Session Presented by NewCore Identity: AI Agents Are Being Authorized Without Accountability. Let's Fix That.
Tuesday, November 10, 2026, 4:15 PM - 4:40 PM
Michael Silva

Agents are already operating against enterprise systems. Most of them got there on borrowed credentials: a cloned service account, a pasted API key, an OAuth grant a developer approved on a Tuesday. The agent holds no identity of its own, so nothing it does is attributable, and nothing it does can be controlled separately from whatever it borrowed.
This session walks through a model that fixes that.

NewCore serves as the central control point, acting as the identity provider for humans and agents alike and issuing every agent its own credentials. Attribution stops being something you reconstruct after the incident. Authorization is granted just in time and scoped to the task rather than held standing. Standing access is what gets stolen, and it allows an agent to do something other than the job it was given.

The human stays in the loop only where control genuinely requires it. Legacy tooling puts a person in front of every step, which removes most of the reason to deploy an agent in the first place.

We will cover the architecture, the failure modes, and what must hold true at scale.

Salon B & C
MGM National Harbor Hotel
101 MGM National Ave
Oxon Hill, MD 20745
United States
Session