WeAreDevelopers World Congress North America 2026: Trust Moves Into the System
San José is home to the world's largest permanent Monopoly board.
Monopoly in the Park sits in Discovery Meadow and covers 930 square feet. The board comes with oversized dice and proportionally scaled game pieces, which means groups can actually play a full-size version of Monopoly instead of simply taking pictures with it.
That feels strangely appropriate for a city hosting thousands of developers trying to figure out the rules for another rapidly expanding game.
WeAreDevelopers World Congress North America made its United States debut September 23 through 25 at the McEnery Convention Center in San José, California. Hundreds of sessions covered software engineering, infrastructure, AI, security, and the rapidly evolving world of agentic development.
Across three days, one theme kept surfacing. Developers want agents that can do more work with less supervision. Giving software that level of autonomy requires moving trust into the systems surrounding those agents.
Prompts can provide instructions. Infrastructure has to enforce the rules.
Agentic Development Needs Plumbing
Oleg Šelajev from Docker provided one of the clearest starting points with “Tools, Sandboxes, and the Plumbing of Agentic Development.”
A lot of the AI conversation still focuses on models and prompts. Oleg went lower in the stack and looked at what an agent actually needs to perform useful development work. It needs an environment, tools, context, and access to external systems. It also needs a repeatable way to receive all of those things.
Docker Sandboxes supplied the isolated environment in his example. The agent could work with the selected project and run containers inside its own sandbox. The surrounding host stayed outside that workspace boundary.
Oleg then expanded the model into teams of agents. One agent could develop while another reviewed the work. Separate contexts help keep those responsibilities independent. His point that a model should not review its own work would return again later in the conference from a completely different speaker.
The harder problems started when those agents needed outside services. Credentials, network configuration, MCP connections, and coding policies become part of the environment. Docker kits offered a way to package those requirements so teams could create repeatable agent environments instead of configuring every sandbox by hand.
That plumbing becomes part of the security model.
Autonomy Requires Boundaries the Agent Cannot Rewrite
Ajeet Raina continued with “Supply Chain Security When Agents Write the Code.”
His demo showed how quickly an unrestricted coding agent could become dangerous. An agent with broad host access could search for credentials and use what it found. It could choose dependencies and generate container files while pulling software from public registries.
Ajeet organized the security response around evidence, baselines, gates, and boundaries. Teams need to know what entered the build and where those components came from. SBOMs provide inventory, while provenance and attestations establish origin and build history.
The same principle applies at runtime. An agent needs room to work inside a defined environment. Network policy can control where it connects. Credential isolation can keep sensitive authentication material outside the agent's direct reach.
Dan Ndombe reinforced that idea later with “Give the Agent Its Own Machine.” His framing was wonderfully direct. As agents become more autonomous, the boundary around them needs to become stronger.
Docker Sandboxes use a microVM and expose only the workspace selected for the agent. Network rules and credential handling can be enforced outside that environment. An agent can still make a bad decision, while the surrounding infrastructure limits how far that decision can reach.
Trust Has to Become a Property of the System
The opening keynote on day two pulled many of those ideas together.
Mark Cavage, Michael Irwin, and Hervé Bizira presented “Manufacturing Trust: Speed and Safety in the Age of Agents.”
The traditional software development process relies heavily on humans. People review code, approve changes, and watch systems move through deployment. Agents can generate and execute work faster than people can inspect every individual action.
That changes where trust has to live.
Mark described four requirements for an agentic software factory: containment, control, choice, and capacity. Containment defines what an agent can reach. Control requires enough observability and enforcement to stop unsafe behavior. Choice lets teams change models and tools without rebuilding the surrounding security architecture. Capacity makes the system repeatable enough to operate large numbers of agents.
The session described a need for enforceable boundaries around nondeterministic agents. Isolation, restricted access, auditability, and reproducibility create an environment that can continue to enforce policy even when an agent behaves unexpectedly.
Agent security starts looking a lot like every other mature security discipline at that point. Trust comes from architecture and enforceable controls.
Responsible AI Needs Checkpoints and Contracts
Ashok Prakash from Apple approached the same challenge through “Responsible AI Architecture with Zero Trust Agents.”
Ashok focused on the systems around long-running agents. These agents interact with models and tools while accumulating context over time. Their architecture needs a way to constrain those interactions.
