Course

AI Security & Identity

Treat every agent as a principal with constrained authority.

AdvancedSecurity, IAM, and platform teams responsible for action-taking AI.Coming soon — self-paced, cohort, or hybrid

Outcomes

  • Model humans, agents, and workloads as distinct principals.
  • Design delegation and token exchange without confused-deputy paths.
  • Place authorization at tool execution, not only at login.
  • Threat-model prompt injection, RAG poisoning, and capability chaining.

Who It Is For

  • Security architects
  • IAM engineers
  • Platform and runtime owners

Prerequisites

  • Working knowledge of OAuth/OIDC
  • Identity & Authorization topic on Learn

Curriculum

Identity

  • Human, agent, workload identity
  • OIDC and OAuth
  • SPIFFE

Delegation

  • Token exchange
  • On-behalf-of
  • Short-lived credentials

Threats

  • Prompt injection
  • Confused deputy
  • Tool poisoning

Runtime policy

  • Capability boundaries
  • Audit
  • Continuous authorization

Architecture Labs

Labs focus on architecture decisions, not toy coding exercises.

  • Red-team an agent tool path
  • Design a PEP for tool dispatch

Included Resources

Threat model templatesChecklistsLabs

Instructor

Hammad Abbasi — AI & Security Architect. 16+ years across identity, distributed systems, and production agent architecture. Speaker at EIC KuppingerCole.

Learn for free first

Join the waitlist

This course is coming soon. Self-paced, cohort, and hybrid delivery will follow.