Ep 98 · May 7, 2026 · 44 min

Who Let All the Agents In? Securing the Agentic Era

Nick Lippis with Tom Gillis, SVP & GM, Infrastructure & Security Group at Cisco, and Matt Caulfield, VP of Product, Identity at Cisco

Prefer audio? Listen on
Who Let All the Agents In? Securing the Agentic Era — watch on YouTube

About this episode

How do you secure AI agents that have no passwords, no MFA tokens, and no biometrics, and why is that a networking problem rather than a pure security problem? In this episode, ONUG co-founder Nick Lippis talks with Cisco's Tom Gillis, who leads infrastructure and security, and Matt Caulfield, who leads the identity portfolio, about the agentic era now arriving inside enterprises. Agents are proliferating faster than any technology the industry has seen, often without IT knowing they exist, while the build-versus-buy curve has flipped: large enterprises, especially big financials, are pausing enterprise software purchases and pointing their own dev teams at AI tools instead. CISOs face board mandates to move fast on AI while agents run on human credentials with, as Gillis puts it, the access of a human and the common sense of a printer.

The conversation lands on a clear architectural answer. Authenticating an agent is the easy part, since certificates and cryptographically assured machine identity are well understood; the hard part is authorization, deciding what each agent may access and what it may do with that access. Because endpoints cannot be controlled, the only place to enforce that is in the network path, through a protocol-agnostic proxy or gateway choke point that sits between agents and the resources they touch, whether MCP servers, REST APIs, websites, or LLM endpoints, distributed across cloud and on-prem.

What we cover in this episode

  1. Agents are proliferating faster than IT can see. Agents and sandboxes are spreading through organizations the way departmental networks once did, while large enterprises shift from buying software to building it with AI tools, and CISOs face board pressure to adopt agentic AI they are not yet confident they can secure.
  2. Access of a human, common sense of a printer. Agents often run on human credentials with long-lasting, broad access but no judgment, so Gillis argues the industry needs an access control policy somewhere between what it gives printers and what it gives humans, and that access control is a network function.
  3. Authorization, not authentication, is the hard problem. Caulfield explains that authenticating an agent is straightforward with certificates and cryptography, but deciding what a persistent agent should access and what it may do with that access is a fine-grained authorization problem the industry has deferred for decades.
  4. The proxy gateway choke point. The framework discovers every agent, authorizes every action, and monitors behavior continuously, enforced through a protocol-agnostic proxy in the path between agents and resources, distributed across cloud and on-prem, that inspects every MCP, HTTPS, and LLM request at Layer 7.
  5. Non-human identity and delegated permissions. Rather than sharing passwords, users can delegate a subset of their permissions to an agent through standards like OAuth 2.1 on-behalf-of flows, while process-level identity distinguishes the human on a machine from the agent running beside them, designed for post-quantum cryptography from the start.
  6. Reasoning-based policy: AI policing AI. Static rule lists fail because an agent told not to buy a Porsche will buy a McLaren instead, so policy enforcement relies on small targeted security models doing anomaly detection on agent behavior, which improves as more customers contribute patterns.
  7. How network engineers start the conversation. Combining identity data, network telemetry, and logs yields most of the visibility needed to inventory the agents already in an environment, and that discovery report is the concrete opening for network teams to engage their identity and security peers.

The lines worth sharing

“The agent has the access of a human, but the common sense of a printer.”

Tom Gillis

“Authorization, more so even than authentication, becomes a problem. Not who is the agent, but what should that agent have access to, and what should it be allowed to do with that access?”

Matt Caulfield

“You can only solve that problem with reasoning. You're not going to solve that problem with a static list of rules.”

Tom Gillis

Common questions from this episode

Why is securing AI agents a networking problem?

Because endpoints cannot be controlled: agents pop up on laptops, in the cloud, in SaaS services, even on printers and Raspberry Pis. The only common point between every agent and every resource it touches, whether an MCP server, a REST API, a website, or an LLM endpoint, is the network path, so the network is where identity checks and fine-grained authorization have to be enforced.

How do you authenticate and authorize AI agents that have no passwords or MFA?

Authentication is the easier half: agents can be issued certificates or verifiable credentials, and cryptographically assured machine identity is a well-understood problem. The hard half is authorization, deciding what a persistent, workaround-prone agent may access and what it may do with that access, which requires delegating a subset of a user's permissions rather than sharing credentials, for example letting an agent read an inbox but not send email.

What is an AI agent gateway or proxy architecture?

It is a choke point placed in the network path between agents and the assets they access, protocol agnostic across MCP, HTTPS, and LLM APIs, that distinguishes humans from agents, inspects every request at Layer 7, and applies reasoning-based policy to each transaction. These proxies must be globally distributed across cloud and on-prem, and the network is used to funnel traffic, including legacy system traffic, through them.

Why won't ACLs or static rules work for controlling AI agents?

Agents are clever enough to route around explicit prohibitions: Gillis's example is an expense agent told not to buy a Porsche that offers to buy a McLaren instead. With agents doing something different every day, maintaining static rule lists per agent does not scale, so the episode argues policy must come from reasoning, using targeted security models that learn normal agent behavior and flag deviations.

How can enterprises discover the AI agents already running in their environment?

