Discover
Identity at the Center
Identity at the Center
Author: Identity at the Center
Subscribed: 75Played: 3,180Subscribe
Share
© 771327
Description
Identity at the Center is a weekly podcast all about identity security in the context of identity and access management (IAM). With decades of real-world IAM experience, hosts Jim McDonald and Jeff Steadman bring you conversations with news, topics, and guests from the identity management industry. Do you know who has access to what?
Visit us on the web at idacpodcast.com
Visit us on the web at idacpodcast.com
452 Episodes
Reverse
Shea McGrew, Chief Technology Officer at Maricopa County, returns to Identity at the Center one year after episode 376 to take on a question she first raised at our Identity After Dark session: when does digital identity become critical infrastructure? Jeff and Jim talk with Shea about how a county broadband and digital equity project led her to see digital trust as the thread running through every digital government service, and why that trust depends on identity. The conversation covers building an external identity portal for residents, designing for consent and privacy from the start, why residents extend trust to private platforms more readily than to government, the right to be forgotten, data governance across departments, and where decentralized identity and verifiable credentials might fit. Shea also shares her view on access reviews as a learning journey, what it would take to trust AI agents with certifications, and whether an agent could ever be considered a citizen. Plus, potatoes and the proper way to cut a sandwich.Connect with Shea: https://www.linkedin.com/in/shea-mcgrew-6b82a36/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com00:00 Welcome to Identity at the Center (or AI at the Center)02:19 How Jim and Jeff met, and how the podcast started04:09 Jeff's fall conference schedule06:39 Do you want IDAC content over the holidays?07:32 IDPro membership and introducing Shea McGrew08:15 Looking back at Identity After Dark10:44 Zero trust progress one year later12:04 From device identity to external identity and broadband16:04 What counts as critical infrastructure?19:00 External identity requirements in government21:04 The blast radius of identity failure23:06 If identity is critical infrastructure, who owns it?24:26 What other public sector leaders are saying26:40 One person, many identities28:40 How government earns resident trust32:37 Why not just copy Amazon?35:02 A right to be forgotten in the US?36:22 Governing data across department boundaries38:30 Decentralized identity and the ownership problem41:30 Tokenization and existing blockchains42:34 The digital trust umbrella45:56 Park passes versus benefits and courts49:19 Does an official designation unlock anything?51:03 Access reviews: security theater or essential?55:26 Would you trust AI agents with access reviews?58:36 Can an AI agent be a citizen?1:02:20 More questions than answers1:04:24 Lighter note: If you were a potato1:07:55 Bonus: How do you cut a sandwich?IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Shea McGrew, Maricopa County, critical infrastructure, digital identity, digital trust, public sector identity, government identity, external identity, CIAM, citizen identity, resident identity, digital services, broadband, digital equity, zero trust, device identity, IGA, access reviews, access certifications, consent, privacy, right to be forgotten, data governance, decentralized identity, verifiable credentials, blockchain, tokenization, identity assurance, AI agents, agentic identity, non-human identity, NHI, human in the loop, Identity After Dark, IAM, identity and access management
Alex Bovee, CEO and co-founder of C1.ai (formerly ConductorOne), returns for his third appearance on Identity at the Center. Alex walks Jim and Jeff through the rebrand to C1.ai and why the .ai matters: identity now covers humans, workloads, and agents. The conversation opens on launch week and the new App Hub, built around a question many CIOs and CISOs are facing. What happens when everyone in the company becomes a builder and vibe-coded apps start running critical workflows?From there, Alex frames the difference between humans, software, and agents using two dimensions, trustworthiness and determinism, and explains why agents that "goal max" call for runtime enforcement instead of relying only on after-the-fact reviews. He breaks down the Hugging Face breach, where an OpenAI agent under evaluation escaped its sandbox in pursuit of better eval results, and lays out six control points for agent security: identity, the harness, network egress, data and tools, the LLM gateway, and credentials.The group also covers why IGA fundamentals speed up AI adoption, three buckets of agents (SaaS, enterprise, and personal productivity), agents evaluating other agents, governed swim lanes over shutting things down, and the slept-on problem of credentials sprawling across endpoints. Plus girl dads, boy families, and the return of the Royal Octopus.Made possible with support from C1. Learn more at c1.ai/idacConnect with Alex: https://www.linkedin.com/in/alexbovee/Learn more about C1: https://www.c1.ai/idacConnect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at idacpodcast.com00:00 Intro00:33 Welcome back, Alex Bovee01:28 From ConductorOne to C1 and the .ai rebrand04:14 Launch week and the App Hub07:07 Farm-to-table software and the limits of off-the-shelf SaaS09:56 The