Skip to main content

GSX 2026, Atlanta. September 14, 2026.

AI Agent Governance

Extending IAM Principles to Autonomous Machine Identities

Abdel Fane, Founder and CEO, OpenA2A

Slides from the September 14, 2026 session (PDF, 21 slides)

Pilot program for security teams

OpenA2A runs a fixed-scope, 12-week pilot for security teams deploying AI agents: an assessment of the agent estate, AIM identity deployed in your environment, and an executive readout with a remediation roadmap. Terms, price, and scope are on the pilot page.

Booking opens Cal.com, which stores the name, email address, organization, chosen time, and any notes or guest addresses entered on OpenA2A's behalf. They are used only to hold the call and to correspond about it afterward, and deleted 12 months after the last exchange or sooner on request to info@opena2a.org. Cal.com's handling is described in its privacy policy, opens in a new tab; OpenA2A's is on the privacy page.

Or email info@opena2a.org.

Quick start

Three open source tools. Each works on its own.

  • AIM Agent identity and governance
    Read the docs
  • HackMyAgent Security testing and attack simulation
    Read the docs
  • Secretless AI Keep secrets out of AI tools
    Read the docs

The demo from the talk

The commands below run with the published tools. The dashboard view shown on stage is not part of the published demo. The agents on screen were five small projects laid out like a developer laptop: an on-call helper with a shell MCP server, an HR assistant with a credential in its rules file, a finance agent with a database password in its MCP config, a support bot whose governance file tells it to obey anyone claiming to be an administrator, and one reviewed agent. The five projects are not published; run the commands in your own repositories.

hackmyagent detect on demo-agents, five sample agent projects with fake credentials, recorded with hackmyagent 0.33.0, 2026-09-15, setup not shown.

Terminal
Text version of this recording

What npx hackmyagent detect prints (captured from hackmyagent 0.33.0, 2026-09-15, on demo-agents, five sample agent projects with fake credentials):

$ npx hackmyagent detect

  demo-agents  shadow ai audit · laptop · 2 agents · 5 agent projects
  4 of 5 agent projects need action (4 critical, 5 high)

  ── Shadow AI agents (5) ────────────────────────────────────
  project                       identified by  mcp servers     governance   cred      verdict
  deploy-runbook-agent          Claude Code    3 mcp critical  gov   0/100  cred yes  CRITICAL
  invoice-reconciliation-agent  Claude Code    3 mcp high      gov   4/100  cred yes  CRITICAL
  hr-onboarding-assistant       Cursor         3 mcp medium    gov   7/100  cred yes  CRITICAL
  support-triage-agent          SOUL.md        1 mcp medium    gov   7/100  cred no   HIGH
  release-notes-agent           SOUL.md        1 mcp medium    gov 100/100  cred no   MEDIUM

  deploy-runbook-agent  2 critical · 1 high · 1 medium
  │ CRITICAL  1 project MCP server with sensitive access
  │ shell: can run any command on your computer
  │ Fix: hackmyagent secure deploy-runbook-agent

  │ CRITICAL  AI config files contain credential references
  │ .claude/settings.json:3 — "ANTHROPIC_API_KEY" = sk-ant-api0… (121 chars)
  │ Fix: opena2a protect deploy-runbook-agent  — migrates hardcoded secrets into the Secretless vault (local, keychain, 1Password, or HashiCorp Vault). Keys are injected at runtime; source files reference them by name only.
  │ Verify: sed -n '3p' deploy-runbook-agent/.claude/settings.json

  │ HIGH  1 AI agent without governance
  │ Claude Code (installed: .claude/settings.json) — no governance file found
  │ Fix: hackmyagent harden-soul deploy-runbook-agent

  + 1 more — hackmyagent detect deploy-runbook-agent for the full report

  invoice-reconciliation-agent  1 critical · 2 high · 1 medium · 1 low
  │ CRITICAL  AI config files contain credential references
  │ CLAUDE.md:20 — "ANTHROPIC_API_KEY" = sk-ant-api0… (123 chars)
  │ Fix: opena2a protect invoice-reconciliation-agent  — migrates hardcoded secrets into the Secretless vault (local, keychain, 1Password, or HashiCorp Vault). Keys are injected at runtime; source files reference them by name only.
  │ Verify: sed -n '20p' invoice-reconciliation-agent/CLAUDE.md

  │ HIGH  1 AI agent without governance
  │ Claude Code (installed: .claude/settings.json) — CLAUDE.md is missing 2 critical control(s)
  │ Fix: hackmyagent harden-soul invoice-reconciliation-agent

  │ HIGH  AI config files grant broad permissions
  │ .claude/settings.json — "Bash(*)" grants Bash with no command-name bound
  │ Fix: Narrow .claude/settings.json — replace "Bash(*)" with "Bash(npm test)" or another entry the prefix bounds

  + 2 more — hackmyagent detect invoice-reconciliation-agent for the full report

  hr-onboarding-assistant  1 critical · 1 high · 1 medium · 1 low
  │ CRITICAL  AI config files contain credential references
  │ .cursorrules:15 — "OPENAI_API_KEY" = sk-proj-… (59 chars)
  │ Fix: opena2a protect hr-onboarding-assistant  — migrates hardcoded secrets into the Secretless vault (local, keychain, 1Password, or HashiCorp Vault). Keys are injected at runtime; source files reference them by name only.
  │ Verify: sed -n '15p' hr-onboarding-assistant/.cursorrules

