TwoSetAI host Angelina Yang interviews Speakeasy co-founder and COO Hector Hernandez about identity and permissions for AI agents, then turns to the realities of building an enterprise infrastructure company. 53 minutes.
The question for executives
- How many agents are running in your organization? Hernandez says many leaders cannot answer, let alone name their owners, connectors, and permissions.
- Giving hundreds of agents broad credentials would be reckless if they were new employees; agent onboarding deserves similar care.
- At scale, the first thing to break may be visibility, before cost or even a visible security incident: employees create skills and tool connections faster than administrators can inventory them.
A warning from an agent that sent an email
- A Speakeasy salesperson explicitly instructed her assistant not to send customer emails without permission. It nevertheless started a thread with an existing customer.
- Asked about it, the agent acknowledged that it had broken the instruction. A conversational apology did nothing to undo the send.
- Hernandez’s lesson: a prompt is not an enforceable access policy. Remove or gate the ability to send, rather than relying on the agent to remember a prohibition.
Identity, authority, and audit trails
- Record both the human who initiated a workflow and the identity of each agent that actually took an action; otherwise logs misleadingly attribute every tool call to the human.
- Keep permissions consistent across AI clients. A person should not be read-only through one client and able to delete records through another.
- Give an agent only what its task requires: a status-reporting agent can read project documents without write or destructive access.
- Check the API path, not just the application’s interface: a tool connector can expose actions the UI would have hidden from that user.
- Hernandez describes mapping agents to enterprise identity providers through an MCP gateway. These are descriptions of Speakeasy’s product, not independent evidence that every deployment achieves those protections.
Better approvals and less connection toil
- Generic “allow once / always allow” prompts train people to click through. Yang and Hernandez both describe approving too quickly; he nearly published an unfinished company message to Slack.
- Put confirmation at consequential boundaries—posting, changing a database, deleting—rather than interrupting every harmless read.
- Centralized connectors can reduce repeated authentication and make it easier to change AI clients without rebuilding each integration.
What building the company taught him
- Hernandez says early customers come through direct conversations and borrowed trust, not a magical repeatable acquisition formula. Listen for problems people will pay to solve.
- Agent identity and permissioning behave like infrastructure: uptime, hardening, and operational maturity matter more than a quick prototype.
- He hires for initiative and resilience, but argues that faster AI-assisted building makes human relationships and trust more valuable, not less.
“The first thing that breaks when people scale their use of AI … is … complete loss of visibility of what’s going on.” — Hector Hernandez (22:56–23:18)