AI systems should use super agents when an organization needs a unified understanding of its departments, a single consistent interface and context, and coordinated workflows across many resources. Secure deployment requires agent swarms, least agency, tool isolation, observability, and human oversight.
Searchable transcript of When Should AI Systems Use Super Agents? — IBM Technology (11:26). Search for a phrase, then click its timestamp to jump straight to that moment in the video.
Captions sourced from the original video on YouTube, published by IBM Technology. The video, its captions and all related intellectual property remain the property of their respective owners; AINotes claims no ownership. Provided for research, accessibility and search — see the Transcript Notice and Copyright Policy.
00:00 Howdy, everyone. In general, we have advised against introducing super agents into an organization. These are agents with superpowers that can do everything we want them to do, but we fear introducing the entity that takes over everything. There are times, however, when we need agents to have more power. The question is, when is it ok to have super agents?
00:27 All right. Let's think about where this whole idea of super agents come from. It's really not new to us. As far back as our early computing days, we had master control programs, MCP. We had Whopper. Even with web services, which was fairly recent, we had the concept and notion of having centralized entry points and centralized control of web sources to distribute it out.
00:53 So it's really nothing new to use. So why are we so concerned about this? Why? Are we against having super agents? Well, let's start by kind of maybe drawing a little bit of an example of a system that we're kind of talking about. First of all, we have our super agent. We have people that want to interact and we have some set of resources within a company and organization that we want that agent to be able to connect and do things against.
01:22 So... Again, why are we against doing this? Well, first thing is privilege abuse. We don't want, or we're concerned about whether a super agent has too much privileges. It can read, it can write, it pull, it can change, it delete. It can do a lot of stuff against a lot different resources. This is the first thing that we're concern about. And why this really starts being a concern is also around an expanded attack surface.
02:04 So think of it this way, we have a super agent, we have bunch of resources that it can interact against, and if something happens anywhere in here, let's say there's some sort of a compromise down here, that can backtrack to a compromise within our super agent. Now that super agent has access to all these other resources, so you have a path to get to everything else.
02:27 This is an expanded attack surface. Any area along this that gets attacked, can attack now anywhere we need it to happen. And so this also gets into a concept of lack of isolation. In other words, if we do have an attack here and it works its way back and compromises our agent, it's not isolated to just this because the super agent has access to a lot of other resources.
02:58 Now... The blast radius, as we say, has expanded. If a compromise happens in a small area, the blast radius is very large. That's a lack of isolation. So these are the things that we're really against when we think about having super agents. So if we're against it, then why do we even talk about this? Why do we want super agents? Well, The first thing that really is starting to pop out for us is we really like the concept of having the brain.
03:34 If you kind of think about how agentic and AI and gen AI and rag models have popped up, different parts of a company, different business units, different areas within, they built up their own, their chats, their interfaces, a way of retrieving information. But that was really compartmentalized to that part of the organization. What we really would like to have is a brain that has understanding of everything going on around an organization so we can really make the determinations of where it needs to go to get an answer.
04:01 So having this brain that understands everything and can look is actually a really nice thing. And that leads us to another point is that we have a single point of contact. In other words, when this user here is interfacing with AI and an organization, we don't necessarily want it, oh, well, you got to go over and interact with this chat. Oh, you gotta go interact with his agent.
04:39 It would be nice to have a single point of contact. That keeps the interface the same, keeps the language the same. Keeps the context consistent. It's really nice to a single point of context when we're talking about. Agentic and AI systems across an entire organization. And of course, because we have organizations that have different departments, different areas within the business, we need to make sure that if we have a single point of contact, that we can then coordinate the workflow across all of these different
05:03 parts of a business. So now we have a single person has a single point of context. And we can coordinate, we understand and see everything within the organization, and we could coordinate all the work across everything. So these are really nice things about having a super agent involved. So, if we really like the concept of having a Super Agent, but we really have things that we're worried about, then how do we approach this?
05:41 How do we have Super Agents in a secure way? Well, the first thing you gotta kind of really start thinking about. Is really think about this in terms of agent swarms. So what we're really saying here is that, yes, you have this main agent, but now you have a set of other agents that are across an organization. So they kind of constitute a swarm, if you will, of agents.
06:12 And with that, we get a collective intelligence. Now this is across everything. We have a collective intelligence across it all, but we still have a single orchestrator, in other words, we have our super agent, the brain, that understands everything, knows how to coordinate workflow across all these agents, and can get to the answers and the responses and the resources we need to do the actions and retrieve information that we want.
06:52 So we still have the single orchestrator happening, but now we introduce this collective intelligence where all of these agents can collaborate. And they can integrate work. Again, if we have different resources and different agents working, we don't necessarily want to have a person that has to go to this area of a business to get an answer. Then we go to another area of the business.
07:21 We want to integrate all that together when we're thinking about our agentic systems. Now, so again, if were thinking about super agents and swarms of agents, how do we think about this in a secure way, especially in what's allowed for an agent to do? So let's think of it in terms of a graph. And so the first thing is we have risk, risk for our resources, and it can go from low to high risk.
07:47 And then we also have agency. How much is an agent allowed to do? And this goes from low-to-high as well. So when we start thinking about this and we think about the orchestrator agent or the super agent, it has a high agency. It can do a lot of stuff. But we don't necessarily want it interacting with these different resources. So we break this down.
08:10 I'm gonna draw this as a step function, but it can be linear, it can whatever, but we have an area here of high agency and the risk increases as we go towards our resources. But we may wanna have something in the middle that's really kind of medium agency, where it has less agency than the super agent, but it still can have some visibility across a lot of different stuff.
08:33 And then we get to a point of low agency. When we start talking about agents that are actually interacting with a resource where your risk is the highest, then we have low agency, then we start looking at things like high cohesion, where only this agent can interact with that resource and nothing else, right? And so then we kind of think it in these terms where you have low, high agency and low risk, and we move to low agency and high risk.
08:59 So this is basically how we kind of want to view this. So when we think about what does this really mean for us, well, we want to ensure by doing, looking at it this way, we ensure least agency. Now we've talked a lot in the past about least privilege. This is a very similar concept. You have to think about where the agent is, what the agent doing, and what's the least amount of agency that that agent needs to complete the task that it's trying to perform.
09:32 We also wanna make sure that we have isolation of tools. So if this agent is the only thing that can interact with this resource, if there's a compromise here, the compromise only happens here. Even if they backtrack this compromise into the super agent, if it goes up this other path, these aren't compromised, right? So, or, you know, at least at this level.
09:59 It retains its isolation so that the blast radius here stays pretty isolated. So this is a very good thing to happen. The other thing that we want to ensure is that we have observability. Make sure that we, everything that's happening, all the decisions we're making, all the agency, all that we have observable means and logging so we can always go back for auditability and see what happens.
10:29 Now, all this said, the one thing that we really want to avoid here then, when we think about this, is a lack of human. Observability. We do not want humans out of the loop. We really either want the human in the loop when necessary or the human on the loop, when necessary. So it's okay to introduce super agents into an organization. And actually it's something we want to do. Just make sure that you're taking into account least agency and observability when you're doing this. Thank you for watching the video.