Notes from LDX3 NYC: Nobody Has a Good Answer for Agentic Identity Yet
Blog post from FusionAuth
At LDX3 NYC, a conference for senior engineers and engineering leaders, discussions centered on how AI is changing software teams, including the implications of AI-generated code, uncertainty over which tools are genuinely useful, and concerns that automating junior-level tasks may weaken future talent development. Conversations at the event particularly emphasized agentic identity and authorization, with a proposed approach for allowing agents to act on a user’s behalf in third-party tools such as Notion while restricting access to sensitive resources. Where providers do not offer granular native permissions, the approach uses an identity provider, on-behalf-of token exchange, a gateway that enforces rules, and a secure credential store that injects the user’s real third-party credential only after validating the agent’s token, audience, and subject. Survey findings presented at the conference added urgency: 69% of teams using AI in software development lack a plan to measure its effectiveness, while 24% allow developers to use personal credentials for AI tools, limiting auditability, separate access controls, and revocation. The account argues that agents should always receive distinct identities and access tokens so organizations can monitor their actions, constrain permissions, and determine whether a human or an agent caused an incident.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| MCP | 3 | 2,241 | 148 | 72 | -74% |
| AI Coding Assistant | 2 | 341 | 115 | 55 | -77% |
| Secrets Management | 2 | 451 | 99 | 43 | -80% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.