Identity, Permissions, and Security for AI Agents | WorkOS | Arize Observe 2026 @arizeai
Identity, Permissions, and Security for AI Agents | WorkOS | Arize Observe 2026  @arizeai
Uploaded June 2026 | Updated September 2026, 2 weeks ago
As AI agents become digital coworkers, the identity and security systems that power modern software are being forced to evolve. Traditional access control models were designed for humans—not autonomous systems that can reason, act, and operate continuously across enterprise environments.

In this fireside chat, Michael Grinich, founder and CEO of WorkOS, explores the emerging challenges of agent identity, permissions, authentication, and security. The conversation covers how enterprises can safely grant agents access to tools and data, why traditional least-privilege models break down in non-deterministic systems, and what new infrastructure will be required as agents become long-running collaborators rather than simple assistants.

The discussion also dives into dynamic permissions, context management, secret handling, agent registration protocols, and the future of agent-native software. Learn why identity may become one of the most important infrastructure layers in the agent era—and what companies need to do today to prepare for a world where agents become first-class users of software systems.

Timestamps
00:00 Introduction to WorkOS and Enterprise Identity
00:59 Why AI Agents Need Their Own Identity Layer
02:22 The Security Challenges of Autonomous Agents
03:05 Permission Fatigue and Dangerous Defaults
04:14 Why Traditional Access Control Breaks for Agents
05:17 Dynamic Permission Resolution
06:05 Local Agents vs Long-Running Agents
07:04 Agent Identity and Digital Coworkers
08:24 Context as a Core Agent Capability
10:10 The Proxy Key Problem and Secret Management
11:31 Building Security Boundaries Around Agents
13:27 Agent Registration and Agent-Native Software
14:08 Introducing the Agent Registration Protocol
15:09 Why Agents May Become Your Best Customers
16:24 Designing Products for Agent Consumption
17:24 Startup Lessons and Building Durable Companies

Key Takeaways
• Traditional identity and access control systems were built for humans and must be reimagined for autonomous AI agents.
• Non-deterministic agent behavior makes static permission models insufficient, creating the need for dynamic authorization systems.
• Long-running agents require different security, identity, and permissioning approaches than local or human-assisted agents.
• Context, tools, and access are essential for agent effectiveness, but they must be balanced with strong security controls.
• As agents become first-class users of software, businesses will need new standards for agent registration, authentication, and service access.

--

#AIAgents #WorkOS #AgentIdentity #AISecurity #Authentication #EnterpriseAI #AgenticAI #DeveloperTools #AIInfrastructure #ArizeObserve

🔗 Try Arize AX & Phoenix OSS: arize.com
🔔 Subscribe for weekly content on LLMs, agents, and evaluation: youtube.com/@arizeai?sub_confirmation=1
Identity, Permissions, and Security for AI Agents | WorkOS | Arize Observe 2026How My AI Agent Rewrites Itself Overnight | Chi Wang, AG2 | Arize Observe 2026Traces and Evals Explained: The Building Blocks of AI and Agent Testing | Ep. 2Nebulocks Ron Cahlon on Building AI for CybersecurityAI Agent Mastery Certification Course: Lab 6 – Agent EvalsHarnessing Splits in your Dataset with Arize PhoenixHomework 3 for AI Evals Course: LLM-as-a-Judge
Arize AI |

Identity, Permissions, and Security for AI Agents | WorkOS | Arize Observe 2026

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER