Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Claroty: AI Agent Guardrails & Non-Human Identity Controls

Claroty
08/23/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


is what we're calling like guardrails, right? And guardrails in the sense of, you can almost think about it if you've ever gone bowling, right? And you think about like putting up kind of the bumper rails, right? Where you can't get the ball into the guard. Kind of the same thing, right? Like how can you allow people to move fast with agents, but also make it so agents can only do what you expect them to do, or at least have kind of a bounding box around them. And this is where we see some of the IDP vendors, right? Like Okta and Entra trying to say like, hey, well, we've kind of had this idea about humans in an IDP for a long time, but non-humans are not in your IDP, right? They have direct access to these environments. And so now we're seeing some codification by the IDP vendors to say, oh, you should also provision your non-human identities or AI agent identities inside of your IDP. So you can start to apply the same type of policies or guardrails that you would around your humans. I think the challenge that we're seeing there is number one, if you're just somebody that works at a company, you can just give your credentials to an LLM or an agent, and it's gonna operate with your credentials, right? And so that's where trying to figure out like, hey, is the activity that we're seeing from this identity still human? Or do we think an LLM is operating with that human's account and it's actually AI behind the scenes? And so that's some of the stuff that we actually do today in our product so that you can kind of see like, wait, this was a human kind of doing click-offs. All of a sudden it's now LLM activity. So is that an adversary doing that? Or is that a person who actually delegated to an LLM to go do a task for them?

TL;DR

  • Traditional IdPs like Okta and Entra were designed for human identities, leaving AI agents and non-human identities with uncontrolled direct access to enterprise environments.
  • Security guardrails — analogous to bowling bumper rails — are needed to let AI agents operate quickly while constraining them to expected, authorized actions only.
  • A critical blind spot exists when employees hand their own credentials to an LLM, making it impossible to tell whether account activity is human or AI-driven without specialized detection.

Summary

In this short clip from the Nexus Podcast, John Laliberte, CEO of ClearVector, outlines a pressing security challenge: as AI agents proliferate inside enterprise environments, traditional Identity Providers (IdPs) like Okta and Microsoft Entra were built exclusively around human credentials — leaving non-human and AI agent identities with direct, unmonitored access to sensitive systems. Laliberte uses a bowling bumper analogy to explain the concept of guardrails: controls that allow teams to move fast with AI agents while constraining those agents to only expected, authorized behaviors. He notes that IDP vendors are beginning to codify non-human identity provisioning, but a critical gap remains — employees can simply hand their own credentials to an LLM, which then operates autonomously under a human identity. ClearVector addresses this by detecting whether observed account activity reflects genuine human behavior or an LLM acting on a person's behalf, helping security teams distinguish between legitimate AI delegation and potential adversarial misuse of human credentials.

Chapters

0:00 - The Guardrails Concept
0:21 - IDP Vendors Respond
0:51 - The Credential Delegation Problem
1:15 - ClearVector's Detection Approach

Key Quotes

0:12 "How can you allow people to move fast with agents, but also make it so agents can only do what you expect them to do, or at least have kind of a bounding box around them."
0:30 "Non-humans are not in your IDP, right? They have direct access to these environments."
0:55 "You can just give your credentials to an LLM or an agent, and it's gonna operate with your credentials."
1:04 "Is the activity that we're seeing from this identity still human? Or do we think an LLM is operating with that human's account and it's actually AI behind the scenes? ..."

FAQ

Why can't existing IdPs like Okta or Entra handle AI agent identities today?

Traditional IdPs were designed around human credentials and provisioning workflows. Non-human identities — including AI agents — typically have direct access to environments outside of IDP governance, meaning the same policy controls applied to human accounts do not extend to them.

What happens when an employee gives their credentials to an AI agent?

The AI agent operates under the employee's human identity, making its activity indistinguishable from normal human behavior without specialized detection. ClearVector claims to identify this shift — flagging when an account transitions from human click-based activity to LLM-driven behavior.


Categories:
  • » Cybersecurity » Zero Trust
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Identity & Access
  • AI & Machine Learning
  • Zero Trust
  • Security Operations
  • Getting Started
  • podcast
  • Non-human identity security
  • AI agent governance
  • Identity and access management
  • LLM credential misuse
  • Security guardrails
  • Enterprise AI risk
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Claroty: AI Agent Guardrails & Non-Human Identity Controls

              Industry Events (Sponsor Hosted)

              • Sep
                17

                Bridging the SaaS Protection Gap: Preventing Data Loss and AI Missteps

                09/17/202610:00 AM ET
                • Sep
                  17

                  The Automation Escalation: Discovering the AI-Driven Underground Revolution

                  09/17/202601:00 PM ET
                  • Sep
                    23

                    Invisible Data: Understanding What You Can't Safeguard

                    09/23/202601:00 PM ET
                    More events

                    Upcoming Webinar Calendar

                    • 09/17/2026
                      10:00 AM
                      09/17/2026
                      Bridging the SaaS Protection Gap: Preventing Data Loss and AI Missteps
                      https://www.truthinit.com/index.php/channel/2119/bridging-the-saas-protection-gap-preventing-data-loss-and-ai-missteps/
                    • 09/17/2026
                      01:00 PM
                      09/17/2026
                      The Automation Escalation: Discovering the AI-Driven Underground Revolution
                      https://www.truthinit.com/index.php/channel/2108/the-automation-escalation-discovering-the-ai-driven-underground-revolution/
                    • 09/23/2026
                      01:00 PM
                      09/23/2026
                      Invisible Data: Understanding What You Can't Safeguard
                      https://www.truthinit.com/index.php/channel/2087/invisible-data-understanding-what-you-cant-safeguard/
                    • 09/29/2026
                      12:00 PM
                      09/29/2026
                      Embracing AI Adoption While Ensuring Robust Security Measures
                      https://www.truthinit.com/index.php/channel/2092/embracing-ai-adoption-while-ensuring-robust-security-measures/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Enhancing Visibility and Control in Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-enhancing-visibility-and-control-in-operations/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version