Travis Lowe
Travis spends most of his days working in the cloud/container/Kubernetes security space. He has worked in security for ~15 years. Most importantly, he is one of the select few individuals to be recognized with an official certification from Microsoft as a Microsoft Office User Specialist in Microsoft Access 2000.
Session
AI agents are increasingly being given the ability to execute commands, access infrastructure, modify code, and interact with real-world systems. But instructions, system prompts, and skills are not security boundaries they influence what an agent should do, not what it is actually allowed to do. This talk explores harness engineering as a means of enforcing those boundaries through capability control, tool authorization, validation, isolation, approvals, and auditing. We’ll also examine the limitations and new attack surface introduced by harnesses themselves, and why the harness should ultimately control what an AI agent can do.