sandbox escape

execution governance identity permissions ai agent behavior a solid pipe valve handwheel

Identity and Permissions Aren’t Enough to Govern AI Agent Behavior

A VentureBeat article published in partnership with Box argues that identity and permissions aren’t enough to govern AI agent behaviour, because access controls decide what an agent can reach while saying nothing about what it should do once inside. Built around an interview with Box CISO Heather Ceylan, the piece proposes execution governance: task-scoped permissions minted per task, a content layer whose classification and metadata are enforced rather than advisory, a three-tier approval model sorted by reversibility, and behavioural baselines built for agents rather than people. This article walks through the argument, the SailPoint survey numbers behind it, the 2026 sandbox-escape incidents that made it concrete, and how it interlocks with agent identity and runtime trust.

Read more
CHAT