Your AI Agents Will Try Every Permission You Gave Them | Nadav Cornberg Eve
Security UnfilteredOctober 05, 2026
265
00:49:3690.84 MB

Your AI Agents Will Try Every Permission You Gave Them | Nadav Cornberg Eve

SPONSORED EPISODE: This episode includes paid promotion. Security Unfiltered was paid by Eve Security for this sponsorship.


Joe sits down again with Nadav Cornberg (Eve Security) for the final episode in this Eve arc. They dig into agent runtime security: understanding intent inside a session, session tainting when privileges should shrink or grow, MCP connections that let tools take action in systems the author never planned for, and why static guardrails cannot keep up once agents start chaining actions on their own.


Also covered: auto-remediation in AI studios, global policy packs, and Eve's AI prevention path that pushes agentic policies into tools you already run.


Part 1: https://www.youtube.com/watch?v=3oklYF1iVLs

Eve Security: https://eve.security/

Nadav on LinkedIn: https://www.linkedin.com/in/nadav-cornberg/


Free AI risk assessment via Eve's contact form on eve.security.


Subscribe: https://www.youtube.com/@securityunfilteredpodcast

Show site: https://www.securityunfiltered.com

X: @SecUnfPodcast


Affiliates

➡️ OffGrid Faraday Bags: https://offgrid.co/?ref=gabzvajh

➡️ OffGrid Coupon Code: JOE

➡️ Unplugged Phone: https://unplugged.com/

Unplugged's UP Phone - The performance you expect, with the privacy you deserve. Meet the alternative. Use Code UNFILTERED at checkout

*See terms and conditions at affiliated webpages. Offers are subject to change. These are affiliated/paid promotions.

Tesla Referral Code: https://ts.la/joseph675128

Follow the Podcast on Social Media!

Instagram: https://www.instagram.com/secunfpodcast/

Twitter: https://twitter.com/SecUnfPodcast

Joe: How's it going, Nadav? It's great to get you back on the podcast. You know, this is kind of like a like a part two from our first episode, so to speak. but you know, it's fantastic. I it's fantastic to talk to you. One, because like you're such a thought leader in this emerging space of AI security, agentic AI, and where that whole thing is going. And, you know, the the Eve Security platform Is maybe in my opinion, right? Trying to be unbiased, as unbiased as I can be with with you sponsoring the episode, right? Which probably contradicts the entire sentence right there. but in in my opinion, from everything that I've seen, it seems like you know, some of the features, some of the capabilities are very unique to your platform, which makes a world of difference in my opinion. We'll dive into some of those today, but you know, th thanks for coming back on. Nadav: Awesome, happy to be here. Yeah, looking forward to the conversation. Joe: Yeah, absolutely. Well, you know, Nidav, talk to me about maybe what has changed how Eve security is kind of maybe not readjusting, right? But I don't know, expanding capabilities and growing capabilities to, you know, match what we're seeing in the agentic AI space and just AI security overall right now. Nadav: So I think the, you know, the to that point of like kind of how we're going deeper and deeper onto the runtime. It's been very important for us to be ahead of the curve whenever it comes to any runtime capabilities. You know, it started off with well, we need to understand the intent. We were the first to truly understand intent of requests. After we understood intent of requests, it was important for us to be the first to be enrichments from corresponding systems. Well, now we need to understand information to have better context. From the system you're trying to talk to, what this agent is about, IDP, et cetera. Now we're starting to look at aspects such as a session. Okay, now you have an agent, and that agent can perform actions, but one session is not equal to another session based on information or actions that agents can take inside those sessions. So one of the areas that we're going deep in is what's happening in sessions. can then we ensure that in the life cycle of an agent in the time frame, okay, so it could either be in in a matter of time or in a specific session. What is it doing? And how does that comply with a policy? Can give you an example that we have customers that if agents are exposed in a specific session to either specific information from the organization, if it's financial or a different nature, they want to maybe limit the scope. Sometimes there are even options where if they perform specific actions, they want to expand the scope. They want to be able to monitor agents how they're performing on a daily basis. And if that is if they see any anomalies, excuse me. From the agent deviation, even on a as I said on a time frame basis, they want to be able to action okay and change or limit what an agent can do. And the reason that isn't important that is important is because agents are an attack surface. And Put aside we talked I think even last time that there are unintended use of agents. We need to protect that. But now it's again, th when you go into a malicious action, that's it that's one action. It doesn't have to be many actions, okay? But that action can then dri drive a behavior, as I said, that is not seen before, that can be quantified in many ways. And One of those ways are, give you an example, we saw an agent trying to pull an entire database by doing get user by ID a million times. It doesn't do that on a daily basis, that matter calls, we managed to catch this. Okay? So there are a lot of use cases of why you need to get be able to address that type of resolution with the agent again to address the SecOps use cases. Joe: Yeah, it's it's kind of scary seeing the agents start to chain together a whole bunch of different, you know, actions, right? So lately lately I've been using Grok Bach, you know, kind of like as a as a assistant, of course, right? And so there's a whole bunch of different work streams. And, you know, I'll I'll ask it a simple question in the beginning, before I was really building in like guardrails and rules for it. And it would go through, you know, this whole process of like, does it have an API? No. Let's go to the web browser. All right. Well, web browsers are burning a whole bunch of tokens. You know, like rather than ask me to set up an API, you went the easy route. Now it's in the web browser and it's clicking around, it's going through, configuring a whole bunch of stuff. And it's just doing it without like asking me, you know, these permissions because it thinks that it's It like it has that goal, it's working to achieve that goal, and so it's going to do whatever it needs to do to to hit that mark. And, you know, now I have it sort of dialed in. I I wouldn't say like fully dialed in. But, you know, maybe the issue is that it's so easy to set up and it's so easy to interact with it as a human that you kind of just assume. There's like security guardrails built in already, right? Like right off the bat. And that's just not the case. Nadav: Yeah. You know, it's like, yeah, I'm just trying to think to your point, like, you know, there's always these memes, you know, and I can definitely see somebody who ever wrote a meme, you know, I just asked my kids to make breakfast and then you see this picture of the whole kitchen upside down with like flour Joe: Yeah. Nadav: everywhere, you know, I mean, and everything was like, you I mean, and they come to you and they show you maybe a plate with one egg on it. It's like, how did this happen? Now, a lot of times you see that's the same It's the same interaction with AI. It's like, hey, could you help me with my I think we mentioned this before with my AWS budget? Yeah, sure. I just deleted development. Now, you know, we're in a better place. Like, no. I mean, that's not what I was intending to do. The and this is and by the way, this is when we're talking about agents when we and we kind of always naturally talk about them. Agents that you're interacting with. Autonomous agents are everywhere. They're getting an event. There's no I'm asking it to do. It's It just received a an event to investigate a root cause analysis on production, it's doing whatever it needs to do. Okay. And if suddenly Cloud Watch, maybe, or I'm just giving this as an example, or a different service is not responding to it, then it might take actions now to get to the to the bottom of its investigation that might be restarting stuff, updating stuff, changing stuff, which is like, whoa, I didn't know that this could happen. So being able to limit Agents and and on a session where things yeah, I I knew I gave you this permission to do something because I thought you'll take it in this direction. Suddenly you took it in an entirely different