Securing AI agent infrastructure
Identity, attestation, and behavioral trust at scale
System prompts are suggestions, not security controls, so the talk moves enforcement to the tool call. Three rings sit around it: an identity that is a keypair the host generates, a capability grant where anything not granted does not exist, and a signed trail of every decision, allowed and refused. Covers tool attestation and drift, a trust score that moves with behavior, and a live run of the same agent code with and without an identity.


