IEEE CTS CTCN/LMAG Zoom Meeting, 8-20-2026, "The Agent Is an Identity: Why AI Agents Need Least Privilege, Limited Access, and Runtime Checks"
This is a Zoom meeting starting at 6:30 PM Central Std. Time.
AI agents are starting to do more than answer questions. They can search systems, choose tools, update records, trigger workflows, and make changes in business applications.
Once an agent can take action, it should be treated like a system identity. It needs its own identity, a clear owner, limited permissions, and rules that control what it can do.
This talk uses a simple employee-badge analogy to explain the idea. An agent is like an employee or contractor, and its identity is the badge. Least privilege means the badge opens only the doors needed for the job. Bounded access means it works only in the right building, on the right floor, for the right task, and for a limited time.
The session also explains why every action should be checked at runtime, why the target system must still protect its own resources, why access should be short-lived, and why every agent action needs a clear audit trail.
Attendees will leave with a practical way to think about AI agent security: treat the agent as an identity, limit its authority, and check every action before it reaches an enterprise system.
Date and Time
Location
Hosts
Registration
-
Add Event to Calendar
Loading virtual attendance info...
Speakers
Venkata Patelkhana
The Agent Is an Identity: Why AI Agents Need Least Privilege, Limited Access, and Runtime Checks
AI agents are starting to do more than answer questions. They can search systems, choose tools, update records, trigger workflows, and make changes in business applications.
Once an agent can take action, it should be treated like a system identity. It needs its own identity, a clear owner, limited permissions, and rules that control what it can do.
This talk uses a simple employee-badge analogy to explain the idea. An agent is like an employee or contractor, and its identity is the badge. Least privilege means the badge opens only the doors needed for the job. Bounded access means it works only in the right building, on the right floor, for the right task, and for a limited time.
The session also explains why every action should be checked at runtime, why the target system must still protect its own resources, why access should be short-lived, and why every agent action needs a clear audit trail.
Attendees will leave with a practical way to think about AI agent security: treat the agent as an identity, limit its authority, and check every action before it reaches an enterprise system.
Biography:
Venkata Phani Patelkhana is an IEEE Senior Member , with more than 19 years of experience in enterprise API platforms, distributed systems, API security, and agentic AI architectures.
His current work focuses on AI control planes, MCP gateways, agent identity, runtime authorization, and helping enterprises transition safely from API-first to agent-first ecosystems. He holds patents related to decentralized API gateway architectures and regularly writes and speaks about practical approaches to securing and governing enterprise API and AI ecosystems.
Email:
Address:Round Rock, Texas, United States
Agenda
The Life Members Affinity Group and Austin Consultants Network Affinity Group (CTCN) meets monthly. Except when meeting jointly with other groups, the CTCN meet on the third Thursday each month. Meetings usually begin with informal networking from 6:25 to 6:40 p.m., followed by presentations from 6:40 to 7:55 p.m. by experts in topics of interest to IEEE Members. Our meetings are open to the public.
Light refreshments may be available during in person meetings.