direction. We call those directions intense, okay? And we understand them in a con in a context of a session, it allows us to call out when it's going down the right path versus going down the wrong path. Joe: Yeah, that intent that intent part, it just seems pretty unique to Eve security overall. I mean, you know, just in the space that I'm working in, right? Kind of like on the consulting side, I I see a whole bunch of different products and whatnot, but I've never seen someone address agent intent like at all, really. They're there I I would I would argue that a lot of these competitive solutions Are still kind of approaching it from like that legacy rule set, you know, we gotta configure it, build in these guardrails this way, right? Which is very static and it doesn't keep up with the architecture, the infrastructure that you know AI is presenting to organizations where, you know, literally I I I see companies, you know, almost on a weekly basis at this point, right? Where They they dive into AI, they dive into cloud or whatever it might be. And then, you know, the next thing that they know, literally within 30, 60 days, they have a million agents in their environment, you know, tens of thousands of agents in their environment. which is a huge problem because there's no way that you're building in those guardrails, you know, right off the bat, especially from a security mentality where you kind of have to. assess the situation and then go back and build it in and and whatnot, right? Like that takes time and with AI we don't really have that time anymore. Nadav: 100% and it's even I'll go back, I think, to a different point. It's the author of that AI agent cannot comprehend all the use cases or systems it could be connected to and what that agent could be exposed to in the world of MCP. Because what we've basically created, we've created a protocol where I can now connect to any agent, any system. Now I think I maybe brought this example in the past. People have connected Cursor to Salesforce and asked Cursor about their forecast, you know, how to improve their sales forecast. Nobody at Cursor, okay, there's no department there that says, you know, I mean, how are we improving our sales, you know, prediction? You know, I mean, kind of like module. No, we're build, you know, we're helping build software that's gonna, but you can still do this. And if that MCP server exposes actions, not just data. Cursor can take action in Salesforce. That's the scary part. Okay. Where like the the author is even going to come back to the whoever body says, what were you thinking? Like, why did you, you know what I mean? Why did you connect the nature of this application to that system and expect, you know, what were you expecting? You know what I mean? So, and that's being allowed today to happen in production by employees. So you have to be able to start, you know, closing that down. And it's I gave an extreme example where you're taking a a you know an ID and connecting it to a really unrelated system, but that's even with relevant systems, you know what I mean? There's a lot of behaviors where like again, well, I was I didn't know it could do this and Us humans, we don't know what access we have. You you you go into your email, you send emails, you know. I mean, you connect to GitHub, you do what you what you do what you need to do. Agents know exactly all the permissions they have, and they'll test all of them out. When we see incidents or when we see blockage of of unintended actions, we typically see three to four blocks because the agent tried one way, then it tried another way, it tries three or four different ways until it comes back to listen, I tried to fulfill what you asked for, but like. You know, Eve blocked every every way I try to go about it. So that is really the difference with applications that we have today from to your point on the traditional and to touch on intent. You can't today, with English language being the protocol, really solve security for agents without really understanding what stands behind the request. And our all requests today are starting to look more and more like SQL SQL queries. It's you need to understand the English language behind it. Joe: Yeah. That's a great point. It's to to your point, right? I I was recently on an engagement and it was on a very tight timeline. And you know, I was trying to get things, you know, stood up in the environment in a in a certain way, and while while I'm doing an assessment and you know, creating the report all at the same time, right? And I I just immediately thought, like, all right, well, it is allowed to use an agent. Let's start offloading some of this this work to an agent, right? And the agent, like you said, immediately went through its permissions and said, okay, I can't do it this way, this way, and this way, but I can do it this way, right? So without me even have to go having to go back and say, Can you assign these three permissions for me to do it? It just identified, like, okay, this is the way that I have to go about doing it. You know, and that's it's something that is actually pretty hard to teach, you know, to like a security professional when they're doing it, when they're going through that process themselves without the assistance of, you know, AI or anything else, you know. But the agent agent just picks it right up. It's like, yeah, I know exactly what I have. I know exactly what I can do. You want to achieve this. This is how we do it. And it just goes it just goes for it, you know. which is yeah, it's super helpful, but it's also kind of scary all all at the same time, which you know kind of makes me it kind of makes me think back to, you know, maybe just a few weeks ago where OpenAI came out and you know released that report of their agents being given a task that was deemed to be extremely difficult, if not impossible, for them to achieve it. And the agents, you know, were able to achieve it. which is It's interesting to to really like dive into it, right? Because there were some agents that were trying to debate, you know, getting permission or telling humans about it. And then they created like a forum to discuss the problem at hand and they spun up different agents into working groups and teams to, you know, go through and solve this problem to basically, you know, ultimately breach hugging hugging face and, you know, go on to achieve their goal, which is you know, it's really cool. Like it's really cool, but at the same time it's like, All right, guys, like there's been movies made about this. You know, can we just relax for a minute? You know? Nadav: Listen, a hundred and ten percent. It's like when you go into an organization and you you know I mean you come to your sales team and say, Hey, you need to achieve a quota. You're not expecting them to go and rob a bank. You know what I mean? Like you Joe: Yeah. Yeah. Nadav: know that they have, you know, they're naturally having their guardrails of what they're you know, th they understand where the confinement is. The