Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Cequence: Safely Enabling Agentic AI in the Enterprise

Cequence Security
06/20/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


I'm thrilled to have Shrayans Mehta on, CTO and co-founder of Sequence Security, that's Sequence with a C. How are you, Shrayans? I'm doing great, Sean. How about you? I'm doing fabulous and I'm excited to have this conversation with you. We're going to look at AI agents and the role of agents in business and of course what they look like in terms of identities, non-human identities, I think people refer to them as. Before we get into that, a few words about your role and a word about Sequence Security. Yeah, first of all, thanks for having me here, Sean. I'm excited to chat about Sequence and our role in the world of agentic AI. So a little bit about Sequence, we've been around for some time protecting enterprise applications and data from abuse. We've been doing that for some of the largest enterprises ranging from telcos, financial institutions, retailers, pretty much anybody and everybody who has data to protect. And the world changed around us about a year ago when AI agents came into picture and it's not just humans who want to access that data and applications, but the agents on their behalf and like trying to do stuff. So Sequence expanded from not just enabling apps and data for humans and mobile apps and APIs, but how do I safely enable the same apps and data to the agents? That's fantastic. And so let's get into it here because what are you seeing when organizations of all sizes, enterprises or otherwise, they're all trying to do something with agents, right? To bring efficiencies and drive the business forward in terms of productivity and growth. What are some of the speed bumps you typically find as you talk to them? I think safe enablement is the biggest issue, right? So think about in an enterprise, your crown jewels, your apps and data, right? It could be your internal data sitting in your GitHub repositories, Confluence pages, Salesforce, ServiceNow, you name it, right? And the revolution actually started on the consumer side when ChatGPT came out, right? And people are okay connecting, making point-to-point connections from your ChatGPT and then eventually Cloud, making up, connecting to the Gmail, your personal Gmail, personal data. But when it comes to enterprise, that safe enablement, when you're opening up your crown jewels to these AI agents effectively, right, is where the challenge actually comes in. We are seeing a world where you might have like a dozen or so mini-me agents working on your behalf. On your behalf is again, very important here. And that safe enablement is the biggest challenge, right? We hear a lot of talk about, as long as you can identify your agents, you're in good shape, right? But it's much more than that. That's correct. So think about, again, I'm sort of extend the thing that I was talking about, the world of mini-me agents that are working on your behalf. It could be a simple email assistant that is sifting through your emails and then identifying which ones are important for you to read or act on. You might have a different role as well that it might be you have an SRE agent that is site reliability engineering agent that is looking at outages and trying to triage stuff. All of these things now, when you are handing it over to an agent that is working on your behalf, number one thing that you get along with it is these agents need to work with your data and they are extremely powerful, but they have a problem around, they can hallucinate, they can be prompt injected, they can go at great lengths to get a job done, right? And so these bring in a ton of challenges in that setup. So giving agent identities, you'll know that this agent is working on your behalf, but what are they actually doing once they're given that access is extremely critical. So same thing applies in here as well. So how does what you and your team have built the sequence and the support you give your customers, how does that help them overcome some of these challenges? Yeah, so think about what we need to for a full safe enablement of agentic AI. We spoke about identities, that's a must have, but it's not sufficient, right? So you want the human identity to be tied to a job, right? But what next is really, we introduced a concept what we call as an agent persona. So these mini me agents are going to do a very specific task that you want to hand them over, right? You have to start with the job description, what they're actually doing. Now, once you have that job description, what sequence does is it automatically assigns them specific access of what they need to do for their job, right? So we spoke about the mini me assistant for email, right? So email or an SRE, right? Now in case of email, even though I want this agent to have my identity assigned to it along with the agent identity, the job of that agent is to just fetch the emails that I have recently received. That means just read email access. Maybe at most also check my calendar, if there is something important that is correlated with this, but not the ability to delete emails, not the ability to send emails, right? So based on the job description, what we call as the kind of the base of everything where everything needs to start, right? And from that job description, we actually derive what kind of access does this agent actually need and assign your identity and the agent identity along with it, right? So that's effectively what we do along with MCP enablement, right? That anybody and everybody can do. But on top of it, what does that agent really need? Assigning that dynamically is what the concept of agent persona that we bring to the table as part of our Sequence AI Gateway Platform. Each company is going to have their own set of scenarios that they have to deal with. How can they connect with you, Shrans, to talk about those? I'd love to share the best practices, what I'm learning from our other large enterprises that are safely enabling this at scale, right? It's not a BOC, but at scale, how they are actually adopting it. They can connect me on LinkedIn and they can find me on LinkedIn, but they can also reach us on our website, sequence.ai. Sequence AI Gateway is a platform that I'm actually talking about. Just ask for a reach out and we'd be happy to help there. Fantastic. Well, Shrans, you're doing good work there and appreciate you sharing the story on this brand highlight. Thanks so much. Thanks for having me again, Sean. You're welcome. Thanks for having me, Sean. Thanks. Thanks. Thank you.

