AI Agent Security, Identity & Runtime Governance
Advisory engagements for organizations designing identity, authorization, access, and runtime controls for AI agents.
Watchlight AI works across architecture, threat modeling, readiness, implementation strategy, and Agent Runtime Governance, from a focused working session to a multi-week architecture engagement.
Executive & Technical Workshops
Focused, facilitated engagements for teams that need rapid alignment, risk analysis, architecture direction, or a readiness assessment. Each is tailored to your environment and delivered as a working session, not a training class.
AI Agent Risk & Governance Clarity
Rapid leadership alignment on agent risk before adoption, investment, or governance decisions.
- Agent risk landscape
- Enterprise governance gaps
- Operating model and ownership
- Control boundaries
- Practical next steps
AI Agent Threat Modeling
Map the attack paths autonomous agents open across tools, identity, and delegation.
- Agent attack paths, tools, and APIs
- MCP, identity, and delegation
- Privilege escalation and agent-to-agent interaction
- Data access exposure
- Runtime controls
AI Agent Security & Governance Readiness Assessment
Assess current state and leave with a prioritized roadmap to close the gaps.
- Current-state architecture
- Agent inventory and deployment patterns
- Identity, access, and authorization boundaries
- Monitoring and evidence
- Governance maturity and prioritized roadmap
Architecture & Implementation Engagements
For organizations actively designing or deploying enterprise AI-agent infrastructure that need deeper architecture work than a workshop can provide.
Agentic IAM Architecture
Design an enterprise identity and access architecture for AI agents, autonomous workflows, machine identities, and human-to-agent delegation.
Discuss this engagementWhat it covers
- Agent and non-human identity
- OAuth 2.0 / OIDC and workload identity (SPIFFE/SPIRE where applicable)
- Identity lifecycle, credential strategy, and revocation
- Delegated authority and impersonation controls
- Agent-to-agent and agent-to-tool authorization
- MCP identity and authorization
- JIT and zero-standing-privilege access
- PAM / PIM and IGA integration
- Human-to-agent authority chains
Potential deliverables
- Current-state assessment and target-state architecture
- Trust model, identity flows, and delegation model
- Sequence diagrams and control recommendations
- Reference architecture and implementation roadmap
Agent Authorization & Runtime Control Architecture
Design the runtime authorization layer that determines whether a specific agent action should execute before it reaches the target system.
Identity establishes who the agent is and what authority it may hold. Runtime authorization determines whether a particular action should execute in context.
Discuss this engagementWhat it covers
- Action-level and dynamic authorization
- Policy decision and enforcement (PDP/PEP) architecture
- Intent and goal context in the decision
- Policy models and policy-as-code (Cedar where appropriate)
- Tool/API and MCP tool authorization
- Approvals, escalation, and revocation
- Enforcement effects, evidence, and auditability
Potential deliverables
- Target authorization model and policy model
- PDP/PEP architecture and integration design
- Reference flows and implementation roadmap
- Optional proof-of-concept or reference implementation
Agent Runtime Governance Architecture
Design the broader governance architecture required to control autonomous agent execution across frameworks, tools, environments, and delegation chains.
Discuss this engagementWhat it covers
- Runtime governance, execution lineage, and agent execution graphs
- Delegated authority chains and plan-versus-execution drift
- Multi-agent governance and containment
- Runtime policy, enforcement, and subtree revocation
- Evidence, auditability, and framework-independent controls
- Network and in-process enforcement patterns
- Sovereign or regulated deployment models where relevant
Potential deliverables
- Governance target architecture across frameworks and environments
- Execution-lineage and evidence model
- Enforcement and containment design
- Implementation roadmap, with Watchlight AI Beacon as one reference platform
Scope is set per engagement. Final scope, duration, and investment are agreed up front.
Who these engagements are for
Typical outcomes
Deliverables depend on the engagement. Not every engagement includes every artifact.
Built on Deep Identity and AI Security Experience
I have spent 23+ years in identity and cybersecurity, most recently as Field CTO at Strata Identity and Director of Solutions Engineering at SGNL, which was acquired by CrowdStrike. I also authored a technical companion to NIST NCCoE’s work on AI agent security.
Watchlight AI is developing the Agent Runtime Governance model and architecture for governing autonomous agent execution, grounded in the 12 Non-Negotiable Principles. Every engagement draws on that work, and remains credible whether or not you deploy Watchlight AI Beacon.
Aldo Pietropaolo, Founder & CEO, Watchlight AI
Common questions
Design the Control Architecture Before Agents Reach Production
Organizations moving agents into production have to answer identity, authority, delegation, authorization, enforcement, and evidence before those systems operate autonomously. We help you answer them, in the right order, with an architecture you can implement.
We typically respond within one business day.