Combine three data sources: identity data from the systems that store it, network telemetry such as NetFlow and DNS, and the logs already being collected. Together those give roughly ninety to ninety-five percent of the visibility needed to inventory agents, and the resulting report, showing which agents exist, where they run, and who talks to whom, is the recommended starting point for conversations between network, identity, and security teams.

Read the complete conversation

Full episode transcript · 44 minutes

First, you've got to be able to tell the difference between a human and an agent. Second is you've got to intercept that traffic and speak the language, right? MCP, HTTP, whatever it is. And then the third is apply the reasoning for the policy. Hi, everyone. I'm your host, Nick Lippis, and welcome to the Built for Trust podcast, where you get to hear from all the folks who are building and shaping AI enterprise infrastructure.

Now, let's get right into it with our guests. Hey, don't forget, there's an AI networking summit coming up, and you're invited. So go to the onug.net website to get your tickets now. And also, if you're on YouTube or Spotify or any of the places where this podcast is being broadcast or streamed, make sure that you hit like or subscribe to it. Thanks.

Tom Gillis, Matt Clafield, welcome to the Built for Trust podcast. Welcome. Thanks, Nick. Thank you so much. Always great to be here. So great to have you both here.

And I am really jazzed about the topic that we're about to have. I think before we start, I just want to make sure everybody knows everybody. Tom, everybody knows you, but we might as well just say a quick hi on what you do over Cisco, but start with you. My wife knows me. I didn't realize everyone knows me.

That's cool. So yeah, Tom Gillis, I'm responsible for infrastructure and security at Cisco. So thank all data center stuff, plus all of our network security stuff, fusing together. Awesome. Great. Matt, I'm not sure if you've been on the podcast before, so be good to introduce yourself.

Sure thing. I work for Tom, but other than that, I'm responsible for everything identity related at Cisco. So I'm probably a new face to the networking lines. Okay. It's useful, Matt, to tell the audience, how'd you get to Cisco? Oh, sure.

Yeah. So right now I lead the whole identity portfolio, but I came in through acquisition, which Cisco tends to do. So I was the founder and CEO of Ort, which was an early leader in the identity security space. We helped create a category called identity threat detection and response, along with a bunch of other companies.

Four years ago, we got acquired by Cisco in 2023. That capability is now the basis of what we call identity intelligence. It's underlies a lot of other Cisco products. So yeah, really proud of that and proud of the kind of the bigger role around identity that I'm now responsible for. Yeah.

So for any startup founders that are out there that are maybe talking to Cisco, Matt is now responsible for a billion dollar portfolio. So not many startups get to go to that scale, but Matt is our thought leader in identity. And I think as we're going to talk about in the podcast, identity is literally at the foundation of networking, right? And, and all that we do.

So there's a lot, a lot of interesting stuff happening. Yeah. Yeah. That's great. And also, I think like, you know, just on a quick note too, you hear that story so many times with Cisco, you know, it's like the acquisitions, you know, that you make and the people just don't scatter, you know, like you have on like other acquisitions.

They stay and they really contribute, you know, and they grow, you know, because I think, you know, it's that now they get to like, see what they were doing and how that could really be applied to, you know, many, many, many organizations and companies. So, so Matt, you know, you know, I don't speak for Cisco, but like welcome aboard. I'm glad you're there. And we're glad.

The talent is, is, is awesome to see. Just like we get to work with startups, we get to acquire startups, we get to invest in startups. It's almost like the best of both worlds because we get to build our own kind of big company stuff, but also live vicariously through the startup community. Yeah.

And you had a liquidity event, you know, it's like, you know, kind of like, you know, like life is good. Awesome. Okay. All right, great. Let's start.

I wanted to kind of give a little bit of a context, you know, to, to our discussion before we start. And we've been spending a lot of time within the ONU around agentic and around what we're calling the agentic AI overlay. And so what we've really discovered is that, you know, agents that we all know that agents are proliferating, they're proliferating, you know, much faster than probably any other technology that we've seen before, which always happens with something really hot.

So I think one during our prep call, I forget who it was. It might've been you, Tom, that mentioned like, you know, agents and sandboxes are kind of growing almost like Novell networks were like back in the 1990s. You have people, you know, all over the organization just putting in these sandboxes and IT has no idea, you know, you know, where they are, how they got there, but they, at some point in time, you need to manage them.

And that's some point in time is really right now. So, so we have that really growing. The other key thing that we also understand is that the buy versus build curve for software, enterprise software has now shifted to, to actually buy or to build. I'm sorry, build, not buy. And so we, we've just kind of did a quick survey across the community.

So many, especially in the large financials are actually pausing enterprise software purchases. And they're basically, they have, they have large dev teams, thousand, 10,000 people in dev teams. Those are the folks who are now writing software with all the AI tools utilizing both LLMs as well as agents. So another major driver around proliferations, the, the issue I think that we have is that a lot of CISOs are scared.

A lot of folks in security that know about agents are really scared, but they, but they are getting edicts from their board that they've got to like be on the AI bandwagon. You've got to understand how we do transformation and how do we utilize this, this technology. And so they, they feel a little bit lost if they don't, actually, I heard this from like two CISOs, like in the last couple of days, if they don't, you know, actually show that they're on board with that, they're worried about, they're going to get fired, you know?

