Go to home page
23 Sep, 2026

Identity, Delegation, and Access Governance for AI Agents

The agentic enterprise runs on a decision most organisations have not consciously made: how much authority to hand software that acts on its own.

That authority rests on two questions, and most organisations have answered neither.

First, who is the agent? Before you grant anything, you need to know this is the agent it claims to be, who built it, who owns it, and that it has not been tampered with or replaced. An agent presenting a shared key proves nothing about any of that.

Second, whose authority does it carry? Sometimes a customer's, sometimes an employee's, sometimes a partner acting for their own client. And sometimes none of the above, because the agent was triggered by a schedule with no human anywhere in the loop. That last case is the one most organisations are least prepared for, and the one growing fastest.

This session is a practical guide to getting agent identity right, with no prior background assumed. Attendees will leave a framework to design agentic use cases into a digital journey from the start, and to put the identity foundations in place before granting autonomy.

Speakers

Ayesha Dissanayaka

Ayesha Dissanayaka

Associate Director & Architect

WSO2

Ayesha is an Associate Director and the Lead Architect for Identity and Access Management for Agentic AI at WSO2. She helps organizations adopt AI agents with confidence; building the identity, delegation, and authorization foundations that let autonomous systems be trusted with real access to real systems. With 12+ years in enterprise IAM, she designs solutions that hold up under production, regulatory, and audit pressure. She contributes to the industry standards shaping a new identity class: agents that act autonomously. She is part of the inaugural cohort of Agentic AI Foundation Ambassadors, and is a recognized voice on agent identity and AI security through her writing and speaking