Token, the biometric identity assurance company, has named Torrell Funderburk, a two-time Top Global CISO, to its Industry Advisory Board. Funderburk brings frontline security leadership from Sealed Air and Maestro Health to a board of CISOs and government security leaders shaping Token's response to a security landscape where AI agents are increasingly trusted to act, and the question of who actually approves their actions has become urgent.
A Board Built for the Agentic AI Era
Token's Industry Advisory Board is made up of senior cybersecurity executives, CISOs, and government security leaders tasked with protecting some of the world's most critical organizations and infrastructure.
The appointment lands at what the company calls a defining moment for enterprise security. Credential compromise remains the leading cause of enterprise breaches, and AI has made the problem structurally worse: phishing, deepfakes, and social engineering now operate at machine speed, even as the credentials underneath them have barely changed.
As enterprises shift AI agents from advisory roles into operational workflows, a second question has emerged: who, exactly, approves the high-consequence actions those agents are now capable of taking?
"Torrell has built and defended security programs at Fortune 500 scale, across some of the most demanding regulatory environments there are. As the question shifts from 'who logged in' to 'who approved this action – a human or an agent,' his judgment is exactly the kind we want guiding us."— Kevin Surace, CEO, Token
Closing the Gap Between Human and Agent Approval
Token recently extended its biometric architecture to address exactly that gap, placing hard gates around high-consequence actions such as releasing funds, changing access rights, or modifying production systems. Under this model, an AI agent can prepare the work, but only a verified, physically present human can approve the outcome.
Token's cryptographic biometric identity assurance is designed to prove the human, not just the credential. Rather than layering additional factors onto weak credential foundations, it binds both access and approval to a verified, physically present person through on-device biometric authentication enforced on secure hardware.
The TokenCore product line, comprising the TokenCore Wearable, TokenCore Portable, and TokenCore Node, integrates with existing IAM, SSO, and PAM infrastructure rather than replacing it.
