Credential leaks continue to happen, even though the controls for human identity have been available for years.
Matt Moore, co-founder and CTO of
@chainguard_dev, joins
@NancyzWang and Dev Tagare to discuss how security changes when credentials belong to people, machines, and AI agents moving through the SDLC.
The controls differ, but the standard is the same; credentials should be protected and scoped, and every use should be attributable.
โ
People need MFA, secure credential storage, and SSO where it fits
โ
AI agents need short-lived, least-privilege access
โ
Keep raw secrets out of agent context where possible, and broker access at runtime
โ
Trace actions to the agent and its authorizing human or service
The gap sits between what teams know works and what's actually deployed.
๐งListen to the full conversation here: