Defense in Depth Defense in Depth

Protecting AI Agents in O365 and Google Workspace

Jul 16, 2026 · 33m

Summary

Hosts David Spark and Steve Zalewski discuss the security risks of granting AI agents broad OAuth access to dormant data in cloud workspaces. Guest Rajan Kapoor from Material Security argues that legacy authorization models are insufficient, advocating for data-layer controls, classification, and retention policies. The episode explores using AI to identify sensitive data and minimize exposure before agents access it.

Topics discussed

Cold open: AI agents and data security Intro and the 'candy store' data metaphor Guest quotes on data concentration and oversight Cloud office environments and agent access risks Re-architecting identity and OAuth limitations The 'boxes in the garage' data hoarding analogy Sponsor segment: Material Security Digital twins and the perils of data retention Real-world data exposure and classification Legal retention policies and data deletion challenges Sponsor segment: Melanta threat intelligence Using AI to interrogate and clean up data Unified visibility across cloud workspaces Moving controls to the data layer Closing remarks and hiring information
Listen ad-free on Castria