VentureBeat
Identity and permissions aren’t enough to govern AI agent behavior

Box’s CISO Heather Ceylan warns that traditional identity and permission controls, designed for human users, cannot contain autonomous AI agents that can rapidly exploit any granted access. She advocates a layered security model that scopes permissions dynamically to each task step and governs execution, limiting tool calls and actions to prevent catastrophic misuse even when access checks succeed.