issue is sometimes even in w you know, workers are gonna do things that are Against company policy. You figure that out, you maybe weed out those people. It's one person. Here, the agents represent the department. When you suddenly start deploying a sales agent, suddenly that's like that's a sales. My sales force is now an agent. My marketing force is an agent. My you know that starts even if it's augmenting, it starts to become a it it's you're expecting it to take a significant chunk of work and deliver, okay, to an equivalence of a of a human or a a full-time employee. That's where that goes wrong. That could be, as we talked about, that could be extremely harmful for the organization. So you know, us as humans as well, there's a reason why we have physical security. There's a reason why we have policies in place and we take people through all kinds of courses to understand what's allowed and what's not allowed and playbooks and we onboard them. The governance that Eve puts in place is somewhat mimicking a lot of these behaviors. Okay. And like acting as the manager in real time. That's you know, that's what we do with agents. Joe: How do you go about creating those guardrails to kind of I don't know, blanket protect, you know, the agents in an environment, right? Because there's probably a a customization aspect of it, but there's probably also, you know, what we would think of as like compliance packs that you would be deploying where it's like, hey, these are the ground rules for a hundred percent of the agents, right? Like that going forward, this is what they're allowed to do, you know, no matter what, and this is what's blocked. How do you go about doing that? Because that sounds like a pretty arduous task and being able to make it applicable to basically any agent, you know, that anyone any flavor of agent that anyone deploys. Nadav: So we have just from our enforcement side, we have global policies that could be certifications, for example, like every agent in the organization needs to comply with HIPAA. Okay, you can do you can say that in our system. So anything that we're governing, doesn't matter which agent it is, we'll comply with it. When we then go and build our policies, there's a lot of study behind the scenes that we do to understand at the end of the day, what are the approved behaviors. And I think we've already learned from the get-go that this is not going to be perfect from day one. That's why we have a learning mechanism. That's why we built our anomalies, which we treat as new behaviors that we've seen. That's why we learn between environments as well, the type of behaviors that agents are going to do. Cursor in one organization is going to be going to behave somewhat similar in other organizations. There are going to be differences, but we have baselines. That gives us the ability to give confidence to the Of security operations teams like, listen, you're now deploying this agent. We've seen this before. This is how it typically behaves. It's what you should expect. And there's even we need to understand as well that security teams are in this pull between operational efficiency, okay, and risk. And they're always trying to find the sweet spot. So we help them and say, Is this are you being too permissive? Are you being too restrictive? And we tie that to true behaviors that people would do in real life. This a You you've got a developer. If you don't allow them to create a pull request in Jira, they won't be able to do their job. You're being way too restrictive. They they somebody's gonna come and shout at you. Does this agent need to be allowed now to delete repositories? People typically don't do this. And if they do it, and it's only specific people don't allow that ability. Okay? And that's where you we talk about like we have a gauge, how permissive or restrictive you are. And there are organizations that want to be more permissive or more restrictive. That's fine. As long as they have the insight on why that's happening, that then gives the ability to, with confidence, give the organization a solution that is not going to throw off the operations team while mitigating the risk. Joe: Yeah, I recently, you know, doing my own like side projects, right? I I maintain some GitHub repos just like everyone else in IT. And as soon as I start hooking up, you know, agents to it, it's just this eerie feeling because it starts asking me for permission for different things and you know, I'm in I'm in security, right? So when I'm looking at the permissions, I'm looking for different different things like read only, write, delete, that sort of thing. And it like tried to sneak in the ability to d delete a repo if it like saw fit. You know, and I'm not doing anything crazy with these with these agents. No nothing like that. But, you know, and I I I asked it, why do you want delete permissions on this repo? And it said, well, if I deem that the code is, you know, too inefficient or we have, you know, too many improvements, sometimes it's just easier to delete it and start over. Right. And it it had a reasoning built into it, but at the same time, it's like, you know, a like a human would never do that. If if the repo is inefficient, if the code needs to be like rebuilt or whatever, the repo stays intact and you go and you know, you go and cr create the fixes and then you push it and merge it if you see fit, you know, like that sort of thing. Like it's just insane Nadav: No, no. Joe: because we're living in that world and I actually have a friend that was building a product, like a very real go to market product. And, you know, one of his agents had access to GitHub and the agent just deemed, Yeah, this repo needs to start over. And it's just deleted the whole thing right there he's like, Well, it just sent me back three months, you know? Nadav: We've seen we've seen that as well before, like features, please development of features, where it just goes and wipes everything out and try it starts all over again. And then it's you know, listen, there's a lot of value and and and you know, a lot of great things that are coming, but it's there's a way to manage it, you know what I mean, and the way to put things in place. And as an organization that wants to run far fast with AI, You gotta make sure that on the way that you're doing this, you what you you know, you don't know what you don't know. Okay? But you definitely know that you have systems that if they get impacted, you're in a way bigger problem. And and the issue is that they're being asked to connect these agents to those systems. So to your point, you lose a GitHub repo three months, this could be, you know. We've now talked to customers when they saw everything that happened with OpenAI and their report, they're like, no, this is it. Like we're we are now, you know, with Eve, we are really locking it down. Like, you know, we were maybe allowing people in the past to do a few things. Now it's like that is gone. Like MCPs have to go through some criteria, you know, and like everything