Joint Webinar
Actionable Signals with Cy5 · Episode 01
Your AI agent won't get a new identity. It'll use one you already made.
01 · The problem
It runs in a Lambda, a pod, a CI/CD job or a workload, using an identity that already exists.
Which means your agent risk is bounded by something that already exists in your cloud estate, and that almost nobody has measured. Across AWS, Azure and GCP, the gap between what a non-human identity was granted and what it has actually used is the largest unexamined number in most organisations.
That gap is what your agent inherits.
We call it the Inherited Perimeter. This session is about measuring yours.02 · The framework
Five links. An AI agent inherits all of them — and the one in the middle is the one nobody has measured.
The Inherited Perimeter is the set of cloud entitlements an AI agent or automated workload acquires by assuming an identity that already exists — an execution role, service account, pipeline trust or access key. It is measured by the Permission Delta: the share of granted permissions that identity has not invoked in ninety days.
03 · Takeaways
Every one of these is yours to run on Thursday morning.
What the granted-versus-used gap measures at across real multi-cloud estates — with the methodology shown, not just the headline. Measured, not surveyed.
Enumerate, attribute, compare, reach, reclaim. Answerable in order, against your own estate. Most organisations discover they stall at question two.
The specific commands to run against AWS, Azure and GCP to answer question one yourself — every non-human identity in your estate, listed. No product required.
What you constrain at the access boundary while the reclaim backlog burns down — from an architect who deploys this across ZTNA and SASE estates for a living.
04 · Audience
Cloud security architects, IAM and identity engineers, platform and DevSecOps leads, SecOps leaders, and the CISOs who will be asked about this before they are ready.
Organisations running production workloads on one or more public clouds.
Anyone looking for an introduction to AI security. We assume you know what an IAM role is, what a service account does, and why a wildcard in a policy document matters.
We will not be defining CNAPP.
This is also not a product demonstration. There is a five-minute segment where we show how we measured the number, because a method you cannot see is a claim you cannot check. The other fifty-five minutes are not about our platform.
05 · The hour
We will keep the hard stop. Your 12:00 is safe.
06 · Speakers
Founder & CEO, Cy5
Vikram was a CISO before he built a cloud security platform, which means he has been on both sides of the conversation about what a security tool actually tells you versus what it claims to. He founded Cy5 in 2021 to close the gap between when a cloud estate changes and when anyone finds out. He'll be presenting the measurement and what it means.
Building in Stealth Mode, Ex- Head of Security, AWS India
20+ years in enterprise security, from blade servers to AI agents. Built AWS India's Security Practice, shaped policy with RBI, SEBI, CERT-In, and MEITY. Mentored Cybersecurity startups and Worked with 100+ CxOs. Now focused on redefining security baselines for a world where everyone builds. Working at the intersection of cloud security, AI governance, and regulatory compliance.
07 · Register
Measured across real estates. Not surveyed. Not projected.
Cy5 and Auxiliary Digitech are co-hosting this session. By registering you agree that your details may be shared between them for the purpose of following up on this event. You can withdraw this at any time by writing to [email protected].
08 · Questions
The Inherited Perimeter is the set of cloud entitlements an AI agent or automated workload acquires by assuming an identity that already exists — an execution role, service account, pipeline trust or access key. It is measured by the Permission Delta: the share of granted permissions that identity has not invoked in ninety days.
The proportion of permissions granted to a non-human identity that it has not invoked during a defined observation window, typically ninety days. A delta of 0.94 means the identity used six percent of what it was given. It is the core metric of the Inherited Perimeter framework.
In production, an AI agent almost never receives a purpose-built identity. It authenticates as its runtime: an AWS Lambda execution role, a Kubernetes pod service account, a CI/CD job's OIDC trust relationship, or a static access key in an environment variable. It inherits every permission that identity already holds.
The three providers model entitlements differently enough that the question does not translate. AWS IAM policies, Microsoft Entra role assignments and Google Cloud IAM bindings use different primitives for grant, scope and inheritance. Asking "what can this identity reach?" returns three answers that are each correct within their own console and cannot be summed.
Start by enumerating per provider: IAM roles, users and access keys in AWS; service principals and managed identities in Entra; service accounts in Google Cloud. Then add workload identities from Kubernetes and any CI/CD trust relationships. Attribution — who owns each one — is usually harder than enumeration.
No. CIEM is the tooling category that measures cloud entitlements. The Inherited Perimeter is a framework for interpreting that measurement once AI agents begin assuming existing identities, together with a five-question assessment for locating an estate's current visibility. It can be applied with any CIEM tool, or with native cloud APIs alone.
They address different stages. The CSA framework designs governance for purpose-built agent identities — lifecycle, just-in-time access, constrained delegation. The Inherited Perimeter measures what agents inherit in estates that have not reached that state yet, which is most of them. The two are complementary: assessment first, governance design second.
Yes, and arguably more so. The non-human identities an agent will inherit already exist — service accounts, pipeline roles, access keys, cross-account trusts. Measuring the gap between what they were granted and what they use is more useful before agents are deployed against them than after.
Measured across real estates. Not surveyed. Not projected.
Get the five questions →
Hosted by Cy5 & Auxiliary Digitech
Actionable Signals with Cy5 · Episode 01
Event-driven protection. Zero blind spots. Infinite scale.