Inside the Room · Interview
The Security Question Changes When Your Users Are Agents
Veridian's CISO on Zero Trust, identity and the uncomfortable questions raised when software starts acting on its own.
The challenge
Marcus O'Brien's team spent a decade building identity controls for human users. Then the company's product teams started deploying autonomous agents that call internal APIs at machine speed.
"Every assumption we had about who is on the other end of a request was suddenly wrong," he says.
The decision
O'Brien decided to treat agents as first-class identities — each with its own credentials, scope and audit trail — rather than letting them borrow a human's access.
Why the decision was made
"If an agent acts using my login, and it does something wrong, the log says I did it. That is not a security model. That is a liability."
What did not work
An early attempt to gate every agent action behind human approval killed the value of automation entirely. The team had to define which actions were reversible and low-stakes enough to run unattended.
Lessons learned
Zero Trust was built for this, O'Brien argues, but most implementations assumed a human at the end of the chain. "Take the human assumption out and the model still holds. You just have far more identities to manage."
What comes next
He is now focused on revocation — how fast the company can pull an agent's access when it behaves unexpectedly. "Speed of revocation is going to be a board-level metric."
“If an agent acts using my login and does something wrong, the log says I did it. That is not a security model. That is a liability.”Marcus O'Brien — CISO, Veridian Software
CXO Brief
There is always another perspective in the room.
The important developments executives should know — without the noise. Two editions a week.