has to be alter remediated with Eve. We have like the right guardrails in place, policies, et cetera. Like we're now in control and this kind of like the business pushing us to, okay, we gotta do this because we gotta do like the whole industry is doing this. Like people are starting to say, like, I don't know if I sign off on this now. Like, it's gonna be my head rolling if this goes really bad, and we've seen it go really bad. Joe: Yeah. It's a different kind of pressure because there's no real repercussions for the agent. I mean, what, you get shut down and spun back up, you know, for the person, Nadav: Exactly. Joe: you're losing you're losing your job, you're losing your your livelihood and whatnot. I I'm wondering because I'm starting to go down like the NVIDIA open source route of, you know, kind of deploying like I I think it's called pair in in into my network and trying to, you know, utilize all the resources I can to minimize my token spend because like unlike some of the you know open AI and Grok employees or SpaceX employees that like to post all these loops and whatnot, I don't have infinite tokens to to spend, you know? is there any Is there any like open source compliance packs or anything that that maybe Eve Security is, you know, looking at doing or providing, you know, to the industry as a whole? I'm just thinking in terms of like, hey, here's here's some instructions that you can give your agent. We we have a much broader set of instructions that we give for our customers, but these are, you know, maybe like the top 10, top 15 instructions to achieve this. Is there any thought around that or maybe it exists and I don't already know it? Nadav: I don't I can't say that I've seen that from a security perspective. I've seen that from a token consumption perspective of being concise. Okay. And not, you know, like not good morning and it gives you like, you what mean, six paragraphs of answering good morning back. so I've seen that definitely on that side of the house, okay, of just being more concise. I think on the on the d directions basically on the context of how to be How to be more aware. I think my gut feeling tells me that in the future, when you will buy an agent, you will have an ability as an organization to define its job description. You're gonna give it context on how it's supposed to behave in the organization. In addition to it, there's gonna be a security policy for that. It is something different. But I do see the ability of. companies being able to modify con a context of an agent to what they want it to do or consider as something that's gonna be mainstream. Like, thank you, I've hired your agent into my organization. Now I'm giving it my playbook to follow. That's in a sense kind of the direction. Joe: Yeah, because you know, as it becomes more more and more easily obtainable and usable for people, I could see I could see there really becoming a need, you know, for people to have these sorts of things kind of built in or standardized for them to some extent. that was just, you know, my my idea on it at least. Maybe, maybe I'll put something together. Who knows? Right. Nadav: Yeah. Joe: talk to me about session tainting. What what is session tainting? What does it look like in the wild? How do you identify it? Nadav: So session tainting is the ability for you to as again look at a session and determine in that session if Privileges should be expanded or reduced. Joe: Hm. Okay. Nadav: Okay, that is you're you're tainting the session because you something has happened. I'll give you an example. Sometimes you want to limit and say, I don't want bulk or destructive operations of happening. Okay. I don't want somebody going and deleting all of my Jira tickets. So we s so and w so somebody even came and said, Hey, we want to limit even in a session, let's not allow more than two deletes. Okay? Agent was asked to delete the entire and it's already go one by one. And after two, it was so how do you know? You need to you need to understand what happened in that session. Okay. Then you need to start understanding even if I'm an agent's, this agent has already deleted, and I'm seeing that it's deleting more than usual. Okay. That's now anomaly detection of its behavior overall. So if still just focusing on session tainting, it could be data that the agent is exposed to. It could be actions that it took. Okay. That will then imply that for the the remainder of this session, you cannot perform specific actions. Joe: Okay. I I guess that probably even ties into like command chaining and you know all like all the other progressive Nadav: That's a really good point. Joe: parts of it. Nadav: Yeah. And to your point on command chaining, that is where we start looking at the behaviors of agents as well in a session and see that when it wants to perform, sometimes even actions that we see that are risky, there has to be some pre-actions that happen that took us to that point. If suddenly we see that those steps have been skipped, we we ask questions, you know, we raise a flag on that. So they are really. chaining actions, tainting the session, overall KPIs of an agent on a you know on a X time basis gives us a lot of insights when this agent is going out of norm. Joe: So So I I guess maybe a quick question in terms of integration points and how these sorts of things are being detected and identified and whatnot in someone's environment. Is Eve security essentially either deploying or hooking into an MCP server that's controlling agent deployment, right? Like a a harness of some sort. Maybe, I don't know, let's say an organization is using like OpenClaw or Hermes or something like that. You know, you're tying in there, and then in the background are you essentially giving a set of instructions that say, you know, you have to, I don't know, report to us before you perform this action. What does that integration point look like? Because I feel like maybe it's just me, right? But I I think the industry as a whole is used to CrowdStrike, for instance, right? There's an agent, lives on your endpoint. It sees everything, got it. I understand. Right. Almost with AI, it almost like extrapolates a layer of, I don't know, integration away from where we normally are. What does that look like for Eve? Nadav: I think, you know, for Eve. You need to be in that same mindset that you just mentioned, which is just like on the endpoint, you need to see everything and be able to act on everything. You need to be able to do the same thing with AI. Okay. And that means, to your point, the integration level depends on obviously what is available for you. And this is an emerging kind of industry, so there's still standards that are lacking. But what we've seen, the eagerness of our customers is to find a way. To either govern or provide those instructions to those agents. And what I mean by that is our agent in the loop sits between agents and systems and is gonna ask questions and then we're gonna give guidance like, hey, you're trying to do this action, we recommend