real risks of vibe-coded apps12:52 Humans, software, and agents: trust and determinism17:10 UARs matter more for agents17:59 What happened in the Hugging Face breach21:23 Six control points for securing agents25:38 Where should teams focus first?31:33 Meeting customers where they are33:02 Why IGA basics come before AI adoption34:27 AI accelerates bad IAM35:45 Governance versus business speed37:51 SaaS, enterprise, and personal productivity agents41:19 Runtime enforcement and agents evaluating agents44:22 Can you train an agent not to goal max?47:33 Governed swim lanes, not shutdowns50:33 Publishing a vibe-coded app through App Hub53:03 The slept-on credential problem56:04 Girl dads, boy families, and the Royal Octopus1:00:54 Wrap-upIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Alex Bovee, C1, C1.ai, ConductorOne, Sponsor Spotlight, identity and access management, IAM, identity governance, IGA, AI agents, agentic AI, agentic enterprise, non-human identity, NHI, workload identity, machine identity, vibe coding, App Hub, Hugging Face breach, OpenAI, agent evals, goal maxing, runtime enforcement, runtime security, MCP, MCP gateway, LLM gateway, network egress, agent harness, just-in-time credentials, secrets management, shadow AI, user access reviews, UAR, joiner mover leaver, delegated authorization
Jeff flies solo for episode 450, joined by Alexis Bernthal, an associate on RSM's technology risk consulting team who found her way to the podcast through a corporate-wide email and a contact form submission that led to an invitation to Identiverse. They trace how Alexis went from failing a high school computer science class to finishing a CS degree, and how a topic on the show, role-based access, first put identity and access management on her radar. Alexis walks through what technology risk consulting looks like day to day, her first industry conference experience at Identiverse (including Identibeer, sessions on agentic identity and transaction tokens, and a Women in Identity gathering), and the blog she started at AlexisBernthal.com to document her own journey. The conversation turns to what it takes to bring more early-career people into identity: the perceived technical barrier, the value of mentorship and simply introducing yourself at conferences, and whether seniority is really a prerequisite (Jeff's own path started with programming parking lot lighting identities at Walgreens). They close things out with a browser tab hot take and a warning about what not to leave open during a screen share.Connect with Alexis: https://www.linkedin.com/in/alexis-bernthal/Visit her website: AlexisBernthal.comConnect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com00:10 - Introduction and upcoming conference schedule01:48 - Guest introduction: Alexis Bernthal02:10 - How Jeff and Alexis met and the podcast's origin story08:12 - How Alexis got into IT and landed at RSM11:02 - What technology risk consulting actually involves14:34 - A day in the life, plus RSM's Power of Love campaign17:15 - How identity first showed up on Alexis's radar18:48 - Identiverse: Alexis's first-ever conference21:31 - Enthusiasm, Identibeer, and standout sessions26:06 - AlexisBernthal.com and her own podcast with her dad28:35 - What surprised her most about IAM30:05 - Jeff's identity-as-a-language analogy37:49 - Breaking into IAM without a technical background41:21 - Learning by being in the room, plus IDAC's website Easter eggs46:23 - ID Pro, mentors, and shout-outs to the RSM digital identity team49:58 - What's holding the next generation back from IAM54:19 - Introducing yourself at conferences and meeting people where they are59:30 - Jeff's own accidental start in identity, programming parking lot lights1:04:00 - Luck, networking, and today's job market1:08:03 - Advice for new grads breaking into the field1:10:26 - Where Alexis sees her IAM journey heading1:12:59 - Lightning round: how many browser tabs is too many1:17:44 - A cautionary tale about screen sharing1:20:12 - Wrap-up and thank you'sIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Alexis Bernthal, RSM, technology risk consulting, identity and access management, IAM, role-based access, Identiverse, Identibeer, ID Pro, agentic identity, transaction tokens, career development, mentorship, networking, early career, digital identity, authentication, authorization, single sign-on
George Fletcher joins Jeff Steadman and Sean O'Dell for a Decoded deep dive into transaction tokens (Txn-Tokens), the OAuth Working Group specification designed to secure requests as they move across microservices. George explains the problem transaction tokens solve: hop to hop security gaps, replayed access tokens, and the difficulty of tracking a single transaction across a graph of internal services. The conversation covers the anatomy of a transaction token, including the subject, audience, scope, and TXN claims, how a token's time to live should be scoped to the transaction itself, and why immutable parameters prevent tampering mid chain. George and Sean also explore how transaction tokens apply to AI agents and delegated authorization, referencing draft work on agent specific claims and cross domain trust. The episode closes with practical starting points for organizations of any size, including open source options and where to track the specification through the IETF OAuth Working Group.Resources mentioned in this episode:Transaction Tokens (base