The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/AI & Data/Enterprise Security Weekly
Enterprise Security Weekly artwork

Mastering agent permissions and Identiverse interviews - Howard Ting, Ajay Gupta, Sandy Bird, Amir Ofek - ESW #466

Enterprise Security Weekly · 2026-07-06 · 1h 18m

0:00--:--

Key moments - from our scoring

Substance score

51 / 100

Five dimensions, 20 points each

Insight Density11 / 20
Originality10 / 20
Guest Caliber13 / 20
Specificity & Evidence9 / 20
Conversational Craft8 / 20

Sandy Bird brings deep expertise from co-founding Q1 Labs (acquired by IBM in 2011 for QRadar) to address a critical blind spot in enterprise cloud security: AI agent permissions. The core problem is stark - between AWS, Azure, and GCP, there are now 350,000 unique permissions available, yet most organizations grant agents far more access than needed. Bird explains how Sonrai Security flipped the traditional permission-remediation model on its head: instead of assigning tickets to fix over-privileged identities (which becomes mathematically impossible at scale with 10,000-100,000 offenders), they implemented a default-deny approach using MCP servers, Slack/Teams integration, and real-time exception workflows. This matters urgently now because generative AI agents using Claude, Bedrock, Vertex AI, and Azure AI Foundry can cause production damage in minutes - Bird illustrates scenarios where an agent might accidentally delete a production database while attempting schema migration. The conversation explores how pricing pressure from OpenAI, Microsoft, and Apple is driving shifts toward smaller local models for routine tasks and larger foundation models only for high-fidelity work. For security leaders, the takeaway is that identity management has become the unrecognized core control layer for AI agent governance, and human-in-the-loop approval workflows (triggered when agents attempt unexpected actions like security group modifications) are now essential baseline controls.

Key takeaways

  • →Default-deny permission models are more scalable than remediation-based approaches for managing AI agent access, since fixing 100,000 over-privileged identities at 30 minutes each is mathematically impossible.
  • →MCP servers, Slack/Teams-based exception workflows, and human-in-the-loop approvals allow organizations to grant permissions instantly when agents need them while keeping them least-privileged by default.
  • →AI agents using Claude, Bedrock, Vertex AI, or Azure AI Foundry inherit hyperscaler permissions and can cause production damage in minutes - securing them requires the same identity controls originally built for malicious actors.
  • →Context window limitations in LLMs force multi-agent architectures with separate identities and data boundaries, making identity isolation a core technical requirement rather than a compliance afterthought.
  • →Pricing models will likely split between cheap local/small models for routine decisions and expensive foundation models for novel high-fidelity work, requiring organizations to architect agent stacks with cost-aware routing.

Guests

Sandy BirdAmir OfekHoward TingAjay Gupta

Topics in this episode

Claude CodeAzureMCP serversBedrockAWSGCPVertex AISonrai SecurityQ1 LabsQRadar SIM

Questions this episode answers

How many unique permissions exist across AWS, Azure, and GCP?

Between the three hyperscalers, there are approximately 350,000 unique permissions available, making least-privilege configuration extremely complex without automated tools.

Why does the traditional ticketed remediation approach fail for cloud over-privileged identities?

At scale, organizations discover 10,000 to 100,000 over-privileged identities; fixing each at 30 minutes of developer time per fix makes the total workload mathematically impossible to complete before production deployments repeat the problem.

What happens when an AI agent using MCP servers has database permissions?

Agents can unintentionally cause production damage - for example, attempting to migrate a schema by deleting and recreating a database, destroying the production database in the process.

How does Sonrai's default-deny model for agents work in practice?

Developers configure cloud resources freely; Sonrai applies default-deny at the hyperscaler's global policy level, then returns permissions based on historical access patterns or human approvals via Slack/Teams, keeping agents least-privileged while removing ticket overhead.

What security risks exist beyond hyperscaler agent permissions?

Developers using Claude Code connected to MCP servers locally can invoke any permissions the developer has; agents can perform unexpected actions like creating VPCs or modifying security groups, requiring human-in-the-loop approval workflows.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

11 / 20

The episode contains a mix of valuable technical content on agent permissions and identity governance alongside significant filler. The Sandy Bird segment delivers concrete architectural insights (default deny models, permission routing, MCP servers), but the Identiverse interviews repeat overlapping themes (discovery, ownership, governance) without adding novel operational depth. Substantial time spent on fried chicken discussion, car preferences, and general platitudes ('no easy button', 'moving at machine speed') dilutes insight density.

What we discovered of course was you would look at someone's cloud and they would have 10,000, some of them way more than 10,000, 100,000 over privileged identities
we basically just default deny all of the privilege and give it back to the things that need it based on historical access or people making exceptions

Originality

10 / 20

The episode recycles familiar identity and access governance frameworks applied to a new domain (agents) rather than proposing genuinely novel approaches. The 'default deny' model and JML (Joiner/Mover/Leaver) analogy for agents are sensible but not original. Multiple guests rehash the same discovery-ownership-governance sequence without introducing counterintuitive or first-principles arguments about why agent security might require fundamentally different models.

you need agent inventory
every agent has to have a human owner

Guest Caliber

13 / 20

Sandy Bird brings credible founder-level experience (Q1 Labs/QRadar sold to IBM, now CTO at Sonrai) with hands-on product development perspective. However, the three Identiverse guests (Amir Ofek, Howard Ting, Ajay Gupta) are all CEOs/founders of relatively early-stage identity/security platforms launched to address AI governance - making them invested salespeople rather than operators who have solved agent security at scale in large enterprises. None demonstrate deep battle-scars from real-world agent deployments.

my history again was always in security analytics. Spent huge amounts of time just doing security analytics for years and years and years. Um, and IBM was a great bit, uh, of time for me
I started my career in identity 25, 26 years ago at RSA

Specificity & Evidence

9 / 20

The Sandy Bird segment provides concrete numbers (350,000 unique permissions across hyperscalers, 10,000-100,000 over-privileged identities per customer, 30-minute remediation lag) and specific technical details (MCP servers, S3 bucket vectors, VPC and security group rule examples). The Identiverse interviews are almost entirely abstract - discussion of 'discovery,' 'governance,' 'intent drift,' and 'runtime authorization' without named customer examples, metrics, timelines, or deployment specifics. No evidence of actual agents running in production or measurable outcomes.

between the three hyperscalers you're talking three 50,000 unique permissions now
you would look at someone's cloud and they would have 10,000, some of them way more than 10,000, 100,000 over privileged identities

Conversational Craft

8 / 20

Adrian Sanabria asks reasonable but mostly soft questions; there is minimal pushback or productive disagreement. The Sandy Bird interview allows the guest to deliver long monologues with few challenging follow-ups (e.g., no pressure on whether default-deny actually scales or costs). The Identiverse interviews are brief, promotional, and hosted by Mike Shima, who asks leading questions designed to elicit positive soundbites rather than stress-test claims. Notable absence of skepticism about vague concepts like 'intent drift' or feasibility of continuous runtime authorization at scale.

Yeah, no we definitely again there's no doubt. Even in cloud it's interesting
I think the challenge is there are a lot of fragmented solutions, a lot of tools

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker C25%
  • Speaker E20%
  • Speaker F15%
  • Speaker A14%
  • Speaker D13%
  • Speaker G9%
  • Speaker B4%

Most-used words

agents112agent80identity65security54human44back32access29different24cloud24today23trying22governance21data20intent19point18sure17

Episode notes

Interview with Sandy Bird, co-founder of Sonrai Security In this week's interview, we kick off the conversation with how Sonrai's expertise in securing cloud identity permissions had the company well placed to address the explosion of AI agents and the clear risks they represented. On the surface, this looks like a cloud/hyperscaler permissions challenge, but it isn't that simple. As agents like Claude Code, Codex, and Hermes are connected to enterprise cloud agents, the risk spreads outside VPCs and onto endpoints. Check out the episode to learn more about some of the most common risks Sandy finds and how Sonrai goes about addressing them. This segment is sponsored by Sonrai Security. Visit to learn more about them! Segment Resources AWS Bedrock agent permissions: what you need to lock down before you go live Making Enterprise AI Agents Accountable with Amir Ofek, CEO and Co-Founder of aizome Organizations looking to unlock the power of Enterprise AI Agents, and in a controlled and safe way at the speed of AI. Identity is at the heart of it. However, NHI Governance Is Not Enough for Enterprise AI Agents.

Full transcript

1h 18m

Transcribed and scored by The B2B Podcast Index.

Speaker A: This week, Sandy Bird from Sonre is with us to discuss locking down AI agent permissions. Then we've got a few interviews for you from Identiverse. So no topic, segment or news segment in this week's episode. First up is going to be an interview with Amir Ofek, CEO of azome. I think that's how it's pronounced. Next we've got Howard Ting, CEO of Opal Security. And finally, an interview with AJ Gupta, President and CEO of SDG Corporation and the Executive Chairman of TrueOps. All that and more in this episode of Enterprise Security Weekly. It's the show where we talk security vendors and aren't afraid to name names. It's Enterprise Security Weekly. Welcome to Enterprise Security Weekly and Happy National Fried Chicken Day. This is episode 466, which will be released on Monday, July 6, 2026. If you're in the United States, I hope you had a lovely extended weekend and stayed cool. I'm your host, Adrian Sanabria, and joining me is the warrior of words, the captain of content, Katie Teitler Sentuo. How you doing, Katie?

