Authorization
2
MENTIONS
2
EPISODES
2
PODCASTS
Search complete. 2 mentions across 2 episodes found for "Authorization".
Sep 1, 2026
How to Stop a Goal-Seeking Agent From Thrashing: Travis McPeak, Security Lead at Cursor
T
21:47Travis McPeakGUEST
Like maybe I want, you know, my bot to be able to perform this action, but only on this subset of resources, you know, like as soon as you get, you can do that well in an AWS IAM, but like most other systems you can't.
T
21:57Travis McPeakGUEST
So I think part of this is just, we're going to have more permissions for these than we want, at least in the medium term until we like redo AuthZ everywhere.
T
22:06Travis McPeakGUEST
And so then it's like, okay, well, how do I control it? That would be like, you know, the review, that would be things like proxy where it just drops it conditionally, but that's also a lot of stuff to implement.
A
22:15Ali HoweHOST
Yes, it's a lot to implement.
NHI & AI Identity Summit : The New NHI Risk Reality
A
29:21Ashay RautGUEST
I would, um-- But if you haven't read the IETF draft on AI agent authentication and authorization, I would highly recommend reading that one because it just tries to cover everything at once.
A
29:31Ashay RautGUEST
That's a really good starting point.
A
29:33Ashay RautGUEST
And then you should definitely look at OpenID's AuthZ work and Shared Signals Framework work for continuous access evaluation protocol.
A
29:41Ashay RautGUEST
I'm throwing a lot of words here.
A
29:42Ashay RautGUEST
But essentially, it's OpenID and Shared Signals Framework group and IETF work.