Summary is AI-generated, newsdesk-reviewed
  • Cequence AI Gateway's Agent Personas secure AI agents with scoped, infrastructure-level access control.
  • Agent Access Keys provide single attributable credentials for headless agents in workflows.
  • 80% of Fortune 500 use AI agents; only 47% deploy AI-specific safeguards.

Cequence Security has launched Agent Personas in its Cequence AI Gateway, providing enterprises with detailed infrastructural control over AI agent operations. This development offers granular control, addressing the critical privilege gap which cannot be resolved through identity verification alone, enhancing security measures for organisations deploying AI agents through the Model Context Protocol (MCP).

As AI agents increasingly connect to enterprise applications, it is crucial to understand that simple authentication does not equate to monitoring agent actions. Unlike human users, AI agents lack the discretion to limit their access privileges. Agent Personas manages these risks by employing plain-English descriptions to define a scoped virtual MCP endpoint for each specific agent role.

Virtual MCP endpoint

The introduction of Agent Personas allows customisation of access permissions for various AI agents. For instance, a customer service AI may access CRM data in a read-only capacity, while a coding agent can interact with GitHub issues and Jira tickets without modifying pull requests. Similarly, CI/CD automation agents are restricted to particular pipeline tools and a single notification channel.

The release also features Agent Access Keys, a new type of composite credential specifically designed for headless agents in automated workflows. These keys consolidate agent identity, user identity, and persona-level privileges, providing security teams with enhanced forensic abilities to determine agent actions and capabilities at any time.

Agent personas capabilities

  • Scoped virtual MCP endpoint per agent role, defining access down to specific API endpoints presented as a single endpoint.
  • Natural language persona creation, enabling plain language descriptions for agent tasks while the gateway selects appropriate tools.
  • Single source of truth, allowing persona updates to apply instantly across all agents using it without code modifications.
  • Composite Agent Access Keys binding agent identity, user identity, and persona privileges for headless agents.
  • Per-tool policy enforcement with rate limits, data masking, and approval workflows at individual tool call levels.
  • Comprehensive audit trail showing each tool call's attribution to specific agents, users, personas, and timestamps.
  • Model-agnostic enforcement across various platforms, including OpenAI, Google, Anthropic, open-source, and custom models.

Complexity of securing agents

Securing AI agents is particularly crucial, as highlighted by Gartner®, noting that the focus should go beyond model runtime and inference security.

It should include the complexity of managing agent actions, suggesting that agents should demonstrate their authority before gaining access to tools and data. Statistics show that while over 80% of Fortune 500 companies utilise AI agents, only 47% have AI-specific security measures in place.

Investments in AI platforms

Early adopters of Agent Personas exhibit the capability to regulate AI agent access within complex systems

Early adopters of Agent Personas exhibit the capability to regulate AI agent access within complex systems. A prominent U.S. telecommunications firm used this technology to manage agent interactions across platforms like GitLab, Confluence, Jira, and Slack, ensuring agents have limited access only to necessary resources, eliminating risks of lateral access.

Ameya Talwalkar, CEO and Co-Founder at Cequence, stated, "Enterprises have made massive investments in AI, and the race to put agents into production across customer experiences, employee workflows, and business operations is accelerating fast. However, security, governance, and scale requirements can’t be ignored. Cequence closes the gap that has been holding organisations back by automatically limiting agent tool access which lowers costs, enhances performance, and improves security."

Powering customer commerce

Shreyans Mehta, CTO and Co-Founder at Cequence, remarked, "AI agents have quickly become a channel as significant as the web or mobile, powering customer commerce, employee productivity, and autonomous operations all at once. Agent Personas is how you govern infrastructure access at the agent level, enforcing exactly what each agent can do down to the specific API endpoint, across any model or platform. It is the control plane enterprises need to confidently and securely enable agentic AI access to applications and data."

Agent Personas expands upon the existing Cequence AI Gateway, which has surpassed 140 verified enterprise application integrations, protects over 10 billion daily API interactions, and safeguards four billion user accounts. Cequence's influence is further recognised through its ranking on the Deloitte Technology Fast 500 and its leadership in the KuppingerCole Leadership Compass for API Security and Management.

In case you missed it

How is the role of biometrics changing in physical access control?
How is the role of biometrics changing in physical access control?

Biometrics today provide better security and frictionless user experiences. Biometric identifiers like fingerprints, facial recognition, and iris scans are unique and difficult to...

dormakaba acquires Alliants for hospitality growth
dormakaba acquires Alliants for hospitality growth

dormakaba has signed a binding agreement to acquire Alliants Limited, the guest experience technology partner behind more than 100,000 hotel rooms for the world’s leading hos...

Allied Universal: Admired workplace in security industry
Allied Universal: Admired workplace in security industry

Allied Universal®, the world's pioneer security and facility services provider, has been named one of America's Most Admired Workplaces by Newsweek for the third consecutive ye...