
Before the first keynote, I was talking with the person in the next seat, which is what you do at a conference while the room fills. At some point I said what I always say: “So I work for DigiCert.” And then I tried to explain what that means for AI in one breath. “We just GA'd our AI Trust Manager solutions, which issue "AI Passports" to add short-term, SPIFFE/SPIRE enabled, digital certificates to agentic workloads while adding policies and control governance so you have cryptographic authentication and then an audit trail of what happened and you can control what agent can talk to what system or other agent. We’re also working with NVIDIA to bring AI Passports to OpenShell.”1 I also admitted I’m not an engineer. I’d built a number of little apps like https://overload.army, where members invite their friends to their own small workout squad to support each other getting to the gym, the way everyone in that room now can build apps. All built on Vercel, Supabase, Resend, Twilio, and Cloudflare.
I mention it because that phrase, the one I’ve said hundreds of times, sounded different by the end of the day.
Paul Copplestone, Supabase’s CEO and co-founder, opened with a story about the company’s own beginning. In 2020, with a hundred days until Y Combinator’s demo day, he told an engineer to build a Postgres dashboard as easy to use as Airtable. It took the hundred days. Then he delivered the punchline to the room: “it’s completely ridiculous to spend 100 days building a dashboard now. This should be done in like two minutes.”23
That wasn’t a boast about speed. It was an admission that the thing they had built for people had stopped being the point. “We know we need to build for our newest type of user, which is agents,” he said. “So agents don’t use dashboards.” His co-founder, Ant Wilson (Supabase’s CTO), put it more ruefully a few minutes earlier. The team had poured itself into a beautiful interface for five years, “and now the agents just don’t care. They just want to connect via ChatGPT.”
For forty years we have designed software around a human being looking at a screen. Menus, buttons, dashboards, a progress bar to watch. On a Friday morning in San Francisco, a company that had won by building the best screen announced it was building for a user with no eyes. These agents, Paul said, “run for longer, they run in parallel, and they keep going after you close your laptop.” He was careful, though, about who was still in charge: “Ultimately, though, it isn’t agents who build; it’s you guys, the builders.”
He also told a story that got a laugh. A colleague testing the slides at 40,000 feet scanned a code on his phone and launched an entire database cluster from inside a coding agent, mid-flight. Then, deadpan: “Don’t do that in production, by the way.”
Andrew Ng (founder of DeepLearning.AI) came on next. He has founded or led half the institutions in modern AI, and the host gave up reading the list. Andrew opened with a forecast. A lot of core infrastructure, he said, “will be used not just by humans but by agents,” and “all the databases have been built for human users today.”
Then he spent most of his time on what agents don’t have. “It turns out when all of us are building applications, we know a ton of stuff that AI agents do not know. You may remember a conversation of a customer, you know, when you said something and there was a funny expression on their face.” He called it a “fundamental context advantage,” and he didn’t think it would go away soon, not until someone decides to “slap a camera on us.”
He was candid about his own habits. Starting a coding agent before bed, he said, “is a different way of getting into the zone, I guess, than debugging some weird JavaScript syntax.” He also confessed: “I still find myself waking up in the middle of the night too often to check on the coding agents.” And he was blunt about the risk. If you don’t understand the fundamentals, “the coding agent will make a bunch of trade-offs that you didn’t even know it made,” and it “just bites you later.” That isn’t an argument against agents. It’s an argument that someone has to know what the agent decided.
He ended by noting the one credential the host had skipped. He was “a proud father of two children,” and he had to dash to pick them up from school. One of the most important people in AI left the stage to do the thing no agent will do for him.
29 seconds · SELECT26
Download captions
The afternoon kept returning to that tension between letting go and staying responsible.
The YC partners Dalton Caldwell (co-founder of Standard Capital) and Michael Seibel (Y Combinator partner emeritus) told the room which work they would never delegate. Michael Seibel described helping San Francisco recruit police officers: the software helped, but “there was something about being in the room with the people that unlocked everything.” Another imagined telling a founder to shut down their company through an AI avatar that says, “Hello, that’s a great point.” The room laughed, because everyone knew exactly how wrong that would be.
