Summary is AI-generated, newsdesk-reviewed
  • Cequence's AI Gateway enhances API security with Agent Personas for infrastructure-level control.
  • Agent Access Keys enable forensic clarity by binding identities and persona privileges.
  • Enterprises accelerate AI deployment with reduced risks, as per Gartner's recommendations.

Cequence Security has announced the general availability of Agent Personas within its AI Gateway, aiming to enhance API security by providing enterprises with detailed control over AI agent actions. This new feature offers infrastructure-level control over AI agents, addressing the crucial privilege issues that identity verification alone cannot solve.

The need for Agent Personas arises as businesses deploy AI agents through the Model Context Protocol (MCP) to connect with enterprise applications. Traditionally, verifying an agent's identity was seen as sufficient security; however, this does not adequately manage what an agent can perform. Unlike human users, AI agents lack the discernment to know when to refrain from using their granted access. Agent Personas resolve this by defining a virtual MCP endpoint correlated to each agent role using a plain-English job description.

Virtual MCP Endpoint and Single Attributable Credential

Agent Personas utilize a scoped virtual MCP endpoint for precise role-based access. For instance, a customer service AI agent might have CRM read-only privileges without modification rights, while a coding agent can access GitHub issues and create Jira tickets but lacks permission to merge pull requests. These endpoints ensure each agent's access is limited to specific responsibilities, thus minimizing lateral access risks.

Agent Personas utilize a scoped virtual MCP endpoint for precise role-based access

The release also introduces Agent Access Keys—a composite credential specifically designed for headless agents functioning in automated environments. These keys consolidate agent and user identities with persona-based privileges into a single, traceable credential, thereby offering security teams forensic precision concerning the actions taken by AI agents.

Features of Agent Personas

Key capabilities of Agent Personas include:

  • Scoped virtual MCP endpoints: Define access rights for each agent role down to specific API endpoints and permission levels.
  • Natural language persona creation: Specify agent tasks in plain language, and the Gateway automatically selects suitable tools.
  • Single source of truth: Update a persona once for universal, immediate application across all related agents without code changes.
  • Agent Access Keys: Bind agent and user identity with persona privileges into a single credential for streamlined forensic tracing.
  • Per-tool policy enforcement: Implement rate limits, data masking, and approval workflows at individual tool call levels.
  • Full audit trail: Attribute every tool call to its specific agent, user, persona, and timestamps.
  • Model-agnostic enforcement: Apply security measures uniformly across OpenAI, Google, Anthropic, and other models.

Importance of Agent Security

The importance of securing AI agents is underscored by Gartner, noting that the primary risk is not an AI's statements but its actions. More than 80% of Fortune 500 companies have active AI agents, yet only 47% incorporate AI-specific security measures. The introduction of Agent Personas aims to facilitate the safe transition of agents from pilot to production phases.

Illustrating this, a prominent U.S. telecommunications firm has utilized Agent Personas to manage agent access in complex systems such as GitLab, Confluence, Jira, and Slack. By employing scoped virtual endpoints, the company effectively restricted agent access to necessary infrastructure, mitigating lateral access challenges.

Enterprise Adoption and Impact

"Enterprises have made massive investments in AI, and the race to put agents into production across customer experiences, employee workflows, and business operations is accelerating fast," commented Ameya Talwalkar, CEO and Co-Founder at Cequence. He highlighted the significance of security and governance, noting that Cequence's solutions help balance security needs with operational scalability.

CTO and Co-Founder Shreyans Mehta added, "AI agents have rapidly emerged as a significant channel like the web or mobile, impacting commerce, productivity, and operations. Agent Personas provides enterprises the control plane needed for secure, scalable AI access to applications and data."

Agent Personas builds upon the momentum of Cequence AI Gateway, supporting over 140 enterprise application integrations and safeguarding over 10 billion daily API interactions. Cequence is noted for its contributions to AI security through initiatives like the co-authorship of CIS Critical Security Controls® Companion Guides.

In case you missed it

Responsible AI Adoption Starts With Governance
Responsible AI Adoption Starts With Governance

The eagerness to adopt AI in physical security is increasing as teams want to implement technology solutions for faster, smarter operations. At the same time, the conversations sur...

How AI-Enabled Cameras Are Becoming Operational Sensors That Power Safety, Automation, And Business Intelligence
How AI-Enabled Cameras Are Becoming Operational Sensors That Power Safety, Automation, And Business Intelligence

The biggest return on investment from an AI-enabled camera might have nothing to do with security. Organizations are increasingly discovering that the same cameras installed to pro...

Solink's AI Agents Boost Efficiency Of Existing Infrastructure With Automation
Solink's AI Agents Boost Efficiency Of Existing Infrastructure With Automation

Deploying artificial intelligence (AI) tools should be seen as a business initiative rather than a technology initiative, says Martin Soukup, CTO of Solink, a cloud-based video sec...