Redefining Access Control: Scaling Policy as Code for Humans and AI Agents - Raz Cohen, Permit.io
Raz Cohen, Permit.io
KubeCon + CloudNativeCon Europe 2025 · Session
Overview
In an era witnessing the rapid proliferation of AI-driven products and an increasing reliance on Large Language Models (LLMs), the discourse around security and control has intensified. This talk by Raz Cohen from Permit.io, delivered at KubeCon EU, addresses the critical and evolving challenge of access control for not just human users, but also for increasingly autonomous AI agents. Cohen highlights a significant shift observed at KubeCon, moving from mere AI-powered chatbots to fully AI-driven products where developers are increasingly writing prompts rather than traditional code or YAML configurations. This transformation, while promising immense innovation, introduces complex security vulnerabilities that traditional access control mechanisms are ill-equipped to handle.

Key moments
- 0:00 KubeCon's AI evolution: from chatbots to AI-driven products
- 2:08 Asimov's Three Laws of Robotics and modern AI challenges
- 4:23 Speaker introduction: Raz Cohen, Permit.io founder
- 4:59 OASP reports: Broken access control, a top vulnerability
- 6:44 Access control explained: binary, RBAC, FGA, AI
- 8:32 Challenges of AI access control: guarding agent's vast actions
Redefining Access Control: Scaling Policy as Code for Humans and AI Agents
Speakers: Raz Cohen, Entrepreneur, Permit.io
Conference: KubeCon EU
YouTube: https://www.youtube.com/watch?v=lQEYxCXVkVU
Overview
In an era witnessing the rapid proliferation of AI-driven products and an increasing reliance on Large Language Models (LLMs), the discourse around security and control has intensified. This talk by Raz Cohen from Permit.io, delivered at KubeCon EU, addresses the critical and evolving challenge of access control for not just human users, but also for increasingly autonomous AI agents. Cohen highlights a significant shift observed at KubeCon, moving from mere AI-powered chatbots to fully AI-driven products where developers are increasingly writing prompts rather than traditional code or YAML configurations. This transformation, while promising immense innovation, introduces complex security vulnerabilities that traditional access control mechanisms are ill-equipped to handle.
The core of Cohen's presentation revolves around the premise that AI agents, much like human users, possess identities and access vast datasets and external services, making them susceptible to misuse, data leakage, and unauthorized actions. Drawing parallels to Isaac Asimov's Laws of Robotics, Cohen underscores the need for sophisticated control mechanisms that move beyond binary "can do/cannot do" decisions. The talk introduces a practical "Four Perimeter Framework" designed to establish comprehensive guardrails for AI agents, ensuring they operate within defined policies from prompt input to final response. This framework provides a structured approach for organizations to secure their AI deployments without impeding innovation, a pressing concern given the pervasiveness of access control issues across both traditional applications and emerging LLM-based systems, as highlighted by recent OWASP reports.
Background
▶ Watch: KubeCon's AI evolution: from chatbots to AI-driven products (0:00)
The journey of access control has evolved significantly, driven by the increasing complexity of applications and user interactions. Initially, access control systems were often binary, distinguishing simply between an "admin" and a "non-admin." This basic model quickly proved insufficient for enterprise applications, leading to the adoption of Role-Based Access Control (RBAC), familiar to many from its implementation in platforms like Kubernetes. RBAC allows for the assignment of roles to users, which then dictate their permissions. While an improvement, RBAC struggles with highly dynamic and context-dependent scenarios.
For modern applications with intricate business logic, Fine-Grained Authorization (FGA) emerged as a necessity. FGA moves beyond roles to consider specific attributes and relationships, such as a parent's access to a child's bank account until the child turns 18. This level of granularity, considering context like user attributes, resource attributes, and environmental conditions, is crucial for real-world applications. However, the advent of AI agents introduces an entirely new dimension of complexity. Unlike deterministic code, AI agents can perform "enormous actions" and interact with a multitude of data sources and external services in ways that are not always predictable.