Speaker B: I am well. How are you, Adrian? And where in the world is Adrian Sanabria for our audience's sake?

Speaker A: Yeah, last week I think, uh, I did the podcast from a WeWork in Hamburg, Germany. And this week I'm in Bern, Switzerland. And this is my hotel. Hotel room. We just got in today. I didn't have time to go around, search the city for, for a. Ah, neat place to record from, but it is kind of a neat little hotel here. No air conditioning. You can tell. I've got the window open here. Uh, you might hear a breeze coming through. Hopefully you hear a breeze coming through. So I don't, I don't melt and die here. But um, but yeah, so Sandy, uh, mentioned Scotland earlier, uh, which is where fried chicken originated. Uh, somewhat surprisingly, yeah, to those of us from, from the U.S. um, but of course, uh, you know, there's nothing, no, no food item, uh, that Scotland can create, uh, that African American people in the US can't, uh, re. Season and reinvent and reimagine which is, uh, the version you're used to, uh, or a lot of people, uh, a lot of people's palette is maybe used to, was born here in the US south and then spread from there to Korea. And we've got Korean Fried chicken. We've got all these different versions of fried chicken.

Speaker B: Uh, so I can't remember the last time I had fried chicken, but now I really want it. So thank you for that I'm sure

Speaker A: that's the goal of National Fried Chicken Day. Whoever came up with that. Sometimes I look into who decides who tries to make these.

Speaker B: I'm pretty sure as well, there's a fried chicken lobby somewhere and they're just all ah, into us having fried chicken. Although in the US as well, we are recording this pre 4th of July. I imagine that also has something to do with it because what's easier than fried chicken to feed a lot of people? Yeah, grilled chicken maybe with hamburgers and hot dogs, I don't know.

Speaker A: Well, it's July 6th. It's a little late, um, if they're trying to get you to plan for uh, the Independence, uh, day with it. So yeah, no idea what goes into it. That's just, uh, that was the best of only a few international and national days on, on July 6th. All right, quick announcement, then we'll jump into the interview. Uh, security leaders, your vulnerability program is overloaded. Thousands of findings, limited resources, and no clear way to prioritize what actually matters to the business. Meanwhile, regulators and boards expect measurable risk reduction, not just scan results. Join the Vulnerability Management Virtual CyberSecurity Summit on July 29 to learn how leading organizations are shifting from volume to risk based prioritization and turning exposure into actionable strategy. Security Weekly listeners can register for free@securityweekly.com vulnmanagement using the promo code CSS26S W. All right, and with that, uh, this interview is sponsored by Sonre. Uh, today's topic is AI agent permissions and just securing AI agents in general. We're excited to have Sandy Bird, CTO and co founder at Sunray Security with us today. Welcome, Sandy.

Speaker C: Hey, thanks for having me. It's good to see everyone.

Speaker A: Yeah, good to see you too. I'm excited about the discussion here. Your bio did mention you're a car guy. Uh, so I've got a quick lightning round of, uh, choices for you. You got to choose one of two. Um, Mazda RX7 or Nissan 240.

Speaker C: Nissan 240.

Speaker A: BMW M M3 or Audi S4.

Speaker C: Ooh, toss up there. Go for the Audi for today.

Speaker A: Kuhntak or Testarossa? Oh,

Speaker C: I think I would own the Countach and drive the Testarossa.

Speaker A: There you go. Firebird or Mustang GT?

Speaker C: Mustang GT. Ford guy all the way.

Speaker A: Favorite F1 team.

Speaker C: Uh, look, a passion for Ferraris, you know, that's the thing.

Speaker A: All right, I think you got about three out of five, but, uh, uh, I'll let the listeners decide which three out of those five you got.

Speaker D: Correct?

Speaker C: Yeah, exactly. Like it's uh, cars are awesome. I, uh, years ago had, you know, whatever, lots of passion for car. Now I have whatever, old cars and they're just as fun to drive too.

Speaker A: So yeah, I am in the market for an E30. So I'm looking for some old cars to tinker, maybe daily drive.

Speaker C: Yeah, yeah, yep.

Speaker A: Before they get too expensive, right?

Speaker C: They've already gotten too expensive. If you're looking for an E30, that's too late.

Speaker A: Uh, um, all right, uh, so your background, uh, as a co founder of Q1 Labs, uh, which I was excited to hear. I was a customer back in the day. Makers uh, of the Qradar SIM product which sold to IBM in 2011. Huge, um, market, uh, in the 2000s and in the uh, 2010s, um, uh, also with your Sunri co founder. Uh, so you guys decided to uh, start another company together.

Speaker C: Yeah, look, we uh, again, my history again was always in security analytics. Spent huge amounts of time just doing security analytics for years and years and years. Um, and IBM was a great bit, uh, of time for me. I was there, had kind of the whole security research team, uh, there kind of working and it was so fun. We learned a lot about quantum safe encryption and crazy things like that, which you didn't. I didn't typically get to spend time in, so it was great to learn all that stuff. They had a large identity, um, set of products and services. And so I learned a lot about identity while I was there. And when we came out and started looking at cloud and saying, you know, these hyperscalers, aws, Azure, gcp, we kind of looked at the identity side of them and said this is really complicated compared to all other systems in the world. You know, I think between the three hyperscalers you're talking three 50,000 unique permissions now. It's crazy. Um, and so that was our goal and summary security. It was basically making sure we could get things to least privilege in these clouds. We learned some hard lessons. We built. It's kind of interesting when you have cloud, you almost have perfection. You have all the audit data, you have all the entitlements. You should be able to make them perfect. But what we discovered of course was

Speaker E: should be able to, should be able

Speaker C: to, um, you would look at someone's cloud and they would have 10,000, some of them way more than 10,000, 100,000 over privileged identities while you would assign the tickets out to the development teams. But let's pretend it takes 30 minutes to fix it and test it and promote it, you know, whatever it is, by the time it gets to prod, maybe you're in 30 minutes of elapsed time for a developer by the time they promoted it, multiply that by 10,000 or 100,000 and it's impossible, it can't be done. And so about two years ago we kind of said, look, this is great for large banks and consulting houses that have lots of people to do it, but for everybody else in the world this is impossible. We need to find a better way. And so we kind of flipped the model on its head. We basically said, look, let the developers do as they do, configure your cloud however you want, we don't care. Um, all of these hyperscalers have these really interesting global policies at the top where you can default deny things. And so we basically just default deny all of the privilege and give it back to the things that need it based on historical access or people making exceptions. And the whole interaction happens through Slack and teams where people work. And so they get the permissions back instantly when they need them. And uh, it keeps everybody at least privileged all the time. And so it was just a better way of doing it. Customers like it a lot better because they don't have 10,000 tickets to fix and uh, that side. And then of course, our new world AI agents have shown up, which we'll spend some time on today.

Speaker A: You're probably sick of the word agent, but here's the problem. Your dev team is handing every new agent in your cloud way more permissions than it needs. And when one goes rogue, you've got four minutes before your data's gone. You need a default deny button that doesn't break every workload. That's Sunree's cloud permissions. Firewall, Native IAM controls, not newfangled AI. Nonsense. Default deny on every agent and human identity automatically. Learn more@securityweekly.com Sonrai I do have to ask. I'm very curious. Spent ah, a lot of time talking to founders, uh, after Q1 Labs and the acquisition, spending some time at IBM. Um, I imagine there are things when you go to start your next company that you decide to do differently. And maybe it's because of lessons you learned or maybe it's just because the environment, uh, that you're starting a new company into, uh, is different. Uh, I think Sonre, you started in 2019, uh, anything interesting there that you learned that you did different With Sonre,

Speaker C: lots of things were done differently. You start your very first company you really don't know what you're doing. So that was Q1 Labs for me. And so probably did stuff in the early days where, you know, we didn't really have sales and marketing, so we did that wrong for a long time before we got it right. Um, you know, funding raising was more complicated and things like that. But what's interesting about this whole space is that everything changes with time. So if you rewind into the Q1 Labs world, even in whatever, 2008 and those eras, you know, you could still use, I'll call them inside sales, whatever you want to call it, Dial for dollars. But I don't know, Adrian, when was the last time you picked up your cell phone when a random number from some random place called you?

Speaker B: Right.

Speaker C: And so that doesn't work anymore, obviously. And so, you know, you have to reinvent things like that and how you do outreach and things. Um, and so as much as many things are different, there's also things that are the same too. You know, you still have to get product, market fit, and build all those things. So lots of lessons learned, you know. What's the one thing I don't know? I think this AI reinvention will be the biggest thing that changes how companies are built in the next five years, say. Um, and that's really a bigger change, I think, than even Q1 labs to the start of Sunray security. What AI does is going to be very drastic, and I don't quite have it nailed yet. I'm still trying to figure it out myself.

