SecretCon 2026
Architecting Autonomy: The CISO’s Playbook for Governing AI Agents
Chandra Inguva & Manoj Kumar
Abstract:
AI agents are already embedded in enterprise workflows—writing code, querying systems, triggering actions, and operating at machine speed. Yet most organizations are attempting to govern them with controls designed for people: policies, training, and approval gates.
That model no longer works.
This session introduces a practical three-stage framework for understanding how AI autonomy progresses inside enterprises: Human-Led, AI-Supported, and AI-Directed. Many organizations believe they remain in the first stage. In reality, teams are already operating in the second—and drifting toward the third—without corresponding architectural safeguards.
We argue that the CISO’s role must evolve from enforcing behavioral controls to architecting machine identity, autonomy boundaries, least-privilege access, and action-layer observability.
Attendees will leave with a diagnostic model to assess their organization’s true maturity and a concrete blueprint for securing AI agents before autonomy scales beyond governance.


Chandra Inguva & Manoj Kumar
Product Managers, Microsoft
Manoj Kumar is a Cybersecurity Leader at Microsoft with 20+ years of experience. A pioneer in AI/ML security, he helped build the Responsible AI Standard for LLMs and led AETHER’s group creating CodeQL rules for AI risk detection. Manoj architected Azure ML for air-gapped government clouds (DOD/DOJ) and specializes in GRC (FedRAMP/NIST). An MBA and CISSP, he transforms complex security into business value, cutting review times by 50% while securing the future of AI enterprise.
Chandra Inguva is a product manager at Microsoft