If you've been building with AI agents, you've probably had this experience: the agent needs access to something, a browser popup appears, you glance at it for a second, and you click Allow without really reading it. As Miguel Pedregosa points out, this is a huge mistake that results in a security flaw. He's a Senior Software Engineer on the Protocols team at Auth0, the team that owns the identity standards implementation that millions of developers rely on without thinking about it.
The door you've opened without reading. Each browser auth flow you click through is a permission you approved without knowing what you approved, and those authorizations may be happening entirely outside your enterprise identity provider.
The protocol that replaces the popup. Cross-App Access routes agent authorization through your existing enterprise identity provider. The agent gets an access token through the back channel, with no browser required, and full audit visibility for IT.
Implementing a standard that's still being written. Miguel's team launched the Cross-App Access beta while the IETF spec was in draft. The spec shifted, they shifted with it, and ended up feeding back directly into the standard itself.
What enterprises ask for that nobody else thinks about. A startup asks "does it work?" An enterprise asks "does it work with our 40-year-old system?" That gap drives more of what the protocols team builds than anything else.
Threat modeling without reading an RFC. What can each part of my system access? How and when? If this agent hallucinates, does it have access to everything? Miguel says those three questions are enough to start.
Things that stuck with me
When you click “Allow” on five consecutive prompts without reading them, you're approving access you can't really explain, and depending on how the agent is set up, those authorizations may be happening outside the identity system your company manages.
I assumed implementing a standard meant reading a spec and building to it, but it turns out early drafts could have gaps, and companies implementing early get to flag them. Sometimes those flags become changes to the spec. Miguel described it as one of the more fun parts of the project, which surprised me, and it makes sense once you hear why.
The threat modeling advice works because it requires no identity expertise. Just map what your system can touch and ask what happens if part of it misbehaves. The answers are often straightforward, and the hard part is remembering to ask before you ship.
You're probably already building agents, so the question is whether the security is something you thought through or something you clicked past.
Have you ever looked back at an agent you shipped and realized it had more access than it needed? Let me know in the comments!
Listen to the full episode
Available on YouTube, Apple Podcasts, and Spotify.
Thanks for reading!
Top comments (1)
Some comments may only be visible to logged-in visitors. Sign in to view all comments.