Speaker A: Well, I mean, to have it nailed, we'd have to know what it's going to look like a year from now. And I'm not sure any of us actually do. Right.

Speaker C: I don't think we do. I don't think we do.

Speaker A: Yeah, we've been, uh. I don't know when the surprises stop, but, uh. But there's still the occasional surprise around the corner every. Every six months or so. Yeah. Um, yeah. So when we saw. When you saw Generative AI uh, evolve from chatbots to agents, was, uh, it immediately clear that, uh, Sun Re would be well positioned, uh, to help people with that?

Speaker C: Again, I have two parallel paths. So I have the paths that my customers are on where they're also building this stuff and using it. And then I have Sunray Security building AI chatbots to agents as well. And so there's two kind of parallel paths here. And I would say they've all happened kind of over the last 24 months. In reality, um, if you look at the customer path. This became very relevant very quickly when kind of the MCP servers started showing up. So what happened? You of course, had humans directing some set of agents that were connecting to these MCP servers doing things. And the MCP servers were backed by sometimes a unique identity or sometimes the human's identity being passed through and for years. Again, m back to our cloud problem. Everything is over privileged. So all of the humans had too many rights, of course, um, or could grant the agent too many rights that it didn't need. And if all of a sudden you ended up, we'll use the database example, right? It thinks it needs to migrate a schema and it deletes the database and creates a new one. And that was your production database. Bad days happen, right? And so there was that path that we were on where we said, look, we've been protecting these privileged permissions for years. It was usually for a nefarious actor coming in or an insider doing something terrible. Now it's just a bad, uh, intent, uh, from an AI agent. And so that makes perfect sense why we're well positioned for that. But there's another story on this too. Back to your. Things change every day. When we started building our own kind of, okay, we need to build a new interface inside of Sunray that's very much a Linux natural language interface where you could ask it to do tasks. When we started doing that, it was very much a chatbot. If you asked it the right things, you know, can you quarantine all of my unused identities? It kind of had a tool for that and it knew what to go do. But over time there were just massive limitations in doing that. You know, it wouldn't be able to do things where there were large result sets that came back. So if you asked it questions like, hey, you know, are we compliant with this NIST uh, framework? And go through all the results and collect all the evidence you need for it and put that in a big report for me or whatever. If you're feeding all of that data from here's the policy and here's all the data Sonray has, all into the context window of an LLM. It just didn't work. And so you ended up having to expand that out to multiple agents with multiple jobs and tools and things like that. Um, and it had to be able to write code so that it could write the code to actually generate the reports and things. And so that's been a pretty unique experience. When you look at the permissions under all of that, though, you now have a Scenario where it's touching, you know, privileged data in some ways. And so identity became this unbelievable core in this whole thing where you had to make sure that the identity that was doing the work and the agent only could see the right sets of data at the other end. So it could never have some, you know, cross user, um, bleed between them. And so we spent a huge amount of time just locking down our own permissions inside of these cloud platforms to make that happen.

Speaker A: So we've seen some. I, uh, have to ask this, given how much it's going on right now. My partner just the other day was complaining about her lovable subscription going from 20 bucks a month to 50 bucks a month with no warning. Um, so with Microsoft Enterprise is a little bit different than the. We should clarify what kind of agents we're talking about. We're not talking about OpenClaw and Hermes and things like that here, right? We're talking about, um, uh, Hyperscaler agents, Bedrock, Vertex AI, uh, Azure AI Foundry, stuff like that. Right?

Speaker C: There's yes and no. So there's no doubt that if you're building in, you know, bedrock, we'll use the example of bedrock because it's easy. Those agents themselves end up with permissions into the hyperscalers. Again, quite easy to do. Simplest one, you want to put your documentation in it, so you put it in an S3 bucket and you get it to kind of vectorize over top of it with Bedrock. Um, and so that's a, that's a permission inside of, of the Hyperscaler. But that's actually not the only thing you have to worry about. So you have a, uh, developer using CLAUDE code and they connect to the Hyperscaler's MCP server. Now that CLAUDE code sitting on your desktop, doing stuff can be interacting with that and causing. It can use any permission, it doesn't matter, whatever, whatever you happen to have, it uses. Um, and so we end up identifying those and hopefully if it does something wrong because it's privileged and it's not needed, it gets interrupted. And then we always show this great little demo where, you know, basically it goes and it can list buckets and it could do all the things. But if all of a sudden the agent goes and tries to do something like create a new VPC or change the security group rules, you get a human in the loop scenario where it reaches out to the team in Slack and says, this agent just tried to change security group rules. Do you want that to happen? And if you hit approve, it allows it to do it. But you may want to question that if you really want your agent doing that or not.

Speaker A: So. Yeah, yeah. So the, the in the, I needed that setup to, to then ask the question about the, the pricing here. How we've seen the pricing change quite a bit. Uh, we've seen both Apple and Microsoft pushing towards the use of, of local models. So I don't think it's uh, um, in isolation. Right. Like uh, there's a lot of talk about having small language models that reason and plan and then you know, some jobs, you really do need some of these larger foundation models to be able to uh, get that kind of job done. You know, like you were saying with context windows and things like that. You know, we now have models that can have huge context windows, uh, or you know, break things down behind the scenes without you having to specify any of that. Um, how do you think pricing is going to impact uh, how people use these agents and uh, how they need to secure them.

Speaker C: Yeah, look again, I'll probably be wrong in any predictions I make, but there's kind of two scenarios, right? One is there's no doubt that there will be for some jobs a much cheaper agent rather that runs on your device or it's just a cheaper agent that runs through some provider. There's got to be a cheaper agent to make simple decisions for sure. Um, there's no reason that we need these massive agents to do something that's simple. But then when you're doing something that's really high fidelity work, you know, you're trying to build something net new that's never been built before, whatever it is, you're going to want to spend the money on that. And so, you know, there's been a couple solutions today. You know, you have all these things, these routers that can kind of flip between models. You can codify it yourself as you do that with multiple agents. Um, there's lots of different ways to do that. You know, I think we all, some ways wish that it's a race to the bottom for price. Um, you know that's probably good for all of us if that's the case. Um, but with such a limited number of these foundation model companies, I don't know that that's true and certainly not with the amount of power that they're consuming. So anyway, I will be wrong in my prediction. I believe what will happen is there will be much smaller, lighter models that will be super cheap to run hopefully on your endpoint, as you see from Microsoft and Apple. And that will do a lot of the Lifting. And then when you need something that's very sophisticated, it will offload that and you'll pay the, pay the price for those tokens at a, At a higher rate. But I'll probably be wrong.

Speaker B: But where is the tipping point? Because right now, like Adrian mentioned his partner and seeing her bill go, um, I. I'm dealing with the same thing, right? Like I do consulting and I work for several companies and some of them give me access to their internal LLMs. Some of them, it's on me to do that. And so I'm really judicious about what I use and when. For instance, I was using Lovable this morning and it pretty much burned all my credits by 9am M. But I need it, right? So I'm going to use it. And especially if I were a full time employee somewhere, I just go to my organization and be like, I need this. And then if they say, all right, your m. Monthly allocation or whatever for, for um, reimbursement is up, I'd probably just suck it up and say, all right, I'll pay the 20 extra dollars. So with that in mind, because we've all become dependent. You mentioned mobile phones before.

Speaker F: Um,

Speaker B: 20 years ago. I would never imagine using it in the way I use it today. So where's the breaking point? Where do we say, I'm not doing this anymore? This is insane. We know the limitations of AI and LLMs. We know that they're problematic for a lot of reasons. And yet you can't apply for a job, much less be in a job. Without answering, how are you using AI and LLMs in your daily workflow? So where. I mean, I know I'm asking you to look in your crystal ball again, but what is the breaking point? And, uh, when do we reach it? When do we say, oh, you know, enough is enough, or do we ever get there? Or do we just. I mean, it's kind of like cars at the beginning. Again, 20 years ago, I wouldn't imagine having to have paid for a car what I paid for a car last time I got one, but here I am, because what's my other choice? I don't live in an area where public transportation is that great.

Speaker C: You might not wish your car to have a carburetor anymore. I may enjoy it, but you probably wouldn't. Yeah, on a cold winter morning or something.

Speaker B: Uh, I. I lease. So I don't have to deal with any of that garbage.

Speaker E: I mean, it's.

Speaker C: You're releasing your LLMs as well? I believe the I. Again, where's the breaking point. The breaking point becomes when people, you know, gets back to the scenario where I can actually do the research myself for cheaper than the LLM does, then the reality is you're going to go back to doing it yourself. But that may actually, you know, we would assume that that won't happen. The price of these things will come down over time. Um, and again there's, there's ways to token maximize. You know, like I say, using a router, if you're making a simple decision, you don't need this very expensive model. And so there will be this cheaper models. And I think, you know, I don't know what's a breaking point. I think it will naturally, you know, adjust itself to wherever it needs to be. Um, you know, if it's, there are definitely. Again I always use this joke in the office. You know, we, the new image models would come out and we always had this thing where it's like okay, I want to see a dog going down a water wearing sunglasses. And we would do that over and

Speaker F: over and over again.