The urgency of this problem is underscored by industry reports. Cohen references the OWASP Top 10 Web Application Security Risks 2021, which identifies Broken Access Control as the number one and most critical vulnerability. More recently, the OWASP Top 10 LLM Application and Generative AI Risks report also highlights pervasive issues related to excessive permissions and unauthorized access within AI applications. These reports demonstrate that while the underlying problem of access control remains constant, its manifestation and mitigation strategies for AI agents require a fundamentally different approach. The core challenge lies in understanding what an AI agent can and cannot do within a given context, especially when its actions are influenced by dynamic prompts and vast datasets.
Key Findings
▶ Watch: Speaker introduction: Raz Cohen, Permit.io founder (4:23)
The central finding of Raz Cohen's talk is the critical and immediate need for robust, fine-grained access control mechanisms tailored specifically for AI agents. Traditional access control models, even RBAC, are inadequate for managing the dynamic, non-deterministic, and context-rich interactions that characterize modern AI systems. AI agents, by their nature, possess identities and interact with a vast landscape of internal data sources and external services, making them prime targets for security vulnerabilities such as prompt injection, data leakage, and unauthorized actions.
To address this, Cohen introduces the "Four Perimeter Framework", a structured and comprehensive approach for securing AI agents end-to-end. This framework is a key contribution, providing a practical methodology for developers and security professionals to implement guardrails throughout an AI agent's operational lifecycle, from receiving an initial prompt to delivering a final response. The framework emphasizes that security cannot be an afterthought or solely reliant on system prompts, which can be easily circumvented. Instead, it advocates for deep, multi-layered enforcement across all interaction points.
Furthermore, the talk highlights that the problem of excessive permissions and unauthorized access, identified by OWASP as a top risk for both traditional web applications and emerging LLM applications, is magnified in the AI domain due to the agents' capacity for "enormous actions." This necessitates a shift towards proactive security measures that ensure AI agents are "guard-railed" without hindering their innovative capabilities. The framework's emphasis on filtering prompts, protecting data in Retrieval-Augmented Generation (RAG) systems, securing external service interactions, and enforcing response policies represents a holistic strategy to mitigate these inherent risks, ensuring AI agents operate within defined and secure boundaries.
Technical Deep Dive
▶ Watch: OASP reports: Broken access control, a top vulnerability (4:59)
The technical core of Raz Cohen’s presentation lies in the "Four Perimeter Framework", a layered approach designed to embed access control throughout the entire lifecycle of an AI agent's operation. This framework segments the agent's workflow into distinct security checkpoints, ensuring that policies are enforced at every critical juncture.
- Prompt Filtering:
The first perimeter focuses on the initial input—the user's prompt or the system prompt. The objective here is to classify the prompt's intent (user, action, resource) before the AI agent performs any action. Cohen illustrates this with an example where a user named Sam requests an "investment advisory." Before the AI agent processes this, a classification agent analyzes Sam's prompt to extract the user's identity, the desired action (generate advisory), and the resource (investment advisory). These three components are then fed into an authorization engine (e.g., OPA, OpenFGA, Permit.io, Opel). The authorization engine evaluates these components against defined policies (e.g., "Is Sam opted into the advisory program?"). Crucially, the AI agent is prevented from taking any action until the prompt is explicitly allowed by the policy. Cohen stresses that relying solely on a system prompt to instruct the AI agent (e.g., "always check user permission first") is insufficient, as these can be easily bypassed by prompt injection techniques. Deeper, programmatic enforcement is required.