So there's James Beeson, who's a CISO over at Pfizer. He said at the last Dallas event, like the edict at Pfizer was either change the people or change the people, meaning skill up or, you know, um, or, or, or, or you won't be around very long. All right. So going back to AI agents.

So, um, agents, they don't have passwords. They don't have MFA tokens. They don't have biometrics, uh, service accounts for a lot of the tools that we all utilize have no MFA, uh, no personal identity, uh, just static credentials and maybe some shared secrets. Um, if you don't believe that, um, the agents and handboxes are growing, uh, unprecedentedly, unprecedented, try to order a Mac mini or a Mac studio.

There's probably a four to six month wait, because that's where that's the preferred, you know, mechanism for running agents. So we need a framework. Um, and also, um, we, as kind of networking and infrastructure, um, you know, community, this is a unique networking problem. So, um, so Tom, I want to like, see if, um, you can start diving in maybe on that topic, you know, so it's okay.

Well, I think the most important thing to remember is that there's a reason why these agents are proliferated because they're useful, right? They solve meaningful business problems and, and all kinds of business problems. So software development is the most obvious place, right? Where, where, you know, we're seeing 10 X and 20 X increases in productivity, like staggering increases, even the most mundane, you know, sort of procedural business task.

In fact, that's where the agents shine. If it's just like something you could write down in an instruction manual, these agents can do really, really well. And agents don't need a break. Yeah. So, so, um, so we are seeing agents proliferate everywhere.

And like the example I use all the time is, uh, every company in the world has to process expense reports. Nobody likes doing it. I personally am wildly incompetent at it. Like you can't believe how incompetent to the point of like negligence. Like I, I, it was like once a year, I like pull out the receipts, like, oh my God, where the hell was I?

And then it's some sort of, you know, trip through memory lane with an agent. You can write an agent that will say, look, I'm going to access our travel system, which is concur. I'm going to give it access to my iCloud photo reel. So we can pull the receipts. I'm going to give it access to my calendar.

So I'm going to look at where it is. And these agents will spit out the report, like, you know, as I'm traveling and then I want that agent to reconcile the expense report and process the credit card. I do not want that agent to buy a Porsche, right? If it's my credit card, it's a used Porsche. I don't want that to happen.

And so this is, I think, you know, indicative of the, of the problem. And these, these agents oftentimes have a human credential. So they do have authorization and they have, you know, humans generally have very long lasting and very broad access. And yet the agent has the access of a human, but the common sense of a printer. And so, so, you know, we need an access control policy that is kind of somewhere between what we provide for printers and what we provide for humans.

Yeah. Networking, you know, access control is what we do in networking, right? This is a network function. Yeah. Yeah. This is a network problem to solve for sure.

Yeah. So Matt, you've been focusing on identity. So like, um, even going back to like what I was mentioning, you know, earlier is that one of the, the key requirements that we've found is, um, kind of agent authentication at a station, um, you know, bringing them in. Um, how do we bring them in safely and keep them once they're in, you know, keep them safely.

So, so you want to kind of take the identity of agents, you know, and, um, and tell us what you're, what you've been thinking. Yeah, of course. So every agent, whether it's running on your laptop or running in the cloud or SAS service has an identity. And a lot of people think about authentication being a hard problem, especially for humans, because we had to deal with like squishy things like fingerprints and, uh, face scans and all that stuff for, for agents though.

Authentication is not the hard part, right? We can pretty easily assess that agent who is, who we think it is. Certificates are really easy to manage. Like a lot of these kind of machine workflow identity stuff is pretty cut and dry because we had in cryptography and we got to worry about post-quantum, you know, encryption, but like, that's a solid problem.

The authorization though, it's really hard. When we just issue service accounts to these things with permissions to go, you know, make modifications and concur, look at all the photos in your photo album, suddenly agents are persistent. So like, they're going to take full latitude on that and try to look at everything, try to access everything and work around problems and run into them. You know, I try to give, um, my personal agents access to my inbox.

Like we get locked down in all kinds of ways at Cisco to rent that, but it comes up with three different options. So you work around those controls. So they're so persistent and authorization more so even than authentication becomes a problem. Not who is the agent, but like, what should that agent have access to and what should it be allowed to do with that access?

And like, that becomes the next battleground in identity that has remained unsolved for the past 30 plus years. Authorization is always, especially fine grain authorization. We've gotten to a point where like, what application should you access, but what can you do with that application, we've always kicked the can on the road because like Tom was saying, like humans generally, like they've got some judgment.

Agents might have the judgment of a printer. And so we need to reinstill that somehow, like the morals, the ethics, the conscience, the kind of fine grain authorization that we do intuitively. Agents don't have that. So we got to find a way to reinstill that when it comes to agents. I think, okay, so I think that's great.

So, but, so let's go a little bit further. So we have agents. These agents, you know, can communicate with clearly inference machines. They can also communicate with MCP, you know, services, gain access to various different data. And also it's like, there are agents that are within a domain that you trust your own environment.