TL;DR

  • Enterprises face unique challenges enabling AI agents to access critical systems like GitHub, Salesforce, and ServiceNow—challenges that differ fundamentally from consumer AI use cases.
  • Agent identity alone is insufficient for security because agents can hallucinate, be prompt-injected, and pursue task completion without proper guardrails on their actions.
  • Cequence's agent persona concept dynamically assigns job-description-driven permissions, ensuring agents receive only the access needed for their specific role—like read-only email access for an email assistant.

Summary

Cequence Security CTO and Co-founder Shreyans Mehta addresses the critical challenge of safely enabling AI agents in enterprise environments. While consumer AI applications like ChatGPT have normalized point-to-point connections to personal data, enterprises face a fundamentally different problem: protecting crown jewel applications and data in GitHub, Confluence, Salesforce, and ServiceNow when multiple AI agents operate on behalf of individual users. Mehta explains that agent identity alone is insufficient for security, as agents can hallucinate, be prompt-injected, and pursue task completion at any cost. Cequence introduces the concept of agent personas—job-description-driven access controls that dynamically scope permissions based on what an agent was hired to do. An email assistant receives read access and calendar checking capabilities, but not deletion or sending privileges. This approach extends Cequence's existing work protecting applications and APIs for major telcos, banks, and retailers into the agentic AI era, where a dozen or more mini-me agents may work simultaneously on a single user's behalf.

Chapters

0:00 - Introduction
0:48 - Cequence Security Overview
2:03 - Enterprise AI Agent Challenges
3:30 - Beyond Agent Identity
5:05 - Agent Persona Concept
7:23 - Connecting with Cequence

Key Quotes

3:17 "We are seeing a world where you might have like a dozen or so mini-me agents working on your behalf."
4:34 "They are extremely powerful, but they have a problem around, they can hallucinate, they can be prompt injected, they can go at great lengths to get a job done."
5:24 "We spoke about identities, that's a must have, but it's not sufficient."

FAQ

Why isn't agent identity sufficient for securing enterprise AI agents?

Agent identity tells you who is acting and on whose behalf, but not what they should be permitted to do once inside systems. Agents can hallucinate, be prompt-injected, and go to great lengths to complete tasks, making permission scoping critical beyond just identification.

How does Cequence's agent persona concept work?

Agent personas start with a job description defining what an agent needs to do, then dynamically assign specific access based on that role. For example, an email assistant gets read access and calendar checking but not deletion or sending capabilities, ensuring agents receive only the permissions required for their intended function.


Categories:
  • » Cybersecurity » Application Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • AI & Machine Learning
  • Identity & Access
  • Application Security
  • Technical Deep Dive
  • Interview
  • Agentic AI
  • AI Agent Security
  • Non-Human Identity Management
  • Enterprise AI Governance
  • API Security
  • Permission Scoping
  • AI Gateway Platforms
  • Job-Based Access Control
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Cequence: Safely Enabling Agentic AI in the Enterprise

