Live LabsFree Live LabEngineersIdentity and guardrails1 hour
Add Auth and Guardrails to AI Agents
An agent that can read your issues and docs can also leak them, or obey an instruction hidden inside them. Most teams give every agent one shared API key and hope the prompt holds. Live, Param gives each agent its own identity in Keycloak, checks every action against the user's permissions with OpenFGA, and blocks a prompt injection planted in a GitHub issue.
Why this matters
An agent that can read your issues, docs and tickets can also leak them, or obey an instruction hidden inside them. Most teams give every agent one shared API key and rely on the prompt to behave. Security reviews stop agent projects for exactly this reason: nobody can say who the agent acts as, what it may touch or what stops a planted instruction. This lab answers all three.
What happens in the hour
The problem4 min
Why one shared API key and a careful prompt fail the first security review.
Built live40 min
An identity per agent in Keycloak, every action checked with OpenFGA on behalf of the user, and a prompt injection in a GitHub issue caught before the agent follows it.
Questions16 min
The checklist for adding identity and guardrails to an agent you already run.
What you will be able to do
Give every agent an identity
Each agent signs in with its own scoped credentials, never a shared key.
Check each action
The agent sees and does only what the person it works for may.
Block prompt injection
Catch an instruction planted in an issue before the agent follows it.
The ideas behind it
An identity per agent
Each agent signs in as itself, with its own credentials, so every action in your logs has a name on it.
Acting on behalf of a user
When an agent works for someone, it carries that person's permissions and never more. It cannot read a document the user could not.
Permission checks per action
Each tool call is checked against a permission model before it runs, not only at sign-in.
Prompt injection
Text inside data that tries to give the agent new orders. The lab plants one in a GitHub issue and blocks it with input and output checks.
Where it fits
The parts of a production agent system, in the order the buildcamp builds them. The lit tiles are the ones this live lab builds; the Agentic AI Buildcamp for Engineers builds all of them.
Week 1Architect
Roles and modelsOne job per agent, a model chosen for that job, and a token budget.
OrchestrationA queue agents pick work from, with hand-offs a person can follow.
Context and memoryRetrieval with sources, memory across sessions, prompts laid out for the cache.
Tool callingTyped tools that act in GitHub, Linear and Google.
Week 2Build
MCP serversEvery tool behind an MCP gateway, scoped to the role that needs it.
Durable executionRuns that resume after a crash and never repeat a write.
Human in the loopA person approves anything that cannot be undone.
Week 3Secure and deploy
Identity and permissionsEach agent signs in as itself and acts on behalf of a user.
LLM gatewayRouting, caching and a budget on every model call.
Traces, evals and costEvery run traced, scored and charged to the agent that made it.
Multi-tenancyEach team or customer kept apart, in data and in the bill.
Week 4Govern and extend
Policy as codeRules checked on every action, not written in a document.
Signed skillsNew roles built from reviewed, signed skills.
Before you come
For
Engineers whose agent demo now has to pass a security review, and the tech leads and platform engineers responsible for what agents may see and do.
You need
None. Knowing single sign-on helps.
Track
Agentic AI for engineers who build and run it.
Questions
Which tools does it use?
Keycloak for identity and OpenFGA for permissions, both open source and self-hostable. The same ideas map to Okta, Auth0, Entra ID or your own policy engine.
Can guardrails stop every prompt injection?
No single check can. The lab shows layers that make an attack fail safely: checks on what goes in, checks on what comes out and permissions that limit what an obeyed instruction could do.
Is this for security engineers or application engineers?
Both. Application engineers learn what to build in; security and platform engineers learn what to ask for in a review.
Do I need to know OAuth?
It helps to know what single sign-on is. Everything else is explained as it is built.
Is the Live Lab really free?
Yes. Live Labs are free on Maven. You sign up with your email and get the join link and the recording.
What if I cannot make it live?
Sign up anyway. Everyone who signs up gets the recording, so you can watch the build later and reply with questions.
Do I need to code along?
No. Most people watch the build and ask questions. Every step is shown, so you can repeat it on your own afterwards.