And there are also agents, um, or they might be communicating with agents in other domains, other cross domains that you don't trust, you know, um, for example, like at open AI or an anthropic or, uh, within Azure or within Gemini or what have you. So, so how does, you know, how do we basically look at that entire system, you know, and, um, provide both a kind of identity, you know, control, make sure like, you know, that, um, there's a whole range of issues that people are concerned about, but I think, do we have a framework, you know, that we can start thinking about that allows us to start building these systems and have guardrails and controls in place that we feel comfortable about, or are we still in the early stages of the marketplace where we're still trying to understand, you know, what we can do?

Yeah. So I'd say like market's still very early on this and like, even meeting with the biggest, most sophisticated customers, just like early today, earlier today, like they're still trying to get their head wrapped around the magnitude of this problem because you do have agents everywhere. Um, no single control is a silver bullet.

Like you say, oh, I solved it at the identity layer. Like it's off. No, the same thing on the end point. Like it's, it's, it's no silver bullet. The one common feature here, I do think, and like, I don't just say this kind of offhand because I'm at Cisco, because I'm the identity guy.

I would love for it to be the identity. It's not like the network and it being in the network kind of between all the agents and all the things they're trying to access, whether that's an MCP server or like a REST API or like a website or even like the LLM API that the agent is, is trying to talk to. Um, the only way to get in there and actually apply some of these fine grain controls we're talking about is by being in the path.

Yeah. Um, in the path that usually means networking, um, in the path between the, the agents and the resources. So when we talk about a framework for agent security, of course, we got to think about the full life cycle of the agent. And there's some really cool stuff like Cisco is doing around like build time for agents.

Like when we create these agents, when we run them through their evals, when we, you know, test their guardrails, that's really awesome. And then there's actually running them and I'm running them at scale. And that's where it gets really, really hard because now everybody in the company has these agents and you need to, at scale, give them access to all of these resources, not just concur, but a thousand other applications that people use every day to get their job done.

That's where it gets, you know, pretty scary. And so having a framework that covers, how do we discover agents, right? How do we, how do we see and get visibility into all of them? Yeah. And then how do we authorize every action based on an identity, strong kind of cryptographically assured identity?

And then how do we provide continuous scrutiny, behavior monitoring, observability for those agents? It's kind of like, all right, discover them all, authorize every action, and then adapt to the risk in, in, in real time and provide continuous monitoring. Those three pieces become really critical to have a complete solution. And they, they, they span identity, networking, security, observability, infrastructure, all the things that we know we need to pull together.

Yeah. I want to put an exclamation point on something Matt said, which is the, the end point is super important here, right? Having an, you know, understanding what's happening in the end point, insight into what's going on in the end point, ensuring the integrity of the agent in the end point. It's all goodness, but a fundamental premise that, that I think this audience understands well is that we can't control what's on the end point.

We can try, but like end points are popping up all over the place. The whole definition of the end point is change. All of a sudden the printer could be running an agent and like that becomes an end point that we never thought of, right? So raspberry pies, you know, can have the intelligence to do pretty amazing things. So, so the network becomes critical and it's, it's think about the problem in reverse, which is what are my assets that I need to protect?

What are my sensitive applications? And then stick this little widget in front of those assets so that whoever is reaching out to these assets. And the other thing you mentioned, Nick, is protocol, right? MCP is amazing. MCP is like, all the cool kids are doing it.

It's, it's new and it, and it's hip. I think there's going to be a ton of agentic traffic using HTTPS, right? The good old fashioned, you know, web, you know? Yeah. And so you need to be protocol agnostic, right? You need to be able to, to speak whatever language the agents are speaking, figure out human versus agent.

And then what Matt was saying is the really hard part here is that authorization. Like what is the agent allowed to do at, we're just going to get better and better and better and better over time. Cause you can only solve that problem with reasoning. Yeah. You're not going to solve that problem with a static list of rules.

Yeah. It's, um, you know, it is, it, the more that you kind of dive into this, you know, the more complicated it gets and, you know, um, especially on kind of like the higher level piece of that being kind of the governance and the policy, but we'll get to there in a second. I think, you know, I think one thing that I want to dive a little bit more into, you know, and Matt, this is, I think in your, you know, in your, you know, wheelhouse and that is, you know, there's been talk about maybe having proxies, you know, uh, within the network infrastructure where, um, okay, right now, the way we've been thinking about kind of how, um, agents communicate with all of the pieces that, you know, that they're interacting with.

Um, it's just kind of just, you know, uh, best effort, you know, a mesh, you know, kind of like, you know, kind of communications. Um, but maybe, um, that's not going to really allow for control, a really good control. So, um, having, um, maybe a proxy or a way to federate kind of a proxy where, uh, agents have always got to go up to this proxy first and maybe that's where the MCP servers and other servers kind of plug in, you know, data, you know, uh, access to various different data, access to other kinds of other zones that are, that you don't trust and so forth.

So have you thought about, you know, you know, a, a, or an, an architecture kind of on that kind of, um, structure? Yeah, absolutely. Yeah. I'd say like, we need to get to a choke point of some kind. Like it's, it's too important not to like, yes, we should let agents proliferate and figure out like, what are all the great use cases that they can provide for organizations.

But at the end of the day, like the beautiful thing about the original firewall was like he, you put it between something inside and outside. Like that was a really nice and clean mental model for like how to secure agents. Like we kind of, I don't want to say recreate that, but like we do need to create some sort of funnel and choke point for those agents. Cause if we're going to look at every action they're taking and scrutinize every website they're going to and every MCP server tool that they're using and every single other API that they're touching, like we're going to have to send them through some kind of inspection point.

