Loading…
2026 September 10-11 | Tokyo, Japan
View More Details & Registration

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.
Venue: Hall B clear filter
Thursday, September 10
 

10:15 JST

Beyond Adoption: From Access Control to Execution Control in Enterprise MCP - Tomomichi Noguchi, Workato
Thursday September 10, 2026 10:15 - 10:40 JST
MCP makes it easier for AI agents to connect to enterprise systems, but moving from experimentation to production raises a deeper question: is controlling what an agent can access enough? An agent may have permission to update customer data, but that doesn't mean every authorized action should be executed in the same way.

This talk introduces the distinction between Access Control — what an agent is allowed to do — and Execution Control — how an authorized request should actually be carried out. We'll explore how mechanisms such as business rules, deterministic logic, and auditability, among others, can work together behind MCP tools to shape how execution happens in the enterprise.

The goal is to provide a practical architectural lens for teams taking MCP beyond adoption and into production: enterprise trust requires controlling not only what agents can access, but how their actions are executed.

___________________________
Presentation Language: Japanese

Captioning will be available for attendees in 50+ languages through Wordly. See instructions in each room to utilize captioning.

Speakers
avatar for Tomomichi Noguchi

Tomomichi Noguchi

Forward Deployed Engineering Lead, Japan, Workato
Noguchi leads Technical Services and Forward Deployed Engineering at Workato Japan, where he works with enterprise customers to turn automation and AI initiatives into scalable, production-ready programs.
Thursday September 10, 2026 10:15 - 10:40 JST
Hall B

10:50 JST

Workshop: Building MCP Authorization with Keycloak and agentgateway - Yoshiyuki Tabata & Michito Okai, Hitachi
Thursday September 10, 2026 10:50 - 12:25 JST
As AI agents move from experimentation to production, authorization is becoming a core architectural concern. The MCP Authorization specification provides a standardized approach for protecting MCP resources and obtaining access tokens, but many developers have not yet seen these mechanisms in action.

In this hands-on workshop, participants will build a secure MCP environment using Keycloak, agentgateway, and MCP Inspector. Starting from an MCP server where all tools are publicly accessible, attendees will progressively introduce authorization controls using Keycloak and agentgateway, and observe how access to MCP tools changes.

Participants will use MCP Inspector to follow authorization flows step by step, including resource discovery, authorization server discovery, user authentication, token acquisition, authorization failures, and authorized tool invocation.

The workshop also explores Step-Up Authorization scenarios introduced in the latest MCP Authorization specification.

By the end of the session, participants will have a working MCP Authorization environment and practical experience securing MCP-based AI agent systems.

___________________________
Presentation Language: English

Captioning will be available for attendees in 50+ languages through Wordly. See instructions in each room to utilize captioning.
Speakers
avatar for Yoshiyuki Tabata

Yoshiyuki Tabata

Chief OSS Consultant, Hitachi
Yoshiyuki Tabata is a Chief OSS Consultant at Hitachi OSPO with more than a decade of experience in identity and access management (IAM), authentication, authorization, and API security. He is a contributor to Keycloak, a co-author of the CNCF IAM Whitepaper, and serves as Tech Lead... Read More →
avatar for Michito Okai

Michito Okai

Software Engineer, Hitachi, Ltd.

Thursday September 10, 2026 10:50 - 12:25 JST
Hall B
  Workshop
  • Presentation Language English
  • Presentation Slides Attached Yes

13:30 JST

Workshop: Governing AI Agent Actions: MCP and Beyond - Shannon Williams & Chris Urwin, Obot AI
Thursday September 10, 2026 13:30 - 15:05 JST
Enterprise adoption of the Model Context Protocol is accelerating, and MCP has become the primary way agents connect to enterprise tools and data. But MCP is only part of how agents act. Agents also run CLIs, execute Skills, and generate code that calls APIs directly. Governing MCP well matters. Governing everything else agents can do matters just as much.

Building MCP servers and writing Skills isn't particularly hard. The real challenges are deciding which actions agents are allowed to take, controlling who can take them, and proving it all later. These are architectural questions, and they need answers before agents scale across an organization.