Speaker C: Well the reality is would I actually pay the power price for doing that in any normal. No, who cares? I don't need a picture of that. It makes no sense at all. But it was a good test over time. Right. And so when these things become a real something you're using for work, it, you know you're going to pay because again it's cheaper than, than you the time that you would do it and accelerate you getting to market faster and all those things you're going to pay. Um, but again if you just want a picture of a dog going down a water slide wearing sunglasses, whatever, use a cheaper model for that.

Speaker A: So if I could uh, maybe reframe that question a little bit and I promise we'll leave the pricing questions behind and uh, move on. But um, at one point, uh, with cloud security, uh, we did see concerns pop up uh, about the cost of cloud. Right. Like things got out of control. You know, the people were launching stuff and forgetting that they had done it, you know, and, and you know, getting the bill later. Right. You know, after, after something had kind of run away. Uh, and we actually saw some crossover between like cloud security, posture management. Uh, we didn't call it posture management. I, I forget what we even called it back then. Uh, but we saw those and the pricing optimization, uh, function, we, we actually saw some companies doing both security and the, the cost optimization pieces. Uh, do you see that potentially happening here, uh, as well? Because it seems like we're right at that point right now where we need something out there catching these runaway uh, and they have a security implementation implications uh as well. Right. You know, anything that you set up to quickly test something out forgot about you probably didn't secure very well. Right. And if it's running away, spending the company's money, uh, it's probably insecure.

Speaker C: Yeah, no we definitely again there's no doubt. Even in cloud it's interesting. One of our features in our product is we have these things called zombies. So the things that get left over that no one's using anymore and uh, you know there's this really nice little cleanup for them that we, we do which allows you to bring them back later. Exactly. Configured in case you uh, need them back. But generally speaking we just leave them quarantined so they're not in use anymore. And you know, if you even rewound six months ago, most of our customers would have had no AI based zombies. They just didn't exist in their cloud because it was also new. But if you look at the same customers today, they all have them creeping in. And we know if you've been in cloud for five years, the non human identities in your cloud, 50% of them are unused and it's across all customers. It's just a statistic that happens. Um, and AI will have the same scenario. So you'll have a lot of those leftover mess kind of sitting there. Um, and so does cost and security, uh, combine. There's no doubt that there's some. If you're going to do this token router thing where you're going to route it to different models, that's a control point that you can use. And so by putting stuff in that control point, um, for sure but I'm not sure that all of the security ends up there. Right. Um, the token router probably doesn't need the same level of security to understand every permission and every tool that things are called uh, or can be called. And so there's probably still a specialization on both sides um, because in some ways they are a different purpose that they're doing it. So you still don't see that many cloud cost vendors and cloud security vendors completely combined. They both may have overlapping use cases but there's always specialization and I think there will be in this case too.

Speaker A: Okay, okay. Um, and I do wonder uh, if this is going to be another uh, S3 bucket age. Like I, I feel like it took a decade uh, for people to learn to stop leaving S3 buckets. We, we still see it today. Right. Like we still see breaches where the entire breach is someone left an S3 bucket with sensitive data open. I, I wonder uh, if misconfigured uh, AI agents is going to have that longevity, uh, as well or if like everything else in this market it's, it's going to blow by in a tenth of the speed that uh, of every other trend that we've seen, uh, in the market here. Uh, but yeah, your thoughts on that and just also, you know, maybe walking us through a bit like, like the advice you would give to somebody, you know, just starting out, trying to tackle this problem. Yeah. As we prepare to wrap up, there's

Speaker C: um, you know, if you look at any of the cloud providers, they've all released this platform to build agents on very quickly. They didn't even call them agents when they started, but whatever, they had these AI services how you could leverage these LLMs. And so in every case and in every cloud there have been security issues with how the cloud provider deployed this initially. Um, and some of them were simple things. AWS started using long lived access keys. Again, like why did we do that? You know, AWS had fixed that problem for years and then all of a sudden they released some AI stuff and because it was the only way to do something, they put them back in. And then during that they discovered that some of the global policies in AWS didn't apply to some of the, the uh, long lived access keys, but it did the short lived ones. Like why is there a different set of rules? Okay, well, because we rushed it out. Right. And so, and now you have the scenario wherein, you know, there's been several pieces of research. You can go read one on our website. Beyond Trust has one, somebody else has one where the actual small VMs that these things are highly susceptible for being controlled by, you know, whatever's putting in the prompt. Um, so if you have one of these sitting on a public website somewhere, it's highly likely you could get something malicious to run inside of that, that agent core. And so all of these things will get fixed over time for sure. But again, if you're using some of these older configurations, maybe they never get cleaned up. And so you have these old agents sitting around that are unused that have these things. So first of all you need agent inventory. You need to know what is an AI agent and what's not and what's there. You need to know is it still in use or it's not who its owner is of. So you need to go through the process of actually defining who the owner of these different agents are.

Speaker A: Asset management, uh, for agents, basically.

Speaker C: And then for us, we always focus on the permission side. What permissions does it have and what can it access and is it actually needed? And if it's not, bring it down to least privilege and put human back in the loop. If you need to have it do sensitive things, make sure that a human checks that before it goes and does it, especially in production environments. So again, I think, you know, you're going to have to give these things permissions. It's how they work. That's the area to focus on. If you can get the permissions. Right, and keep it to the minimal that it needs. And, uh, you know, if you can get an inventory, you know, who owns it, then you can get rid of it later.

Speaker A: And kind of the, um, to wrap up the conversation, last, last question here, um, what are maybe some of the most common or, and, or the most surprising mistakes you see people making with these?

Speaker C: There is a lot of.

Speaker A: Or do we not have time for that?

Speaker E: We don't have that time, but we

Speaker C: have a couple of good ones. One is there's no doubt that the way. And again, we won't pick on aws, but we use AWS as the example. So they have these great MCP servers you can use. However, you probably shouldn't allow them in production. I really don't believe that's a good use case. So you should turn them off in those areas. That's key. Um, you definitely. We have seen some atrocious permissioning of these things, um, where you have a shared agent that's used by a huge number of people that has privileged access into these environments, the hyperscaler environments or data environments, the same thing. Um, that's clearly not supposed to be that way. And so you just end up with horrendous identity and permissioning configurations on these agents. It's terrible. And so it needs to be locked down.

Speaker A: Got it, got it. Well, uh, Sandy, thank you so much for joining us today. This was delightful.

Speaker C: Uh, thank you, guys. It's great to have you.

Speaker A: All right, make sure you visit securityweekly.comsonri to learn more. And that is spelled S O N R A AI. And stay tuned. When we come back, we've got three identiverse interviews for you. And Katie, thank you for joining me. Since we won't be coming back, uh, after this break.

Speaker B: We will not be coming back after this break. Maybe I'll go get some fried chicken.

Speaker A: But we will be coming back next week. Uh, so we will see you then. Thank you. Enterprises are adopting AI tools such as AI agents, MCPs, LLMs and skills at ah, 10x speed. These agents have access to business critical workflows, applications, tools and sensitive data. But access without governance and control isn't acceleration, it's exposure and critical risk. The question isn't whether to build or use AI agents. It's whether security teams can govern the AI environment. Akto is the leading AI agent security platform, helping enterprises solve this gap with continuous agent discovery, automated AI red teaming, agentic guardrails, AI security posture management and runtime protection. Octo helps enterprises secure AI adoption across the entire AI lifecycle. Learn more@securityweekly.com October welcome to Identiverse 2026.

Speaker E: I'm Mike Shima. Joining me today is Amir Ofak, CEO and co founder at Azone. Amir, thanks for joining us.

Speaker D: Thanks for having me.

Speaker E: So I want to start off, there's more important things to talk about, but Azoem, tell me a little bit about this.

Speaker D: Yeah, everybody asks us about our name. So Aizom actually comes from the Japanese culture. So you know, in Japan there's like top arts like pottery, calligraphy, knife making. One of them is weaving and the process of dyeing the indigo color that a lot of Americans refer to as Japan. Japanese blue, um, is actually called aizome, or in Japanese pronounced aizome, uh, which would be hard for others to pronounce. So azom is really the process of dyeing the indigo color. It's a very, very laborious process. Uh, there's 48 different shades of indigo and you need to keep doing it. And it's all kind of a living organism of no chemicals, of course. It's all natural with a lot of enzymes and sake and everything involved. And then at the end of the day what you get is this kind of shades of indigo, um, which is in Japanese culture is used for the where for the samurai as an auspicious protection on their clothes. And that's kind of what we are doing. We are all about kind of weaving the process of AI agent security so that at the end of the day it can provide security, um, for those crazy samurais, which are the AI agents, um, that are running around. They can do a lot of harm. But if they're confined and they're kind of in order, they actually bring a lot of good to society.