That's pretty smart and robust and like absolutely apply, you know, network segmentation everywhere. But when it comes to like, like really deep L7 inspection, looking at every single MCP request and every single LM request, we've got to go to more of a proxy architecture for that. And those proxies can't just be in one place. They've got to be globally distributed, both in the cloud and on-prem so that we can actually apply this as many places as possible, as close as possible to where the agents are.

Yeah. Yeah. Hey Matt, so when I'm talking to customers, obviously Matt and I tell the same story, right? We're talking about this proxy, this gateway that, that protects your assets and from anything, God knows where the agent's coming from, et cetera. A question people ask me all the time is, well, how did, how did, how do you do that?

If, if, what if my data is in Salesforce, what if my data is, you know, sort of running out on Azure, what if my data is like, you know, you know, legacy, uh, uh, system. And the answer is. Oh, is that to me? No. I was going to guess, but go ahead, Matt.

Yeah. So I, I'd say like, even in those legacy systems, we can absolutely get in front of them. Um, a lot of the way that we do that is like, we had to lock down the system. So there's no way around that proxy and the way that we can funnel traffic to it, you know, whether it's kind of a legacy system or not is because of the network. Like we can connect to those end points and meet them where they are and make sure that traffic's going through the proxy.

Tom, I don't know if that is the answer. Yeah. And also we have like, when you think about this in abstract, it seems like a scary, hard problem. It's like, Oh my God, everything's connecting everything. What do I do?

But they're very mature mechanisms for sticking gateways in front of the stuff you care about. Yeah. Oh, off. Right. So, so, so this exists, we just need to make sure that we apply these same mechanisms and techniques to all traffic, human and agents, HCP, MCP, right?

We don't care. It's, it's all traffic is going to flow through this kind of unified gateway. And that's the choke point you were talking about. That's the control point where, where we get in. And now we can apply, we solve the hard problem of, is this transaction okay or not? Okay.

Yeah. Right. And so I described the first part as plumbing, you know, kind of a scaffolding that's necessary to be able to, to control these agents, which is first, you got to be able to tell the difference between a human and an, and a, and an agent segment is you got to intercept that traffic and speak the, the, the language, right?

MCP, HTTP, whatever it is. And then the third is apply the reasoning for the, for the policy. So, and there's work to be done in each one of those three domains. Yeah. Policy one is really where that, the magic is. I feel like you're right, Tom.

Like a lot of the first stuff, the things you mentioned is like, it's plumbing and then it's magic. Yeah. It's like, you look at behavior and decide like appropriate or inappropriate to go over the bush. Well, you know, a lot of networks with plumbing, dude.

Right. And so like our audience, we love plumbing. So let's talk about, talked about redirection and how you get to the gateway. How do you tell the difference between a human and an agent? Can I do one thing before we do that? Yeah, of course.

I got, Matt mentioned something that I was like, okay, that's really interesting. And that is kind of quantum networking, you know, you know, and how that might play a role in here. You know, is that just like another kind of option that, that Cisco is looking at, or is that something that you're really just thinking it's time? Tom, you want to take that one?

What do you mean? You mean quantum encryption? Yeah. Like, yeah. Okay. Sorry.

I thought you were saying quantum networking, which is like really networking using quantum entanglement. But like, yeah, I'm sorry. I'm thinking about, you know, you know, quantum, quantum keys and, you know, distribution and so forth. Yeah.

Yeah. I think that's just as important, especially as identity becomes the front door of, and the lock on the door of how we get into these proxies and like identify things. Like you're going to need cryptographically assured identities and it's going to do nobody any good if like, you know, you can crack them using, using post quantum capabilities. So, it's really important that as we build out these systems and we think about how do we issue a certificate or a, you know, verifiable credential for every single agent, it's going to do us no good if we're ignoring this kind of, you know, looming storm that's approaching, which is, which is PQC.

It absolutely should be designed from, you know, from the beginning. It's 2026. The algorithms are there. The standards are there. We might as well start there. Yeah.

Okay, great. Sorry, Tom. Yeah. So, let's get back. So, you were kind of drawing a line, you know, around kind of plumbing and being able to kind of create these proxies, you know, do all the stuff that we would normally do within networking.

And I think you were going to kind of jump into like, you know, policy, but. Well, that'd be the third, the third tier. This is a second tier, which I still think is pretty sticky, which is identity. So, so how do you tell the difference between Tom on a Cisco managed machine and an agent running on Tom's machine that has my credential and I wanted to go do some business task, you know, versus an agent in the wild?

Like, you know, Matt, what, how do we think about non-human identities? Yeah, this is a super hard problem. Like, I would love to say, just don't run agents on your machine, run them somewhere else. I'm like, I feel like that's not happening. Yeah, it was. Well, yeah, that's a super expensive solution to the problem.

Some, some customers, by the way, they're going down that direction. It's like, no, you can't run anything there. You got to run in sandboxes. I don't like, that's how we're going to make sure that you're not sharing credentials, you know, back and forth. Way more companies.

It was blocked, you know, sort of Facebook when it first came out too, right? Yeah, exactly. I think the, the, the, the more common scenario is like, we, we do have cloud code and cursor running on our systems. People are, you know, for better or worse, installing open claw locally. And in that case, do I just share all my credentials with it?