In this workshop, we will:
  1. Show how to control agent actions with policies that apply across MCP servers, CLIs, Skills, and agent-generated code — including allowlists, access control by users and groups, and human-in-the-loop approvals.
  2. Explain why enterprises need managed registries for MCP servers and Skills, and how admin review and approval change the trust model.
  3. Work through audit and compliance requirements: capturing complete logs of agent and tool activity, exporting to enterprise storage, and generating reports.
  4. ⁠Demonstrate how to discover shadow AI — unmanaged agents, MCPs, and Skills already running in your organization — and how to block them or bring them under management.
  5. Look at token usage and spend visibility by agent, user, and group.

You'll leave with a clear picture of the architectural decisions ahead of you, and a better sense of what your security team will require before signing off on scaling AI agents across your organization.

___________________________
Presentation Language: English
Captioning will be available for attendees in 50+ languages through Wordly. See instructions in each room to utilize captioning.
Speakers
avatar for Shannon Williams

Shannon Williams

President, Obot AI
I am the President and co-founder of Obot AI, and have been building open source software for the last 20 years. Prior to starting Obot, I co-founded Cloud.com (creator of CloudStack) and Rancher Labs (creator of Rancher, k3s, Longhorn, etc). I was a board member of the CNCF for 4... Read More →
avatar for Chris Urwin

Chris Urwin

VP of Field Engineering, Obot AI
Chris Urwin is VP of Field Engineering at Obot AI and a veteran engineering leader. With deep hands-on experience in cloud‑native platforms, Kubernetes, containers, CI/CD, and developer tooling, he builds and scales global technical teams. Chris bridges product, engineering, and... Read More →
Thursday September 10, 2026 13:30 - 15:05 JST
Hall B
  Workshop

15:35 JST

Architecting Agent-Native Data Layers: Managing Persistent State Across MCP Tools - Tomohiro Ichimura, Yugabyte Japan
Thursday September 10, 2026 15:35 - 16:00 JST
As multi-agent systems move to production, managing persistent state and data lineage across independent tools is a critical engineering bottleneck. This session explores the architectural gaps in current agent workflows and introduces an open-source approach to building structured, tiered datastores using the Model Context Protocol (MCP).

We will present the concept of an "agent-native data layer" and the "datapack" framework—designed to decouple and layer data specifically for multi-agent environments. Attendees will learn how an open-source MCP server can act as a unified abstraction layer to securely bridge public and proprietary data. You will walk away with actionable design patterns to ensure independent tools seamlessly retain state and context without vendor lock-in.

___________________________
Presentation Language: English

Captioning will be available for attendees in 50+ languages through Wordly. See instructions in each room to utilize captioning.

Speakers
avatar for Tomohiro Ichimura

Tomohiro Ichimura

Head of Japan and Korea, Yugabyte Japan
As Head of Japan and Korea, leading both commercial strategy and technical operations to bridge the gap between business growth and complex engineering. With a deep background in distributed systems, cloud-native infrastructure, and data platforms—built across technical and business... Read More →
Thursday September 10, 2026 15:35 - 16:00 JST
Hall B
  Multi-Agent and Distributed Systems

16:10 JST

Workshop: Enterprise Agentic AI: Architecting Autonomous Java Systems for Production - Daniel Oh, Red Hat & Kevin Dubois, IBM
Thursday September 10, 2026 16:10 - 17:45 JST
Step into the future of enterprise automation by building production-ready agentic AI systems using Java. This hands-on lab guides you through designing scalable multi-agent architectures that seamlessly connect with enterprise infrastructure. You will gain practical experience implementing key design patterns such as sequence, parallel, routing, loop, and supervisor models while enabling direct agent-to-agent (A2A) collaboration. We will also address real-world deployment challenges by integrating human-in-the-loop control points and robust observability features. Leave equipped with functional code and the architectural blueprints needed to bring robust agentic AI into your organization.

___________________________
Presentation Language: English

Captioning will be available for attendees in 50+ languages through Wordly. See instructions in each room to utilize captioning.

Speakers
avatar for Daniel Oh

Daniel Oh

Senior Principal Developer Advocate, Red Hat
Java Champion, CNCF Ambassador & TAG DevEX Co-Chair, AAIF Ambassador, Microsoft MVP, Developer Advocate, Technical Marketing, Keynote Speaker, Published Author
avatar for Kevin Dubois

Kevin Dubois

Sr Principal Developer Advocate, IBM
Kevin Dubois is often featured as a (keynote) speaker at conferences around the world, where he shares his passion and knowledge about developer experience, Agentic AI, open source, cloud native development and Java. He is also an author, java Champion, and an accomplished software... Read More →
Thursday September 10, 2026 16:10 - 17:45 JST
Hall B
  Workshop
 
Friday, September 11
 

10:20 JST

Sponsored: Reliable Agents by Design: Reasoning + Deterministic Execution - Hiroyuki Suzuki, Workato
Friday September 11, 2026 10:20 - 10:45 JST
As AI agents move from answering questions to taking actions across enterprise systems, reliability cannot be achieved through model quality alone. A practical production architecture separates non-deterministic reasoning from deterministic execution.