Speaker E: And the metaphor works especially for the laborious process. Decades and decades of cybersecurity is struggling to keep up with what's Changing in technology. And the other thing that you've done this week is you're launching, you're very, very new. Tell us a little bit about this.

Speaker D: So we're very excited to be here in Identiverse and launching the Azon platform. Um, we are an AI native company, so we move at the speed of AI. I keep telling everyone it's not a question of how many employees we have, it's how many agents that are working with us. And we have just deployed our Azon platform. The Azon platform is all about making AI agents accountable. Going back to this samurai analogy, making sure that those samurais are in order that they're actually bringing value to the business. And where we focus on is really enterprise AI agents. So enterprise AI agents are type of agents that are driving business logic as opposed to let's say coding agents or kind of bots, et cetera. And those I believe are the future of the agentic world. Agents that will drive HR process processes, finance processes, uh, warehousing processes, all of those kind of enterprise grade workflows and activities. And what we want to make sure is that organizations can enable them so can drive unlock the value of agents to the greatest extent possible, but also have a layer of safety which in our mind needs to be an identity first and intent based, uh, approach.

Speaker E: Yeah, and the beginning and end of that got my attention quite a bit because the safety is important and especially the business logic because coming from my perspective has been geared more towards let's say applications and the coding agents. Writing the code and there's still safety is important, but ostensibly you can look at the code before it goes to production, say let's not let this out, but an agent in charge of business logic making the decision, lots of bad things can go wrong there that are consequential and cost the company money. That sounds too scary. Tell me a little bit more, how are CISOs especially reacting to this?

Speaker D: So yeah, so enterprise agents are far more powerful to the business, they bring business impact, but uh, they're far more in my mind dangerous than a coding agent. So you said rightfully like a coding agent, the developer owns it. The developer is a savvy person that you would wish that understand how the agent is built, what it's supposed to do. To some good extent. When it comes to enterprise AI agents, we believe the world is going to a place where every employee within the company will be an agent creator. Now with Claude Cohort with a kind of concept like Nemo Claw or Microsoft, just kind of launched within their um, a365 agent.365, their version of ah, Open Claw version. Every person will be able to build his or her own agent and then you drive to areas where people are not always tech savvy, they don't know always what the agent can potentially be doing, et cetera. So it's becoming a much more dangerous from that perspective aspect. And also those agents are touching really core enterprise systems like your HR system, your ERP, your CRM, your ledger account and so on. So CISOs are actually very much in kind of a mind boggling situation of how do we on one hand give to the pressure of the business to allow those agents to actually be deployed because the business needs them and on the other hand how we keep control. Our philosophy is that you need to treat them like other employees in the company. So yeah, they're non human but they are different type of non human because they could be also superhuman. They actually carrying a lot of capabilities that the human person cannot do at much faster speed and so on. And you need to give them the identity same way as you give an identity to a human being joining the company. So the whole kind of JML approach that's applicable for humans in my mind also is applicable very much to agents. But it needs to be adopted and

Speaker E: there's got to be some nuances in there. The reason I'm hesitating there is that identity. You mentioned accountability, very important at the beginning. But what you were just describing too sounds like it's not necessarily a one to one mapping of one human employee creates one agent. And maybe my employee access isn't the same as the access given to the agent. That sounds kind of hard to swallow from an accountability perspective as well. How are you seeing that unwind, how are you trying to corral that and contain that?

Speaker D: So yeah, you touch exactly that. The point like agents do not behave like on a um, one to one basis. So the moment there is let's uh, say uh, an HR agent or a finance agent, there's multiple people that can actually use that agent. The real combination of the user with the agent with the target system, that three layer combination, that's what builds the context of the identity that needs to be assigned to that agent. In that specific context of let's say person A gets agent versus person B gets that agent, the agent will not be able to expose the same information because each one of them has different permission and the agent gets like a different identity for that specific context. Okay, so that's how we look at it, yeah.

Speaker E: And it almost sounds like hybrid identity. It almost sounds like that's what's evolving here from machine to service to non human to hybrid.

Speaker D: It is really a hybrid identity. It's not a kind of proper human identity and it's definitely not what the industry calls today nhi, non human identity. Even though agents are non human. Um, because non human identities are more gearing towards machine, towards deterministic approach, they don't have this combination of user and agent like we spoke about. And of course with the human part it's much easier. They're very kind of assigned to a specific person with a specific role. And that's it. With agents, the combination first is really what matters, the context that the agent is running with. But even more so those hybrid identities, what they need to be um, addressed with is the intent player. And we can double down into that as well. But I think intent is really kind of the next level of what makes those identity agents much, much, much different.

Speaker E: And that's where, yeah, let's definitely jump onto that. Because intent, I hear that. I think this is what the agent was supposed to do, or here is the access that it needed within the world of actions that we expected to take. But that still feels fuzzy. That still feels like I want to have some policy that I can say exactly, this should happen, this should never happen. You're smiling. Help me out here. This is worrisome.

Speaker D: So why intent is so important for agents, uh, is because agents change over time. So an agent that you build 8am in the morning, not necessarily is doing the same task. 8pm in the evening, 8am in the morning, you build an invoice reconciliation agent that is accessing your finance systems, your SAP, your ledger account and so on, driving invoices. 8:00pm all of a sudden that agent is trying to access your HR salary data within the company. That was not the intention of that agent. So you need to know about it, you need to know about before it accesses that data. Just the initial intent of the agent to try and get some permission for workday or for some HR system that already should trigger some kind of intent Drift alert. And the other aspect is that the intent can change very, very quickly over time. But how do you know the original intent? That actually is fairly easy with agents, unlike human beings, that the intent is in their brains. And I don't know of anyone that knows how to read minds yet.

Speaker E: It's not yet.

Speaker D: But with agents the intent is in the prompt. So you can actually read the prompt of the agent. I Would like to find all of the invoices that have not reconciled in the last 30 days and uh, ship it to my, uh, HR to M. My VA business workflow. Exactly. You can read into that prompt and understand what's the intent of the agent. So then you can monitor that and see that constantly the agent is doing things that are aligned with that original intent. And that's kind of the unique. Well, I'm trying to kind of explain it in a simple way, but the complexity is in the back. The complexity is really underlying the intent from the prompt and really constantly monitoring so that you can highlight any drifts early on.

Speaker E: And that's where my threat modeling spidey sense is starting to tingle. Uh, in the sense of reading the invoices. Just to riff on that as a good example, there's also the subtleties of the intent should. It should only be allowed to read invoices. Good. But you start to get into the granularity of it should only read invoices for this tenant or this user. It shouldn't give this user's data to this other user. Right. So how does that become a very predictable control that you can enforce? Does that still rely on the agents? What's the story there?

Speaker D: Yeah, so I think at the end of the day, it's the identity. Okay. Each agent is assigned. Like in the AZOM concept, each agent is assigned an identity. And you need to see that the identity still holds. Uh, for every action that the agent takes, the complexity is driven again, when the identity is not just the only element, but the intent couples with that. Okay, and the other aspect maybe that you alluded to is the fact that the agent can talk to another agent and start kind of a chain of events, um, that you were not thinking or call for a skill that was not the original kind of, uh, part of the development of the agent. So all of those chain of events that agents can trigger, you need to make sure that the identity somehow cascades from the original invoker of the agent that was invoking that chain. Exactly. All the way down the chain. And that of course, something that is very, very different from a human identity or, or from a machine identity.

Speaker E: And then it absolutely is different. But ultimately it's still humans trying to reason through and understand that. So what does it look like that. Well, I'm going to wave a magic wand because I don't think any organization has quote unquote solved agent security or just security.

Speaker D: I haven't seen anyone.

Speaker A: No.

Speaker E: But if they were to get close, if they were at the further, more mature end of that scale. What would, what should or uh, what could that look like?

Speaker D: So I believe organizations at the end of the day that want to address AI agent security to the furthest extent, they need to have a few layers. First layer is discovery. You need to know what you're up against, otherwise you're in the dark.

Speaker E: Common team.

Speaker D: So like putting the lights on is this discovery piece of uh, finding all of the AI agents that exist in the organization. That's the first piece. Piece. The moment you did that, you need to build an inventory of all of your AI agents. You need to have a repository of all of the AI agents to know what it is you're now going to constantly monitor. And by the way, that discovery is not a one off, it's a continuous uh, aspect. So you don't build AI agents and don't deal with that, it's going to be ever evolving. The second piece is this applying identity concept. So once you have that repository of AI agents, each AI agent that you care about needs to get an identity. Same as birthright rules for employees that are joining the company. Those are new employees that are joining your workforce and that's how you need to treat them. Third aspect is again the analogy to humans is the M M for the jml. Okay, the mover. That's kind of where the intent comes into place. Uh, because those agents, they change behavior, they change activity, they change intent very, very quickly and continuously. And that's what you need to monitor on that end M part. And the last piece, you need to make sure that when those agents are no longer relevant or nobody owns them, you need to assign the ownership to somebody else or deprecate them. And that's kind of the L part that is associated with humans.

