The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Identity at the Center
Identity at the Center artwork

#431 - Tectonic Shifts in Identity Security with Martin Kuppinger

Identity at the Center · 2026-06-29 · 1h 1m

0:00--:--

Key moments - from our scoring

Substance score

57 / 100

Five dimensions, 20 points each

Insight Density11 / 20
Originality12 / 20
Guest Caliber14 / 20
Specificity & Evidence10 / 20
Conversational Craft10 / 20

Martin Kuppinger, founder and distinguished analyst at Kuppinger Cole, discusses the unprecedented challenges that agentic AI poses to traditional identity and security frameworks at EIC 2026. Unlike previous paradigm shifts in identity management - from workload identities to federated access - agentic AI introduces non-deterministic, non-directed access patterns where autonomous agents may trigger other agents across distributed resources in unpredictable ways. Kuppinger argues that centralized identity models, LDAP standards, and traditional IAM principles cannot be directly applied to this new landscape. Instead, he proposes adopting decentralized identity thinking alongside tactical measures like MCP server authorization and immutable logging for auditability. The discussion explores the AI Security Fabric framework - comprising five capability pillars: AI identity, AI security, safety, governance, and explainability - and examines where organizations should focus: discovery first, then governance, while building toward more sophisticated resource-level access controls. Relevant for identity leaders, CISOs, and enterprise architects wrestling with agentic governance, audit compliance, and the intersection of IAM and AI safety.

Key takeaways

  • →Agentic AI requires a shift from centralized, deterministic identity models to decentralized and autonomous approaches since agents act independently without the control mechanisms available in traditional workforce identity management.
  • →Discovery of agents and their activities across multiple platforms, browsers, endpoints, and networks is the logical starting point for governance since you cannot protect what you don't know.
  • →Organizations should implement immutable logs and traceability as the foundation for explainability, especially given the fast-moving nature of language models and the regulatory requirement to explain authorization decisions.
  • →MCP server authorization is only a first step similar to early CA policy tools from 2000, and the real challenge is controlling direct resource access in backend systems beyond proxy layers.
  • →The shift from large language models to specialized smaller language models will improve security, reduce costs, and enable better learning governance and explainability since organizations can own and understand their models.

In this episode

  1. 1EIC 2026 Conference Overview and Thought Leadership
  2. 2Tectonic Shifts: AI and Agentic Identity as Paradigm Change
  3. 3Decentralized Identity and Autonomous Agents
  4. 4AI Security Fabric Framework and Core Capabilities
  5. 5Discovery and Governance as Starting Points
  6. 6Explainability, Immutable Logs, and Specialized Language Models
  7. 7Market Evolution and Future Identity Challenges

Mentioned

Martin KuppingerKuppinger ColeEICPing IdentityPatrick HardingSAPLDAPOAuthMCP server

Guests

Martin Kuppinger

Topics in this episode

Agentic AIRetrieval Augmented Generation (RAG)AI security fabricDecentralized identityMCP server authorizationAutonomous identitiesImmutable logsSpecialized language models versus LLMsAgent lineageEIC (European Identity Conference)

Questions this episode answers

What makes agentic AI different from traditional identity and access management?

Agentic AI operates autonomously and non-deterministically - agents may trigger other agents whose actions end at unpredictable resources, unlike deterministic user access. Additionally, LLM behavior can change between versions even for identical inputs, making centralized identity standards and traditional IAM controls unsuitable without reimagining the approach.

What are the five capability pillars of the AI Security Fabric that Martin Kuppinger outlined?

The five pillars are AI identity (giving identities to agents), the intersection of AI and identity, AI security, safety, governance, and explainability. These capabilities form the foundation of a reference architecture needed to protect autonomous and agentic AI systems.

Where should organizations start when addressing agentic AI governance?

Organizations should begin with discovery - understanding what agents and workloads exist across platforms, browsers, endpoints, and networks - because you cannot protect or govern what you don't know. After discovery, governance is the logical next step to set guardrails and establish proper controls.

Why does Martin Kuppinger prefer the term 'autonomous identities' over 'non-human identities'?

Kuppinger argues that 'autonomous identities' (humans and agents) versus 'dependent identities' (workload identities, IoT) is a more precise abstraction that better captures the fundamental differences in how these entities operate and should be managed.

How should organizations approach explainability for AI-driven access decisions in identity systems?

The foundation for explainability is immutable, standardized logging to enable traceability of decisions. Organizations should also shift toward specialized smaller language models (SLMs) rather than large language models, as SLMs offer better transparency, lower costs, and allow organizations to control and understand their models' behavior for security and compliance purposes.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

11 / 20

There are genuine substantive passages on agentic AI as a non-directed, non-deterministic identity problem, the case for decentralized identity frameworks in agent meshes, and the shift from LLMs to SLMs - but these are heavily diluted by a prolonged self-driving car tangent, humanoid robot speculation, dog cancer vaccine anecdote, and conference promotion that collectively consume roughly a third of the runtime.

It's non deterministic because we don't know where it ends. It's also non deterministic because if we have the next version of the LLM, it may do it differently even if we try to do the same thing.
MCP server authorization is a little bit like what CA Sitemander brought to us in the year 2000. So we have a layer in front and we say, okay, we do some, in that case authorization, very coarse grain, and then we pass it by.

Originality

12 / 20

The reframing of NHI taxonomy as 'autonomous identities vs dependent identities,' the argument that agentic AI constitutes a genuinely new problem rather than old problems at scale, and the recursive distrust framing (using AI to control AI) are reasonably fresh; however, most of the broader AI-identity narrative is circulating widely in the industry and the frameworks are high-level without delivering truly contrarian or first-principles conclusions.

maybe we think more about autonomous identities like humans and agents versus dependent identities like workload identities or IoT identities, et cetera as a better abstraction
It's not just um, the old problem on steroids. It's a new problem.

Guest Caliber

14 / 20

Kuppinger is a legitimate 35-year veteran who founded a respected analyst firm and demonstrably shaped industry frameworks like the identity fabric; he has real historical credibility and is not a career podcast guest, though he is an analyst-observer rather than an operator who has built and run these systems at scale inside an enterprise.

of all the 35 plus years I'm in identity and security, it's probably the intellectually most fascinating challenge I've seen over all these years
When we did the first EIC and that was in a market where There were maybe 50 or 80 vendors back in 2007... right now we have truly way north of 1,000 vendors in this identity security space

Specificity & Evidence

10 / 20

A handful of concrete anchors exist - the CA SiteMinder year-2000 analogy, vendor count growth from 50-80 to 1,000+, the 200-person pre-conference workshop, named actors like Max Schrems and Patrick Harding - but there are no enterprise case studies, dollar figures, breach data, or measurable security outcomes; most recommendations remain at a conceptual level without grounding in real deployments.

MCP server authorization is a little bit like what CA Sitemander brought to us in the year 2000
we had some more than 200 people in the room... I had 10 fundamental changes back then. When we started, we had the workshop 15 already a few days later, plus we had a backlog of I think nine others

Conversational Craft

10 / 20

The hosts land one genuine productive disagreement - pushing back on whether agentic AI is truly a new problem vs. old problems at scale - and the NHI verification/consent chain shows some topical ambition, but the episode is undermined by extended unchallenged tangents on self-driving cars, failure to probe for specific evidence behind framework claims, and a closing segment that wanders into health AI and humanoid robots with no substantive follow-up.

So you think this is a new problem?
I would say in this case probably maybe the first time we have something where the problem is new. Because as I've said, this mesh of age and this non directed, non directed, non deterministic thing is really something which is, is different.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker C66%
  • Speaker B24%
  • Speaker A10%

Most-used words

identity54agent32different28human21certain20security19problem18back17sense17agents17cetera15better14access14first13understand13decentralized12

Episode notes

Recorded live at EIC 2026 in Berlin, Jeff and Jim sit down with Martin Kuppinger, founder and distinguished analyst at KuppingerCole. They dig into the tectonic shifts AI is bringing to identity and security, the AI security fabric framework, why decentralized identity thinking may be essential for governing the agentic mesh, the ongoing debate over NHI terminology, what organizations can do tactically today, and what concerns Martin most about where the industry is heading by 2030.

Full transcript

1h 1m

Transcribed and scored by The B2B Podcast Index.

Speaker A: Foreign. This is Identity at the Center.

Speaker B: Welcome to the Identity at the center podcast.

Speaker C: I'm Jeff and that's Jim.

Speaker B: Hey Jim.

Speaker A: Hey Jeff, how are you?

Speaker B: Not so bad yourself.

Speaker A: Doing great. Hey, we're here at EIC 2026. We've got the guest that we've all been waiting for, the man who requires no introduction. But uh, anyway, it's podcast, right?

Speaker B: Yes, it is. Uh, yeah. So we're at EIC in Berlin. This is our second year here. Another amazing conference. Um, we've done a couple episodes like this. Uh, this is I think the last episode that we'll release as part of our journey here and some of the conversations. But yeah, let's welcome our guest, Mr. Martin Kubinger from Kubringer, Cole. Uh, let's see. Founder and distinguished analyst. Hopefully I'm getting that correctly. Okay, so what does it mean? Let me ask you a question, kind of off the cuff here. So, so what does distinguished mean? Distinguished analysts?

Speaker C: It means that I will focus more on the, um, thinking about trends, um, influencing, trying to influence the industry. Um, clearly there's a lot of networking stuff, um, speaking some advisory, more strategic stuff overall than day to day business. So that is basically the shift, um, being in that business, um, for more than 20 years. Um, so stepping a bit back from the front line or to a different frontline in a sense because it's clearly still a lot of visibility. So that is the change behind us.

Speaker B: Sounds like fun. I guess we might know, right?

Speaker C: Real time.

Speaker B: Uh, so from your perspective, um, how many times has this conference been in play?

Speaker C: It's number nine.

Speaker B: Number nine. 19.

Speaker C: Okay.

Speaker B: And so what is something that you think for people who haven't been able to come out here and be part of this, like, what's something they should take away from this conference? I know we're going to get into like AI and fabrics and things like that, but why should people be coming out to this conference?

Speaker C: I think, you know, in the early days we had a tagline I still would love to see again, which was thought leadership and best practice. And I think this describes this event very well. So we focus on identity, everything around identity, um, cloud being quite important again these days with all the debates around serving cloud and the related topics are the identity security thing, AI security, data security, a lot of privacy, uh, following the decentralized identity, udi, wallet stuff since it exists or since people started thinking about it in a way. This is um, really focused on certain topics with a lot of thought leadership talks, but also a lot of best practice Talks from people from their projects and how to do it, how to make it work. I think this combination is good and we have a very dense program, um, so up to six tracks in parallel, um, which means there's something for everyone at every time. We also have a lot of really networking opportunities, long breaks, the great area outside of the venue with the food trucks, et cetera. So um, it's very interactive as well and I think this makes a difference to many of the other um, events that exist.

Speaker B: It's a very well run event so I can appreciate that. We think with the number of conferences we tend to go to, I think the intention is always to like okay, what can we make next year bigger, better, more efficient, whatever, me. But it's, it runs with very good efficiency. The biggest problem that I have with this conference is that there's too much good content. So I have to choose, you know, which ones to go to. I have taken advantage of the stream more than I thought that I would have than I think compared to last year. So hats off to that if people want to view the content later. This is available for attendees, but it's also for members.

Speaker C: Yeah, exactly. And that means um, if they're two or three things happening in parallel that you find interesting, you can always say okay, I'm good to this. And then I look this one or this one later on, um, in the recording. So we make it all available, we stream it and we record it and I think this is ah, definitely an advantage.

