AI Security, Cyber Risk, and Cloud Strategy on ClearTech Loop

Your AI Agents Are Already Running. Can You See Them? | Alvaro Gonzalez

ClearTech Research / Jo Peterson Season 3 Episode 8

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 17:11

AI agents can hold credentials, access sensitive data, make decisions and even create other identities. But many organizations still cannot answer a basic question: what is actually running in the environment? 

In this episode of ClearTech Loop, Jo Peterson sits down with Alvaro Gonzalez, SVP of Product and Go-to-Market at Assured Data Protection, to talk about what AI governance looks like when identity and access are changing at machine speed. 

Alvaro explains why organizations should start with three things: inventory, observability and remediation. They also discuss whether AI governance committees are actually governing or merely documenting, why CISOs should inventory agents before building more policy, and how Alvaro’s idea of “controlled aggression” can help enterprises experiment with AI without losing the ability to recover when something goes wrong. 

You cannot govern what you cannot see. 

Listen to Learn 

  • Why AI agent governance should start with inventory 
  • What least privilege looks like when identities can create other identities 
  • Why observability matters alongside access control 
  • Why remediation belongs in the AI identity conversation 
  • Whether AI governance committees are really changing behavior 
  • What Alvaro means by “librarians and warriors” 
  • How “controlled aggression” can help organizations move faster without losing control 

Featured Soundbite 

“You cannot govern what you cannot see.” 

— Alvaro Gonzalez 

Featured Guest 

Alvaro Gonzalez 
SVP of Product and Go-to-Market 
Assured Data Protection 

Alvaro leads product, alliance, marketing and go-to-market functions at Assured Data Protection, with a focus on data protection, cyber resilience and the systems that support field and channel execution. 

Host 

Jo Peterson 
CIO, Clarify360 
Chief Analyst, ClearTech Research 

Episode Links 

Full episode webpage:
https://cleartechresearch.com/ai-agent-governance-alvaro-gonzalez/ 

Subscribe to ClearTech Loop:
https://www.linkedin.com/newsletters/7346174860760416256/ 

Watch on YouTube:
https://www.youtube.com/@ClearTechResearch 

Additional Resources 

Assured Data Protection: 5 Ways You Can Improve Your Cyber Recovery Plan
https://assured-dp.com/guides/5-ways-you-can-improve-your-cyber-recovery-plan-with-assured-data-protection/ 

NIST AI Risk Management Framework
https://www.nist.gov/itl/ai-risk-management-framework 

Model Context Protocol — Security Best Practices
https://modelcontextprotocol.io/specification/draft/basic/security_best_practices 

Previous ClearTech Loop: AI Agents Shouldn’t Be Trusted by Default with Elliott Mattice
https://cleartechresearch.com/ai-governance-trust-elliott-mattice/ 

🎧 Listen: In Buzzsprout Player
Watch on YouTube: https://www.youtube.com/@ClearTechResearch/videos
📰 Subscribe to the Newsletter:
https://www.linkedin.com/newsletters/7346174860760416256/  

Jo Peterson:

Hey everyone! Thank you so much for joining this week's edition of Clear Tech Loop. I'm Jo Peterson. I'm the CIO of Clarify 360 and the Chief Analyst at ClearTech Research, and I've got a lovely guest with me today-lovely and smart. Both are important. It is Alvaro Gonzalez. Hi, Alvaro.

Alvaro Gonzalez:

Hi, Jo. Thanks so much for letting me have this opportunity to talk with you today.

Jo Peterson:

Oh, I'm so glad you're here. In case y'all aren't following Alvaro yet, you need to. Alvaro is the SVP of product and go-to-market for assured data protection, so our normal three-question format. We're just going to roll right into it. Alvaro, AI agents hold delegated credentials, make authorization and decisions in real time, and can spawn subagents with their own permission sets, traditional I am and Pam that wasn't built for this. What does a realistic path to least privilege access for AI agents actually look like for a large enterprise today?

Alvaro Gonzalez:

Yeah, absolutely. So you know, in an ideal sense, because least privilege was actually you know pretty good place to be when identity was generally static. Now that you have such a high rate of change, identities that come and go and proliferate all the time, and you know the fact that you can have identities generating identities, it is like a really tough spot to be in. So, like the best way to be trying to handle it now kind of is a three-layer thing, like so many other things in security. You know, they say that security is Swiss cheese. If you think about it in three layers, the top would be you want to be able to have a live inventory of what the identities are to begin with. This can be a moving target, but that ability to discover, to auto discover, to know what the the risk surface is to begin with, begins it absolutely. The second level of it, though, is okay. Now I know what all of the identities are, but what's my mechanism to be able to be seeing in real time what they're doing, because again, rate of change doesn't apply just to the absence or presence of the identities. It's actually the things that they can be doing along the way. So you have to have observability in all of this, and then you know the the third layer of it is going to be how am I going to recover when my first two layers of security protection have still gotten overcome, right? Like it's just like you know I'm big on the principles. So many attacks of ransomware, so many other things that we talk about, they don't happen because people didn't have countermeasures in place because things still go wrong. The things that make them noteworthy ultimately is, in spite of good preparation, they still managed to happen. But the people couldn't remedy the problem. So if you try to address it at the first, you know, those three layers, what are the identities? What are they doing? And how do I undo what they do when it's inappropriate? You know, that is the concept. that takes you where least privilege itself couldn't go. Like that's a static construct. When everything's in motion, you need to add the resilience layer to make it a viable thing, because the alternative is, you know, no one crashes the car when it's not moving. But you know the powerful thing about AI, of course, is the velocity that it brings to the good stuff. But that means you have to have countermeasures against how quickly the bad things can happen too.

