Identity, Least Privilege, and Audit for AI Agents with IBM Verify Identity Access and HashiCorp Vault

Sponsored By:
Tuesday, October 1st
3:00 PM ET
‼️NOTICE: This workshop includes hands-on exercises using AWS. To fully participate, attendees must have access to an active AWS account prior to the session. Because the workshop follows a guided self-paced format, an AWS account is required to complete the exercises alongside the presenters. We recommend creating and validating your AWS account before the event to ensure the best experience.
AI agents break the assumptions security tooling has relied on for two decades. An agent is neither a human persona nor a classic workload — it acts on its own behalf one moment and on behalf of a user the next, and bearer tokens with hard-coded scopes and standing database GRANTs don’t compose across that moving boundary. When something goes wrong, “which user authorized this action?” is unanswerable across IDP, secrets, and database logs that share no correlation key.
This hands-on workshop deploys a working reference implementation of five control objectives for agentic systems — verifiable agent identity, no standing privileges, actions tied to user intent, enforcement at the point of use, and audit evidence correlated across all three trust planes (user, workload, data) — using IBM Verify Identity Access and HashiCorp Vault on Amazon EKS. Against a realistic banking application, you build and inspect three progressively-layered AI agents:
1. A non-personalized read-only agent on pure workload identity with just-in-time Vault credentials.
2. An OAuth Authorization Code + PKCE personalized agent that propagates user identity down to per-row database isolation.
3. A privileged refund agent requiring out-of-band human approval via OIDC CIBA, proving delegation and rich authorization with RFC 8693 token exchange and RFC 9396 RAR, and producing a single audit row correlating IBM Verify, Vault, and PostgreSQL on one request ID.
You leave understanding the security primitives at the layer enforcement actually happens — and how they map to Vault’s newly announced native AI-agent authorization model.
Register Below:

Oscar Medina
Technical Field Strategy Director - IBM

Claudia Cornali-Motta
Sr Product Manager - Vault - IBM