              Upcoming Webinar Calendar

              • 06/23/2026
                01:00 PM
                06/23/2026
                The AI-Powered VMware Alternative
                https://www.truthinit.com/index.php/channel/2009/the-ai-powered-vmware-alternative/
              • 06/24/2026
                11:00 AM
                06/24/2026
                LATAM: Accelerating Insights on AI Through an Engaging Webinar Series
                https://www.truthinit.com/index.php/channel/2012/accelerating-insights-on-ai-through-an-engaging-webinar-series/
              • 06/25/2026
                01:00 PM
                06/25/2026
                Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier
                https://www.truthinit.com/index.php/channel/1998/generative-ai-security-preventing-ai-from-becoming-a-data-breach-multiplier/
              • 06/30/2026
                01:00 PM
                06/30/2026
                Mastering Active Directory Certificate Services for Long-Term Success
                https://www.truthinit.com/index.php/channel/2018/mastering-active-directory-certificate-services-for-long-term-success/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Integrating Security in AI: Automated Red Teaming Strategies for Private Models
                https://www.truthinit.com/index.php/channel/1969/integrating-security-in-ai-automated-red-teaming-strategies-for-private-models/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Schutz von KI in Anwendungen, Agenten und APIs.
                https://www.truthinit.com/index.php/channel/2008/schutz-von-ki-in-anwendungen-agenten-und-apis/
              • 07/01/2026
                01:00 PM
                07/01/2026
                How to Prevent Your AI from Taking Control of You
                https://www.truthinit.com/index.php/channel/2021/how-to-prevent-your-ai-from-taking-control-of-you/
              • 07/02/2026
                10:00 AM
                07/02/2026
                When the cloud goes dark: Resilience lessons from hybrid threats
                https://www.truthinit.com/index.php/channel/2011/resilience-insights-from-hybrid-threats-when-the-cloud-faces-challenges/
              • 07/07/2026
                01:00 PM
                07/07/2026
                A Comprehensive Demonstration of DLP Solutions and Strategies
                https://www.truthinit.com/index.php/channel/2030/a-comprehensive-demonstration-of-dlp-solutions-and-strategies/
              • 07/09/2026
                01:00 PM
                07/09/2026
                Agentic Trust in Practice: Enhancing the Human Experience
                https://www.truthinit.com/index.php/channel/2026/agentic-trust-in-practice-enhancing-the-human-experience/
              • 07/14/2026
                11:00 AM
                07/14/2026
                Discover the Latest Innovations in Netwrix 1Secure During This Technical Session
                https://www.truthinit.com/index.php/channel/2014/discover-the-latest-innovations-in-netwrix-1secure-during-this-technical-session/
              • 07/21/2026
                04:00 AM
                07/21/2026
                Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
              • 07/21/2026
                01:00 PM
                07/21/2026
                HUMAN Dialogue: Insights from Attackers Revealed at the FIFA World Cup
                https://www.truthinit.com/index.php/channel/2029/human-dialogue-insights-from-attackers-revealed-at-the-fifa-world-cup/
              • 07/22/2026
                06:30 AM
                07/22/2026
                Understanding the Dynamics of Data Privacy and Protection Regulations
                https://www.truthinit.com/index.php/channel/2000/understanding-the-dynamics-of-data-privacy-and-protection-regulations/
              • 07/28/2026
                01:00 PM
                07/28/2026
                Illumio: Zero Trust in the Age of AI Autonomy
                https://www.truthinit.com/index.php/channel/2031/illumio-zero-trust-in-the-age-of-ai-autonomy/
              • 07/29/2026
                04:00 AM
                07/29/2026
                Real-Time Strategies for Safeguarding Against Prompt Injections
                https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
              • 09/30/2026
                04:00 AM
                09/30/2026
                AI Command Center: Optimizing Visibility and Control in Your Operations
                https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/

              Upcoming Events

              • Jun
                23

                The AI-Powered VMware Alternative

                06/23/202601:00 PM ET
                • Jun
                  24

                  LATAM: Accelerating Insights on AI Through an Engaging Webinar Series

                  06/24/202611:00 AM ET
                  • Jun
                    25

                    Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier

                    06/25/202601:00 PM ET
                    • Jun
                      30

                      Mastering Active Directory Certificate Services for Long-Term Success

                      06/30/202601:00 PM ET
                      • Jul
                        01

                        Schutz von KI in Anwendungen, Agenten und APIs.

                        07/01/202604:00 AM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version