Well, for organizations that have gone to like phishing resistant authentication, the good news for the security team there is that you can't, you can't physically give your biometric, your, your face ID, touch ID to the agent running on your system. There's no way for you to transfer it to that. But then even then it's like, okay, great. So what, what do we do?

Like, what kind of identity do you give to that agent? And so there's this whole field of non-human identity, which uses a whole bunch of different techniques. Certificates are really, you know, a big part of it. In order to give an issue, every one of those agents, a credential of some kind, but then where it gets really interesting is like, okay, that's, that's great.

But like, I'm not going to give the agent, like it's on email inbox. Nobody's going to talk to it, right? It's not an interest. So like, we need to somehow delegate permissions to the agents on the systems. And that's where there are lots of interesting standards that make that possible for me to delegate a subset, not all, but a subset of my permissions to the agent, just so that it can go and, you know, read my email inbox, but not, you know, write to my email inbox or send emails.

So it can move things between folders or categorize things. So that ability through standards like OAuth 2.1 to do on behalf of flows and delegated authorization become really important so that I don't actually have to share my credentials. If I, especially if I care, especially if I'm in an organization that's still using passwords so that I don't have to share my password with that agent, but I can still share some of my permissions with that agent.

Yeah. Yeah. Awesome. And I think, you know, as we get into a more sophisticated iterations of humans and agents working together, you know, one thing that I've always believed, and I think Matt, you share this, is understanding identity at the process level is going to be really, really important, right?

The fact that it's Tom on a Cisco managed machine, it's kind of not that useful anymore from a security standpoint. I want to know what process on Tom's machine is initiating a connection. Yeah. And likewise, on the server, what process is terminating that connection? And ooh, now you have a level of context that you otherwise wouldn't.

And there's a lot of processes out there. So it seems like, whoa, how could you do that? You know, in this kind of post-AI world, yeah, we can, right? Yeah. We can. We can measure it.

We can see it. We observe that already today. We've been doing that for more than a decade. Process-level identity and correlating that to flows. It's just a ton of data. And now we have the ability to actually process all that data and make sense out of it.

Yeah. Tom, I feel like since you came back to Cisco like three years ago, you've been talking nonstop about like the importance of like looking at the processes on these individual systems. And like, I feel like all of that's just been truly vindicated with the agent stuff. It's like suddenly- Oh my God, that's for sure.

Everybody's joking about this. Like on the endpoint, it's like, okay, which process is a human? Which one's an agent? And like, how can I figure that out? And like, what do I do with it? Once I identify those flows, can I treat them differently?

Like a lot of the controls we had in place in networks today are kind of at the endpoint level, especially for network access control. But we need to get down to like per flow level. It's like, okay, this IP port number is from the agent, this IP port number is from the human on the browser and starting to provide a differentiated treatment depending on which, not which endpoint, but which process is actually sending.

Yeah. Yeah. So there'll be a ton of development thinking on some of this plumbing issue, which we talked about of just figuring out what is an identity, a human versus a machine, keeping track of that and then passing that identity through the network so that that gateway can interpret that. Yeah.

Which, you know, we all have jobs. So the gateway functionality is going to really incorporate a lot of the plumbing features associated with how we're going to like secure and lock down agents and all the devices that they're interacting with. So, but one of the hard parts, and Tom, you mentioned this like during the prep, so I want to make sure we hit this, is around policy.

Right. And so like, why don't we talk a little bit about policy and not only just from a point of view, how it gets implemented, but just how you start to create it. And then once you go down that rabbit hole, you know, how deep the hole actually gets. Yeah. Yeah.

So I think that's the hardest part. But what's cool about AI is that while AI creates these problems, it also presents the solution. And here's what I mean, is that I don't think it's practical to have some sort of static set of rules to say, this is what an agent can't do. Right. You know, many customers are like, ah, but I want guardrails.

Okay, fine. You can put guardrails in, but let's, let's pick that example of the expense report processing. That little agent, I want it to access the credit, my credit card to reconcile expense reports. I don't want it to buy a Porsche. And if I tell it, don't buy a Porsche, these agents are so clever. They'll be like, all right, I'll buy a McLaren.

And if I say, oh no, don't buy a McLaren either. It's like, okay, cool. I'll buy a Rolls Royce. Right. And so, so, you know, it just keeps getting more expensive every single time I write a rule.

Yeah. So, so the only way to solve this problem is reasoning. So yes, folks, the AI is going to be policing the AI. You have nothing to worry about. It's going to be all okay. But this is something we've been working on for a couple of years now where, where, you know, we've realized from the chat era that like, you just can't have kind of static, like the traditional security mindset of like, here's a list of things I block, or here's a list of things I don't allow.

That's irrelevant now. And so, so you have to be able to understand context and look at what do we think is okay and what is outside of okay. And there are kind of small targeted security models, one of which Cisco has created and open sourced that, that are tuned specifically for that type of analysis. It's really anomaly detection, right?

I'm looking at an agent talking back and forth and behaving in a certain way. And then if I see a deviation outside of the norm, I'm going to flag that. Yeah. So while that's not a silver bullet, it has the advantage of it's going to get better and better and better over time. Like what's constantly refining that and making that, you know, more and more effective.