Speaker B: So let's talk a little about your keynote. You talked about the idea of AI acting decentralized and autonomous and this idea of a centralized identity maybe isn't the way to go, at least maybe not specific for agentic or NHI or workload, whatever we're calling non humans, you know, for lack of our cohesive term, um, tell me a little bit about that item and you know what's driving you

Speaker C: with that mindset so maybe to scope it even a little bit bigger. Uh, we had a um, pre conference workshop. So on the morning of the first day, uh, very well attended, I think we had some more than 200 people in the room, um, a lot of people standing um, around tectonic shifts that AI brings to identity and security. And um, part of that is when we look at the agent AI that you have these agents and these agents act um, rather autonomously. Um, so it's not that we have the same level of control as we have in a traditional for instance workforce identity management where we know these are our people. And they have certain types of access. This is not happening anymore. It's really autonomous, distributed, fragmented. I think applying the decentralized identity thinking can be extremely helpful here. Instead of saying okay, we try to do traditional, whatever, LDAP stuff for agents which go a little maybe over the top. But um, this is I think now the thinking that can work in the world that is way more volatile, dynamic, fragmented, partially ephemeral, um, when you look at the lifespan of certain of these things. And so we need to take a different route. I think this is um, behind that. And at the end what I'd like to trigger is that we really do apply quite some shift left thinking, uh, and understand that this is a very different and probably a more complex challenge. I would even dare to say of all the 35 plus years I'm in identity and security, it's probably the intellectually most fascinating challenge I've seen over all these years. There's so much changing because simply said, we are used to say, whatever Martin or Jeff or Jim, they have access to SAP that is directed Jeff to SAP and it's deterministic to SAP. Right now we have a situation that we do something that triggers an agent that may trigger other agents that end up at some resource service and the results server not even have an idea about which agent will knock on their door the next minute and why. So it's non directed and it's non deterministic by the way, in more than one meaning. It's non deterministic because we don't know where it ends. It's also non deterministic because if we have the next version of the LLM, it may do it differently even if we try to do the same thing. And that means it is uh, really very different the way we need to do identity access and access now than everything we did in the past. And this is why I said okay, it doesn't probably uh, I don't see that it can't work just to try to use the same concepts, uh, from a centralized identity world, the same standards, the same principles, to apply them to something which is different, which is more autonomous or in a sense decentralized. I think it's very worth to look at um, the stuff we developed around decentralized identity, etc. And think about where does it fit, where can it also maybe complement things like oauth, et cetera to enable us to solve this fascinating challenge.

Speaker B: Think of how I want to phrase this. So you talked about this being one of the most momentous shifts in, in, in Your career. I can certainly agree with that. Right. It's, it's a huge shift. From a speed perspective, where do you think we are from really understanding what the problem is to actually getting into a state where we feel comfortable from a governing standpoint, especially when, yeah, uh, agentic identity is very hot, obviously. And you're talking about agentic networks inside of agentic networks inside, inside of each engine works and so on. Right. It's like Inception. You're going downwards through these things. Are we at a spot where we think that the pace of our thinking to address this, the pace of vendors trying to figure out, okay, what are the solutions that we think we can put in place to help their customers. Right. Things like that. But I'm curious, like from a speed perspective, where do you think we are? We're moving too fast, too slow, about as best as we can do and

Speaker C: as best as we can do. Um, but so behind that I think that the one point is, um, so when we take the cloud, this was a very fundamental paradigm shift which took years with quite some peaks in evolution, but it was a very long term thing. During the pandemic we had certain things that needed to happen much faster. Right now it's even faster and it's way, way more disruptive. So this is a situation we are facing. Um, are, uh, we lost? No, I think we can handle it. We will learn. We need to understand what we can do with what we have now tactically, but also work hard on uh, delivering the more strategic, more comprehensive approaches. Because some of the things like this applied, uh, decentralized thinking will not be something we do in the next two weeks. That will take us a little longer. But we also need to act now, uh, with technical measure. We can uh, look at this a little bit more in detail later on. For the speed thing, I think what was interesting, just anecdotal, um, uh, so we decided to do this pre conference workshop roughly 10 days ahead of EIC. And that was when I said I did one or two talks at vendor events about um, the changes, uh, AI identity and AI, uh, security bring and we need to think about it. I had 10 fundamental changes back then. When we started, we had the workshop 15 already a few days later, plus we had a backlog of I think nine others. Um, I would say the speed will go down a bit. So I think we're getting closer to an understanding, which at least means we have probably understood the most aspects, roughly the detail work still to be done. But I think we are getting closer in the Conversations to have a good picture of what we need to do. So when I go back half a year, I did roughly, uh, half a year maybe I did a podcast with Patrick Harding, the CTO of Ping Identity, or It was a LinkedIn Live. And since then I think I have learned an incredible lot of new stuff and understanding and ideas. But it's still, um. So literally all of my business conversations include AI. And in many, many of these, I still detect new facets of this challenge that needs to be considered. So it's still a moving target, but we are getting closer. And as I've said, we also, I think, can do some things tactically now and we must do to act, but we also need to speed up things to, to solve it more fundamentally, strategically, um, rather fast because the thing is moving very quickly.

Speaker A: I like Jeff's question about distinguished analysts, because I think the analyst takes a lot of information, does pattern discovery, and then helps people understand what's going on in the industry and where are things within a track or heading. But I think use the word, the term influence, right? You're actually influencing. So last year you were talking about identity fabric. This year you talked about AI security fabric. And I think it was like, you know, horizontally oriented, if you will, identity, uh, governance, explainability, and behavioral.

Speaker B: I got that right?

Speaker C: Not exactly, I think. So the fabrics, all of them have a structure basically of, um, the who to what and in between, at the center, there are capabilities you need, services you then build, and tools that deliver this. And for the AI security fabric, so the identity fabric, I think we brought it up in 2018 or so, uh, back then I at least started my keynote with a slide from the EIC 2019, where I had this main themes of EIC 2019, which were decentralized, identity, identity fabric and AI back seven years back, um, so maybe a bit trancing sometimes. Um, and so the AI security fabric, um, what we see there is AI identity, so giving identities to agents, the intersection of AI and identity, AI security, safety, governance and explainability. These were the five capabilities sections, the blocks of capabilities we need to look at. We will underpin this with a reference architecture. We go then more into detail in the building blocks. And some of them we have at a certain maturity level, some at a little bit more mature level, some probably in the early stages, some almost lacking, um, still. But that will be the job of the industry to deliver on that. And that gives them a guidance on what we need, which pieces of the puzzle we need to deliver the full, so to speak, AI security Um, picture um, over time so that we can protect this fast moving, complex and super, super important and also business, super helpful and powerful world of agentic AI and so to speak, non agentic, more traditional AI.

Speaker A: Yeah. It's interesting you've run up Patrick Harding and he's been on our show a few times. I think he was one of the first people to talk about the importance of AI and Iam, um, on our show anyway. And now it's like we can't go in an episode without talking about it. Um, but you're kind of building these frameworks to think about it for other people to organize their alert maps around which. That was my point on the distinguished analyst piece. Um, but what I was wondering. So the different pillars that you mentioned, you talk to a lot of identity leaders within their organizations. Are there certain ones of those pillars where organizations tend to be more strong? Um, need to put more. Either they're good or they need to put more emphasis. Where are the strengths and weaknesses in terms of organization or do they need to grow in all the areas?