Jo Peterson:

Yeah, no, that's that's. I'm smiling because I was thinking about we've both dealt with teenage drivers, and it feels a little like that, right?

Alvaro Gonzalez:

Too soon, Joe. Too soon.

Jo Peterson:

All right. Question: 50% of large enterprises now have dedicated AI governance committees. Is that structure actually working, or is it creating the appearance of governance without the substance?

Alvaro Gonzalez:

Yeah, I'm sure that both of those can be true. Really, the difference about it from the difference between success and failure, I think, kind of comes down to it's one thing to have governance structures, but it's another thing for those governance structures to be doing something useful. So, if the governance structure is a matter of we're going to make policies, and then enforcement goes downstream. It goes somewhere else, and things like that. Effectively, you kind of have the librarians that they're compiling documentation, they're writing things down. But if you know the construct is this thing of librarian. And warriors. If you don't have anyone who's carrying out that, if they're not actually saying no, we know what the inventory is. We know what is being done with them, and we change practices when they get off course. That's the difference, right? If we have again governance layer that governs on paper, then no. I mean, probably there's some you know benefit that's not being realized out of that governance that is activist governance that is involved and close to what's going on can be highly effective, right? Like it's people get better by doing things, and so the question is: All of the governance participants, what is it that they're doing? Are they governing by writing, or are they governing by doing and interacting and iterating? That's the side of it where there's disproportionate benefit to be had. And on the other hand, you know, if it is just governance by policy but not by action, then you know it's not gonna mean a whole lot. It's not gonna mean a great deal.

Jo Peterson:

I think that's fair, and I'm gonna forever remember librarians and warriors. It seems to me like you may have talked to a board or two in your time that way.

Alvaro Gonzalez:

Yeah, yeah, they were all bored. I'll tell you that. Like by the time I was oh, I

Jo Peterson:

meant that's a great storytelling thing.

Alvaro Gonzalez:

Yeah, yeah, yeah, yeah. I tell you, speaking of boards and things like that, just it's been two weeks ago now. I was actually assured data protection. We do a lot of work with the rubric portfolio in particular. They are sort of the the cornerstone of a lot of things that we do, and at Rubrik Forward, they're doing really exciting work actually in this field, interacting with all of these problems. Which is why, yeah, like this is the sort of thing that we're talking about all day, every day right now. And there's some really great work that's being done in the field. Just earlier today, actually, I had the huge pleasure to meet, and I was having a conversation with the the founder and CEO of Strata.io, one of the companies that Rubrik actually just bought, that is bringing some additional, really interesting identity resilience capabilities into the rubric fold, and you know, one of the things that's really driving that a lot is again all of the challenges in which those guys are already doing very exciting work around identity and artificial intelligence because it's rate of change, high velocity, that combination, and there's just there's so much good work being done in this field right now by so many people. It's a very exciting time to work. It is

Jo Peterson:

exciting, yeah. So give us a little bit of advice. You get to talk to lots of professionals in the field and lots of customers that are grappling with this problem today. If a CISO in this audience is starting from zero on AI agent governance, meaning no inventory, no agent-specific controls, no monitoring, what is the single most important thing they should do in the next 30 days?

Alvaro Gonzalez:

Inventories first. You cannot govern what you cannot see, right? So, like that is absolutely the first place to go. Like, what are the agents that are already running? What are the non-human identities that are in there, and what are people doing with them? And you know, this is not a new problem. When the in the in the advent of the cloud business, it was shadow IT was, you know off the books hyperscale cloud. Like on the one hand, it's not a new problem, and on the other hand, of course, we all have seen a number of times like it's not a pretty process necessarily to get a handle on it, but you do, and then things get better. You got to start. You must start with the inventory. It's the prerequisite for everything else.

Jo Peterson:

And so, on that same scale, where does building a risk register fall for you? Middle of the scale, closer to the end of the scale. Where are you at?

Alvaro Gonzalez:

No, I mean I would say that actually the way that I would say it would be what are the actors, and then what are the consequences of the actions from those actors. So I think that that's actually yeah something that is a pretty high high value activity to do. The thing about it, and the thing that's kind of giving me pause a little bit, is that it's an excellent practice. I'm sort of just thinking about the velocity of change that we started from. That like things that are incredibly well suited to environments that can be-I don't want to say static. But they're not moving at the same pace. I think that you know the proactive thing of saying, "All right, I know what the identities are. I know the sorts of things that are possible. Let me rest. Let me go to my risk register thing. I would be tempted though to work on remediation first. How do you undo the unforeseen consequences of things before I start, I start to try to foresee all the consequences of the things that can happen. You know what I mean? That's that's the reason why I think it's very important. When I put it second or third, I think that I might put it third to be identify. Then it would be all right. What is my reverse clause? How's how's the way that actually I'm in a proper place to be able to back out of the unintended consequences, and now let's get to trying to figure out removing the need to do that. But I think that the risk register for me would be in third position of those three. Yeah,

Jo Peterson:

and then you know I've been thinking through this, and I'd love to get your thinking on it. Remember back in the day when we were taking cloud workloads off premise, right to the cloud, right, and we did an application rationalization, and I was thinking about that in terms of agentic AI. How do we figure out everything they touch?