Thomas Dohmke (co-founder and CEO, Entire), who used to run GitHub and now runs a company called Entire, gave the best image of the day for where we are. A year ago, he said, you could build with agents, but “you couldn’t take your hands off the steering wheel. Now you can take your hands off the steering wheel, but only until you get out of the coverage area. You know, until you get to Oakland.” Anyone who has ridden in a driverless car in San Francisco understood immediately. We’re in the coverage area now. The map is expanding every month.
Dohmke is building around the record an agent leaves behind, which he calls the trace, and he described it in terms I hear in my own work every day. The trace “is exactly reflecting my intent… you cannot argue after the fact that that’s not what you wanted.” He admitted what everyone does: “when my agent tells me that it has ran all the tests and fifty-eight out of fifty-eight passed, I’m not looking for the trace.” Being able to prove “what the agent claimed it did did actually happen,” he said, “is incredibly valuable.”
Parag Agrawal (founder of Parallel and former CEO of Twitter) told the story of how Parallel began. Just out of the CEO job at Twitter, “unemployed in sitting in a coffee shop,” he started building agents and ran into a wall. “I saw that the web was a very hostile place for agents,” he said. They got blocked, treated “like a bot.” He concluded that agents “will become the primary customers of the web,” using it a thousand times more, and he thinks a thousand is low. When agents fail today, he told Caryn Marooney (general partner, Coatue), it’s often “because they can’t access content that you can, or they can’t take an action because they don’t have the privileges that you do.” And sometimes it’s on us: “The problem is we struggle to specify tasks well enough.”

OpenAI session

Late in the day, Ant brought Anthropic’s Angela Jiang (who leads product for Claude Platform) and Katelyn Lesse (who leads platform engineering) on stage and went straight to the hardest question: agents breaking out of sandboxes. “Yeah, this is terrifying a lot of people in a lot of places,” Katelyn said. Her advice was plain engineering. “You probably want your agent harness running over here and your sandbox is over there, right? And like your credentials in a separate place.” Training the model to behave is an alignment problem, she said. Keeping it from reaching what it shouldn’t is “a classic engineering problem.”
Asked whether agents should have direct access to a production database, Angela didn’t hedge: “It’s probably a bad idea, which I feel like is not a controversial thing to say.” The panel talked about agents that run while you sleep, and about teaching a model when to approve its own tool call and when to stop and wait for a person. They talked about giving agents a budget, so the question becomes “less like, here’s how long you should work for, and more like, here’s how much you should spend.”
38 seconds · SELECT26
Download captions
Nobody on stage all day used the word “revocation.” I noticed, because it’s the word I think about most.
It wasn’t an oversight. The pieces were everywhere. Paul announced that Supabase’s old access tokens “inherited all the permissions of the developer who created those tokens,” and the new ones can be restricted to “a specific action, a specific project,” with “an expiry date.” He announced a human-approval step because, without it, “agents can basically do anything with your MCP, and they can cause a lot of disasters.” Parag’s agents fail because they can’t prove they hold the privileges a person holds. Dohmke wants a record you “cannot argue after the fact.” Katelyn wants the credentials kept somewhere else.4
33 seconds · SELECT26
Download captions
In my world those have names: identity, authorization, non-repudiation, key separation, expiry. They are the oldest questions in trust, much older than computers. A merchant’s seal pressed into wax told a distant buyer who sent the letter. A letter of credit let a traveler draw on a bank’s name in a city the banker would never visit. The certificates we issue today let a medical device, an EV charger or a sensor on a factory wall prove to another machine what it is, for fifteen years at a time. Every era that learned to delegate had to answer the same three questions. Who sent this? On whose authority? How do we take it back?5

The third one is the hard one. In device trust, I’ve learned not to assume revocation takes effect everywhere at once. Revocation lists get cached. Sessions stay open. A partner keeps honoring a credential issued last month. An agent in the middle of a weekend run carries the same baggage. That’s why Paul’s expiry date may be the most important thing he announced. The web’s certificate system has been learning this lesson: the maximum life of a publicly trusted TLS certificate steps down to 47 days from March 15, 2029. A credential that expires on its own asks less of revocation. For agents, I want credentials that live about as long as the task.6
That’s the work behind DigiCert AI Trust Manager. It ties each agent to a verifiable identity and an accountable owner, and enforces policy where the agent acts. It can allow or deny an action, end a session, or withdraw authority when conditions change. No product removes the need to prove that in your own environment.7
Paul had promised that morning that “we’re gonna close out the day with one of the OG builders who is Woz.” And so the day that began with agents that don’t need dashboards ended with the man who built computers on paper.
