I spent 2 days in Washington DC last week at Identity Week America. Emre and I had booth 720 and about half the swag we planned, because British Airways kept my suitcase in London. It didn't slow the conversations down though!

Federal agencies, defense contractors and SaaS teams brought the same authorization question
DC gives this show a different crowd from other shows like Identiverse. Federal agencies, defense contractors, and the banks and SaaS companies that sell to them. What struck me was how little the conversation changed as the badges did. A government team, a defense contractor and a B2B software company would each walk up with a different system and the same problem. Who or what is asking, what is it trying to do, to which resource, in what context. Solved (or half solved) for humans, part way through for workloads, and now agents ask it a third time, faster and with less patience for a quarterly review.
So we drew the same sketch over and over. An enforcement point in front of the action, a policy decision point behind it, a log of every decision, and no interest in whether the principal is a person, a service account or a model. Same conclusion I brought back from Identiverse in June, with a more federal accent.

License to Thrill, the Identity Week America panel on AI agent governance
The panel that captured it best was "License to Thrill," on whether we can control and authorize what AI agents do in the field. George Fletcher (OpenID Foundation) moderated Andrew Ashcroft (M&T Bank), Anna Pasupathy (KeyBank), Ken Huang, Hemang Upadhyay (LG Electronics) and Donovan Blaylock (Cerby). Practitioners from regulated industries, saying from the stage what we'd been hearing at the booth.
AI agent ownership and blast radius, the leaver problem repeats for non-human identities
Donovan's team only gets called in after something has gone wrong. "We only see the unsuccessful side of the house." His word for it was blast radius. "Even if someone owns the agent, the access it has could be somebody else's." The leaver story is the one every sector recognizes. Someone resigns, and a year later you find their shared account still being used by something, because it was never tracked. Swap "shared account" for "service account" and it's the workload problem from 5 years ago. If people did the basics, "we would never get called. But we do get called."
Andy from M&T Bank was blunt about the fix. "We have to go to policy based access control. We have to be in the runtime." Assistive agents you can kill when their owner leaves ("cool, kill them, those agents go with me"). Workload agents run the business, so you need an ownership construct and, in his words, "a throat to choke when something goes wrong."
A policy enforcement point between the agent and the action, tiered by risk
Anna and Ken sketched the architecture Emre and I had been drawing all week. Bound what the agent can see, sandbox where it runs, put a policy enforcement point between the agent and the action, decide deterministically behind it. Hemang tiered it by risk. Product comparison is low. Placing a supplier order is medium, so a human in the loop and a spend threshold. Refunds are high, so approval, no exceptions. That "not yet, go get approval" outcome is a decision in its own right, and it's the shape we've been building towards. Which, yes, is the thing we sell, but the panel got there without any prompting from me.
Audit trails are still unsolved for AI agents
Audit is still unsolved, and the panel said so. Donovan's story from his own booth that morning was an ad agency whose bots posted unapproved creative to 7 platforms, with a factual error, under a contract that said nothing about AI. Working out who was accountable is "really, really hairy." And Andy's warning stands. If you haven't solved the audit log problem, you can't trust an agent to audit the agent.
What I'm taking back from Identity Week America 2026
So that's Identity Week. Governments, defense contractors and businesses at the same whiteboard, with humans, workloads and agents on it. Agents get in through identity. What they can touch is an authorization question, answered at runtime, per action, by something deterministic, with a log that says why. Ownership and audit are still open, us included, and I'd rather hear a panel admit that than pretend otherwise.
Try Cerbos to see what a runtime decision on an agent's action looks like, with the reason it was allowed or denied recorded, or book a call and we'll go through how it sits downstream of your IdP.
FAQ
Tagged in