Alvaro Gonzalez:

Yes,

Jo Peterson:

you know, like, like, like. How do we build that and figure out what they're touching? Because they are deterministic. Like they are going to go after whatever and try to get their job done. What are they touching in the process? You know, I just I think about that sometimes.

Alvaro Gonzalez:

Yes, and I think that you know actually even before you get to the applications, something that's been it's whatever it's certainly present to the work that I've been doing over the last couple of years is before applications even it is actually localization of PII or other sensitive data because actually like you don't need an application to be able to inadvertently release sensitive data. So I think that like like everything else, right? It's easy to say, it's hard to do. Organization and knowing what is where is the the hedge that you got against that sort of thing, right? To say, hmm, first I'm going to be trying to be pretty conscientious about tagging and cataloging and knowing what is where from an information standpoint to begin with, and then that you go into, in my opinion, right the what applications can be reaching what things where I'm as you know a bit of a propeller head, and I'm having a ball on working with a bunch of different MCP servers. I have my personal Claude Max, and I have this very annoying, to my wife's perspective, and expensive group of all these applications that I tinker with the MCPs to see. But it's it's interesting to walk a mile in the shoes, right? My stakes are pretty low again. Like if I wrong, like, but I think that there's no substitute though for getting and mucking around in it to have insight into. Oh gosh, right? Like that actually didn't happen the way that I expected it to, but now I'm going to learn because of that. Like the sandbox is a brilliant thing, right? When you can experiment and you can find out the hard way when the stakes are low, as we did in test devs, right? When we were first going hyperscale cloud, you're like,"Whoa, that spun out of control! Thank God it's not actually available for somebody to drain my bank account forever because it wasn't really public facing. You have kind of the same thing going on here, right? How do you have the right combination of no control and enough control to get the best benefit out of it? And I think that you just you kind of like you iterate. You know, you do it in a safer spot, and then you say, "All right, now it's a less safe spot. But I have, you know, moved. I have ways to mediate, to remediate PII or inadvertent disclosure of anything sensitive, and kind of move in that direction because the speed that you get out of all all of this is incredibly valuable. But it's not as valuable as not blowing yourself up to begin with, right? There is the combination you mentioned: teenage drivers. Like, yeah, you want to go fast, but you don't want to be like zero to 60 in four seconds every time, right? Because when you get stopped 10 times for speeding tickets, you didn't actually get there any sooner. This is like that. You be aggressive, but be Controlled aggression, structurally controlled aggression. Oh,

Jo Peterson:

I like that. And you know, you know, back to your point, and maybe we'll leave it here. I think that what you're doing with the MCP servers is great, because even though you're not in an enterprise environment, and nor do have the high stakes. Of the folks in the right, what it allows you to do in your role is to ask better questions.

Alvaro Gonzalez:

Yeah,

Jo Peterson:

and then you have a sense of maybe what your customer is experiencing on the daily, just a little bit of an inkling of that and and empathy for that as you approach solving their problems,

Alvaro Gonzalez:

there's nothing more important than that actually, and I would say right, like it's the stakes are low. My lab is like everyone else's. An epidemiologist ideally does their best work in the lab, not in the general population, right? Like you do it in the lab, because you don't want to have to have the downside in so like absolutely yes. And to be honest, like again, for me it's because I think it's fascinating. And yes, I lead our product shop. I'm certainly not the person who is doing the real deep work. Like we have proper professionals who are doing, you know what I mean. But like for me, it's absolutely true that my work is inadequate if I'm not trying to expand my empathy, my understanding by thinking. Hmm, that's these are the problems that we're trying to solve for people. Yeah, that it's worthwhile. Like, and it's fun, of course. Again, like love to spend money on more toys on the computer lab. So,

Jo Peterson:

so are you saying that Alvaro with an MCP server, you're like a teenage driver. I'm just asking a question here.

Alvaro Gonzalez:

Oh well, I'm a little better. I'm a little. I think I'm a little beyond the category of teenage anything anymore. But you know, maybe I'm a 25 year old driver. I'm not sure that's much better.

Jo Peterson:

You have your MCP permit,

Alvaro Gonzalez:

yeah, yeah, yeah, yeah. Well, it's by I'm paying the bills, like the teenager. You know what I'm saying? Maybe that's

Jo Peterson:

maybe that's it. All right. Well, you're always fun and always interesting to talk to. So thank you for taking time today, and thank you all for joining. I hope you have a little bit of a laugh with me as well.

Alvaro Gonzalez:

Yeah. Thank you.