TLDRocket
Sign in

Vanderbilt University extends identity governance to AI agents

SiliconANGLE Victoria Gayton

Vanderbilt is extending its identity system to AI agents. The tricky part is figuring out who’s responsible when those agents wander past their guardrails.

Based on reporting by SiliconANGLE, Victoria Gayton — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Vanderbilt University is taking its identity governance playbook and applying it to AI agents, because the old boundaries around access are getting messier by the minute. The school already runs OneVU, its Okta-powered single sign-on setup, across an environment that includes residential life, athletics, its own police department and more than $1 billion in research. That kind of sprawl makes identity decisions hard enough for people. Add software agents into the mix, and the questions get sharper.

Shane Callahan, Vanderbilt’s chief information officer, said a university can contain several identities at once. A person may be a student, a staff member and a donor, each with a different security profile and different rules for how they move through the institution. Keeping that straight is already difficult, and AI only raises the stakes because an agent can be given scoped access without solving the bigger question of accountability.

That was the core issue Callahan raised in a conversation with theCUBE Research’s Krista Case and co-host Rebecca Knight at Okta’s Oktane event. If an agent acts outside its guardrails, he said, the hard part is not just limiting what it can touch. It is deciding who carries the blame if something goes wrong. If the damage reaches another group or another company, the responsibility question gets even murkier.

Callahan’s answer is not to invent a whole new control stack for AI. Vanderbilt is leaning on the same basic machinery it already uses for technology intake and cross-functional governance. His view is blunt: AI is still identity data moving through another tool, so the institution should use the processes it already has instead of pretending every new system needs a fresh bureaucratic religion.

My take — AI-written commentary, not fact-checked reporting

This is the sane response, which is why it’s rare. Everyone wants to sell “AI governance” as if it needs a moonshot, when most of the work is still basic identity discipline and someone willing to ask who gets blamed when the bot freelances. The industry keeps acting surprised that old controls still matter; that’s not innovation, that’s amnesia.

Read more about this at: SiliconANGLE

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.