Agenda setting is the opening step in an unconference where participants agree on the topics to discuss. It turns a broad meeting into a focused working session by selecting the most relevant themes, assigning them to rooms or time blocks, and giving the group a shared plan for discussion.
Expanded Definition
Agenda setting is the collaborative step where an unconference converts a broad, open-ended gathering into a workable session plan. In NHI and agentic AI governance conversations, the term is useful because it describes the moment participants decide which risks, controls, or design questions deserve shared attention before deeper breakout work begins. It differs from general meeting planning because the agenda emerges from participant priorities rather than a fixed speaker order. That makes it especially relevant in fast-moving topics such as secret sprawl, service account ownership, and agent permissions, where the group needs to surface the highest-friction issues first.
Usage in the industry is still evolving because some teams use agenda setting to mean topic triage, while others use it to mean the full scheduling process that assigns sessions to rooms or time blocks. The most useful interpretation is operational: it creates a common work plan that lets the right people engage the right problem at the right time. For governance teams, that means turning a broad discussion into bounded, actionable tracks aligned to identity risk, control ownership, and remediation priorities. For background on why focused discussion is often necessary in NHI programs, see the Ultimate Guide to NHIs and the NIST Cybersecurity Framework 2.0.
The most common misapplication is treating agenda setting as a facilitator-only task, which occurs when participants are not given real influence over topic selection and prioritisation.
Examples and Use Cases
Implementing agenda setting rigorously often introduces a tradeoff between openness and structure, requiring organisations to weigh broad participation against the need to keep sessions focused and time-boxed.
- A security unconference invites attendees to propose NHI topics, then groups them into tracks such as secrets lifecycle, service account visibility, and agent tool access.
- A governance workshop uses agenda setting to elevate urgent questions about API key rotation after reviewing patterns highlighted in the Ultimate Guide to NHIs.
- An AI operations forum lets participants vote on whether to discuss privileged agent design, approval workflows, or incident response, then schedules the top topics into parallel rooms.
- A risk steering session aligns agenda items to the NIST Cybersecurity Framework 2.0 so the discussion stays tied to identified outcomes and ownership.
- A cross-functional review of service accounts uses agenda setting to ensure engineering, security, and platform teams each have a defined slot to address remediation blockers.
Why It Matters in NHI Security
Agenda setting matters in NHI security because the highest-risk identity issues are often buried under competing priorities. If a discussion is not deliberately shaped, teams may spend time on low-impact operational detail while missing issues such as excess privilege, stale secrets, or unclear ownership of autonomous agents. That is especially dangerous in environments where NHI risk is already widespread: NHI Mgmt Group reports that 97% of NHIs carry excessive privileges, and 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, according to the Ultimate Guide to NHIs.
For practitioners, the value of agenda setting is governance clarity. It forces a group to decide which control gaps deserve attention now, which teams own follow-up, and which risks should be deferred. That discipline becomes especially important when discussions span secrets management, Zero Trust alignment, and agentic AI access patterns. It is also where policy and execution begin to meet: a strong agenda can expose missing telemetry, weak rotation practices, or unclear escalation paths before they become operational failures. Organisatons typically encounter the need for agenda setting only after a review stalls, an incident broadens, or a remediation meeting becomes unfocused, at which point the term becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OV-01 | Agenda setting supports governance oversight by structuring what the group must review and decide. |
| NIST Zero Trust (SP 800-207) | J1 | Zero Trust discussions depend on clear prioritisation of identities, resources, and access paths. |
| OWASP Non-Human Identity Top 10 | NHI-01 | NHI governance reviews need a structured agenda to surface identity risk and control gaps. |
| OWASP Agentic AI Top 10 | A1 | Agentic AI oversight requires prioritising discussion of tool access, autonomy, and escalation paths. |
| CSA MAESTRO | M2 | MAESTRO emphasises operational controls that benefit from agenda-driven cross-functional review. |
Set agendas around trust assumptions, access boundaries, and verification steps before discussing implementation.