Speaker E: Yeah. So yeah, that, that offboarding is there's technical debt and then there's how did this account still have access? Exactly. And that's a classic problem that would be lovely not to reproduce in the world of NHI or hybrid or whatever the agents are going to be. All right, well Amir, we're in Vegas so I'm going to give you some time to go find. You might be able to find a mentalist or a mind reader. We'll see.

Speaker D: Maybe.

Speaker E: But until then, thank you for joining us. Thank you very much.

Speaker D: I love the conversation.

Speaker E: To learn more about izone, please visit securityweekly.comizomidv for all of our Identiverse 2026 coverage from Cyber Risk alliance, visit securityweekly.comidv Stick around because we will be back after the break.

Speaker A: Zero trust is clearly the future as threats get faster, quieter and harder to detect. But implementing it shouldn't disrupt the business. Threat Locker enforces default deny at execution in a way that remains enterprise ready, scalable and operationally clean. Unknown software is stopped cold, Trusted apps stay contained and drift is locked down across the environment. It's Zero Trust that works in real enterprises and prepares you for the threats ahead. See why CISOs are adopting it@securityweekly.com ThreatLocker

Speaker E: welcome to Identiverse 2026. I'm Mike Shima. Joining me today is Howard Tang, CEO at Opal Security. Howard, thanks for being here.

Speaker F: Great to be with you, Mike.

Speaker E: So I appreciate you being here to help me kick things off for the day. This is going to be our first interview and one of the things I'd love to get your sense of is identiverse and some of the themes, especially AI and agents, that those, those words are going to show up all over the place, get repeated. But what does that actually mean in terms of identity security? How are they actually changing the way people are approaching governance or just security securing them in general?

Speaker F: Yeah, this conference feels like an AI conference just like RSA did.

Speaker E: Yeah.

Speaker B: Okay.

Speaker F: Uh, everything's about AI. I think at RSA there was a lot of focus on the threats that AI could pose, uh, on the uh, offensive side, uh, by attackers and what the defenders can do to leverage AI Here. I think a lot of the conversations about how are we going to govern all these new identities that we have to both register, discover, manage provisions, uh, and then govern, uh, and uh, we're right in the middle of that conversation. You know, we're an access governance platform that is unifying, uh, both human and non human identities, trying uh, to create a single control plane for uh, all identities for enterprises. And uh, I think the conversation's really advancing rapidly as far as how we should attack this problem and how we should even think about the problem.

Speaker E: Yeah, I think one thing, I definitely want to get to the defender side of using AI. But even just we've had machine identities, we've had service identities for a while. In my mind it almost sounds like it should just be AI or agents is a synonym. That's just another identity. But clearly there's a different concern and feels like it's one of volume but one of complexity of what the agents do. How do you see the challenge? What's different when you're approaching the governance of these AI agents?

Speaker F: Yeah, I think there are a number of different models being proposed right now for how agentic identities should be governed. There's some people that think that we should just treat them like service accounts. Uh, and that's a starting point because we've had some history with service accounts and how we should manage those. But there's so many flavors of agents that we have to account for and I don't think service accounts accounts for all of them.

Speaker D: Right.

Speaker F: There are a number of accounts, uh, agentic identities that are acting on behalf of humans. So we've heard of this term OBO on behalf of behalf of Y. Uh, and so in that model you really have to understand who's the human that provoked it or prompted the agent to act and what's the accountability chain in that scenario. Then there are more and more autonomous agents that I think are going to arrive. Uh, and if you just think back on autonomous long running agents if you will, in our consumer lives, I think the enterprise autonomous agents are going to follow a similar path. Like think about a self driving car, which is probably the most autonomous agent we have in the consumer world. There's some people that think that enterprise agents should just be uh, uh, approved. All actions should be approved by human. But just imagine if you could translate that same concept to autonomous vehicle. Right. My vehicle, I have a Tesla, it's you know, speeding up, uh, braking, turning left, you know, moving, you know, shifting itself, uh, steering the wheel all the time. And there's no way that I could be there approving every single, should I change lane now?

Speaker E: Do you want me to merge this exit? This exit, none of that stuff.

Speaker F: It would, it would render that product unusable. Yeah, and I think the similar thing is going to happen to enterprise agents where we can't have a human in the loop many times when we're trying to govern what these agents are able to do. Especially as we think about more and more of these autonomous agents. I think right now with coding agents, which is the most commonly deployed type of agent in the enterprise, um, having a, ah, user in loop, reviewing the pull request that these agents are churning out I think makes a lot of sense. But when we deploy other types of agents, I think this model breaks down. So we have to come up with new models of governance.

Speaker E: And that's what scares me. Because an agent coding, that's a point in time. But it's not that creating some code until it gets deployed, that's not a potential disaster happening. You have that human in the loop as you said, they can be Looking at this and, oh, probably we shouldn't allow this code to go out, but there's customer support agents, there's a lot of things that agents can take. As you were seeing these autonomous agents throughout the system. How are CISOs even looking at that? Because, okay, we can say least privilege, but is that going to work? Because we don't exactly know what the agent's really supposed to do. We can't, as you, I think rightly pointed out, can't ask the human to approve everything. That's got to be extra complexity about what these agents are doing. How do you even approach it?

Speaker C: Yeah.

Speaker F: So in the human world, I think we've centered a lot of our identity controls on what I would call pre and post access, uh, or pre and post action. So what I mean by that is we use IGA tools, identity governance administration tools to provision the access, you know, set the entitlements, and then we do an audit after the fact. After these eight, uh, humans have done their work, we check to see if the permissions and entitlements are still legitimate. That's usually known as a user Access Review or uar. Um, we have some exciting announcements in both of these areas I'd love to talk about. But what most identity products don't do for humans today is sit in the middle of this workflow in the runtime, checking every time that a user trying to do something, should this be allowed to happen? That's happening in the target system today, in the applications, natively in the applications. Applications. I think with, uh, agents, I think we're going to have to do a lot more in the runtime. And we heard this in the keynote yesterday and I think there's a lot of talk about what does that runtime authorization layer look like. It needs to be continuous, it needs to be contextualized, it needs to be checking every action that the agents are trying to take. So I think it's going to create um, a new uh, uh, control, uh, point that we need because we need this control point to be in runtime, reviewing every single action that the agent's trying to take and then making a decision about whether we're going to allow it or not. Take into account all of the context and analyzing the risk. Yeah.

Speaker E: And it feels like, hopefully it feels daunting, but it feels, I'm going to guess that a CISO would rather have, let's prevent this bad thing from happening. Let's review at the moment rather than have my incident response team go and figure out, oh, this bad Thing this action was already taken. Should it even happen the first part? Well, you mentioned there continuous happening in a runtime. You're going to burn some people out if you're doing that. So this is where I want to bring in that aspect. Is AI helping with this problem as well? And if so, how?

Speaker F: I think it has to be AI managing AI. Uh, just think about access, uh requests today. If you do a just in time access request that many of our customers do, on average they're waiting probably 15 minutes, sometimes hours for that request to be approved. And you can imagine if that's rough if we have to have that kind of wait time for agent requests, it's going to break the whole workflow because a lot of these agents have sub agents that they need to prompt and if you factor that in, the whole system design is going to come under pressure. So I don't think we can have humans in the loop approving every agent request. Especially since agents are going to be running at odd hours of the day, 3:00am for example, uh, uh, you know, some agent may be doing some SRE DevOps thing to you know, update the production systems. Uh, there's no human awake at the time to approve that. So I do think we're going to need AI to manage AI. And I think one of the things that a lot of customers are thinking is they're using AI to shrink the funnel. And what I mean by that is most decisions are pretty straightforward. Either it's a clear allow or clear deny. Uh, just like most UARs are pretty clear. Like these people still need access and these people don't. And I think what AI can do is really shrink the funnel of what humans actually need to make decisions on and what to review. And 98, 99%, maybe even more of the, of the requests and the reviews can be done with AI and, and I think the AI will continue to get smarter and maybe push that number higher and higher. Maybe it's like you know, four nines, five nines of the volume can be shrunk with AI over time as the AI gets better, gets more intelligent, understands the business better and better and has that self learning loop that I think all the AI products are being built with.

Speaker E: And I think that's what you're doing right with you have AI assisted access review. To say this is rather than have the human in the loop at every single point it sounds like have the AI say well by the way, this one here's an outlier, here is something behavioral throw that, that's probably Another word we're going to hear a lot today.

