Northern Europe webinar series
Most organizations can tell you who has access to a database, a repository or a production pipeline, but not what that access was used for once someone, or something, connected: the audit trail stops at “connected from the app tier,” engineers are already pointing AI agents such as Claude Code, Codex CLI and Copilot at internal systems through Model Context Protocol (MCP), and automation platforms hold standing credentials that nobody has rotated in years. Control and Governance with Delinea is a three-part series for security, platform and engineering leaders across Northern Europe, showing, in a live demo each session, how Delinea and StrongDM move access control down to the individual query, tool call or agent action and attribute each to a named identity.
Get answers to these important questions:
- Why "who has access" and "what they did with it” are different questions, and how to answer the second one
- How access moves from the connection level down to a single query or tool call, with column masking and result caps to match
- How step-up multi-factor authentication (MFA) and written justification apply to destructive actions, not just logins
- How Model Context Protocol (MCP) tool calls get checked against policy before they reach the server, and logged under a real name
- How one command revokes access for a single agent or an entire tagged fleet of non-human identities (NHIs), in one action
Who should attend this webinar series?
- CISOs, CTOs, CIOs and executive leadership
- Directors of information security
- Database administrators and platform teams
- Security architects working with AI agents and MCP
- DevOps, automation and CI/CD teams
- IAM and PAM teams
Inside the three sessions (Three sessions, 20 minutes of content and a live demo in each)
Session 1, Tuesday, October 13: Who ran that query?
Statement-level policy and per-user audit for databases
Most organizations can tell you who has access to a database, but far fewer can tell you what those people did once connected: access runs through a shared account, and the audit trail stops at “connected from the app tier.” In 20 minutes, we close that gap live, showing how StrongDM authorizes the individual action rather than just the connection, masks sensitive columns, caps how much data a query can return, requires step-up multi-factor authentication (MFA) on destructive statements and attributes every query to a named person, all without changing your tooling, since engineers keep connecting with psql, SSMS, DBeaver, DataGrip or Tableau as they do today.
Session 2, Wednesday, October 21: Who approved that tool call, and how do you switch it. off?
Policy and audit for MCP tool invocations
Your engineers have already connected AI agents such as Claude Code, Codex CLI and Copilot to internal systems through Model Context Protocol (MCP), often via a personal access token pasted into a local config file, so the agent inherits the token's full scope and there's no record of which tools actually got called. In 20 minutes, we put StrongDM in front of the MCP server, so the agent no longer holds the credential; every request is checked against the identity of the person it acts on behalf of, and each tool call is evaluated against policy, permitted or refused, before it reaches the server, with the full invocation logged.
Session 3, Wednesday, October 28: Giving NHIs and agentic AI controlled access.
Credential-free access and instant revocation for service accounts and AI agents
Your RPA bots, CI/CD jobs and autonomous AI agents hold standing credentials for production that were set years ago, never rotated and rarely watched, so when a pipeline or an agent starts doing something unexpected on a Sunday night, the honest answer to “can we stop it” is often “we can shut the server down.” In 20 minutes we show how non-human identities (NHIs) get several layers of security instead: a Delinea Platform API integration, external key vault rotation, and StrongDM, which authenticates service accounts with a token, applies the real credential on the last hop, logs every action under the agent's own name, and lets you revoke a single agent or a whole tagged fleet with one command.
Register for the series
One form covers all three sessions. Register for the full series, and select the session most relevant to you and your team.