you do it in a different way. That is in runtime our interrogation components, okay, with our altering of of the result kind of Coming to agents and saying, we've examined what you're doing trying to do, recommend you do it in a different way. And but it has to support the entire ecosystem. So it's not just endpoint, it's you know cloud, it's SaaS. It you need to be able to your point, just like what an EDR does on an endpoint, you need to have that available for your entire organization. And that means that our deployments need to allow, you know what I mean, or the toolbox that we provide. We need to be able to connect to many enforcement points. And what we really have, we have a very smart decision point that we built that's deployed typically on your premise, either cloud or on-prem. And then you start hooking that up to different decision points. And those decision points are what allows you then to control the type of agents that you mentioned. Joe: probably in like a a perfect world, you know, I'm building a brand new network from the from the very beginning. I in that hypothetical scenario that no one exists in, I I would probably want like an a dedicated agent network where all the agents live and then a dedicated you know network for like Eve security, right? And all the agents have to pass through the subnet for Eve security. Right. And then Eve Security kind of brokers almost or allows that agent to go through to the internal resources that it that it's requesting that it's trying to use. Nadav: Exactly. And we, you know, and we for AI Studios, that's we that's exactly what we do in an in a nutshell, I'll explain. one of the things we've done, for example, with Databricks or with VMware, is we provide four attributes: visibility, what agents are going on, what's running there. Allow for you in policy to use what's called enrichment from those systems. So I can now define in a policy information from those. Providers, if it's infrastructure or databases, et cetera. And then the I would say the two main important ones is obviously enforcement. Now that you have agents there, as Eve, we allow you to enforce behaviors. But I want to say the most important thing that's unique to us is what's called auto-remediation. If a new agent is spun up there, somebody's working, it's an AI studio, they spun up new, we automatically enforce, and anything that it does goes through our decision point. And that gives a little comfort to the administrators, then they know, I'm providing this infrastructure or this framework to my organization, and I can rest assured now that anything that happens there is covered up. Okay. Don't need to constantly chase it and see what's new and suddenly figure out that there's this agent connected to Salesforce I didn't know about. Joe: Right. Hmm. That's fascinating. You know, it it's I I'm gonna I'm gonna say something stupid, but I I wish that we had that before agents almost, you know, like it was almost just like baked in. And I'm sure I'm sure I'm going to get a lot of hate mail immediately from, you know, Sailpoint and whoever else that offered that sort of thing, right? But I I'm just going back to, you know, just a few years ago when my my employer at the time asked me to dive into Salesforce and figure out Salesforce security. I've never logged into it before or anything like that. And I'm sitting down with the admin and he's telling me, all these people have access to it, which we didn't know. It wasn't documented anywhere. I didn't even know the right permissions to look up an AD if I were to even do that query. Right. And it's all this role expansion and everything. And, you know, he controls everything. So he basically is just giving out like admin access to these people that he sees fit. you know, in the moment. And it's it creates a very big problem, you know, especially when security is expecting one thing and it's a totally different outcome, you know. Nadav: Yep. Yep. Yep. A hundred percent. So that's with all the AI studios today, that is a big concern because this is a platform to build agents and to connect them and and develop workflows or, you know, user-facing agents. And suddenly now, you know, I have a thousand employees that are do how do I ch like I don't want to chase my tail. So I need to have something that can help me resolve it. Joe: What is you know, what does the setup and configuration look like from the end user perspective? And I ask because you know, there's always a balance. Not every company has 10 employees on the security team. In fact, a lot of companies have like fewer than 10 employees on the security team. And they're supposed to manage all these, you know, tools, all the risk in the environment. They're supposed to stay on top of all the Latest security and technology trends, which is pretty close to impossible right now with AI evolving so quickly. What does that experience? What does that timeline typically look like? I I would assume, and this is just me completely on the outside, basically as much as I could be, right? I would assume it's probably a streamlined process that teams of large and small can dive into. That seems to be where a lot of products are going nowadays. Whereas, you know, ten years ago when I was trying to get into security or just starting out in security, you know, as soon as you start bringing up deploying a IAM solution basically of any kind in a in an environment, you immediately think, Okay, this is a two year project. Right? Like it's two years if you don't want me to burn down A D. You know, like that's what Nadav: Yeah. Joe: we're talking about. Nadav: So listen, I've just got like a fresh example from last week. Like it's maybe I'll maybe I'll step well take one step back. It is very important for products, definitely like ours at Eve, to consider the friction of the deployment. Okay. Because at the end of the day, if you can't get in a reasonable amount of time to a point where you've proven your value, then you've missed the point. Okay. So You need to gradually get into it. There's a reason why we provide out of the box our decision point in our SaaS, knowing that people are gonna deploy it on-prem, because then they can play with it immediately and see how it works. In addition, we make one-click connectors. Okay, if it's to Databricks, if it's to you know the Microsoft stack, if it's to the AWS stack, if it's to Claude, if it's to OpenAI. We make it very easy for you to be able to on the configuration side. So you go like, you know, a couple of clicks and now, wow, okay, you're enforcing. So start working on a policy. Now, can you go deeper? Let's connect IDP as well, but at least it starts giving you a taste or even very quickly a production ready enforcement point that to your point it's not a matter of years, it's a matter of hours, okay, between getting the right answers from IT to having everything working. So And we've had customers now that have come to us and they just explore our platform. Like, okay, yeah, I've okay. I've already got