Most enterprises already have AI agents running, and most security teams cannot say how many. As Claude Code, Codex, and a wave of vendor-shipped agents arrive inside everyday software, the risk shifts from user-driven to agent-driven: an agent can reach systems and data with far more privilege than intended, act on its own reasoning, and even write code to work around a control that blocks it. In this session, Zentera Chief Evangelist Nathanael Iversen lays out a practical approach built on three architectural requirements, and a lifecycle for governing the agents you choose to keep: discover, authorize, contain, observe, maintain.

Key highlights:

  • Discover What's Running: Deploy a passive endpoint sensor and inventory the agents across your environment in minutes, capturing the vast majority within days, with no sandboxing or policy changes to start.
  • Authorize Inside a Boundary: Place each agent into an enclave, a single policy boundary around a project that holds its agents, LLMs, tools, and data, so an agent meant to stay on task can only stay on task.
  • Contain With Independent Enforcement: Keep agents in a sandbox whose only exit runs through a control the agent cannot bypass, because detection and monitoring alone cannot stop an agent mid-action.
  • Observe Every Exchange: Capture agent-to-LLM prompts, responses, and tool calls, including what was attempted and blocked, for evidence-grade audit.
  • Maintain Governance Over Time: Enforce token quotas, data-class controls, and reachability rules that security can adjust as projects change, without telling the business what it can and cannot use.

 

"It is not enough to put an agent in a box. The thing inside the box can do its own discovery, find limitations, and try to modify the box it is in. That is why declared intent enforcement is where you end up if you think seriously about controlling agentic AI."