- RAG Data Protection:
Many AI agents utilize Retrieval-Augmented Generation (RAG), a technique allowing LLMs to fetch and integrate data from external data sources (databases, data warehouses, knowledge bases). The second perimeter ensures that data retrieved via RAG is protected according to access policies. Using the example of "Dr. Berto" querying "Robert's upcoming procedures," the framework ensures that only data Dr. Berto is authorized to view is returned. The prompt classification yields the user (Dr. Berto), the action (read), and the resource (Robert's procedures). The authorization engine then filters the database query or the resulting data set, ensuring that any procedures not related to Dr. Berto or where Dr. Berto lacks permission are filtered out before they reach the AI agent for response generation. This prevents sensitive data leakage, particularly critical in domains like healthcare.
- Secure External Access:
AI agents often interact with external services (e.g., calendars, email, CRM systems). The third perimeter secures these interactions. Cohen refers to an MCPS (Multi-Agent Communication Protocol/Server) as an intermediary that interfaces the LLM with these external services. When "Sam" attempts to "schedule a meeting with Robert" via the AI agent, the authorization service again evaluates the user, action, and resource. It checks if Sam (and by extension, the AI agent acting on Sam's behalf) has the necessary permissions to interact with the calendar service for that specific action. This prevents harmful actions, such as an AI agent deleting all of Sam's emails, even if inadvertently instructed.
- Response Enforcement:
The final perimeter ensures that the AI agent's generated response adheres to organizational policies, compliance requirements, and safety guidelines. Even if previous perimeters have been passed, the final output must be vetted. Cohen gives an example where Sam asks a "weird question about the Chinese square," and the AI agent prepares a risky or non-compliant response. In this step, the framework intercepts the generated response and evaluates it against policies. If the response violates a policy (e.g., sensitive content, misinformation, or inappropriate advice), it is denied or modified before being delivered to Sam. The talk mentions Pentic AI as a tool that can help structure agents and facilitate this enforcement.
The implementation example provided by Cohen for a Kubernetes agent demonstrates how these perimeters are integrated. Using Pentic AI, the agent is initialized with a dependency component, acting as middleware to inject the authorization service (Permit.io) into the agent's flow. The LLM used in this example is Claude 3 Sonnet.
A system prompt instructs the agent to act as a "Kubernetes operation assistant" and "always check the user permission first," but this is complemented by explicit code-level enforcement.
For prompt filtering, the agent classifies user intent (e.g., "read all ingresses in the cluster") to extract the user, action, and resource, sending this to Permit.io for authorization. A policy example shown is that if a user has not "explicitly consented to receive AI generated advice," the prompt is blocked.
For RAG data protection (where Kubernetes itself is the data source), if Sam asks for "all ingresses that has internet access," Permit.io's permit.filter_object function is used to return only the ingress objects Sam is authorized to view, preventing unauthorized exposure of cluster resources.
For secure external access (again, interacting with Kubernetes), the agent determines which namespaces Sam is trying to modify and uses Permit.io to ensure Sam has the required permissions for those specific namespaces before any action is executed.
Finally, for response enforcement, the agent enhances the response with warnings, such as "this response contain Kubernetes operation that may modify the cluster. So you should add the flag of dry run," rather than outright denying, as the core actions would have already been filtered in previous steps. This demonstrates how the framework can apply granular control, from outright denial to subtle guidance, based on policy and context.
Demo / Proof of Concept
▶ Watch: Access control explained: binary, RBAC, FGA, AI (6:44)
While Raz Cohen did not conduct a live, interactive demonstration during the talk, he provided a detailed walk-through of a practical implementation serving as a robust proof of concept for securing an AI agent operating within a Kubernetes environment. This example showcased the application of the Four Perimeter Framework using specific tools and an LLM.
The core of the PoC involved building a Kubernetes operation assistant using Pentic AI as the agent framework and Permit.io as the authorization engine. The chosen LLM was Claude 3 Sonnet.
- Agent Initialization and System Prompt: The agent was initialized using Pentic AI's
dependencycomponent, which functions as a middleware to inject the Permit.io authorization service. A system prompt was provided, instructing the agent to act as a "Kubernetes operation assistant" and to "always check the user permission first," "only provide operation guidance if the user has proper role," and "only attempt resource access if user has required permission for the namespace." This initial setup established the foundational security mindset for the AI agent.