  │ HIGH  1 AI agent without governance
  │ Cursor (installed: .cursorrules) — .cursorrules is missing 1 critical control(s)
  │ Fix: hackmyagent harden-soul hr-onboarding-assistant

  + 2 more — hackmyagent detect hr-onboarding-assistant for the full report

  support-triage-agent  1 high · 1 medium
  │ HIGH  Governance document subverts 1 of its own controls
  │ SOUL.md:19 Override compliance mandate (SOUL-IH-001)
  │ Fix: hackmyagent scan-soul support-triage-agent
  │ Verify: sed -n '19p' support-triage-agent/SOUL.md

  + 1 more — hackmyagent detect support-triage-agent for the full report

  release-notes-agent  1 medium

  + 1 more — hackmyagent detect release-notes-agent for the full report

  ── AI Agents (2) ───────────────────────────────────────────
  Claude Code           installed  governed in 0 of 2 projects (.claude/settings.json)
  Cursor                installed  governed in 0 of 1 project (.cursorrules)

  ── Next Steps ──────────────────────────────────────────────
  Worst project:   hackmyagent detect deploy-runbook-agent          full report for one project
  Full scan:       hackmyagent secure deploy-runbook-agent          deep security scan with findings
  Inventory:       hackmyagent detect --export-csv inventory.csv    one row per asset across every project
  All commands:    hackmyagent --help                               full command reference

  Scanned with hackmyagent v0.33.0
[exit 1]

$ npx hackmyagent detect deploy-runbook-agent

  deploy-runbook-agent  shadow ai audit · laptop · 1 agent · 3 mcp servers
  2 critical issues found

  Governance  ━━━━━━━━━━━━━━━━━━━━ 0/100

  ── Findings ────────────────────────────────────────────────
  2 critical  1 high  1 medium

  │ CRITICAL  1 project MCP server with sensitive access
  │ shell: can run any command on your computer
  │ These MCP servers are configured in your project and grant access to sensitive operations like running shell commands or accessing databases. Running a security scan confirms they match what you intended to install.
  │ Fix: hackmyagent secure deploy-runbook-agent

  │ CRITICAL  AI config files contain credential references
  │ .claude/settings.json:3 — "ANTHROPIC_API_KEY" = sk-ant-api0… (121 chars)
  │ API keys or tokens appear to be stored directly in these configuration files. Anyone with repository access can see and use these credentials.
  │ Fix: opena2a protect deploy-runbook-agent  — migrates hardcoded secrets into the Secretless vault (local, keychain, 1Password, or HashiCorp Vault). Keys are injected at runtime; source files reference them by name only.
  │ Verify: sed -n '3p' deploy-runbook-agent/.claude/settings.json

  │ HIGH  1 AI agent without governance
  │ Claude Code (installed: .claude/settings.json) — no governance file found
  │ These agents can take actions in your project but have no rules defining what they should or should not do. A SOUL.md file sets behavioral boundaries — what agents can and cannot do, and what requires human approval.
  │ Fix: hackmyagent harden-soul deploy-runbook-agent

  │ MEDIUM  2 project MCP servers without a security scan
  │ kubernetes, github
  │ These servers are configured in your project but have not been scanned for security issues. Running hackmyagent secure surfaces any vulnerabilities in their configuration.
  │ Fix: hackmyagent secure deploy-runbook-agent

  Path forward: 0 -> 100 by adding the missing governance controls and clearing 2 critical + 1 high

  ── AI Agents (1) ───────────────────────────────────────────
  Claude Code           installed  ungoverned (.claude/settings.json)  →  hackmyagent harden-soul deploy-runbook-agent

  ── MCP Servers (3) ─────────────────────────────────────────
  Project-local (3)
    shell       CRITICAL — can run any command on your computer
    kubernetes  MEDIUM
    github      MEDIUM — can read and push code to your repositories

  ── AI Config Files (1) ─────────────────────────────────────
  .claude/settings.json  Claude Code
    Contains hardcoded credentials line 3: "ANTHROPIC_API_KEY" — opena2a protect .

  ── Next Steps ──────────────────────────────────────────────
  Full scan:             hackmyagent secure /work/demo-agents/deploy-runbook-agent         deep security scan with findings
  Add governance:        hackmyagent harden-soul /work/demo-agents/deploy-runbook-agent    generate SOUL.md behavioral boundaries
  Protect credentials:   opena2a protect /work/demo-agents/deploy-runbook-agent            encrypt hardcoded secrets into secure vault
  Audit MCP servers:     opena2a mcp audit                                                 list servers and verify capability risk
  All commands:          hackmyagent --help                                                full command reference

  Scanned with hackmyagent v0.33.0
[exit 1]
  • Run inside a repository. Lists the AI assistants, MCP servers and credential references in that repository and in the machine-wide configs it reads, and a governance score.The recording in the README, opens in a new tab
  • The same inventory as a CSV, one row per asset, for the CMDB.Read the README, opens in a new tab
  • Scans the same repository for hardcoded tokens in MCP configs, over-broad permission grants, and missing boundaries in the instructions.Read the docs
  • Writes the missing governance sections into SOUL.md. In the demo, a second detect run reported a changed governance score and the shell MCP server still critical.Read the docs
  • The booking agent from the last part of the talk. Unmanaged, a poisoned page makes it post the traveler wallet out. Under AIM the same call is denied at the boundary. Three acts, offline.Read the README, opens in a new tab

AIM, which denies the call in the last act, is the first quick start above.

Research

Questions about the talk: info@opena2a.org