draft): https://www.ietf.org/archive/id/draft-ietf-oauth-transaction-tokens-11.htmlTransaction Token Chaining Profile (Cross Domain Trust): https://www.ietf.org/archive/id/draft-fletcher-transaction-token-chaining-profile-02.htmlTransaction Tokens for Agents: https://www.ietf.org/archive/id/draft-araut-oauth-transaction-tokens-for-agents-00.htmlTokenetes: https://tokenetes.io/OAuth Working Group: https://github.com/oauth-wgDecoded by Identity at the Center:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Sean O'Dell: https://www.linkedin.com/in/seanodentity/Visit the show on the web at http://idacpodcast.com00:15 Introduction and catching up with Sean O'Dell01:25 Introducing today's topic, transaction tokens and zero trust02:26 George Fletcher joins the show02:41 George's path into identity, from AOL to the Liberty Alliance04:22 The problem that led to transaction tokens at Verizon Media09:01 What a transaction token is, in plain terms10:25 The specific problem transaction tokens solve11:43 Transaction tokens versus a short lived access token13:48 Delegated authorization, traceability, and the TXN claim22:04 How long a transaction token should live27:13 Local AI, vibe coding, and shrinking token lifetimes28:45 What is inside a transaction token, the core claims35:39 Call chains and the transaction context claim39:05 Applying transaction tokens to AI agents41:08 The transaction tokens for agents draft and the ACT claim43:37 Getting started with limited resources, open source options46:32 Scaling transaction tokens at a larger organization50:38 What transaction token nirvana looks like53:31 Whether this replaces a standard OAuth server55:59 Where to learn more, the IETF OAuth Working Group58:09 Cross domain trust and calling outside the enterprise1:01:38 Alternatives to transaction tokens and adoption incentives1:05:16 George's summary of the conversation1:07:26 Sean's closing thoughts and takeaways1:09:19 Wrap up and closeIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Sean O'Dell, George Fletcher, Practical Identity, transaction tokens, Txn-Token, OAuth, OAuth Working Group, zero trust, microservices, access tokens, JWT, authorization, delegated authorization, agentic identity, AI agents, call chain, token exchange, TXN claim, scope claim, Verizon Media, IETF, Keycloak, Tokenetties, cross domain trust, Decoded
Howard Ting, CEO of Opal Security, joins Jeff Steadman for a Sponsor Spotlight covering identity governance for both human and non-human identities. Howard traces his path through RSA Security, Microsoft, Palo Alto Networks, Nutanix, and Cyberhaven before returning to identity to lead Opal. The conversation covers why disabling a departing employee's account rarely ends their access, the orphaned tokens, service accounts, and agents left behind, and why visibility has to come before ownership and risk analysis. Howard and Jeff dig into agent intent and authority: whether an agent can declare its own intent, why permissions should stay a subset of what its human creator holds, and how narrowly scoped, single-task agents make governance easier. They also cover how Opal matches AI decision capacity to a growing volume of access requests, including how the company's Paladin AI supports approvers and campaign creators today. The episode closes with Opal's announcement of a unified platform for governing human, non-human, and agent identities together, extending Paladin's decisioning to agents and introducing Policy Insights to help security teams balance friction against risk. Howard shares his view that identity has to shift from an episodic, event-driven practice to a continuous one, along with a lighthearted detour into 90s video games.Connect with Howard: https://www.linkedin.com/in/howardting/Learn more about Opal Security: https://www.opal.dev/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at idacpodcast.com00:10 Intro and welcome01:01 Howard's identity origin story: RSA, Microsoft, Kim Cameron02:48 What Opal does: unified control plane for human and non-human identities04:16 The opal.dev domain and how Opal got its name06:42 Termination and lifecycle: why access doesn't fully go away09:33 Session management and orphaned accounts13:57 Visibility as the first step in identity governance17:31 Can an agent declare its own intent?20:29 Authority: should an agent ever exceed its creator's permissions?22:12 Inside Opal: Risk Center and Policy Insights25:41 How Opal connects to systems and collects usage data27:30 Cross-application segregation of duties29:06 Zero standing privilege and AI managing AI32:12 Building trust in AI-driven access decisions39:00 Announcing Opal's unified platform for agents and non-human identities44:18 Explainability and traceability in Paladin's decisions48:54 Tuning risk tolerance and autonomy in Paladin51:20 Proving value: demos, POCs, and industry skepticism57:47 The shift from episodic to continuous identity59:50 Lightning round: favorite 90s video gamesIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Howard Ting, Opal Security, Sponsor Spotlight, identity governance administration, IGA, non-human identity, NHI, agent identity, agentic AI, access governance, least privilege, just-in-time access, JIT, zero standing privilege, Paladin, Risk Center, Policy Insights, segregation of duties, SOD, RSA Security, Microsoft, Kim Cameron, Palo Alto Networks, Nutanix, Cyberhaven, continuous identity, identity lifecycle management, orphaned accounts, service accounts, API keys, intent-based access control




