<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=1611884&amp;fmt=gif">

 

Autonomous agents are already acting on our behalf, booking travel, managing calendars, shopping, but most organizations can't answer basic questions about them: who is this agent, who does it belong to, and what is it allowed to do? In this episode of To The Point, Rosalyn Curato of Vouched joins Rachael Lyon and Jonathan Knepher to break down why identity and access models built for humans fall apart when the "user" is an agent, and what it actually takes to verify one, tie it to a responsible human, and shut it down if it goes rogue.

Key Takeaway 

  • Agents vs. bots: Bots are deterministic; agents are probabilistic and goal-oriented. That shift, from automation to autonomy, is why traditional authentication (like OAuth) doesn't hold up for agents.
  • The three questions every organization must answer: Who is this agent? What human is it associated with? What permissions has it been delegated to perform?
  • Real fraud, real cost: Organizations are already forecasting higher chargebacks and fraud tied to agent activity, including credential hijacking, prompt injection, and hijacked agents completing unauthorized transactions.
  • Controls that actually work: Delegated permissions, immutable audit trails, human-agent binding, and yes, a literal kill switch.
  • KYA-OS: Vouched's open standard for agent identity, built on W3C and donated to the Decentralized Identity Foundation, has seen over 10,000 interactions with the spec in its first four months.
  • The liability gap: When an agent completes a transaction or clicks "agree" on terms and conditions, who's responsible: the human, the agent, or the company that built it? The industry is still figuring this out.

Speakers

Rachael Lyon — Co-Host, To The Point Podcast

Jonathan Knepher — Co-Host, To The Point Podcast

Rosalyn Curato — Chief Innovation Officer & General Manager, Agentic Security, Vouched