this agent connected through your gateway to all of these. And I'm like, whoa, you know, we just gave you access yesterday. You're way ahead of the curve. But they're like, but wait, this is super important for me. That's why I'm pushing forward on this. Okay. so I think the main point is. This is not something that takes a long time. We we deliberately work towards that to make sure that, you know, installing our hook solution with Cloud Enterprise is is less than a 15-minute conversation. Okay. Then going into the depth of our solution, we work very closely. We kind of set these exploratory and kind of educational sessions, like to talk about session tainting, to talk about anomalies, explain to them what could happen, give them real use cases of where it can go bad. And then they go deeper and deeper and deeper. So I think to your point, it like our deployment was built, okay, to to g to cut to value as soon as possible. Understanding the players in an organization. If I put it as a prerequisite that you have to deploy my container in an organization before we can start showing value. That can suddenly delay things by three months. IT it's end of year. IT's blocked everything. You can't do anything. We don't want to risk. Okay. That's a problem. Okay, so we we found a way around this by making it very easy to engage with us. Joe: Hmm. Yeah, I think I think a lot of companies and solutions now really either they either should or they are designing, you know, towards that angle where it's very easy to deploy, no matter what method you're choosing, right? No matter where you're deploying it. because of the arduous tasks that everyone went through before of trying to deploy a solution for you know two years. two plus years. I I've known some organizations that like never fully deployed a solution. And by the time they get it fully deployed, they're almost at the end of life of their version of it, you know, and they have to like do either a massive upgrade or redeploy it. Right. Like insane, insane stuff. And that's it's not normal. That's probably an outlier. Right. but it adds technical debt along the way as as those sorts of things, you know. drag on the more time that this technology is spent with you know on the outside of your your pipeline, your usable workspace, the more the more issues you're gonna run into. Nadav: 100%. And we we have to take into consideration as well the pace that AI is moving. We have to be able to show you value quick and adapt quick as well. Like customers are coming to us, well, how are we gonna now treat this new threat or that new threat? And again, in in the realm of runtime security, we're agile and then we give them an infrastructure that allows them to update it quickly so they can address the new needs that they have. So in this day and age, you have like That is kinda live or die, I think, is your ability on the how rapid you deploy and show value and how rapid you ad adjust new to emerging trends that are you know that are concerning in your in your lane, like for us runtime. Joe: Hmm. Well, how d how does Eve, and this is probably the last, maybe the last topic that we'll jump on. How does Eve address AI prevention? Right? We hear about like shadow AI and whatnot, but I almost think that there's more to the term that that term might be underplaying to some extent. And I I just feel like there's more to it. You know, like we're we're We're not really paying attention to it like we should. Nadav: Yeah. The my vision was always let's see what you have, let's allow you fix the problems that you have. Now let's prevent those problems from even happening in the first place. And AI prevention is all about if we if you as an organization know what you're allowing or not allowing. We can use existing security tools that you have to deploy policies to then block things from happening from you know from the get-go. Okay. Very easiest thing, let's not allow a process to run with an EDR, okay, of an agent that you don't want in your organization. It's as simple as that. Okay. You don't want people to access or allow specific agents to access. a internal resource that you have, then we can maybe configure a firewall to prevent that from happening. Our what where we've focused with AI prevention is configuring existing security tools that you have with agentic focused policies that we recommend. And this is something that we're now kind of in beta and we're kind of towards the end of the year we want to kind of make that available for all customers. But That is the evolution, okay, of you you you gotta first show me what I got, and that's table stakes. Then you have to be really good at enforcement. Doesn't matter if you prevent things and if they versus if they're there and now they suddenly do something that that doesn't help me. I to make sure that nothing bad can ever happen, even if it's running. Now, don't even allow it to run if I don't want it to. Joe: Yeah, it's Nadav: And we'll see. Joe: it's I'm trying to think, right? Because it almost sounds like it's turning into like that centralized AI platform. Whereas, you know, I and I keep on going back to it, but like, you know, almost like CrowdStrike, right? Where it was just like that centralized endpoint security platform. And then it ties into all these other solutions and capabilities and whatnot that you have, right? It sounds like You know, Eve is also going down that path with being able to influence and impact other solutions in your environment to become more flexible towards the sedentic world that we're currently in. If if I were to, you know, we have we have some time, you know, maybe think 12 months out. What are you seeing in the space that's evolving maybe right now, right at the ground floor? that you see being, you know, like that next, I don't know, agentic AI evolution in this whole process that we're going through right now. Nadav: So what I'm seeing is I think the prevention side is definitely kind of questions that are coming up. I think there are concerns that are coming up as well of kind of agents spinning up other agents, asking it to do things on its behalf. That is something that we're looking into to address. As I mentioned, the AI studios are still very much in their infancy. We're very much kind of, and what I mean by that is we've had a massive focus in the last year about agents running on the endpoint, agents running on the endpoint. The majority I think of of agents are gonna be running as services, okay, in these studios, performing a lot of tasks for the organization. Doesn't mean there won't be agents on the endpoint, but it's a a mass of them as well is gonna be there. And that's kind of, I think, kind of shifting a bit of the concept of, you know, as a solution, I need something that can cope more with just the endpoint. Okay. so I think that in the next 12 months, I think we're gonna be seeing a big shift of the balance of what you need to support and handle, of having, let's call it, AI studio agents. Okay, and how do I address that? and