Speaker F: So Opal announced yesterday at the conference, uh, AI Guided Access reviews. And uh, we believe this is a first in the industry. And what's interesting is that most of our customers that use us for access reviews, the number one requested feature is bulk approvals, meaning they are not even taking the time to review each individual access entitlement and to decide yes or no. They just want to do a bulk. It's like, I trust all my employees on my team. I hired all these people, they're trustworthy. I just want to improve all this. And so it becomes a performative exercise a lot of times in most enterprises today. Uh, but what AI can do is take that performative exercise and make it a real risk reduction exercise because we can then shrink the number of things that the humans actually review, but we shrink it to the right things. See, today someone does a bulk approval. They're approving some entitlements that probably need to get a second level of review or scrutiny, but they're doing it because they just want to get it off their plate. What AI can do is like, okay, take all of the uh, uh, basic, uh, decisions off their plate and just have them review the things that really matter, the things that require real human judgment and context.

Speaker E: Yeah, I was going to say it can be so boring to be like, this is something that this person does all the time. They need to do that. You're just going to bore someone to death. Think, yeah, we need that, we need that. You, you have that review for governance that doesn't go away, but embrace that human ingenuity. And I'm curious too, then all these approvals, these approvals that you're talking about are for humans and agents alike, right? I'm curious, what are the agents introducing into this in terms of complexity?

Speaker F: You know what's interesting is I think there are a couple different ways that this could grow. One way I think is that we start giving agents one time entitlements, meaning, uh, there is no need to do a review after the fact because the entitlement has been used or expired.

Speaker C: Right.

Speaker F: And so there is no standing entitlement to go review. Um, I think that's one way it could go. I think it's going to be a while before we get there. I do think that in the interim there will be a need to review the age of entitlements again, using AI to shrink that funnel of what requires the human review. And uh, I think there's also schools of thought that say, you know, a simple way to think about it, especially with the user, uh, prompt or delegated agents, is agents should always have the same or less privileges than their human master or their human owner. Yeah, uh, I think that works in a lot of contexts, but there's some contexts where that may not work. So there are a lot of different thoughts. None of this is settled. I think it's a pretty dynamic environment and uh, uh, this is a fun conversation to be part of.

Speaker E: Well, I'm curious How are CISOs reacting to this? Because I can imagine that, uh, I love what you were describing, that entitlement, because that means also if there's a prompt injection, if something goes bad, even if there's just a mistake, it's going to limit the consequences of that impact. Is that our CISOs, that's a story. But are CISOs seeing the actual story play out in real life? Are they still struggling that actually why did this agent have more permissions than the human owner did?

Speaker F: I think just like uh, most people, everyone's just drinking from the fire hose and they're just trying to get their arms around things. They're trying to take steps to start to reduce their risk. The CISOs I talk with, they're just trying to get foundational pieces in place. They're just trying to get some risk reduction because right now it's wild, wild west. There's very little control or visibility of it. And most CISOs tell me they're just trying to give the best visibility they can have. Like what are all the agents that are running, uh, who are prompting these agents? What are these agents doing? So they're just starting with discovery classification, registry, uh, these agents and I think governance or control of these agents is going to be the next phase and then the final phase will be that runtime, you know, fine grain control. So I think, I think we're going to go in phases but the first phase that everyone's just trying to get, get to today is just, just discovery

Speaker E: that I'm laughing because discovery, asset inventory, identity inventory, these are just such simple things that we've talked about for decades, right?

Speaker G: Yeah.

Speaker E: But we're still early days in that just now with agents. That's scary.

Speaker F: One of the things that brought me back into the identity world, I started my career in identity 25, 26 years ago at RSA.

Speaker A: Okay.

Speaker F: Uh, RSA security. And I did a bunch of identity stuff including startups. And then I left and did some other stuff uh, in the last 15 years. But I came back into identity because so many of these problems that we worked on 25 years ago are still unsolved. And for me, my last 10 years of my career, whatever is left, I want to go back to that unfinished business. So it's a very exciting dynamic time to be in identity, and it's the place to be.

Speaker E: We clearly could use a lot more solutions. I'm glad you came back. Let me squeeze in one last question here. Having these conversations with the ciso. They say we need to secure our agents. Okay. We talked about discovery. You mentioned that a lot. What's maybe the next thing that gives you confidence or that you would say would give them confidence that they're actually securing agents in a way that's going to help them?

Speaker F: You know, I think it comes down to analyzing what agents are doing relative to their manifest or intention. See, I think the more drift that we see of these agent behaviors and actions, uh, the more concern we should have, because agents are pretty doggone determined. They might be the most determined, you know, quote, unquote, employee, or in those tokens.

Speaker G: Yeah, you said.

Speaker F: Yeah. Uh, they want to achieve their goal. And so I think the more that we can understand the goals or the intentions of the agent through its manifest of some sort, uh, and then evaluate whether these agents are staying within their predetermined, uh, uh, guardrails and how often they drift outside of that, I think that's the next thing that we absolutely need to do. Uh, we have to have better tooling to have that visibility and analyze that risk, and that's not available yet in the market. Uh, there are lots of vendors that are starting to come up with solutions. We're going to be one of those providers, uh, as well. Uh, but there's nothing really mature yet in the market, and we should be seeing more solutions, uh, in the market in the next six months.

Speaker E: Well, I'll keep my fingers crossed and we can be optimistic that it does happen in six months. Howard, thanks for joining us.

Speaker F: Thanks, Mike. Thanks for having me.

Speaker E: To learn more about Opal Security, especially their announcement from yesterday, visit securityweekly.com opalidv for all of Identiverse 2026 covers from Cyber Risk Alliance. Check out securityweekly.com idv and stick around. We'll be right back after the break. Welcome to Identiverse 2026. I'm Mike Shima. Joining me today is Ajay Gupta, president and CEO at svg. Ajay, thanks for being here.

Speaker G: Thank you. Appreciate it, man.

Speaker E: So one of the things I'd, uh, love to get a chance to talk to you about is a little bit of, let's say, economics or just the value of platforms. Now that's pretty generic, but identity platforms have been around for several decades and even before we get into AI and agents, how do people continue to struggle or why do they continue to struggle to get the full value out of a solution that they buy when identity platforms are one of those solutions that pretty much everybody has, right?

Speaker G: Well, I mean identity platforms have been around for a long time. Um, and when they first started they were really around access, provisioning, authentication, compliance, so largely, in some cases even a back office administrative and governance platform. Uh, but the, the challenge is that identity platforms touch every aspect of the business and they impact every process. So unless organizations give it the sort of the full scope and attention that it deserves, uh, they never get implemented fully for them to realize the value. So part of it is that it's a complex problem to solve. Part of it is that the payback is not very obvious.

Speaker E: Uh, when it doesn't work, it's obvious.

Speaker G: It is obvious. You know, it was the old saying, right? Nobody thanks uh, the building when they flip the switch and the lights come on. But people do complain about it when the lights don't come on.

Speaker A: Yeah.

Speaker E: And now in these days, in addition to people complaining, we could get AI and agents complaining. Um, I'd be a little bit facetious, but to your point about the history, there's on prem platforms, right then cloud, that added complexity. AI and agents have some complexity to them, but they're obviously adding something to that. But how are they changing either the attacker side, the threats that we have to worry about, or just what that platform, how should that platform be wrangling? Are these just additional identities or are they something new and different?

Speaker G: Well, you're absolutely right. I mean it is on the one hand, AI is enabling the attackers to scale up their attacks, exploit vulnerabilities a lot faster. But on the other two sides, the way we look at it is AI for identity and identity for AI. So where identity platforms can leverage AI is to automate and actually solve a lot of the challenges of the old IAM platforms, which are largely dependent on manual processes. Um, had a lot of disconnected apps. So combining all of that, there's a lot of this poor visibility to identity data. Now AI can help transcend that. Um, but as businesses are deploying AI, that's creating additional challenges for the identity security team because these agents are acting on behalf of users in the business and they have access to sometimes Very sensitive, uh, corporate data. And they are executing processes or triggering workflows that do things that if they're not, um, audited or controlled or somebody's not held accountable for them, that can run amok. So identity for AI and AI for identity both have to work hand in hand.

Speaker E: Yeah, that run amok is a great phrase to use because that's one of the big worries, especially when you could have one employee, not just have one agent working on their behalf, could have a whole multitude of them. And I'm curious too, and there's a theme that comes to my mind. I'm, I'm well fed after lunch. I'm thinking of money right now. I'm going to jokingly say there's no like a per seat license for agents. It has to be crazy if you're thinking of a thousand agents and one employee. But the reason I bring that up is more of companies want to figure out how do they get the value of their platforms and how they spend the money, spend their budget on the right ways to control and audit to govern these things. I wanted to get your insight. Looking over the decades of how the industry is changing, are people getting smarter about spending or the solutions getting better about offering more efficient, being more efficient?

Speaker G: Well, I think the fundamental problem really hasn't changed. Businesses still want to move faster than technology or cybersecurity can sometimes keep up. Um, so the goal of cyber organizations is not to say no, it's figure out how to enable the business, uh, securely and safely. Um, so it's about deploying these solutions. So really when I sort of step back, the way I see it is it's a convergence of identity security, which is sort of core discipline, AI security, because now there are AI agents running around, uh, and then AI governance. How do you govern this entire platform? Um, and that is where organizations need to spend a lot of focus. And the challenge as I said, is still the same disconnected tools, uh, poor identity, uh, visibility to identity data, a lot of manual processes. So the solution sometimes is not just buying another identity tool. So coming back to your point about economics, it's not just spending more money buying more product. Sometimes that may be the right answer, uh, given where the particular organization is. But it's really about connecting all of these disparate systems and get a single pane of glass view of what's actually going on, what's happening within the organization and how they can address that risk.