Steve Wozniak (Apple’s co-founder) learned from whatever he could find: a technical journal, an architecture manual, a chip’s documentation. He drew his designs by hand, and when a new chip arrived he would draw the same machine again with fewer parts. “Design things with fewer parts than I originally thought of,” he said. He wanted the Apple II design shared so others could learn. And he told a few gentle stories about AI getting small things wrong, the kind you catch only if you’re still looking.

I heard his idea earlier that afternoon, from Anthropic. Early on, a panelist said, the people building elaborate harnesses around models were right. But over time “you start to take out bits and pieces of that harness because they’re embedded into the nature of the model.” The scaffolding comes off, piece by piece, the way Woz’s chip count fell with each new manual. That’s worth doing on purpose.
Some parts don’t come off, however good the models get. Someone owns the agent. Someone knows what it can reach. Someone can stop it, and can show afterward what it did. Woz drew his machines so a person could understand them. The agents we’re building won’t fit on a sheet of paper. The people responsible for them can still write down who owns them, what they’re allowed to do, and what happens when we say stop.
So here’s the drill I’d run on one agent your team wants in production. Name its owner, and the person who steps in when the owner is away. List every system it can reach and what each one allows. Mark the actions that need a human yes, and confirm the agent actually waits. Then, with representative data in a controlled run, revoke its access halfway through. Write down what stops, what doesn’t, and how long it takes.
I walked out of SELECT26 thinking we are at the very beginning of handing real work to software that acts for us, and more convinced that trust is the part we have to build on purpose. The sentence I’d said that morning, about authentication and audit trails and governing which agent talks to which system, didn’t sound like a pitch anymore. It sounded like the job.
If you revoked your agent’s access right now, what would it still be able to do?
If you run the drill, I’d like to hear what you found.
Sources and notes
- Product overview: DigiCert AI Trust Manager. DigiCert announced general availability on September 15, 2026: launch announcement. DigiCert announced support for NVIDIA’s Open Agent Safety Platform, beginning with OpenShell, on September 29, 2026: DigiCert NVIDIA/OpenShell release. NVIDIA announced the platform on September 28, 2026: NVIDIA release. ↩
- Supabase SELECT26, October 2, 2026, 555 20th Street, San Francisco, CA 94107. Date, venue and speaker roles: official event. Session sequence: official agenda. ↩
- Speaker quotations were drawn from Tim McAllister’s SELECT26 recordings and machine-generated transcripts. Separate review notes identify transcript differences and quotations awaiting audio confirmation. The opening quotation is Tim’s supplied account of his conversation. ↩
- Scoped tokens and confirmation prompts: Supabase, Operate with confidence. MCP confirmation prompts require an agent client that supports elicitations. ↩
- Historical background: The National Archives, Seals and NatWest Group Heritage, Lettre d’indication, 1860s. These support the general authentication and banking analogy, rather than the particular scenes described. The wax image is a generated illustration. ↩
- The 47-day maximum applies to publicly trusted TLS subscriber certificates issued on or after March 15, 2029: CA/Browser Forum TLS Baseline Requirements, section 6.3.2. It does not set the lifetime of private device or agent credentials. ↩
- Current product scope is enterprises building or operating their own agents and MCP servers in their own workloads, which may call hosted model APIs. DigiCert AI Agent Trust describes passports, short-lived X.509/SPIFFE identities, SPIRE, policy enforcement and audit. Standards background: SPIFFE Overview and SPIRE Concepts. ↩