SecretCon 2026

Identity in Crisis: Authorization, Accountability, and Who Gets Fired

Lee Tschetter

Abstract:

AI agents have moved from simple chatbots to autonomous “agentic” workers but our IAM and IGA programs haven’t adapted. We are no longer just managing human access; we are managing a complex web of agents autonomously making decisions. There are agents managing the flow of information and deciding what is sensitive. This isn’t a “non-human identities” talk; yes, some AI agents might use traditional service accounts, but more often than not we expect agents to act on behalf of user identities.

Can you answer this question: If an approved and authorized AI agent performs an action that results in an incident, who is held accountable?

This session explores technical and practical challenges of identity and authorization in the age of AI agents. We will attempt to analyze both aspects of agentic identity—autonomous machine identities versus human user delegating access—and analyze the risks inherent in credential sharing, OAuth grants, and (lack of) least privilege. Attendees will leave with a better understanding of how we can work towards implementing “agent-aware” policies that ensure actions are attributable, auditable, and authorized.

What must be done to safely allow AI agents to deliver real value without losing accountability?

Lee Tschetter

Agentic Identity Architect

Over the course of his 25-year career in information technology, Lee Tschetter has transitioned from implementing technology solutions to delivering security products to building security ecosystems. Over a decade ago his focus shifted to identity and access management, a decision driven by his firsthand experience in identifying the root causes of numerous IT and security failures.

He believes in giving back to the security community and participates in various organizations — acting as a founding member of the Twin Cities Identity and Access Management User Group, working with the Identity Defined Security Alliance, and previously serving as a board member for the Minnesota chapter of the Information Systems Security Association.