Speaker C: I think they need to grow everywhere. I think what the common understanding with most of the practitioners um, is that there are some logical starting points where we can already now can get a grip on the entire thing. And the one area to start with obviously is discovery because we can't protect, we can't govern what we don't know. So we need to get good on discovery which is not super easy to discovery thing because um, we need to have discovery at quite a lot of different places. So that might be the platforms where we build agents on, but it might be also the browser, the endpoint, the network. So we need to gather data from different sources to bring it together to have an understanding of what exists, what is managed, what is unmanaged. If it's unmanaged, is it still something which is good or is it malicious? All that stuff we need. So the discovery part is the one and this is where we can act and I think where we see quite some evolution also from a tools perspective, the other um, is the other side of the edge, so to speak. So here we are the user and then to the agents to discover the agents and then the agents go to resources maybe via an MCP server. And this is in a sense the edge where we have a bit of a control point. We need to be clear about that. This is if you do MCP server authorization where we see a lot of vendors um, starting to offer something around. This is definitely just the first step. First we have Also some direct resource access. Um, we have not only MCP servers, but in a way, um, MCP server authorization is a little bit like what CA Sitemander brought to us in the year 2000. So we have a layer in front and we say, okay, we do some, in that case authorization, very coarse grain, and then we pass it by. We need to work hard on going really into the backends because there's something behind the MCP server and we must not forget that. And this is definitely the more challenging, more difficult thing to solve, but still better start there and do something than do nothing.

Speaker A: I think you're right. I think organizations need to focus on all of it. I wanted to pick on two things. One was governance, because I've actually heard of some of the biggest American banks where they were actually telling their employees, join only use an older version of the model. Because that's what we've tested. And it's like I'm afraid of, uh, you know, hey, we need to govern this thing and we're going to do it in a way we don't know what we're doing. So we're going to take old models of governance and apply it to this new technology and stunt your grains or stunt the growth of our business. So I want to get your comment on that. The other area is explainability. I feel like identity 20 years ago as a practice of taking what could be done with paper and pencil or Excel spreadsheets and who gave access to this person or who logged in at this time and tried to automate it. Right. Well now it's happening so fast and the volumes are so high does an AI potentially is making the decision. So explainability seems like such a bigger challenge and probably out of most IAM leaders hands. Maybe by explainability just make sure that you don't forget that. Make sure that your system is not making decisions that you can't explain to a judge.

Speaker C: Yeah. So I think two huge and super fascinating areas. So on the governance side, I think banks clearly are a bit of a special kind of beast, um, in the sense of they have the biggest audit pressure, um, they also have the most mature, usually the most mature governance approaches and risk controls, et cetera. So I also hear it from European, um, CISOs and leaders that they say, okay, we are relatively restrictive. We run um, our own instances of certain, uh, models in a controlled manner and you're only allowed to use these. So being very restrictive. I think there's obviously a risk of still things going wrong, um, and someone bypassing it. I think this risk must um, be underestimated. But I think that makes sense in such an environment. Um, on the other hand, we clearly have in many, many areas the situation of how can we move fast, how can the business evolve fast, how can we use it for whatever, improving our speed and development of solutions and whatever else, um, optimized business approach, et cetera. And still I think it's important to understand, um, and this goes all the back to discovery. What do we have, what made this be allowed to do? And how do we contain stuff, how do we keep it under control? And that goes into safety. I'm not a big friend of the year. A lot of people then saying oh, we need this agent kill switch. The kill switch is always, is the last result. Um, because you don't know necessarily whether this is a super important agent for the function of the business. And so better thinking, containment in potential isolation, in slowing things down until human in the loop could check it or stuff like that. Um, so I think we need to be careful. But governance is the logical starting point. As I've said, it starts with understanding what we have, what is managed unmanaged, what's the purpose. And then we will need to do a lot of things over time by setting proper guardrails, delivering that information with the agent having an agent lineage to understand the entire chain of agents and humans and workload identities and all the other stuff that comes into that. As I've said, I'm not a big believer in the term m non human identity. I used it for a while, but I never was 100% convinced. And in my keynote I proposed maybe we think more about autonomous identities like humans and agents versus dependent identities like workload identities or IoT identities, et cetera as a better abstraction because the non human is not precise enough for my understanding. Um, anyway, back to your question. The other aspect is explainability and I think this starts with so um, we need to have the understanding partially also from a legal perspective, from a regulatory perspective of uh, why was a certain decision made. We have this in the traditional, so to speak, analytical AI et cetera. We already have this in certain regulations, um, whatever price finding or is credit scoring, stuff like that where this explainability is required. And I think the first thing we will need is, are really immutable logs, the standard for immutable logs so that we can trace what happened. And uh, so the traceability in effect is the foundation for explainability. And it's even more important in this world of um, fast moving language models, be it Large or specialized small language models. I don't really believe that large language models will be the normal. I think they are more the standard tool for when you don't have a better thing over time. I think this will change rather quickly because LLMs are far too expensive from a compute cost perspective, et cetera and they are just inefficient. So at the end of the day I think we will see a clear shift to specialize to smaller language models, uh, with lesser overhead, with better understanding and also better training. You can also do some of the security aspects much better. So I have, in my governance list I have the learning governance. So how do you ensure that things are learned that should be learned, but others not that shouldn't, uh, uh, retrieval augmented, um, generations or rag isn't the answer on that because this is black white. Either you learn or you don't learn. Doesn't make sense. If you have an SLM you own, then you can learn. And then you also have a lot of advantages for the explainability because it's your model and you know what it does. So I think that will be also part of the evolution. Uh, we are seeing um, on various fronts, on various areas, but it will definitely remain super, super interesting the next couple of months.

Speaker B: And just when we think we've figured it out, it will change probably.

Speaker C: Yes, I think. But isn't that what we had, an identity for decades.

Speaker B: It's not a new problem.

