Security Weekly Podcast Network (Audio) Security Weekly Podcast Network (Audio)

Getting Granular with Access, Attributes, and Intent - Alex Olivier - ASW #403

Oct 6, 2026 · 1h 10m

Summary

In this episode, hosts Mike Shima, John Kinsella, and Tyler Shields interview Alex Olivier, co-founder of Serbos and co-chair of the OpenID AuthZen working group. They discuss the standardization of authorization for AI agents and MCP servers, focusing on the AuthZen spec to create a common interface between policy enforcement and decision points. Olivier explains how intent-based authorization and deterministic policy checks can mitigate risks from non-deterministic agents, emphasizing defense-in-depth strategies like egress proxies and sandboxing. The conversation also covers the use of L…

Topics discussed

Intro: Episode 403 and guest introduction AuthZen Working Group: Need for new standards Externalizing authorization and standardized interfaces Design patterns and the authorization information model Complexity, least privilege, and open-ended resources Intent-based authorization (IBAC) for AI agents Deterministic policy gates for agent tool calls Defense in depth and MCP protocol bindings Performance considerations and distributed decision points Delegation models: Humans, agents, and subagents Agents exposing existing security flaws and standing privileges Role of LLMs in policy authoring, audit, and decisioning Sponsorships and transition to news segment Apple's granular full disk access controls for agents LLM-assisted discovery of Linux SMC privilege escalation Formula One battery management and complex system failures GLM-5.3 cyber capabilities and risk reduction strategy
Listen ad-free on Castria