

Agents in Production: Trust, Access & Control
We spent a decade learning to lock down what our software can do. Then we handed agents the keys and asked them to improvise.
An agent with real access is either your fastest teammate or your worst insider threat - and the only thing standing between the two is what it's actually allowed to do. Least-privilege instead of god-mode credentials. Execution that's sandboxed, not trusted by default. An audit trail for the moment an agent does something surprising - so you can see what happened, and why.
For this London edition we're teaming up with Docker to get into the unglamorous half of agents in production: giving them real power without handing over the whole building. Including a guest talk from Pivot, exploring what changes when the data is client-confidential and the rules aren't yours to set. Expect honest talks, live demos, and engineers who've made this work in prod - not just on a slide - plus food, drinks, and the hallway conversations Zoom never delivers.
Agenda
6:00 PM - Doors open, food & drinks
6:45 PM - Welcome
6:55 PM - Talks + Q&A
8:15 PM - Networking
9:00 PM - Close
Talks & Speakers
We gave AI a shell. What could possibly go wrong? | Sr Director, Developer Success Programs, Docker
AI agents are becoming developers: running code, installing packages, reading files, calling APIs, and occasionally doing things nobody explicitly asked for. So why are we still treating AI governance as an enterprise policy problem? Per looks at Docker Sandboxes as a way to put practical boundaries around agents on the developer machine, and what "secure by default" should actually mean when your newest developer is an AI.
Access control for multi-agent systems | Tobie Morgan Hitchcock, Co-Founder & CEO, SurrealDB)
In most multi-agent systems every agent reads from the same shared memory, so the support agent, the finance agent and a partner's agent all see the same customer record - sentiment, contracts, PII, EU and US data alike. The usual fix stops at the identity provider: hand each agent a scoped token and hope something downstream honours it. Tobie makes the case that access control belongs one layer deeper, on the data itself, and shows it live - one shared memory, one unchanged query, four agents, four correctly scoped results.
Pivot speaker - coming soon
A note on photography: we'll have a photographer in the room and may film short clips on the night. Photos and footage may be used by SurrealDB and Docker to share highlights from the event, on our websites, social channels and future event listings. If you'd rather not appear, just say so to a member of the team when you arrive and we'll keep you out of shot.