Speaker C: I remember when we did the first EIC and that was in a market where There were maybe 50 or 80 vendors back in 2007. Someone came to us and said, why do you do a conference for such a small market? Right now we have truly way north of 1,000 vendors in this identity security space without a specific cyber security vendors. I think if you count them we are uh, someone count 12,000, be it 6 or 8,000. But it's a huge market. And one of the things that was fascinating also in retrospective, uh, to me is when you think it's calming down, it's settling, then the next big evolution happens. And that is the case for the last 20 or 25 years. Always. Then, um, you think, okay, right now we have a quite stable situation. Then workload identities pop up or a identity pops up or in earlier times, whatever. Then the saver X elect came uh, in into effect and we had access governance which changed meta directories and user provisioning fundamentally and so on and so on and so on.

Speaker B: I feel like it's waves in the ocean, right? There's periods of Calm. And then something comes along that kind of breaks the surface. Okay. Right now everyone is, I don't say freaking out, but let's say freaking out of okay, how are we going to control these non human agentic workload, whatever we're going to call them. Right. But it's because it's relatively new. The problem isn't new. What's new is the scale of it and the speed with which these things are proliferating. And so you end up in this kind of race condition of okay, how are we going to catch up?

Speaker C: I would say in this case probably maybe the first time we have something where the problem is new. Because as I've said, this mesh of age and this non directed, non directed, non deterministic thing is really something which is, is different.

Speaker B: Interesting. So you think this is a new problem?

Speaker C: Um, I think it's a new problem, yes. It's not just um, the old problem on steroids. It's a new problem. I would say clearly there are things which are similar to the old or the known problem. So the workload identity M, that was basically um, just um, like a service account. Yeah, it was something we knew, but uh, way more of these um, lesser control structures and different way to handle it, different parties involved, et cetera. But there wasn't ah, that much really fundamentally new in it right now. As I've said, there's a lot of things that change fundamentally. Um, clearly we could always say we still need whatever behavioral analytics, but it's, and it's just right now multidimensional and that's uh, unidimensional. So traditionally we say, okay, this is Martin's behavior and we detect an anomaly right now we see the agent, but if the agent works for you, and then for me we um, can't say this is the correct agent behavior because you may do fundamentally different things with the agent than I do. So it's more than one dimension. And all these things sum up to something where I would say it's a, it's really probably more than a uh, bigger dimension. It's probably more a new dimension than a bigger dimension.

Speaker B: So the way I think about this is the reason I don't think it's necessarily a new problem is because it's a combination of existing problems with different facets. So we've got, let's just break it down to human and non humans just for simplicity. Right now humans and their behavior is not um, patterned. There might be some loose patterns, but for the most part they act in a variety of different ways I might log in from one thing, I might access the other application, et cetera. Um, a service account traditionally is extremely repeatable. Right? Service account exists to connect A to B and that's all it does.

Speaker C: Trust some data by core.

Speaker B: Exactly right. So it's doing whatever it needs to do. It's plumbing. When we talk about non human identities though, the behavior of a non human identity is much close. Well, depending on the non humanity is, can be much closer to a human behavior pattern than a non human or a traditional service account. And so that's why I don't think it's necessarily a new problem is what we're doing. We're saying, okay, we've always had a problem of trying to figure out what does behavior look like for humans. We have some tools that will help us to kind of determine what that looks like for a non human. We're still establishing what the behavior looks like. But if I say okay, like the example you were using where I have an agent that we both share, isn't that any. How is that any different than a admin or an analyst that we will both share? We're both giving them different directions. So if a human was performing that task, they would still be acting in a way that's like, okay, well I'm not quite Martin, I'm not quite Jeff. I'm doing a little bit of both.

Speaker C: If you take a travel agent that books travel for you and for me, your travel preferences might be very different than my travel preferences.

Speaker B: But a good agent and a good admin would know what those preferences are.

Speaker C: But uh, it may learn it and when we observe it, we still need to understand who is the agent acting on behalf of which is there's more than one dimension to look at. When we have whatever Linux admin and you're using the same root account as me, then you still do a certain. So if it's maybe it's not a root account but a more specialized backup, uh, so you do a backup, I do a backup. There's not much room for um, deviations in the behavior. Um, so I think it's probably um, a bit different. But I see that there's uh, the other side. When we look at it from an access perspective, until now we do everything with the assumption that we know who will need which access to which resource. And that is changing. So we can't predict who or what will ask for which access to which resource. Um, there's this intent thing coming in, trying to understand the intent of, of the query which is a bit um, uh, so it's a backwards analysis in a sense probably not the final solution. Um, and this is really uh, a fundamental shift I believe. So I think we are well advised. So first taking tactical measures to what we can do now. We do now. But then we should look at how can we solve that um, problem of for instance agents acting uh, relatively uncontrolled in the mesh, including maybe unmanaged agents. If you have solved that. We also have solved a scenario where we have a very purpose built, very restricted agent which in a sense still acts directed and deterministic uh because this is then just a simple subset of the building bigger challenge. But let's wait and see where we end with this.

Speaker A: I'm going to throw a curveball at you. Something that's been brought up at all is humanoid robots. And I'm wondering do you need. How far into the future we talking about humanoid robots and the impact of humanoid robots in identity. Have you given any thoughts in this? I mean is this something that. Because you're like a futurist. I'm thinking this has got to be something you thought about.

Speaker C: I haven't thought about that much. I think um, as of now AI is relatively good in a relatively restricted use case. We are far away from uh, general artificial intelligence. So uh, AGI, artificial intelligence intelligence. I think this is still a long way to go if it ever will happen. Um, you know when I was studying um, quite a, quite a couple of decades ago I read a book from even a couple of years more ago from the early AI thought leaders and then it went calm and then there's the next sort of enthusiasm and we made massive progress. But honestly when we right now talk with, and that's not yet the robot but when we talk with uh, um, ah, just whatever prompt on one of these gen AIs, um, sometimes it really reminds me a bit like talking with a relatively young child and then explaining no, not that way, blah blah blah, but no, and so on. Then sometimes you give up or not. Um, I think when we transfer it to humanoid robots, um, I think we see them for certain use cases, we see them for certain scenarios. We probably can combine some of these things. Um, it still will be probably somewhat restricted. And I think some of the AI things also the smart things work when they have a very focused problem to solve. Your um, assisted driving in a vehicle, in a modern vehicle that is something which works reasonably well in most vehicles. Especially then when they really put in enough sensors and don't just rely on the camera, um, and then they really work reasonably well. Um, but they are really very, very focused on a certain use case. Building a humanoid robot for certain specific use cases probably is anyway doable happening today. Um, the more that things should do, probably the more complex is it. Especially I think when we look at AI today. AI is really not good in reasoning. So, um, this is computer. Yeah, it doesn't understand the context, the reason unless it's explained to it and it can learn it. But whatever. If you have a system that analyzes whatever the access in your financial, um, application and you start with this in February and your fiscal year goes until December, what most likely will happen in December? A lot of unknown things, A lot of anomalies. Because your fiscal year ends that year's end bookings. A lot of anomalies. If you let an AI look at it untrained, then trust anomalies. If a human looks at it, how long will it take the human to understand where the anomalies come from? The second five seconds, not long at least. It then can drain it. But I think this reasoning, this broader context understanding is still something, uh, which is not really there. And why do we have the hallucinations? Because something is lacking in them. The system starts to hallucinate, I think, which can be ignored in some cases, which can go wonderfully wrong in other cases when it gets public knowledge that something hallucinated where it shouldn't. And it can be really a safety issue. And the more we go into human aid, robots may become a safety issue.

