Why Agents Break Your Access Control — Umaimah Khan, Opal Security | Enterprise Ready Conf 2025 @WorkOS
Why Agents Break Your Access Control — Umaimah Khan, Opal Security | Enterprise Ready Conf 2025  @WorkOS
Uploaded November 2025 | Updated September 2026, 2 days ago
Opal Security CEO Umaimah Khan argues authorization has been under‑invested compared to authentication—and that the rise of agents makes access control the first domino to fall. She discusses MCP, JIT, dynamic access beyond RBAC, and founder advice for balancing productivity and risk as enterprises adopt AI from much smaller teams.

CHAPTERS:
0:04 - Intro: Opal Security and intelligent access controls
0:23 - Who/what/how: tying identity and access together
1:03 - We solved authn; authz was ignored in fast‑moving teams
1:54 - Agents create a pivot point for authorization
2:24 - Prior tectonic shift (cloud); now identity/access will shift first
3:05 - First to fall: access control before governance
3:30 - Reactive controls: MCP auth, JIT; early and messy
3:50 - “Printer driver” analogy; standards likely from model providers
4:12 - Expect new attack vectors while building fast
6:00 - Who is “you” with thousands of agents? Identity persists
6:56 - RBAC as a building block; dynamic, context‑aware access
8:03 - Security as judgment; need dynamic systems making calls
10:26 - Advice: weigh productivity vs risk early; hard to rip systems later
Why Agents Break Your Access Control — Umaimah Khan, Opal Security | Enterprise Ready Conf 2025Can Your AI Survive Crashes? Fault-Tolerant Gen Code — Maxim Fateev, Temporal | HumanX 2026AI Is Rewriting Healthcares Hidden Layer — Zack Kanter, Stedi | re:Invent 2025Live July 20Agent Night: Is AGI Already Here? Jaya Gupta, Flo Crivello & swyx on AI AgentsLower Your Incident Cost to Ship Faster — Chris Evans, Incident.io | re:Invent 202510x the Tokens, Only 2x the Output — Nicholas Arcolano, Jellyfish | AI Engineer Worlds Fair 2026Dwarkesh Patel | Dwarkesh Unplugged presented by WorkOSThe Danger of Giving AI MetricsWhy AI Agents Can’t Run Your Business (Yet) — Colin Zima, Omni | HumanX 2026The Secret to AI AutomationAudit Harness: An Audit Trail for AI Coding Agents (No API Keys Required)
WorkOS |

Why Agents Break Your Access Control — Umaimah Khan, Opal Security | Enterprise Ready Conf 2025

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER