

Agents in Production: Trust, Access & Control
We spent a decade learning to lock down what our software can do. Then we handed agents the keys and asked them to improvise.
For this London edition, SurrealDB is teaming up with Docker on the question underneath all of it: how do you give an agent real power without handing over the whole building? Including a guest talk from Pivot, exploring what changes when the data is client-confidential and the rules aren't yours to set.
Expect honest talks, live demos, plus food, drinks, and plenty of time for networking.
Agenda
6:00 PM - Doors open, food & drinks
6:45 PM - Welcome
6:55 PM - Talks + Q&A
8:15 PM - Networking
9:00 PM - Close
Speakers
Docker - Per Krogsland
SurrealDB - Tobie Morgan Hitchcock
Pivot - Jonathan Aiken
Talks
We gave AI a shell. What could possibly go wrong? | Per Krogslund (Sr Director, Developer Success Programs, Docker)
AI agents are becoming developers: running code, installing packages, reading files, calling APIs, and occasionally doing things nobody explicitly asked for. So why are we still treating AI governance as an enterprise policy problem? Per looks at Docker Sandboxes as a way to put practical boundaries around agents on the developer machine, and what "secure by default" should actually mean when your newest developer is an AI.
Access control for multi-agent systems | Tobie Morgan Hitchcock (Co-Founder & CEO, SurrealDB
In most multi-agent systems every agent reads from the same shared memory, so the support agent, the finance agent and a partner's agent all see the same customer record - sentiment, contracts, PII, EU and US data alike. The usual fix stops at the identity provider: hand each agent a scoped token and hope something downstream honours it. Tobie makes the case that access control belongs one layer deeper, on the data itself, and shows it live - one shared memory, one unchanged query, four agents, four correctly scoped results.
When your agent stops reading and starts asserting | Jon Aiken (Chief Architect, Pivot)
Sandboxes constrain what an agent can do. Data-layer access control constrains what it can see. Regulated work adds a third question: what an agent is allowed to say.
On legal matters, the challenge is the assertion. Pivot's platform is built on a bespoke "Polyphonic Assertion Ontology" - every statement in a matter is an assertion by a voice, never a bare fact. That makes something visible that most data models flatten: the moment an agent summarises a case file, it isn't reading any more, it's asserting. A new voice has entered a client-confidential matter, in a profession where the rules are the SRA's, not the engineering team's. Jon shows how Pivot handles this in production - per-matter isolation on SurrealDB, audit trails built for a court, not a debugger - and makes the case for what's next: agents with registered roles, deriving authority from certified, federated matters.
A note on photography: we'll have a photographer in the room and may film short clips on the night. Photos and footage may be used by SurrealDB and Docker to share highlights from the event, on our websites, social channels and future event listings. If you'd rather not appear, just say so to a member of the team when you arrive and we'll keep you out of shot.