- Prompt Filtering Implementation: When a user, such as "Sam," submits a prompt (e.g., "read all the ingresses in the cluster"), the agent first classifies the prompt to identify the user, the desired action (read), and the resource (ingresses). This classified information is then sent to the Permit.io authorization service. A key policy demonstrated was that if a user had not "explicitly consented to receive AI generated advice," the prompt would be blocked at this stage, preventing any further processing by the AI agent. This validates the concept of pre-action authorization.
- RAG Data Protection for Kubernetes: In this scenario, Kubernetes itself serves as the data source for the AI agent. If Sam requests "all of the ingresses that has internet access," the agent constructs a resource request. Permit.io's
permit.filter_objectfunction is then invoked to filter the list of ingresses, ensuring that only those Kubernetes objects to which Sam has explicit access are returned. This prevents the AI agent from inadvertently exposing unauthorized cluster configurations or resources.
- Securing External Access (Kubernetes Operations): For actions that involve modifying the Kubernetes cluster, the agent first identifies which namespaces the user is attempting to interact with. It then consults Permit.io to confirm that Sam has the necessary authorization to perform actions within those specific namespaces. This ensures that the AI agent's interactions with the Kubernetes API are strictly confined to the user's granted permissions, preventing unauthorized cluster modifications.
- Response Enforcement Example: As the final step, the agent's generated response undergoes enforcement. In the given example, if the AI agent's response included Kubernetes operations that could modify the cluster, instead of outright denying the response (since earlier steps would have already filtered unauthorized actions), the agent enhances the response. It adds a warning such as "this response contain Kubernetes operation that may modify the cluster. So you should add the flag of dry run," guiding the user towards safer practices.
This detailed, step-by-step implementation, while presented as a series of code snippets and architectural diagrams, clearly illustrates how the Four Perimeter Framework can be practically applied to secure an AI agent interacting with a critical environment like Kubernetes. Cohen also mentioned a similar example for "financial advisory" as an alternative application of the framework, further suggesting its versatility.
Defensive Implications
▶ Watch: Challenges of AI access control: guarding agent's vast actions (8:32)
Raz Cohen's talk provides crucial defensive strategies for organizations grappling with the security implications of AI agent deployment. The primary implication is the absolute necessity of adopting Fine-Grained Authorization (FGA) for AI agents. Traditional, coarser-grained access control models are simply insufficient to manage the dynamic, context-dependent, and vast range of actions AI agents can undertake. Defenders must transition to systems that can evaluate permissions based on user attributes, resource attributes, and environmental conditions in real-time.
The Four Perimeter Framework offers a prescriptive defensive blueprint. Organizations should implement these perimeters end-to-end:
- Prompt Filtering: This is the first line of defense. All prompts, whether user-generated or system-generated, must be classified and evaluated by an authorization engine before any action is initiated by the AI agent. This preempts prompt injection attacks and ensures that the agent's intent aligns with policy from the outset.
- RAG Data Protection: For AI agents utilizing Retrieval-Augmented Generation (RAG), defenders must ensure that data fetched from external sources is rigorously filtered based on the user's authorization. Tools capable of dynamically filtering data objects, like Permit.io's
filter_objectfunction, are essential to prevent sensitive data leakage. - Secure External Access: AI agents' interactions with external services must be mediated and authorized. Every call to an external API should trigger an authorization check, ensuring the AI agent (acting on behalf of a user) has explicit permission for the requested action on that specific service. This guards against unauthorized modifications or data exfiltration from integrated systems.
- Response Enforcement: The final output of an AI agent must be scrutinized. Defenders need mechanisms to intercept and evaluate the agent's response against compliance, safety, and content policies. This prevents the dissemination of risky, non-compliant, or harmful information, even if earlier perimeters were successfully navigated.