Speaker A: Yeah. So you talk over the years about, um, decentralized identity and trust frameworks. And in your keynote you kind of applied it to the AI world. And I infer for what you had to say that you think those things become more important in a world with AI. Did I get that right?

Speaker C: I didn't fully get the first part of the question.

Speaker A: So talking about decentralized identity and um, the reusable trust frameworks.

Speaker C: So for decentralized identity, um, I think we have a way to share information about a lot of different actors or entities. Um, for instance, with the DID decentralized identity verifiable credentials. So we have something that logically fits into a world where we have a mesh of different actors, different entities, human workload agents. And so I think it makes a lot of sense to think about how can we, um, or is this something which helps us to better solve, um, the challenges we are facing? And that is a bit the way I'm thinking about it. Um, as I said at the beginning we talked about this being a bit of a decentralized problem. And then there's trust, this logic that it makes potentially quite a lot of sense, um, to apply the thinking because we will need to deliver a lot of information um, to be able to properly authorize um at the resource and back end level. So understanding my personal guardrails, the um, background so the contexts, maybe um, intent as I said is a difficult term, the intent, et cetera. But also maybe a corporate guardrail that comes into it, certain restrictions and other um, context information of the agents involved, the entire agent lineage and other, whatever behavioral signals, fraud signals. That means we may end up with whatever 50 or 100 or more signals in a single interaction and we need a means to deliver them. Where I feel that for instance very fabric credentials might be a good thing, uh, maybe combined with the OAUTH token exchange and other stuff. So think about how to bring these things together. And then we need to do an authorization which is a bit different than the traditional way we did it because as a human we may define a policy with three or four or five attributes or signals, but when you're talking 50 or 100 or more, then we probably need something that helps. Unfortunately it's an AI so we have a bit of a recursive distrust problem where we try to use AI to control AI because we don't trust AI, which is a bit tricky. So we end up with a little bit of philosophical problem. But we still may have a certain AI that is more uh, the one who looks at it and as a control instance and say okay, looks good, doesn't look good, I think we can reduce that risk quite um, strong. And I think the other point is the more signals we have, the more we move from a black, white, whatever authorization approach to a gradient where we can apply it rift thresholds. And the cool thing is that all the seeds can deal very well with risk thresholds because that's what they do in any area. So I think it can work also from that perspective that we say okay, we understand the risk level and depending on that we didn't make a decision, then we can go back from this super complex into a relatively static decision. If the combined threshold is at that level, then do that will be mathematically quite interesting.

Speaker A: So it keeps going back to this identity verification conversation. And I feel like personally I'm doing this maybe once or twice a year. And I'm wondering as the technology got ahead of the demand or where exactly is the market, uh, with demand for identity verification Technology versus, um, where the technology actually else

Speaker C: is it the same? Like, I think in a sense it might be close to identity verification. I think the signal with all these signals that also came up in conversations we had around passive authentication with some people, uh, where you also could argue if you have a lot of signals, then you probably don't need to actively authenticate anymore because you have enough that identifies u. Um, so starting with whatever, when I take my phone out of the, um, my suit, then I do it in a certain manner and usually for some reason I hold in the wrong direction. So um, I need to first flip it by 180°, then I swipe or do something and then this device already has a lot of signals. Um, and I think that way, yes, you could argue that we are not that far away from that. I think we could also argue that in a sense there's way more identity verification done than you feel, than you see, because a lot of this already happens in background. Um, so in that sense, um, I would say, ah, this analogy is probably quite similar and the, the technical approach is quite similar. How do you deal with a lot of signals to uh, sort of know whether you've passed a certain, um, risk threshold or not?

Speaker B: I want to tag onto that question with what does identity verification look like for a non human identity? Is it just a simple matter of looking uh, at certificates? Does it get more advanced? Does it look more like a human at some point point where identities for non humans also need to go through some sort of verification process? Because that leads me to my next question, which is consent. That was something that you had a panel with Eve Mailer and some others. And I kind of want to talk about a little bit of that blending of identity verification for non humans. And what does consent look like when we start thinking about that? Is there a concept of consent when it comes to a non human identity? Okay, that's a little philosophical, but I'm kind of thinking here like, okay, what does this look like when Jim's AI robot walks in the room and say, is that really Jim's AI robot? And is there a matter of consent when it comes to that?

Speaker C: Yeah, I think the first thing is, um, ownership. So who owns the agent? That's the one element you have. Um, and who is the agent acting for? That could be delegation. So the agent says, I'm doing this for Martin, I'm booking the travel for Martin. It could be impersonation, which is very different. The agent saying, I'm Martin. The letter leads more to the question of, um. In the old days of a couple of weeks ago, we called it bot detection. But at the end it's not very different from that. But in most cases we don't need a very specific agent identity verification, because at least when it's registered a known managed agent, we basically have in some way assigned an identity. We can assign an identity to instances of this agent. Um, we have ideally a lineage, um, which says, okay, this, this is the agent doing this for Martin, and these are the sub agents. And we understand how this entire thing goes. I think it would be more tricky, um, to um, say, okay, what is the new agent? Bringing agents under management. I think this goes more a bit into, um, this field of, um, identity verification. But it's probably more an ownership management to understand, um, who might be the owner and then finally bring it under management. So I'm not exactly sure whether we need identity verification in the narrow sense for an agent or whether this is more ownership management and discovery, et cetera. Um, and then the um, second part of the second question was about consent. Um, and consent is something which is not so super far away from intent. Um, so we have an intent and we consent the system or consent that the system does something because we want to achieve something. So in a sense there's an analogy this panel, it was quite interesting one because we had, as the third panelist, we had Max Schrems, who is the lawyer who was, um, doing all these lawsuits around privacy, finally leading to things like gdpr, et cetera. And we talked about, basically, can we use technology to, for instance, get rid of all these annoying cookie consent boxes?