This session explores how to define that boundary with MCP-enabled tools. Agents can interpret ambiguous requests, gather context, and choose among bounded options. Deterministic workflows, services, and policy checks can then perform repeatable operations such as validation, approvals, system updates, notifications, audit logging, and recovery.

Using common enterprise action patterns, we will examine how this division of responsibility improves output quality while reducing unnecessary reasoning, latency, and token cost. We will also discuss how to design action interfaces with clear intent, constrained outcomes, and recoverable execution.

Rather than treating agents and workflows as competing approaches, this session presents them as complementary parts of a single execution architecture. Attendees will leave with a practical framework and checklist for designing reliable, cost-aware MCP capabilities across open-source agent frameworks and enterprise environments.


In order to facilitate networking and business relationships at the event, you may choose to visit a third party's booth or access sponsored content. You are never required to visit third party booths or to access sponsored content. When visiting a booth or participating in sponsored activities, the third party will receive some of your registration data. This data includes your first name, last name, title, company, address, email, standard demographics questions (i.e. job function, industry), consenting to receipt and use of such data by the third-party recipients, which will be subject to their own privacy policies.

___________________________
Presentation Language: Japanese

Captioning will be available for attendees in 50+ languages through Wordly. See instructions in each room to utilize captioning.
Speakers
avatar for Hiroyuki Suzuki

Hiroyuki Suzuki

Field CTO, Workato K.K.
I am a founding member of Workato Japan and currently serve as Field CTO. Since launching Workato’s Japan business in 2018, I have worked with enterprises to put enterprise orchestration into practice—connecting AI agents securely and reliably with business processes, data, and... Read More →
Friday September 11, 2026 10:20 - 10:45 JST
Hall B

10:55 JST

Workshop: From goose to GDK: Building Your Own Agentic Applications - Abhijay Jain, AAIF goose
Friday September 11, 2026 10:55 - 12:30 JST
In this workshop, we’ll talk about goose and goose development kit, and look at the building blocks that make it possible to build your own agentic applications with goose.

We’ll start with goose and the **Goose Reference Client (GRC)**, looking at how the reference client demonstrates the capabilities and patterns of the goose ecosystem. We’ll then dive into the **Goose Development Kit (GDK)** and explore how developers can use its APIs and libraries to incorporate goose capabilities into their own applications.

Through a step-by-step walkthrough and live examples, we’ll look at how the GDK can be used to work with model providers, stream model responses, handle tool calls, and build application-specific experiences on top of goose. We’ll also explore how the reference client and GDK fit together and where different layers of the goose stack make sense for different use cases.

By the end of the workshop, attendees will have a clearer understanding of goose, the role of the Goose Reference Client and GDK, and how they can start using the GDK as a foundation for building their own agentic applications and experiences.

___________________________
Presentation Language: English

Captioning will be available for attendees in 50+ languages through Wordly. See instructions in each room to utilize captioning.

Speakers
avatar for Abhijay Jain

Abhijay Jain

Maintainer & Contributor, AAIF goose

Friday September 11, 2026 10:55 - 12:30 JST
Hall B
  Workshop

13:40 JST

Workshop: Delegated Authorization for AI Agents: Build an Agent with Fine-Grained Permissions - Sohan Maheshwar, AuthZed
Friday September 11, 2026 13:40 - 15:15 JST
DevOps and Platform teams now work with hundreds of AI Agents in their internal systems. These Agents usually run with credentials that can touch everything, including your production servers. This could lead to problems.

This workshop will teach you how to add delegated authorization to your AI Agents, at scale.

We'll build a DevOps deploy agent on goose - the open-source agent from the Agentic AI Foundation and then give it fine-grained permissions using Relationship-Based Access Control (ReBAC). Along the way you'll get hands-on with the Google Zanzibar model of fine-grained authorization (ReBAC) and why it fits AI agents: scoped delegation, expiring grants, instant revocation, and hierarchical permissions where revoking staging access automatically suspends production too, something role-based systems can't express cleanly.

