About
I've spent over 10 years working in identity and security, and I'm really passionate about helping people understand and navigate cyber safety. I love diving deep into new things in this space and sharing that knowledge to keep others safe online.
Session
"On Behalf of Whom?" How to Safely Propagate Identity in Multi-Agent Workflows
TalkSay you're asking a chatbot AI to address a billing issue with your account. That AI does its thing by starting three other microservices in the background to retrieve your information, query your records and update the system for you. But as the frameworks behind these Agent-to-Agent (A2A) workflows are gaining adoption (via open-source protocols like the A2A protocol), it raises one of the biggest security questions imaginable: how can your backend systems trust which user approved an AI agent to perform that work? In the process of one agent kicking off another agent, all context about the human user gets deleted in the first jump — it gets translated into a "machine key" by the first AI agent. The result is the nightmare scenarios of systems being exposed to accidental information leaks or unauthorized use. This talk cuts through code to describe a common, working example of how we can safely pass a "security baton" from a person to an agent and back, even to another agent.
Speaking at
- View event →
Cloud Native AI Summit — Melbourne
October 28–29, 2026
