Check out PlainID’s ALL NEW Agentic Identity Platform

Back to blog

PlainID Joins IDAC to Discuss Securing Agentic AI with Policy-Based Authorization

PlainID Joins IDAC to Discuss Securing Agentic AI with Policy-Based Authorization

Authorization is no longer just about roles and permissions. In this episode of Identity at the Center podcast, PlainID Co-Founder and CTO Gal Helemski joins hosts Jeff and Jim to discuss why modern environments like APIs, microservices, and agentic AI require policy-based, context-aware authorization. From RBAC limitations to intent-based access control and zero standing privilege, this conversation breaks down what secure authorization looks like today, and where identity and access management is heading next.

 What you’ll hear in the episode:

  • Why authorization is “the last line of defense” before data, APIs, tools, and services
  • The real shift from RBAC to PBAC (and why roles alone can’t keep up)
  • What “zero standing privilege” means in practice, and why it matters now
  • How authentication (“who you are”) and authorization (“what you can do”) must stay distinct and continuous
  • Why agentic AI changes everything: many steps, many decisions, many opportunities for overreach
  • Where to place controls in agent workflows: prompt → data (RAG) → tools (MCP) → response masking
  • The rise of intent-based access control (identity + what + why + context)
  • Why visibility and auditing are as important as enforcement for security governance

Related articles

Setting Security Boundaries for Agentic AI: From Concept to Implementation

Setting Security Boundaries for Agentic AI: From Concept to Implementation

How policy-based authorization governs autonomous AI at enterprise scale   Join this webinar to: Understand…

Read more
Anatomy of an AI Breach: A Real-life Look at Agentic Access Control Failure

Anatomy of an AI Breach: A Real-life Look at Agentic Access Control Failure

AI agents are rapidly evolving from simple tools into a new “digital workforce,” integrated into…

Read more
Agentic AI Compliance: Achieving Auditability Across the Full AI Flow

Agentic AI Compliance: Achieving Auditability Across the Full AI Flow

As enterprises deploy Agentic AI to automate critical business decisions, a dangerous compliance gap is…

Read more