Speaker B: I think you find a lot of people in favor of that.

Speaker C: Yes. And interestingly, I believe we can use technology, and I think we agreed on that. Um, there are some things going on and people like Max and Ian are much deeper into the standards thing than I am. But there are things going on that potentially can help us to, um, balance privacy, uh, better in a way with the, um, um, usability, um, or combine it with usability. I think balancing is always a bit tricky as a term. And um, so that was the part of the thing. So what does it mean for, for an agent? Um, I think the concern is probably something which is more for the human side of things, where it comes from. For an agent, I would better think in guardrails, uh, in what is this agent allowed to do or not. That might be like if you have a travel agent. A logical guardrail is the corporate travel policy, which basically says we only consent in that Sense to this agent doing travel bookings that are within these guardrails, the corporate guardrails, plus, um, within further restrictions the human gave consent for.

Speaker B: I want to ask you one last question and I want to hopefully I don't want to put you on the spot. Is there anything that, um, concerns you, scares you about where the industry is heading when it comes to how we're going to tackle this idea of identity security in 2030, 2035? I'm curious, like, is there anything on your radar? I think that's a big challenge and I'm not quite sure how we're going to surmount that. Or is there something else that just causes you concern? And the reason I asked this because you're always so calm, you're always cool and collected. And I'm curious if there's something behind the surface. Like I'm still kind of struggling with this thing and where this might go.

Speaker C: Yeah, two things that scare me. Um, the first thing is, um, that we oversimplify the broader AI then the AI security challenge. So I think we need to shift left security and we need to understand the tectonic shifts. We need to act upon it. Simple solutions may help tactically. They may be a step on our journey, but we must not stop too early. This is the one thing where I'm a bit scared that we just may fall short. The other thing which really scares me is the incredible weakness we have across the globe when it comes to securing OT operational technology and critical infrastructures. This is where I really feel that is something that is scary. We had the book, it's right now also for a couple of years available in English language. Uh, it was a German book called Blackout by Mark Ellsberg. This is a book that has been written, um, ahead of Fukushima. He describes an attack on the European power crits. Um, the scariest thing with that book is you read it and say, okay, shit. As a somewhat cybersecurity expert, I have the strong impression this can happen. This is really something very well researched and unfortunately, yes, that can happen that way. And then, um, it ends up in a really disastrous, um, situation. Very worse. To read it from that perspective. And we are still not good at all in that respect. This is, I think, where I'm really scared that, um, something goes really, really wrong.

Speaker B: Okay, well, we're going to end on a lighter note so we're going to bring it back up so a little more positive. I want to ask you what your favorite thing about AI is right now. And it can be anything. You know, it could be music generation. It could be just the value that it provides maybe in drafting things. But I'm curious if there's like a thing that's like. Yeah, like I kind of like this thing.

Speaker C: Assisted driving.

Speaker B: Assisted driving.

Speaker C: Assisted driving. This is where I really benefit from in my German car. Um, this is really something which I like, you know, um, it's so much more safe and relaxed. Um, and it really helps me. It's still that when there's a queue in front of me, my leg still moves and maybe my wife also alerts me. But basically I trust more and more that it works and it makes for many, many situations. It really makes life so much better. This is something where I feel AI is really super helpful.

Speaker B: I'm with you because I got. So I drove a Tesla many years ago and the first time I turned on sort of what they called autopilot, which is really just lane keeping assistance and you know, adaptive cruise control, things that are relatively standard time now. Um, it was one of those events like, oh, like, yeah, this is going to change the way people travel. The more people who have it means now you've got more people on predictable behaviors on the road, which means fewer accidents theoretically. Right. There always be some things, but the more people using it the better. But it took me a while to trust it. How long did it take you to not grab the wheel and try to like position yourself in the lane? Because I have a theory that the way a person drives is a biometric factor.

Speaker C: You know, um, the point is my trauma vehicle, um, when I don't take the wheel, after a few seconds it starts alerting me and then starts alerting me more. So I can't, I have to have my hand on the wheel anyway. But for instance, for not, um, pushing a brake when there's a queue ahead or so or someone stopping ahead of you. That took me quite a while. Also when I shifted my or changed my car, it again took me a while to sort, um, of reconfirm that it works. Works better. By the way, in my new car, I won't tell which is the old and I won't tell which is the new one. Um, but at the end, um, it takes a bit. But I would say the systems I started using, I'm, um, uh, pretty, um, confident in them. But if there's for instance, uh, a situation where you need to stop very, very fast, uh, something really unexpected and I still act very quickly because it's still double safety.

Speaker B: Yeah, I've been fortunate enough to drive Many electric vehicles are typically where you see most of these advanced systems and I've seen a big disparity in the capability between all of them. Still I think they're all heading to the same direction of hands off. You're a passenger more than you are a driver, which we'll get there at some point. Um, but I have noticed that there is differences in the way that each the different manufacturers approach it. So you know, I'm fortunate. I have a Rivian vehicle and I have a polestar vehicle and they're both relatively the same but they have different strengths and weaknesses. The Rivian I can be today, I can be hands off and take a nice two hour commute to my, my local day job office if I want to. And that works out really well. Um, but it doesn't do well on certain other roads. Whereas my polestar, which is other vehicle actually works in more roads but doesn't have the same hands off mentality. And it is super annoying when it comes to are you looking straight ahead? Stop looking at this thing, that thing. And they. I find it interesting to see these different vehicle manufacturers have different approaches to what they're willing to release to the wild.

Speaker C: Going back to Sperry, do you know which data uh, your vehicle sent to whom?

Speaker B: M. No, I mean I know it's going somewhere.

Speaker C: I think we don't open the that can right now. But also an interesting topic to look at when we look at a lot of the security things in the world.

Speaker B: It's a trade off.

Speaker A: Right.

Speaker B: It's a convenience factor. Do we need assisted driving? No. Do we find benefit and value in it?

