Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Cequence: Safely Enabling Agentic AI in the Enterprise

Cequence Security
06/20/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


I'm thrilled to have Shrayans Mehta on, CTO and co-founder of Sequence Security, that's Sequence with a C. How are you, Shrayans? I'm doing great, Sean. How about you? I'm doing fabulous and I'm excited to have this conversation with you. We're going to look at AI agents and the role of agents in business and of course what they look like in terms of identities, non-human identities, I think people refer to them as. Before we get into that, a few words about your role and a word about Sequence Security. Yeah, first of all, thanks for having me here, Sean. I'm excited to chat about Sequence and our role in the world of agentic AI. So a little bit about Sequence, we've been around for some time protecting enterprise applications and data from abuse. We've been doing that for some of the largest enterprises ranging from telcos, financial institutions, retailers, pretty much anybody and everybody who has data to protect. And the world changed around us about a year ago when AI agents came into picture and it's not just humans who want to access that data and applications, but the agents on their behalf and like trying to do stuff. So Sequence expanded from not just enabling apps and data for humans and mobile apps and APIs, but how do I safely enable the same apps and data to the agents? That's fantastic. And so let's get into it here because what are you seeing when organizations of all sizes, enterprises or otherwise, they're all trying to do something with agents, right? To bring efficiencies and drive the business forward in terms of productivity and growth. What are some of the speed bumps you typically find as you talk to them? I think safe enablement is the biggest issue, right? So think about in an enterprise, your crown jewels, your apps and data, right? It could be your internal data sitting in your GitHub repositories, Confluence pages, Salesforce, ServiceNow, you name it, right? And the revolution actually started on the consumer side when ChatGPT came out, right? And people are okay connecting, making point-to-point connections from your ChatGPT and then eventually Cloud, making up, connecting to the Gmail, your personal Gmail, personal data. But when it comes to enterprise, that safe enablement, when you're opening up your crown jewels to these AI agents effectively, right, is where the challenge actually comes in. We are seeing a world where you might have like a dozen or so mini-me agents working on your behalf. On your behalf is again, very important here. And that safe enablement is the biggest challenge, right? We hear a lot of talk about, as long as you can identify your agents, you're in good shape, right? But it's much more than that. That's correct. So think about, again, I'm sort of extend the thing that I was talking about, the world of mini-me agents that are working on your behalf. It could be a simple email assistant that is sifting through your emails and then identifying which ones are important for you to read or act on. You might have a different role as well that it might be you have an SRE agent that is site reliability engineering agent that is looking at outages and trying to triage stuff. All of these things now, when you are handing it over to an agent that is working on your behalf, number one thing that you get along with it is these agents need to work with your data and they are extremely powerful, but they have a problem around, they can hallucinate, they can be prompt injected, they can go at great lengths to get a job done, right? And so these bring in a ton of challenges in that setup. So giving agent identities, you'll know that this agent is working on your behalf, but what are they actually doing once they're given that access is extremely critical. So same thing applies in here as well. So how does what you and your team have built the sequence and the support you give your customers, how does that help them overcome some of these challenges? Yeah, so think about what we need to for a full safe enablement of agentic AI. We spoke about identities, that's a must have, but it's not sufficient, right? So you want the human identity to be tied to a job, right? But what next is really, we introduced a concept what we call as an agent persona. So these mini me agents are going to do a very specific task that you want to hand them over, right? You have to start with the job description, what they're actually doing. Now, once you have that job description, what sequence does is it automatically assigns them specific access of what they need to do for their job, right? So we spoke about the mini me assistant for email, right? So email or an SRE, right? Now in case of email, even though I want this agent to have my identity assigned to it along with the agent identity, the job of that agent is to just fetch the emails that I have recently received. That means just read email access. Maybe at most also check my calendar, if there is something important that is correlated with this, but not the ability to delete emails, not the ability to send emails, right? So based on the job description, what we call as the kind of the base of everything where everything needs to start, right? And from that job description, we actually derive what kind of access does this agent actually need and assign your identity and the agent identity along with it, right? So that's effectively what we do along with MCP enablement, right? That anybody and everybody can do. But on top of it, what does that agent really need? Assigning that dynamically is what the concept of agent persona that we bring to the table as part of our Sequence AI Gateway Platform. Each company is going to have their own set of scenarios that they have to deal with. How can they connect with you, Shrans, to talk about those? I'd love to share the best practices, what I'm learning from our other large enterprises that are safely enabling this at scale, right? It's not a BOC, but at scale, how they are actually adopting it. They can connect me on LinkedIn and they can find me on LinkedIn, but they can also reach us on our website, sequence.ai. Sequence AI Gateway is a platform that I'm actually talking about. Just ask for a reach out and we'd be happy to help there. Fantastic. Well, Shrans, you're doing good work there and appreciate you sharing the story on this brand highlight. Thanks so much. Thanks for having me again, Sean. You're welcome. Thanks for having me, Sean. Thanks. Thanks. Thank you.

