DevOps and Platform teams now work with hundreds of AI Agents in their internal systems. These Agents usually run with credentials that can touch everything, including your production servers. This could lead to problems.
This workshop will teach you how to add delegated authorization to your AI Agents, at scale.
We'll build a DevOps deploy agent on goose - the open-source agent from the Agentic AI Foundation and then give it fine-grained permissions using Relationship-Based Access Control (ReBAC). Along the way you'll get hands-on with the Google Zanzibar model of fine-grained authorization (ReBAC) and why it fits AI agents: scoped delegation, expiring grants, instant revocation, and hierarchical permissions where revoking staging access automatically suspends production too, something role-based systems can't express cleanly.
This is a self-guided, hands-on workshop, and everything runs locally with open-source tooling.
Prerequisites:
- Docker (can build a GitHub devcontainer as well)
- goose installed, plus an API key for any LLM goose supports
___________________________
Presentation Language: English
Captioning will be available for attendees in 50+ languages through Wordly. See instructions in each room to utilize captioning.