Yeah. It's hard to predict. Do you think that would be something, what tools an agent's going to use? Unless it's like really rigidly defined, like this help desk agent is just responsible for shipping people replacement laptops. Like, fine.

You can probably write a rule around that. But for the most part, I want to walk up to my, you know, clod, chat GPT, whatever, and ask it to do something different today than it did yesterday and use all the creativity at its disposal to go figure that out. So it's really hard to write static all the screws. And if you, if you could, you had to maintain so many of them for the number of different agents in the environment, it's just like Tom said, like kind of, you need to use AI to protect guys.

Yeah. Yeah. Good point. You know, it's like so funny. It was like, we're so used to thinking about like, and especially in the networking, you know, you, you do, um, ACLs, you know, so very detailed, you know, um, you know, it's like you, you shall do this, you shall not do this, you know?

And, uh, and now we're kind of moving into something that's more cerebral and more reasoning, uh, reasoning based. Um, yeah, that's going to take a little bit of time for, I think for, for people to kind of wrap their mind around and, um, and for them to get comfortable with. But I wonder, like, are you thinking about these kinds of policies and this reasoning, uh, to be shared amongst, for example, like Cisco customers, you know, um, you know, so that they all can learn from each other, you know, on what's working and maybe what's not working, you know, or is that still going to be, and that might, companies might have regulations that are prevent them from doing that too.

You know, so I'm not sure if there's kind of an opportunity to kind of have kind of shared, you know, best practices around policy. Probably more of a legal, like regulatory issue than it is a technical issue. I think we, we often give customers an opportunity to kind of opt in to using their data to train these models that might benefit other customers. And it really varies based on the organization.

Yeah. But assuming you get over those, those legal, uh, uh, issues, I do think that, you know, like it's just a little bit of common sense. Like the bigger your population, the more accurate your, your models become. Right. So, so having customers sharing the, uh, this and like, oh, cause a lot of these patterns are going to be the same.

Like they're going to want my agent to access source code, but it's read only, you know, like, okay. You know, like, like these policies, um, uh, there will be a lot of commonality, a lot. Yeah. Okay. Um, I want to dive into one topic, um, and, uh, before we, uh, adjourn and that is how do we equip network engineers to talk with their security peers and their identity peers and kind of the CISOs that are running their organizations that they own this?

Um, so how do we, you know, kind of help them have that kind of conversation? Um, you know, so that they can be successful. Yeah. I mean, it all starts with discovery and Matt, I'll, I'll, I'll, I'll turn to you. You, you, you taught me this lesson, right? But like we, we have discovery tools for identity systems right now that, that uncover, you know, eye popping things pretty consistently.

Right. Like, you know, yeah. Let's talk about discovery. How do we, how do we see what's out there? Yeah. I think starting with discovery and it's cross disciplinary, like nobody sees the whole elephant, right?

So if you, if you can get identity data out of the many systems that store it along with network telemetry, along with all the logs, you might be collecting environment. I'm not going to tell you get a hundred percent, but probably like 90, 95% of the visibility you need from those three sources to see all the agents in the customer's environment. And that, yeah, it's right. Like right now discovery is sort of like that number one problem that everybody needs to come together to work on.

So like network engineer has something around netflow data, DNS data, um, whether it's a Cisco tool or, or otherwise, like that is a really compelling data source that we find with the entities, logging pieces to get a more complete picture of what's going on. Okay. So you're thinking that, okay, the way that network engineers can actually start having this conversation is just one, Hey, we've done a bunch of discovery.

These are the agents that we have, and this is, and this, and this is where they are. And these are the kinds of interactions that they're having. Um, you know, and we need to start thinking about how we're now going to like manage this, control this and govern this. Is that kind of like. Network engineer talking to the identity isn't saying like, Hey, how are you thinking about identity for agents?

You know, we're looking at, you know, print some kind of proxy or gateway in place that we can put in between all the agents and the, the assets in our environments. Like let's work together on this one. Cause that, that proxy is going to have to be. Yeah. Here's a real life example.

I was out, uh, spent the day with the, uh, infrastructure network team for one of the largest healthcare organizations in the U S and we were talking exactly this topic. And one of the senior executives was like, yeah, I know agents are a problem. We're on board with Microsoft and we're using the Microsoft, um, you know, agentic frameworks. I think like we're good and it took like a half an hour to convince this executive that like, that's a useful, I'm not knocking on Microsoft.

The thing about the Microsoft framework is it's amazingly good for Microsoft, right? What else is out there? And, and, and just that, you know, if you can produce a report and be like, yeah, there's, you know, 20% of our agents are actually Microsoft agents. 80% of our agents are Workday, Salesforce, OpenClaw, blah, blah, blah. You just show who's talking to who.

Yeah. And again, the network is the place to take that picture. I think that's a great starting point. Yeah. So it'll highlight the need for like, oh my God, like these, and I guarantee you're fine stuff.

You had no idea. Yeah. But this healthcare is healthcare organization was funny. They were like, you know, we see in the hospital, we see X boxes. Yeah. Because we've got children's wards.

We see fish tanks, right? We, we, like, we see all kinds of crazy stuff on the network that like, I didn't think that was an end point, but yeah, a fish tank is an end point, right? Because. Yeah. I wouldn't have thought that would not have come to the top of mind.

