking forward to. What we're working on is and I'm not gonna hint too much because we have our upcoming show now in September with with VMware Explore, but we're definitely gonna talk about AI. We definitely have some really, really good announcements, and we're working on them. It's like, you know, till the last minute. So, you know, stay tuned, and you're here you'll hear a lot about it.

[00:23:40] - [Speaker 0]
I do love a good teaser. Rule one of a podcast, leave your audience wanting more. So it sounds like we will have to get you back on later in the year to discuss some of that. But for everyone listening right now, what's the best place for them to find you, your team online, or anything we talked about? Any way you'd like me to point everyone?

[00:23:59] - [Speaker 1]
I think in the short term, VMware Explore is the best place to find us all. LinkedIn is a great place as well. You find me, Sabina Anya, on LinkedIn. I sometimes work with ACMQ on all things AI. I've recently published a paper on actually the topic of isolation that, you know, all of this is there for you to find.

[00:24:17] - [Speaker 0]
Well, I, for one, have absolutely loved chatting with you today. So many big actionable takeaways. And, also, you've even given me a few flashbacks from my IT career as well on those Sunday afternoon calls, but I wish you the best of luck for the event. I'd love to stay in touch, speak with you again later in the year, but thanks for sharing your stories today.

[00:24:35] - [Speaker 1]
Thank you for giving me the time. See you soon.

[00:24:38] - [Speaker 0]
I think, Sabina, leave CIOs with a task that is simply enough to take away. Inventory every nonhuman identity with production access. Record what it does, who owns it, and where it can go. Then choose one agent and audit its infrastructure activity. Did it reach systems that nobody expected?

[00:25:00] - [Speaker 0]
Did it test boundaries simply because the permissions allowed it? If the answer is yes to any of those, then a policy document will not contain the damage. And, also, love Sabina's comparison of agents with teenagers. Yes. Give them responsibility, but gradually keep a record of what happened, and don't just assume silence means a house is safe.

[00:25:23] - [Speaker 0]
So a massive thank you to Sabina and Broadcom for combining technical depth with some hard earned humor from her time in the field there. And remember, you can find Sabina on LinkedIn. Follow VMware Explore for her latest work. But over to you, would your infrastructure pass a one agent audit today? Food for thought.

[00:25:44] - [Speaker 0]
But that's it for today, so thank you for listening as always. Bye for now.