Uploaded November 2025 | Updated September 2026, 9 hours ago
Formal founder Mokhtar Bacha explains how least‑privilege and PAM are returning to the spotlight with AI agents. He describes granular, policy‑driven guardrails for human and AI identities, why RBAC alone isn’t enough for MCP tools, and why systems should enforce guardrails regardless of whether code came from a human or an AI.
CHAPTERS:
0:03 - Intro: Formal and least privilege at scale
0:30 - Principle of least privilege and reducing blast radius
1:45 - PAM returns with AI identities (Okta, Palo Alto acquisitions)
2:13 - Fitting PAM for AI: cover human and AI identities
2:35 - Per‑agent policies; tool/data guardrails; granular examples
3:25 - Why RBAC alone falls short for many MCP tools
4:14 - Strict controls and guardrails; where Formal shines
4:26 - Humans vs agents blend; focus on system guardrails
5:02 - PR approval guardrails over provenance of code
5:59 - AI already blended into SaaS; provenance becomes moot
6:38 - Enterprise Ready Conf experience and details
Formal founder Mokhtar Bacha explains how least‑privilege and PAM are returning to the spotlight with AI agents. He describes granular, policy‑driven guardrails for human and AI identities, why RBAC alone isn’t enough for MCP tools, and why systems should enforce guardrails regardless of whether code came from a human or an AI.
CHAPTERS:
0:03 - Intro: Formal and least privilege at scale
0:30 - Principle of least privilege and reducing blast radius
1:45 - PAM returns with AI identities (Okta, Palo Alto acquisitions)
2:13 - Fitting PAM for AI: cover human and AI identities
2:35 - Per‑agent policies; tool/data guardrails; granular examples
3:25 - Why RBAC alone falls short for many MCP tools
4:14 - Strict controls and guardrails; where Formal shines
4:26 - Humans vs agents blend; focus on system guardrails
5:02 - PR approval guardrails over provenance of code
5:59 - AI already blended into SaaS; provenance becomes moot
6:38 - Enterprise Ready Conf experience and details










