Book a demo
Cy5 × Auxiliary Digitech
Joint live webinar Joint Webinar

Actionable Signals with Cy5 · Episode 01

AI Agents and the Identity Crisis of 2026

Your AI agent won't get a new identity. It'll use one you already made.

Date
Wed 7 October 2026
Time
11:00–12:00 IST
Where
Zoom
Cost
No cost
Reserve a seat → Free · Recording to all registrants
  • Vikram Mehta - Founder & CEO, Cy5 (ex-Group CISO, MMT)
  • Lalit Kumar - 20+ Years in Enterprise Security, Ex-Head of Security (AWS India)

01 · The problem

Nobody provisions an identity for an AI agent

It runs in a Lambda, a pod, a CI/CD job or a workload, using an identity that already exists.

Same credential. New capabilities.
The agent is new, the credential isn’t.

Which means your agent risk is bounded by something that already exists in your cloud estate, and that almost nobody has measured. Across AWS, Azure and GCP, the gap between what a non-human identity was granted and what it has actually used is the largest unexamined number in most organisations.

That gap is what your agent inherits.

We call it the Inherited Perimeter. This session is about measuring yours.

02 · The framework

The Inherited Perimeter

Five links. An AI agent inherits all of them — and the one in the middle is the one nobody has measured.

Definition

The Inherited Perimeter is the set of cloud entitlements an AI agent or automated workload acquires by assuming an identity that already exists — an execution role, service account, pipeline trust or access key. It is measured by the Permission Delta: the share of granted permissions that identity has not invoked in ninety days.

03 · Takeaways

Four things, all usable without buying anything

Every one of these is yours to run on Thursday morning.

  • 01

    The number

    What the granted-versus-used gap measures at across real multi-cloud estates — with the methodology shown, not just the headline. Measured, not surveyed.

  • 02

    The five questions

    Enumerate, attribute, compare, reach, reclaim. Answerable in order, against your own estate. Most organisations discover they stall at question two.

  • 03

    The queries

    The specific commands to run against AWS, Azure and GCP to answer question one yourself — every non-human identity in your estate, listed. No product required.

  • 04

    The enforcement pattern

    What you constrain at the access boundary while the reclaim backlog burns down — from an architect who deploys this across ZTNA and SASE estates for a living.

04 · Audience

Built for

Cloud security architects, IAM and identity engineers, platform and DevSecOps leads, SecOps leaders, and the CISOs who will be asked about this before they are ready.

Organisations running production workloads on one or more public clouds.

Not built for

Anyone looking for an introduction to AI security. We assume you know what an IAM role is, what a service account does, and why a wildcard in a policy document matters.

We will not be defining CNAPP.

This is also not a product demonstration. There is a five-minute segment where we show how we measured the number, because a method you cannot see is a claim you cannot check. The other fifty-five minutes are not about our platform.

05 · The hour

Agenda

  1. 11:00The identity nobody provisionsHow agent runtimes actually authenticate
  2. 11:08The Permission DeltaWhat we measured, across how many estates, and how
  3. 11:18The Inherited PerimeterAnd the five questions that locate your estate on it
  4. 11:26Three clouds, three answersWhy the question doesn't translate across AWS, Azure and GCP
  5. 11:34Enforcement at the access boundaryMr. Lalit Kumar (Ex- Head of Security, AWS India)
  6. 11:42What to run on Thursday morning
  7. 11:45Live Q&A
  8. 12:00Hard stop

We will keep the hard stop. Your 12:00 is safe.

06 · Speakers

Who's presenting

  • Vikram Mehta

    Vikram Mehta

    Founder & CEO, Cy5

    Vikram was a CISO before he built a cloud security platform, which means he has been on both sides of the conversation about what a security tool actually tells you versus what it claims to. He founded Cy5 in 2021 to close the gap between when a cloud estate changes and when anyone finds out. He'll be presenting the measurement and what it means.

  • Mr. Lalit Kumar (Ex- Head of Security, AWS India)

    Lalit Kumar

    Building in Stealth Mode, Ex- Head of Security, AWS India

    20+ years in enterprise security, from blade servers to AI agents. Built AWS India's Security Practice, shaped policy with RBI, SEBI, CERT-In, and MEITY. Mentored Cybersecurity startups and Worked with 100+ CxOs. Now focused on redefining security baselines for a world where everyone builds. Working at the intersection of cloud security, AI governance, and regulatory compliance.

07 · Register

Wednesday 7 October
11:00–12:00 IST

Measured across real estates. Not surveyed. Not projected.

  • No cost
  • Recording to all registrants
  • 60 minutes, hard stop
  • Live Q&A
Reserve a seat →

08 · Questions

Before you register

What is the Inherited Perimeter?

The Inherited Perimeter is the set of cloud entitlements an AI agent or automated workload acquires by assuming an identity that already exists — an execution role, service account, pipeline trust or access key. It is measured by the Permission Delta: the share of granted permissions that identity has not invoked in ninety days.

What is a Permission Delta?

The proportion of permissions granted to a non-human identity that it has not invoked during a defined observation window, typically ninety days. A delta of 0.94 means the identity used six percent of what it was given. It is the core metric of the Inherited Perimeter framework.

What identity does an AI agent use in a cloud environment?

In production, an AI agent almost never receives a purpose-built identity. It authenticates as its runtime: an AWS Lambda execution role, a Kubernetes pod service account, a CI/CD job's OIDC trust relationship, or a static access key in an environment variable. It inherits every permission that identity already holds.

Why can't you measure cloud entitlements across AWS, Azure and GCP together?

The three providers model entitlements differently enough that the question does not translate. AWS IAM policies, Microsoft Entra role assignments and Google Cloud IAM bindings use different primitives for grant, scope and inheritance. Asking "what can this identity reach?" returns three answers that are each correct within their own console and cannot be summed.

How do you find every non-human identity in a cloud estate?

Start by enumerating per provider: IAM roles, users and access keys in AWS; service principals and managed identities in Entra; service accounts in Google Cloud. Then add workload identities from Kubernetes and any CI/CD trust relationships. Attribution — who owns each one — is usually harder than enumeration.

Is the Inherited Perimeter the same as CIEM?

No. CIEM is the tooling category that measures cloud entitlements. The Inherited Perimeter is a framework for interpreting that measurement once AI agents begin assuming existing identities, together with a five-question assessment for locating an estate's current visibility. It can be applied with any CIEM tool, or with native cloud APIs alone.

How does this relate to the CSA Agentic Identity Governance Framework?

They address different stages. The CSA framework designs governance for purpose-built agent identities — lifecycle, just-in-time access, constrained delegation. The Inherited Perimeter measures what agents inherit in estates that have not reached that state yet, which is most of them. The two are complementary: assessment first, governance design second.

We haven't deployed AI agents yet. Is this relevant?

Yes, and arguably more so. The non-human identities an agent will inherit already exist — service accounts, pipeline roles, access keys, cross-account trusts. Measuring the gap between what they were granted and what they use is more useful before agents are deployed against them than after.

Wednesday 7 October, 11:00 IST

Measured across real estates. Not surveyed. Not projected.

Get the five questions →

Hosted by Cy5 & Auxiliary Digitech
Actionable Signals with Cy5 · Episode 01

Joint webinar · Episode 01

Reserve your seat

Wed 7 Oct 2026 · 11:00–12:00 IST · Zoom · Free

Free · Recording sent to every registrant · 60 minutes, hard stop

Start Evaluating ion Cloud Security Platform

Event-driven protection. Zero blind spots. Infinite scale.