TL;DR

  • Enterprises face unique challenges enabling AI agents to access critical systems like GitHub, Salesforce, and ServiceNow—challenges that differ fundamentally from consumer AI use cases.
  • Agent identity alone is insufficient for security because agents can hallucinate, be prompt-injected, and pursue task completion without proper guardrails on their actions.
  • Cequence's agent persona concept dynamically assigns job-description-driven permissions, ensuring agents receive only the access needed for their specific role—like read-only email access for an email assistant.

Summary

Cequence Security CTO and Co-founder Shreyans Mehta addresses the critical challenge of safely enabling AI agents in enterprise environments. While consumer AI applications like ChatGPT have normalized point-to-point connections to personal data, enterprises face a fundamentally different problem: protecting crown jewel applications and data in GitHub, Confluence, Salesforce, and ServiceNow when multiple AI agents operate on behalf of individual users. Mehta explains that agent identity alone is insufficient for security, as agents can hallucinate, be prompt-injected, and pursue task completion at any cost. Cequence introduces the concept of agent personas—job-description-driven access controls that dynamically scope permissions based on what an agent was hired to do. An email assistant receives read access and calendar checking capabilities, but not deletion or sending privileges. This approach extends Cequence's existing work protecting applications and APIs for major telcos, banks, and retailers into the agentic AI era, where a dozen or more mini-me agents may work simultaneously on a single user's behalf.

Chapters

0:00 - Introduction
0:48 - Cequence Security Overview
2:03 - Enterprise AI Agent Challenges
3:30 - Beyond Agent Identity
5:05 - Agent Persona Concept
7:23 - Connecting with Cequence

Key Quotes

3:17 "We are seeing a world where you might have like a dozen or so mini-me agents working on your behalf."
4:34 "They are extremely powerful, but they have a problem around, they can hallucinate, they can be prompt injected, they can go at great lengths to get a job done."
5:24 "We spoke about identities, that's a must have, but it's not sufficient."

FAQ

Why isn't agent identity sufficient for securing enterprise AI agents?

Agent identity tells you who is acting and on whose behalf, but not what they should be permitted to do once inside systems. Agents can hallucinate, be prompt-injected, and go to great lengths to complete tasks, making permission scoping critical beyond just identification.

How does Cequence's agent persona concept work?

Agent personas start with a job description defining what an agent needs to do, then dynamically assign specific access based on that role. For example, an email assistant gets read access and calendar checking but not deletion or sending capabilities, ensuring agents receive only the permissions required for their intended function.


Categories:
  • » Cybersecurity » Application Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • AI & Machine Learning
  • Identity & Access
  • Application Security
  • Technical Deep Dive
  • Interview
  • Agentic AI
  • AI Agent Security
  • Non-Human Identity Management
  • Enterprise AI Governance
  • API Security
  • Permission Scoping
  • AI Gateway Platforms
  • Job-Based Access Control
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Cequence: Safely Enabling Agentic AI in the Enterprise

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Jul
                    14

                    Crafting a Championship-Caliber Security Team for Lasting Defense

                    07/14/202601:00 PM ET
                    • Jul
                      14

                      Understanding the Crucial Role of Context in Safeguarding AI-Accessible Data

                      07/14/202602:00 PM ET
                      • Jul
                        22

                        Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue

                        07/22/202601:00 PM ET
                        More events

                        Upcoming Webinar Calendar

                        • 07/14/2026
                          01:00 PM
                          07/14/2026
                          Crafting a Championship-Caliber Security Team for Lasting Defense
                          https://www.truthinit.com/index.php/channel/2025/crafting-a-championship-caliber-security-team-for-lasting-defense/
                        • 07/14/2026
                          02:00 PM
                          07/14/2026
                          Understanding the Crucial Role of Context in Safeguarding AI-Accessible Data
                          https://www.truthinit.com/index.php/channel/2037/understanding-the-crucial-role-of-context-in-safeguarding-ai-accessible-data/
                        • 07/21/2026
                          04:00 AM
                          07/21/2026
                          Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                          https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
                        • 07/22/2026
                          06:30 AM
                          07/22/2026
                          Insights and Strategies in Data Protection and Privacy Management
                          https://www.truthinit.com/index.php/channel/2000/insights-and-strategies-in-data-protection-and-privacy-management/
                        • 07/22/2026
                          01:00 PM
                          07/22/2026
                          Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue
                          https://www.truthinit.com/index.php/channel/2029/insights-from-attackers-during-the-fifa-world-cup-a-human-dialogue/
                        • 07/28/2026
                          01:00 PM
                          07/28/2026
                          Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                          https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                        • 07/29/2026
                          04:00 AM
                          07/29/2026
                          Real-Time Strategies for Safeguarding Against Prompt Injections
                          https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                        • 07/29/2026
                          01:00 PM
                          07/29/2026
                          Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                          https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                        • 08/19/2026
                          12:00 PM
                          08/19/2026
                          Becoming Agent Ready: Insights from Cyera's Expertise
                          https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-from-cyeras-expertise/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version