This is a self-guided, hands-on workshop, and everything runs locally with open-source tooling.

Prerequisites:
  • Docker (can build a GitHub devcontainer as well)
  • Python 3.10+
  • goose installed, plus an API key for any LLM goose supports

___________________________
Presentation Language: English

Captioning will be available for attendees in 50+ languages through Wordly. See instructions in each room to utilize captioning.
Speakers
avatar for Sohan Maheshwar

Sohan Maheshwar

Lead Developer Advocate, AuthZed
Friday September 11, 2026 13:40 - 15:15 JST
Hall B
  Workshop

15:35 JST

Trace-Based Evaluation of Open-Weight Coding Agents: Measuring Real Agent Behavior - Kota Tsuyuzaki, NTT DOCOMO BUSINESS, Inc.
Friday September 11, 2026 15:35 - 16:00 JST
Teams are moving coding agents onto self-hosted open-weight models to control inference cost, and real sessions routinely span tens of turns and hundreds of thousands of tokens. But the only common signal for judging those models is the static accuracy benchmark, which says little about how a model behaves across a real, multi-turn session.

This session closes that gap with a trace-based evaluation method built on open technology: OpenTelemetry for capture and MLflow for analysis. Through a case study tracing real Claude Code sessions on a 120B-class open-weight model and a frontier model, it surfaces behaviors no leaderboard reports. For example, in the sessions we traced, the model's logged reasoning recorded a user's constraint, and the same turn violated it. An accuracy score sees only the wrong action; the trace shows the model had the rule in hand and did not follow it.

Attendees leave with a reusable observability architecture for their own agents, metrics that go beyond accuracy, and a clear view of what running a coding agent on open weights actually costs, in reliability and not only in dollars.

___________________________
Presentation Language: English

Captioning will be available for attendees in 50+ languages through Wordly. See instructions in each room to utilize captioning.
Speakers
avatar for Kota Tsuyuzaki

Kota Tsuyuzaki

Engineering Manager, NTT DOCOMO BUSINESS, Inc.
Kota joined Nippon Telegraph and Telephone Corporation in 2010 and has been a core developer of OpenStack Swift, the open-source on-premise cloud storage. He later moved into the AI/HPC area, working with the Lustre file system and Slurm Workload Manager. In 2023 he joined NTT DOCOMO... Read More →
Friday September 11, 2026 15:35 - 16:00 JST
Hall B
  Evals & Testing

16:10 JST

Workshop: Building Secure & Discoverable Agent Infrastructure with agentgateway & agentregistry - Mehmet Hilmi Emel, ACEDEMAND IT Consulting Services
Friday September 11, 2026 16:10 - 17:45 JST
As AI agents move from local tests to real-world use, developers face a big problem: How do we easily find, direct, secure, and track AI traffic going to MCP servers? Standard API gateways do not understand LLM tool calls, and writing static lists of agents is too hard to manage.

In this hands-on workshop, we will connect AI agents and external tools easily using the standalone versions of Solo.io’s agentgateway and AgentRegistry. We will show you how to build a strong control layer for the Model Context Protocol (MCP) using simple local tools like Docker.

Participants will learn how to:

  • Discover: Run AgentRegistry locally to list, version, and find MCP servers dynamically.
  • Control: Set up agentgateway as a smart proxy to catch and manage agent requests.
  • Secure: Add AI-specific rules, like rate limits and basic access control, to agent tool calls.
  • Observe: See exactly which tools the agents are using and how fast they respond.

Join us to learn how to build a safe, easy-to-run foundation for your multi-agent systems right on your laptop!

___________________________
Presentation Language: English

Captioning will be available for attendees in 50+ languages through Wordly. See instructions in each room to utilize captioning.
Speakers
avatar for Mehmet Hilmi Emel

Mehmet Hilmi Emel

AI Engineer, Acedemand IT Consulting
As a AI System Engineer, I specialize in securing AI agent interactions at the infrastructure level. I have extensive experience designing AI-driven MCP architectures and tackling the complex security challenges of GenAI on Kubernetes. I build open-source blueprints for zero-trust... Read More →
Friday September 11, 2026 16:10 - 17:45 JST
Hall B
  Workshop
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.