His reference design introduced explicit checkpoints and budgets into the agent loop. Teams could limit steps, tokens, tools, or overall execution time. Actions could also be classified according to whether an agent could perform them automatically, assist a human with them, or leave them entirely to a person.
Tool access became a contract. Each tool could define expected inputs and outputs along with its risk level. Rate limits and data classifications could travel with that contract. Policy engines could then make deterministic decisions around the agent's proposed actions.
That architecture gives human approval a more useful role. A person can receive a bounded decision with the relevant context instead of watching an agent execute every individual step.
Autonomy becomes easier to manage when the system knows which actions deserve scrutiny.
The Reviewer Cannot Be the Author
Manish Kapur brought the trust discussion back into code with “The Reviewer Can't Be the Author: Independent Verification for AI-Generated Code.”
AI-generated code creates an interesting psychological problem. Output that looks polished becomes easier to accept. Small failures can survive because the code reads well and the reviewer expects the model to be right. Manish described the accumulating result as verification debt.
His answer was independent verification.
The system that generates code should have a separate verification layer using different methods. Algorithmic analysis can find issues that can be determined mechanically. A separate agent can provide another layer of review. CI can enforce quality gates before code reaches production.
Oleg had made the same observation a day earlier while discussing multi-agent development. A model reviewing its own work brings the same assumptions and patterns into both creation and review. Independent systems create a better chance of catching failures.
The larger pattern goes beyond code. Agentic systems need separation of duties.
Authorization Is Becoming Infrastructure
One of the most useful sessions for understanding where agent security is heading came from Alex Olivier with “It Passed Auth, Then Production Caught Fire.”
Modern authorization decisions are scattered throughout applications. API gateways make decisions. Middleware and handlers make more. Feature flags and agents add additional decision points.
That fragmentation gets harder to reason about as machine identities multiply. One service may allow an operation while another silently skips it. An older role system can continue enforcing rules nobody remembers. Each component can behave as designed while the entire workflow fails.
Alex argued that authorization should be treated like a dependency. It needs ownership, service-level expectations, and a runbook. Decisions should also be explainable so teams can trace an outcome back to the policy version and inputs that produced it.
The emerging AuthZEN model gives these systems a common contract between policy enforcement points and policy decision points. An authorization request can describe a subject, an action, and a resource. The policy system can then return a predictable decision.
Agents make this architecture increasingly important. An autonomous system can call many tools across many services. Every one of those boundaries becomes another place where the enterprise needs to decide whether that agent should be allowed to take that action.
Authentication establishes who or what is making the request. Authorization determines what happens next.
Software Supply Chain Trust Is Becoming More Explicit
Jeroen van Erp approached trust from another familiar direction with “Stop Running Mystery Meat in Production.”
His food analogy worked because modern applications arrive with a long ingredient list. Application libraries sit on top of language runtimes. Those runtimes depend on operating system packages and container images. A simple base image can bring far more software into production than the application itself requires.
Jeroen organized software trust around provenance, attestation, and introspection. Provenance answers where something came from and how it was built. Attestation provides evidence about who approved or signed it. Introspection lets teams understand what is actually inside the artifact.
This lined up almost perfectly with Ajeet's earlier agentic supply chain talk.
Agents can accelerate how software gets assembled. The organization still needs to know what was assembled, where every component came from, and which policies were satisfied before it entered production.
Trust becomes a process carried alongside the artifact.
The Agentic Era Is Moving Security Into the Architecture
WeAreDevelopers World Congress North America covered far more than AI security. The sheer size of the event made it possible to wander from container hardening to Kafka data contracts and PHP engine exploits within a few hours.
Agentic development still dominated many of the conversations your author followed.
Agents need identities and scoped authority. They need constrained environments and controlled access to credentials. Their output needs independent verification.
The software they assemble needs provenance. Their actions need enough context and auditability for humans to understand what happened.
Developers are building systems that can take increasingly meaningful actions on their behalf.
The next phase of agentic development will depend on how well the industry builds the trust layer around them.
Two cities named San José ended up providing a fitting bookend. One became known for investing in a national theater that has endured for more than a century. The other spent three days hosting developers working out how today's rapidly changing technology might be built to last.