Beyond the framework, defenders must understand that relying solely on system prompts for security guidance is a critical vulnerability. These prompts can be easily bypassed. Instead, security logic must be deeply embedded and enforced programmatically at lower layers of the AI agent's workflow. Integrating authorization engines (like OPA, OpenFGA, or Permit.io) early in the development lifecycle of AI agents is paramount.
Furthermore, Cohen emphasizes the importance of real-time monitoring, robust alerting, and comprehensive auditing and tracing for AI agent workflows. As AI agents become more autonomous and potentially interact with each other, understanding "who did what, when, and why" will be critical for incident response and compliance. Intuitive user interfaces for managing these complex permissions will also become increasingly vital as the scale of AI deployments grows. Preparing for a future where AI agents communicate and collaborate means extending these access control principles to inter-agent interactions, ensuring that every communication and action between agents is also governed by explicit policies.
Key Takeaways
- AI agents require robust access control: Unlike deterministic code, AI agents can perform "enormous actions" and interact with diverse data sources and external services, necessitating strong identity and access controls.
- Fine-Grained Authorization (FGA) is essential: Traditional access control models like binary or RBAC are insufficient for the dynamic, context-rich, and complex access patterns required by AI agents. FGA provides the necessary granularity based on attributes and relationships.
- The Four Perimeter Framework offers a comprehensive approach: This framework—encompassing prompt filtering, RAG data protection, secure external access, and response enforcement—provides a structured, layered methodology for securing AI agents from input to output.
- Security must be deeply embedded, not just prompted: Relying solely on system prompts for AI agent security is inadequate due to the risk of prompt injection. Access control logic must be enforced programmatically at deeper layers of the agent's workflow.
- Real-time visibility and control are crucial: For future AI agent deployments, especially those involving inter-agent communication, real-time monitoring, alerting, auditing, and tracing of AI agent workflows will be indispensable for security and compliance.
- Proactive defense is key to innovation: By implementing comprehensive access control, organizations can establish guardrails that mitigate risks associated with AI agents without stifling the innovation they promise.
About the Speaker(s)
Raz Cohen is an entrepreneur from Israel with a deep passion for technology and exploration. He describes himself as a passionate traveler and food explorer, balancing his professional pursuits with a keen interest in diverse cultures and cuisines. For the last eight to nine years, Cohen has dedicated his expertise to the realms of DevOps, Kubernetes, and platform engineering, developing a self-proclaimed "nerdy" fascination with these complex domains. Currently, he is focused on solving critical access control challenges at Permit.io, a company specializing in authorization solutions. Cohen is also a returning speaker at KubeCon, having previously delivered a talk at KubeCon Paris on the fundamental aspects of access control, demonstrating his long-standing commitment to educating the community on this vital area of cybersecurity.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Raz Cohen's talk effectively addresses the critical and immediate challenge of securing AI agents through a comprehensive 'Four Perimeter Framework.' It highlights the inadequacy of traditional access control for dynamic AI interactions and proposes a layered, fine-grained authorization approach from prompt filtering to response enforcement. While presented by a vendor, the framework provides actionable, technically grounded strategies for mitigating pervasive AI security risks like prompt injection and data leakage, making it highly relevant for anyone deploying or defending AI systems.
Heather Calloway (CISO) — STRONG ACCEPT
Raz Cohen's KubeCon talk tackles the urgent and complex challenge of access control for AI agents, moving beyond traditional models to propose a practical "Four Perimeter Framework." This framework provides a much-needed, layered approach to securing AI from prompt to response, directly addressing critical business risks and offering actionable guidance for security leaders and practitioners navigating the proliferation of AI-driven products. While presented by a vendor, the focus on a generalizable framework and its alignment with emerging OWASP risks makes it a highly valuable contribution to the conversation on AI governance and operational security.