Securing Agentic Intent: What Your Agents Are Built For vs. What They Actually Do
Picture the most useful agent your team shipped this quarter. It reads support tickets, checks the account database, and posts updates to Slack. Every one of those capabilities was approved. None of them tells you what the agent is actually trying to do with them.
That's the gap Forrester names in Securing Intent: A New Security Domain for Agentic AI. An agent's credentials describe what it can do; its nondeterministic logic explores paths that are technically permitted but functionally outside its purpose. Identity tools ask "who is this?" Prompt filters ask "what did the user type?" Neither answers the question that matters: is this agent still doing what it was built to do?
Guest speaker Jeff Pollard, VP & Principal Analyst at Forrester, and Yuval Sarel, Senior Product Manager at Cyera take that question apart: how intent becomes something you can define, observe, and enforce, rather than a line in a system prompt nobody rereads.You'll Learn:
- A working vocabulary: Understanding the different types of intent, from creator intent to user intent, agent intent and organizational intent.
- The ways intent breaks: Learn the risks associated with violations of intent and intent drift.
- Intent as an access decision: How data context and least agency turn intent from a monitoring signal into something that changes what an agent is allowed to touch.