Speaker E: And that's gotta lead exactly into governance that you mentioned. You need to know we know who Our employees are because they got hired. HR has records of them, agents.

Speaker A: True.

Speaker E: And sometimes they may not. They may be coming from North Korea or um, these other things.

Speaker G: They may not be who this claim they are.

Speaker E: Yeah, exactly. But at least that's uh, I'll say at least that's constrained to a degree, you know, that the, in the physical space of where all these humans are, they're getting hired agents is definitely different. And agents also can't necessarily say at least to be trusted. Hey, I need access to this and this and this. Just give it to me. There's a little bit of the accountability. So I'm curious, how do you actually add governance to agents? Who is that person that should be accountable for.

Speaker G: So it is so every agent has to have a human owner number one. Um, and that human ultimately is responsible for the actions of the agents that are assigned to that human that they own, essentially. And so, uh, the ability to audit, the ability to hold an agent accountable, ergo the human accountable for the agent's actions is very critical.

Speaker E: Yeah, and that's got to lead into, as I mentioned too, you know, malicious insiders being hired. But also agents could be acting as malicious insiders through prompt injections, downloads, so many downloads of malicious skill. But I mentioned those because I think they have corollaries to malicious insiders from a decade ago or just downloading malware. And what I'm getting at, as you see, has governance changed that much? Meaning if someone 10 years ago was dealing with governance in the cloud and shadow cloud, things like that, what are the differences that they, that they need to understand about AI or what's a mistake that they should avoid making when they're like, what is this AI that we have to deal with?

Speaker G: Well, I mean the first thing is that agents are moving at machine speed, right? So in say a decade ago or 15 years ago, uh, the time between detecting a vulnerability and the exploitation of the vulnerability was quite wide, uh, which we called sort of the aperture of exposure. And that was wide today that has shrunk to a few hours, maybe a few minutes in some cases. And so the ability from a governance standpoint to automate governance and to ensure treating agents, just like today we should treat humans, which is give them least privileges just in time privileges and short lived privileges so they get the privilege that they need to do the task at hand. And that privilege then should be taken away so that agent cannot run amok with that privilege.

Speaker E: And part of my background is a bit more on just application security. I think of the ways that systems are going to be compromised. But a lot of times it's not just because a vuln exists and it's exploited. It's exploited, but then credentials are obtained because it's so much easier to have access into a network with valid credentials rather than relying on somebody downloading, uh, an npm, some package that has a vuln in it. And where I'm going with that is then do you have AI on the Defender side? We've been talking about the machine speed, the scale there. Is AI helping at least address the problem in a way or how does that. Because how does AI on Defender work with that governance aspect?

Speaker G: Yeah. So another aspect of leveraging AI for governance is uh, detecting anomalous behavior.

Speaker E: Okay.

Speaker G: Right. So integrating ITDR or detection and response, uh, along with identity security, so understanding what a particular credential is expected to do, what data that they might have access to and what is the risk created for the organization with that agent or with that human accessing that data. So I think anything that the common sense, um, approaches that apply to human uh, identity security still apply to AI identity security, but at a much faster pace, at a much higher scale. Yeah.

Speaker E: And part of that, I'm curious, have you seen either CISOs or just from directly your direct experience too, the idea of the governance, I don't want to mischaracterize it too much as an after the fact type of exercise. Here's an agent or a human that did something, should they have done it and the reason. But damage has been done. Is there an element there that becomes more preventative? Is AI helping to actually say this is a just in time credential and it's ended. That's a good thing. I like that. Is the story with that kind of credential becoming better now with AI, um,

Speaker G: it's just becoming faster. And then the power of AI is processing data. And I think in the space of cybersecurity there's tons of data that's generated every second, uh, with the traffic. So the ability to detect patterns, uh, and good patterns versus risky patterns, and then making those decisions faster is where you can derive that benefit.

Speaker E: And that's got to be, that's got to be the appealing then for, for a ciso, because their question is, as you say, machine speed, that's, that's a term I'm going to hear, we're going to hear a lot more of that this week I'm sure too they still need to be informed about decisions. So I'm trying to frame this question as we can't give the CISO or that, you know, whoever's in charge there, machine speed data at machine volume because you're just going to overwhelm them. So what does it look like first for one of these identity platforms to give them the helpful signals?

Speaker G: I'm not sure.

Speaker E: So yeah, I'm to trying, trying to think of just basically it's that idea of going back to value. So you were very rightly I think pointing out here's anomalous behavior. That's something that's helpful. What is something else that can lean more towards here is what the platform provides in the sense of discovery, identity or inventory.

Speaker G: Yeah, discovery ownership and then governance.

Speaker E: And then governance.

Speaker G: Yeah, yeah, I mean, I mean those are sort of key tenets. And then within that of course there's AI enabled process to speed that up. Um, but it's not an easy task. There's no easy button in identity security, unfortunately.

Speaker E: No. And I wonder too then if you were to maybe fast forward just even six months from now, somebody is starting off with, let's say they had a decent story with their cloud environment, their services, their service identity, machine identity. What would you hope to see as they're describing how they've approached agents? What are they doing that would give you confidence that uh, you understood the problem and they're addressing it in an effective way?

Speaker G: Well, I mean if they had a good story with machine identities and API security, so essentially other forms of non human identities, uh, then they're pretty well positioned to tackle uh, the uh, agentic onslaught if you will. Uh, but it really, I think having that awareness and um, um, I guess uh, humility to know that this is a huge uh, risk to the organization and this is going to create uh, the kind of challenges that most organizations have not dealt with in the past. And approaching this with that sort of pragmatic view I think is really critical.

Speaker E: I'm curious, do you think there on the one hand you mentioned before too that the enterprise is moving ahead? You know, don't say no, tell us how to enable security here. And they're seen ostensibly doing this because they see benefits to the business. Have you seen that those benefits show up in the security side as well? Or security just being, just still following through and saying AI is helping the business, but AI hasn't really helped us yet.

Speaker G: No, we're seeing that in helping uh, security as well. I mean especially in the SoC. I think AI is helping um, uh most uh, security operations centers, um, and even within the identity security ecosystem, um just helping with MFA fatigue, uh, phishing resistant authentication. Uh, you're seeing a lot of interesting solutions in the market and with a easier path to deployment and realizing value uh, to solve those sort of challenges. I think the biggest challenge is there are a lot of fragmented solutions, a lot of tools. So the trick again I go back to is really from a ah, um, organization to for the organization to realize full value is to create what we call an identity security operating model and be able to connect all these various applications and get the full visibility to what a CISO really requires.

Speaker E: I think that's a great message to end on, just defrag and have a visibility into all of the agents, non human identities and people as is. So I want to say thank you for that message Ajay. I appreciate that, appreciate it.

Speaker G: Thank you you so much.

Speaker E: To learn more about SDG visit SecurityWeekly.com SDGIDV for all of our Identiverse 2026 coverage from Cyber Risk alliance, check out SecurityWeekly.com IDV and stick around. We'll be right back after the break.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • AI Was A Waste of Time, Until It Wasn't with Megan BoshuyzenMaking Sense of Martech · on Claude Code91 / 100
  • He quit Stripe and hit $10M ARR in 4 years - with $0 marketing spend. | Anurag Goel, Founder of RenderA Product Market Fit Show · on AWS89 / 100
  • How Organizations Can Thrive in the Human + AI Era with David ChestnutThe Edge of Work · on Claude Code85 / 100
  • Episode 018: Season 2, the $75 Consult and the Frankenstein StackAI Tools for Practicing Lawyers · on Claude Code84 / 100
  • AI for Engineering Is Leaving the Demo PhaseAI Across The Product Lifecycle Podcast · on Claude Code83 / 100
  • 477. The Nitty Gritty of AI From an Attorney and AI Expert with Mike BrownThe Game Changing Attorney Podcast with Michael Mogill · on Claude Code81 / 100

More from Enterprise Security Weekly

All episodes →
  • Fixing pentesting, Meta is destroying its engineering org, the weekly news - Adriel Desautels - ESW #465
  • Navigating Shadow AI in the Enterprise, Verizon's SECOND 2026 report, and the news - Ankita Gupta - ESW #464
  • Safe AI at scale, what happens after initial access, and the weekly enterprise news - Albert Estevez Polo, Shiva Pillay - ESW #463
  • The State of AI in SecOps, the Unintended Consequences of Vulnmaxxing, and the News - Filip Stojkovski - ESW #462
  • Helping defense's use of AI catch up with offense, cost of the vulnpocalypse, news - Evan Powell - ESW #461
Explore the best B2B AI & Data podcasts →
All Enterprise Security Weekly episodes →