Getting Granular with Access, Attributes, and Intent - Alex Olivier - ASW #403
Oct 6, 2026 · 1h 10m
Summary
In this episode, hosts Mike Shima, John Kinsella, and Tyler Shields interview Alex Olivier, co-founder of Serbos and co-chair of the OpenID AuthZen working group. They discuss the standardization of authorization for AI agents and MCP servers, focusing on the AuthZen spec to create a common interface between policy enforcement and decision points. Olivier explains how intent-based authorization and deterministic policy checks can mitigate risks from non-deterministic agents, emphasizing defense-in-depth strategies like egress proxies and sandboxing. The conversation also covers the use of L…
Topics discussed
Intro: Episode 403 and guest introduction
AuthZen Working Group: Need for new standards
Externalizing authorization and standardized interfaces
Design patterns and the authorization information model
Complexity, least privilege, and open-ended resources
Intent-based authorization (IBAC) for AI agents
Deterministic policy gates for agent tool calls
Defense in depth and MCP protocol bindings
Performance considerations and distributed decision points
Delegation models: Humans, agents, and subagents
Agents exposing existing security flaws and standing privileges
Role of LLMs in policy authoring, audit, and decisioning
Sponsorships and transition to news segment
Apple's granular full disk access controls for agents
LLM-assisted discovery of Linux SMC privilege escalation
Formula One battery management and complex system failures
GLM-5.3 cyber capabilities and risk reduction strategy
Listen ad-free on Castria