Agents are redefining sensitive access...P0 is using AI to extend coverage just as fast

Resource | Webinar

The identity layers behind AI agent access

Why governing AI agents starts with the identities and permissions they inherit.

 

August 20 is National Bacon Day, so we leaned in! Every AI agent action has three layers: the Bot, the Launcher and the Target. That is the BLT problem of agent access (see what we did there?). The BLT problem (Bot, Launcher, Target) is a useful frame for what makes agentic access hard. But it understates where most teams are actually exposed right now.

If agent deployments have access controls in place, they are typically live at the MCP layer: they filter which tools the agent can call, maybe which resources it can name. What they critically miss is the entitlement underneath, the shared service account or delegated human permissions the agent actually uses to act. There is no context about who triggered the session or the business intent for the task at hand. It just has access, usually far more and long lasting than any single job requires.

You cannot govern the agent without understanding who or what invoked it and what system it is trying to access.

When those identity layers carry standing privilege, stale access or poorly scoped credentials, the agent inherits a bad baseline, and no tool-level filter catches the gap. This 30-minute session covers why controlling what an agent can call is not the same as controlling what it can do, and how just-in-time access and Zero Standing Privilege give you a model where the credential itself enforces the grant.

 

What you will learn:

  • Why every agent action is a BLT event: bot, launcher and target
  • Why tool filtering is not access control, and where the real exposure lives
  • How standing privilege and shared credentials undermine agent governance before it starts
  • Where attribution breaks down when users, NHIs and agents are managed in siloes
  • How just-in-time access and automated approval workflows create a sustainable Zero Standing Privilege model
  • How to assess whether your current identity baseline is strong enough for enforceable agent policy

Who should watch:

  • Security and identity teams deploying or preparing to deploy AI agents for the workforce who want to understand how human and NHI access hygiene strengthens and enables effective agentic access control.

As Chief Product Officer of P0 Security, Neha Duggal has deep expertise in cloud security, observability, and enterprise SaaS. With more than 15 years of experience, she has led multiple products from early concept to wide-scale customer adoption, built high-performing cross-functional teams, and driven product strategies that delivered measurable business outcomes. She has a track record of launching differentiated security capabilities, improving product-market fit, and guiding organizations through periods of rapid growth and transformation.

Gergely Dányi is the co-founder and Chief Technology Officer at P0 Security, where he leads the development of the first unified identity governance and privileged access management platform purpose-built for the cloud. With deep expertise in cloud security, access management, and startup execution, he’s driving a modern approach that replaces fragmented legacy tools with an identity-native platform that governs and secures all forms of access across hybrid environments. Gergely’s work at P0 centers on eliminating privilege sprawl and enabling just-in-time, policy-driven controls that scale with today’s complex infrastructure, and he’s recognized for pushing the boundaries of how organizations think about secure access in the cloud era.