Speaker C: Uh, do we want to go back? Probably not once you got used to it. Um, it's not only a convenience, it's also a safety factor.

Speaker B: And how much of that safety factor are we willing to trade our personal data to contribute to? Now we're getting into it.

Speaker C: Yeah, now we're getting into it. Um, I don't want to trade that but at least I have a trauma.

Speaker B: Jim, I don't think you've gotten yet into the self driving stuff yet. Right?

Speaker C: You probably are driving, you're probably driving a 9080 F150 or something like that, the truck.

Speaker A: But I also have a uh, 2026 Lincoln Nautilus. It's got, they call blue.

Speaker C: Okay.

Speaker B: Blue Cruise.

Speaker A: Yeah.

Speaker B: Okay.

Speaker A: And it only works on the interstates but it's full self driving, hands off. It'll even pass cars. So yeah, I mean I love technology and that's what I was going to say my favorite thing about AI is the rate of change. Right. And on one hand it's great. It's like if you think about what you can do in ChatGPT now versus, you know, three months ago, especially when it comes to like image generation or whatever. The thing is that they determine to put their focus on for long, it's incredible. And there's no reason to think it's going to slow down. Right. This whole idea of recursive self improvement is that these models are building themselves 24 hours a day. The only limitation is how much a compute capacity you could throw at them. Right. I personally also think the physical manifestation of AI is humanoid verbal effects. I think 5 years, 10 years, 15 years is definitely within our lifetime if we die of natural causes. Right. We see humanoid bronze and everywhere we're at EIC and humanoid robots are walking all over the place. That's what I think.

Speaker B: Okay, okay.

Speaker C: Let's see. Vesari.

Speaker A: We'll see if it happens in our lifetime. We'll have to come back here and, and see if I'm right.

Speaker B: I, I grew up in the era of the Jetsons and I'm still waiting for Rosie the Robot in my flying car.

Speaker A: Yeah.

Speaker B: Will we get there? Yes. Will it happen in my lifetime? I don't know.

Speaker A: I want Star Trek and say Earl Grey hot.

Speaker B: You can kind of say that now with uh, you know, a, a voice powered microwave of some sort or maybe some sort of a, you know, fancy espresso machine, right. That is like automated to some degree. It is very cool. I, I, I will, I'll say there's one thing that I find really fascinating is and very neat is the idea of using some of these generative tools in the health things. So I'm not sure if you guys are familiar with this story of uh, this guy who has a dog and dog had cancer and he used essentially, I think it was Chachi Matino owe into that. But it was one of these generative AI systems to research and develop an MRNA vaccine to cure his dog. Which is amazing if it's true. Now I don't have any reason to doubt it because I think he got a lot of press coverage at least

Speaker C: in the U.S. yeah, but you know, I heard so many stories, worries about all the things going wrong and here and that and that and you always question what of this is true or not, right. There's side effects and which access or which access you had to certain sources others don't have, et cetera, et cetera. So I think um, but yes, we see huge improvements. I see AI anyway, for instance, in uh, curing, uh, cancer, curing other, um, uh, other stuff. Um, I think there's an incredible potential. I think it's also, uh, the use of AI when you're whatever, um, by doctors to full of screening for skin cancer, um, uh, et cetera. It's a huge, huge improvement. And I think that makes a lot of sense. Um, so, yeah, I think there's. And I'm not all negative on AI. You know, I like change because I think it keeps things interesting. And um, I think we need to be a bit careful with some of things. Um, and we need to work hard on AI Identity and AI security.

Speaker B: You know, we were saying in the consulting business, I'm sure you've heard before, is get comfortable being uncomfortable. And that's kind of where we're at right now. Um, you know, the health thing I think is, is very interesting because it's not. Sometimes it's not about finding the answer, it's about ruling out all the ones that, you know, aren't the answer. That helps you get to that. So I think it's a fast things base. Uh, it's a. I think every generation says this. We are living in interesting times. And here we are yet again, you know, saying that again. But Martin, you're always so generous with your time. Really appreciate you coming down and kind of staying with us. Congratulations. Another great conference. Um, I know you've got about a day roughly left or so of uh, of stuff to go through, but it's been a great conference. Thank, uh, you again for, for having us here. We hope to see you again next year and I'm sure we'll, we'll talk, you know, virtually, you know, before that as well.

Speaker C: Thank you for being here and always a pleasure to be on your podcast.

Speaker B: No, I appreciate it.

Speaker A: Thank you.

Speaker B: We'll go and leave it for this week. Uh, we'll have some links in our show. People check out idacpodcast.com like and subscribe. That helps us do fun, cool things like this. And uh, yeah, we'll leave it there for this week. Uh, thanks everyone for watching and or listening and we'll talk with you on the next one.

Speaker A: You've been listening to Identity at the Center. We hope you've enjoyed the show. Make sure to like, rate and review and we'll be back soon. But in the meantime, hit the website@identityatthecenter.com See you next time on Identity at the Center.

Speaker C: Sa.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • 226: The Eye of context (The Dungeon of martech architecture, part 2)Humans of Martech · on Retrieval Augmented Generation (RAG)95 / 100
  • Decision Logic: The Difference Between an Answer and a DecisionThe AI Forecast · on Agentic AI87 / 100
  • KYA Won't Always Protect You. The Real Risk Is the Swarm!Fintech Conversations & Insights with Efi Pylarinou · on Agentic AI86 / 100
  • Agentic AI in Sales: What Business Leaders Need to KnowScaling with AI · on Agentic AI86 / 100
  • Is RAG Dead? The Pioneer Who Invented AI's Memory Layer Answers - with Douwe Kiela, Co-Founder, Contextual AI {ICYMI}Making Data Simple · on Retrieval Augmented Generation (RAG)86 / 100
  • EP284 Closest Alligator to the Canoe: How Transforming SOC Became P0 for Lloyds BankCloud Security Podcast by Google · on Agentic AI85 / 100

More from Identity at the Center

All episodes →
  • #430 - AI for IAM and IAM for AI with Martin Sandren
  • #429 - Sponsor Spotlight - SailPoint
  • #428 - Modernizing IGA with Thomas Zarnhofer
  • #427 - Identiverse 2026 Preview with Heather Flanagan and Andi Hindle
  • #426 - Sponsor Spotlight - Crowdstrike
Explore the best B2B Engineering & DevTools podcasts →
All Identity at the Center episodes →