
Security Will Always Lose If It Gets in the Way: Joel de la Garza (a16z)
Every security leader knows that developers will work around security tooling when they can if it gets in the way of their job. The truth is, employees don't get paid to be secure; they get paid to do their job. Joel de la Garza, partner on the infrastructure team at a16z and former CISO of Box, tells us that the moment security gets in the way of what people want to do, security loses. For a lot of teams, this has meant tolerating uncomfortable security gaps to get the value agents can bring. At Keycard, we call the underlying bind the trilemma of autonomy, capability, and security: teams can only pick two. Joel walks through what securing agents looks like in practice, from a consumer agent logging into an auction site through a browser with every alarm bell ringing to a16z's own coding agents opening tunnels out to Cloudflare to route around egress controls in a secured GCP cluster. We get into why least privilege and agent performance pull against each other, and why some of security's first principles have to be rethought rather than reasserted. We also talk about the pressure CISOs face as they're expected to say yes to agents and lead the agent rollout. Joel also shares his love for Grok Bot and the need for model providers to give blue teams the same advantages attackers now have.