That's for sure. You know, uh, you know, a fish tank. Yeah. Well, I think, I, I think that's like super, um, you know, super helpful. Uh, it was interesting too, Tom, as soon as you basically said the whole is your, you know, thing is that really, and I totally agree not knocking anything that they have around their controls around agents, but it's almost like it made me think back to like, you know, um, 2014 or 2015 when everyone thought it was like a single cloud world, right?

You know, it's like, this is a multi-cloud world and there's a multi-agent world and there's a multi-vendor world and you really have to have controls to go across all of that. And I think that's, that's fundamentally why this is a networking problem, you know, and it's not, it's not a single. Again, you guys will be like, yeah, we've got it. I don't think so.

Right. That's an important part of it. Right. But you know, you know, a, your, your IDP, your identity store, that thing was built for humans and, and, and it doesn't go away. And now all the narrative we're talking about, like, there's no scenario where like, oh, you know, retire your, you know, active directory or your intro.

Like, nope, that's not worth saying at all. What we're saying is we're going to read that in, understand it, and then we're going to build non-human identities on top of that, of which there's, you know, one or maybe two orders of magnitude more, maybe three orders of magnitude more. There's a whole lot of non-human identities out there in your, just in your environment, to your customer.

Yeah. And, and I think one of the cool things that Matt and team are doing is we link those two. Yeah. So when we see an agent that's running on Tom's machine, we know it's Tom and we know what Tom's entitlements are. So then we can cross-reference to like, well, what is the agent trying to do?

Does it match with Tom's privileges? That's like 1.0 policy thing making, right? Like that's pretty basic, but, but important. So linking non-human and human identities in one comprehensive view is super. Yeah. Human accountability is really important.

And a lot of organizations do have pretty robust systems for managing human identities. It's kind of like a kind of, but it's human scale. It's like, oh, we got a trigger to onboard a new person. That happens on the order of days. In the case of ageites, it's like, yeah, five minutes ago I spun up an agent and now I'm signing up another agent.

It's like, you don't really have a chance to send it through, you know, onboarding training and ship it a laptop, right? And all these things. It's like a whole different order of magnitude. Right. Let alone all the devices popping up in your environment, the fish tanks, you know, like the right raspberry pies.

So, yes. Well, I think this is like this really kind of tip of the iceberg because I think what we're going to start to discover is that there are so many problems that get presented in an AI era that only networking can actually solve. So, and we're going to really be talking about one of these in the next podcast around, you know, glass wing and that's using a cloud mythos and how, you know, it's really, you know, super powerful, you know, technology, obviously the banking industry where they basically pulled, you know, Anthropic pulled it, you know, because there was concern about it would create vulnerabilities within the financial services sector.

But the most important thing about it is that, you know, it can really start to now look at software and understand vulnerabilities. So it's almost like we're going to start to see a whole replatforming occur within the industry, but also it's going to drive a massive, and Tom, you've been saying this, you know, so I'm kind of like stealing your words here, you know, but it's going to be, you know, driving a major patching, you know, environment all across infrastructure.

So we're going to kind of tease that out, you know, you know, for, for our next time, but that's also a networking problem too. Yeah. You know, what's interesting is this AI revolution, the network is becoming increasingly important, more important than it was before. And I'm going to argue in the data center, like in the computers themselves, the network is the backplane for stitching together the AI supercomputers that are to be running all these applications.

Okay. And that has profound implications in the North South, you know, access control world, like with agents springing up out of nowhere, as we talked about in this broadcast, the network is the only reliable place to put those, those, those controls. And then the issue you just referred to, you know, sort of this new class of models was driving, you know, kind of a hyper red team environment, you know, little teaser for, for our next broadcast, but, you know, our customers are looking at, you know, a hundred log 4j events in the same week.

That's the magnitude of the tsunami. It's that bad, right? Microsoft announced two, 125 vulnerabilities on SharePoint last week, or yesterday, sorry, 25 vulnerabilities, right? And this is, that's not a knock on Microsoft. Like it's the tools that are finding these, you know, vulnerabilities at a pace that humans have never been able to operate.

So we, the industry have to respond dramatically. It's not going to be like, you know what, please try harder to patch. That is not the answer. And fortunately at Cisco, we're on our, our heel, on our toes, not our heels here. And that we've been thinking about a proactive approach to applying compensated controls to switches, routers, firewalls, infrastructure, but we can also apply compensated controls to your application software to your customer to shield those vulnerabilities while we can patch in an orderly fashion.

Awesome. Times are changing. Yeah. Yeah, that's what, that good teaser, you know, for, for the next podcast. But this was really great. You know, Tom, thanks so much, you know, for your insights, Matt, you know, thanks so much for like, you know, your core expertise, especially around identity and thinking about how we're actually going to bring these agents, you know, into, into the fold in a safe place.

So, well, thank you both. Thank you everyone for like watching as well. Um, and we'll see you all at the, um, AI networking summit. Um, this gets published on May 7th. So in about a week or so. Nice.

Yep. Looking forward to it. I'll be there. Uh, thanks everybody. Thanks.

The episode summary, topic list, and questions on this page were generated with AI assistance from the episode recording and show notes.