About this webinar
Your agent knows too much. In most multi-agent systems every agent reads from the same shared memory, so a support agent, a finance agent, and a partner's agent all see the same customer record - sentiment, contracts, PII, EU and US data alike - and 2026's fixes mostly stop at the identity provider or a policy gateway, handing each agent a scoped token and hoping something downstream honours it.
This webinar makes the case that access control belongs one layer deeper - on the data itself, as a permission the database checks on every single read - and shows it live: one shared memory, one unchanged recall query, four different agents, four correctly-scoped results, where the finance agent never sees support sentiment, the EU-resident agent can't read US rows, and only an explicit admin grant unmasks PII. You'll leave knowing why record-level scope defuses the lethal trifecta in a way a gateway can't, and why the same mechanism delivers EU data residency for free ahead of the August 2026 AI Act deadline.
Speakers
Tobie Morgan Hitchcock
Co-Founder & CEO at SurrealDB
In this session you'll learn
Why access control belongs on the data layer - a permission checked on every read - not just at the identity provider or a policy gateway.
How record-level scope defuses the "lethal trifecta" in a way a scoped token or gateway can't.
Why the same mechanism delivers EU data residency for free, ahead of the August 2026 AI Act deadline.