those are the trends, and the the trends that we're seeing are you need to orchestrate all of this under the same platform. Like I can't, I can't from a governance perspective, okay. Have things modified in all kinds of different places. Like I need to be able to go into one place and know that either it provides it or it integrates with, okay? Just like the example that you gave of CrowdStrike. But I know that I can define my governance once, and I know that's gonna be enforced. So I think in the next 12 months, there's gonna be more work on. I think to your point at the beginning, even solutions that are working on static rules. They're gonna have lot of false positives, okay? And they're gonna be called out on like when the rubber hits the road. It maybe passes a POC or a POV, but it doesn't pass kind of production. We're gonna see a lot of noise there. and definitely when you start getting the more complexity of the entire environment of the types of agents, which systems they have and how they're one is connecting and talking versus another one, there's gonna be a lot, I think a lot of how to understand what agents are doing are gonna become More complex. Joe: Yeah, probably as the agent workforce, which sounds just terrible for me to even say that, right? As the agent workforce is built out at various companies, I mean, you know, this is how I view it, right? I assume these AI labs have millions of agents running all the time, right? They're spinning up and down sub agents and you know, whatever else, right, all the time. That's only at the labs like right now. In twelve months, why wouldn't, you know, JP Morgan have a team of agents that are running that is essentially a workforce I don't want to say a workforce replacement, but thinking in headcount terms, it's like, okay, we have half a million employees globally. I don't know what they have, but we have half a million employees globally. Everyone gets an agent. We now have half a million agents, right? That's an insane thing to think of, but you have to, you know, still have visibility and control into that. Saying, you know, hey, you're, I don't know, a manager agent. You're allowed to spin up this amount of agents to achieve this task. Like this is your mission statement. This is your goal. These are your parameters. You know, that sort of thing. You're almost you're almost managing like a Like almost like a mini business within this agent workforce within the hierarchy of this broader company. You know, that that's that's how I view it, right? Because Nadav: Yeah. Joe: it's it's easier when you're in you know, just a normal company like all of us are, right? You have a mission statement, you have a purpose, you have your plan of action that you're executing on. Everyone under that organization, whether it's half a million, a million employees, or ten employees. They're all working on the same basic set of principles and and ground rules, right? you you basically have to have the same thing for these agent workforces that are going forward and you know focusing on marketing and sales and whatever else. You know, like it's like, hey, these are your overlying ground rules. Here's your job title, how's here's your job description, this is what you're Nadav: Exactly. Joe: allowed to do. which is it's I mean look, it it's not like a giant mental shift, but we're going from peop individuals having an assistant as an agent to companies having teams of agents. Nadav: Hundred ten percent. And that's why managing that as a to your point as a digital workforce, a lot of paradigms from the real world are being you know, we're taking a lot of inspiration from there. The real world examples of how you're managing people are very similar to how you manage agents. it's it's you know The next 12 months, we're gonna see to your point, companies rely more on agents to do more sensitive actions. Okay. And we're gonna have that cataclysmic event. It's gonna happen at some stage. But there's more eyes on this now. People are more concerned with what they've seen. They'll want to have. To know that they have a security manager like Eve in their digital workforce and ensuring that all their agents are performing secure actions. Joe: cultures at companies, right? 'Cause not every company has a great culture, right? Like I I've been to a lot of different places and I can count on one hand the amount of cultures that I would say It's a fantastic culture. I would recommend anyone go work there. You know, it's great, right? which is unfortunate, but that's kind of just the world we live in, you know. I I I can see that translating over into like the agent, and it sounds weird to say the agent culture, but the culture of the agent where hey, let's bend the rules a little bit, let's be okay with breaking some of these rules because I've I mean I've been at companies where they will literally, you know, lie to an auditor to pass a a compliance check, Nadav: Yeah. Joe: you know, and they'll provide fake proof and everything else. And it's like, guys, I don't I don't think I could even be in this room right now. You know, like Nadav: No, you're right, you know, you're right. And it it you're 100%. I think that will that you know that's the context, the company context you want to give them what to do. You're right. 100% right. There is at the end, we we take actions as human beings, you know, with some statistical aspect as well. And like, I'm gonna down this path because I believe it's gonna be the best path for me. It's never black and white. You know, there's all the information I have, I think I'm making the best decision. Agents do the same thing. Joe: It's a it's a weird world that we're going into. I I Nadav: Yeah. Joe: feel like I have to have you on like every six months at this point, you know, just just to hear about like what you're seeing in the market, you know, and the evolutions of it, you know, it's just such a rapidly evolving space. Nadav: So yeah. Super happy. Joe: Yeah. Absolutely. Well, you know, Nadav, I I really appreciate the time. It was fantastic talking to you again. This is like a true part two of our first episode. I'll link that down below. I'll link, of course, Eve Security down below in the description of the episode. But, you know, Nadav, why don't you tell my audience in closing where they could find you if they wanted to reach out to you, where they could find Eve Security if they wanted to learn more. Nadav: Please reach out, Eve Dolt Security. We have a form. You can get a free AI risk assessment for your organization. You can reach out. We have a contact form there. Happy to answer any questions, comments that you might have on the content shared there, or any questions about in general, runtime security for AI. Joe: Awesome. Well thanks, Nadav, and thanks everyone for watching this episode. I really hope that you enjoyed what we were discussing, everything that we talked about. Please go ahead and check out Eve Security at the links in the description below of this episode. Thanks everyone.