Skip to content
PodcastsTechnologyIdentity at the Center

Identity at the Center

Identity at the Center
Identity at the Center
Latest episode

439 episodes

  • Identity at the Center

    #439 - Sponsor Spotlight - Tuebora

    2026/08/05 | 54 mins.
    This Sponsor Spotlight episode, made possible with support from Tuebora, features Jim McDonald in conversation with Sanjay Nadimpalli, CEO and founder of Tuebora. Sanjay shares his path into identity beginning as one of the first engineers at Aveksa, then discusses how intelligence is reshaping identity governance and administration by replacing static configuration with continuous, context-aware decision making. The conversation covers the concept of governance debt, how AI can interpret organizational intent expressed in natural language, and where human oversight remains essential. The discussion also explores governance of agentic identities, including how they differ from traditional service accounts, the challenges posed by their ephemeral and dynamic nature, and the policy-driven frameworks needed to manage them. Sanjay closes with a reflection on what identity practitioners should be thinking about for the next few years.

    Connect with Sanjay: https://www.linkedin.com/in/sanjaynadimpalli/

    Learn more about Tuebora: https://www.tuebora.com/idac

    Connect with us on LinkedIn:

    Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/

    Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/

    Visit the show on the web at http://idacpodcast.com

    00:00:00 - Introduction and welcome
    00:00:56 - How Sanjay got into identity
    00:02:40 - Full circle moment with Deepak Taneja and Zilla
    00:03:05 - What Tuebora does
    00:04:14 - The story behind the name Tuebora
    00:05:20 - Can intelligence replace configuration
    00:10:05 - Why static configuration falls short today
    00:14:52 - Customer frustrations with legacy environments
    00:21:09 - Comparing this to everyday AI tool use
    00:23:31 - How intelligence drives outcomes
    00:28:42 - Maintaining security control alongside AI
    00:32:38 - The orchestra analogy for AI and human roles
    00:35:28 - Introducing agentic identity governance
    00:36:10 - Why agentic identities differ from service accounts
    00:42:20 - The scale problem of agentic identities
    00:44:00 - Building a framework for agent governance
    00:47:35 - Closing advice for identity practitioners
    00:52:06 - Where to find Tuebora next

    IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Sanjay Nadimpalli, Tuebora, Sponsor Spotlight, identity governance, IGA, agentic identity, AI agents, governance debt, explainability, IAM, access governance, non-human identity, Aveksa, continuous governance, identity governance and administration
  • Identity at the Center

    #438 - Identiverse 2026 - Sean O'Dell

    2026/08/03 | 39 mins.
    Recorded live at Identiverse 2026 in Las Vegas, Jeff sits down with Decoded co-host Sean O'Dell for a wide-ranging state of the union on continuous identity, shared signals, and the identity questions AI keeps raising. Sean shares what he is hearing on the ground about the upcoming transaction tokens spec, why continuous identity has moved from concept to mainstream adoption, and how shared signals are expanding into commerce. The conversation shifts to AI: the real cost of securing it, why model provenance matters, and the murky question of who is on the hook when an AI agent makes an expensive or harmful decision on your behalf. They debate companion agents, consent versus power of attorney, and whether the identity industry even owns this problem. Sean closes with a simple piece of advice for anyone feeling overwhelmed by AI right now.

    Connect with Sean: https://www.linkedin.com/in/seanodentity/

    Connect with us on LinkedIn:

    Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/

    Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/

    Visit the show on the web at http://idacpodcast.com

    Timestamps:
    00:00 Intro and a Decoded update
    00:44 Transaction tokens spec preview
    01:51 State of the union on continuous identity
    03:39 The questions organizations are asking
    04:34 Is it still all about the data
    05:07 Shared signals framework moving into commerce
    06:40 Is AI a fad at Identiverse this year
    07:11 The real cost of securing AI
    08:00 Model provenance and indemnity
    09:39 IAM for AI versus AI for IAM
    10:18 Trusting agents to act without oversight
    14:51 Assigning authority to the who and the what
    16:13 The cruise booking example and who is on the hook
    20:16 Companion agents, consent, and power of attorney
    23:00 Does the identity industry own this problem
    25:00 Relationship and intent as the real issue
    28:03 Could an insurance market emerge for agentic AI
    29:18 An access review scenario gone wrong
    30:41 Small specialized language models for identity tasks
    32:11 Favorite hallway conversations at Identiverse
    36:05 Wrap up and words of wisdom on AI FOMO

    Keywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Sean O'Dell, Decoded, Identiverse 2026, continuous identity, transaction tokens, shared signals framework, agentic AI, AI security, model provenance, IAM, digital identity, identity and access management
  • Identity at the Center

    #437 - Identiverse 2026 - Pam Dingle

    2026/07/27 | 55 mins.
    Live from the IDAC booth at Identiverse 2026, Jeff and Jim sit down with Pam Dingle, Director of Identity Standards at Microsoft, to unpack agentic identity. Pam breaks down assistive versus autonomous agents, walks through where standards like SPIFFE and OAuth hold up, and explains the difference between delegation, impersonation, and partition. The conversation also covers credential discovery risk, shared signals and revocation, what enterprises should prioritize now, and the value of hallway conversations at Identiverse.

    Connect with Pam: https://www.linkedin.com/in/pameladingle/

    OAuth Actor Profile for Delegation: https://www.ietf.org/archive/id/draft-mcguinness-oauth-actor-profile-00.html

    Connect with us on LinkedIn:

    Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/

    Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/

    Visit the show on the web at http://idacpodcast.com

    Timestamps:
    00:00 Intro and Identiverse 2026 vibes
    04:01 Defining agentic identity
    07:06 Has the earth really shifted
    11:38 An old problem thats been bejeweled
    15:13 From Nulli Secundus to Microsoft
    16:00 How standards are holding up
    19:27 Client ID metadata and just in time trust
    21:41 Shared signals and the revocation problem
    24:43 Deploying agentic identity at scale
    28:11 Registries at scale
    29:04 Delegation authorization and attenuation
    32:33 Delegation vs impersonation vs partition
    36:03 The one thing you can fix right now
    37:56 Favorite hallway conversation
    42:29 The solar system of hallway conversations
    45:51 Remembering Kim Cameron
    48:00 New voices to watch
    52:08 Wrap up and thank you

    Keywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Pam Dingle, Pamela Dingle, Microsoft, Identiverse 2026, agentic identity, agentic AI, non-human identity, delegation, impersonation, SPIFFE, OAuth, identity standards, IAM, digital identity, workload identity
  • Identity at the Center

    #436 - Sponsor Spotlight - P0 Security

    2026/07/22 | 46 mins.
    In this Sponsor Spotlight episode, Jeff Steadman flies solo and welcomes Greg Danyi, co-founder and CTO of P0 Security, to the show. Greg walks through P0's approach to runtime access control, covering how it applies to humans, non-human identities, and AI agents alike. The conversation digs into the difference between authentication and authorization, why zero standing privilege is more achievable now than before agentic adoption took hold, and how dynamic, evidence-based policies can reduce reliance on manual approvals. Greg also shares real examples, including row-level access control for data lakes and a CRM mishap that shows how easily agents can misinterpret intent. The episode closes with a look at where enterprise AI agent governance may be headed over the next few years, plus a lighter conversation about explaining IAM to a 10-year-old. This episode is made possible through the generous support of P0 Security as part of IDAC's nonprofit Sponsor Spotlight series. Learn more at p0.dev/idac.

    Connect with Greg (Gergely): https://www.linkedin.com/in/gergely-danyi/
    Learn more about P0: https://p0.dev/idac/

    Connect with us on LinkedIn:

    Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/

    Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/

    Visit the show on the web at http://idacpodcast.com

    00:00 - Introduction and sponsor acknowledgment
    01:13 - Greg Danyi's path into IAM
    02:18 - What P0 Security solves for
    03:21 - Where P0 fits versus PAM and IGA
    04:46 - Agentic identity as a driver of adoption
    05:27 - MCP servers and unpredictable agent actions
    07:10 - Defining runtime access control
    08:50 - How authentication and authorization work together
    09:07 - Standing access versus expressed intent
    10:16 - Zero standing privilege in practice
    12:27 - Agentic identity as a distinct identity class
    19:24 - Automated evidence for approvals
    20:42 - Walking through a support agent example
    22:13 - Row-level access control for data lakes
    23:35 - Dynamic roles explained
    29:55 - CRUD risks and underestimated concerns
    31:32 - Human intent and giving agents clear direction
    36:32 - Where enterprise AI agent governance is headed
    39:36 - Advice for CIOs and CISOs getting started
    41:15 - Explaining IAM to a 10-year-old
    42:29 - Board games, dice, and calculated risk
    44:00 - Closing thoughts and where to learn more

    Keywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Greg Danyi, P0 Security, runtime access control, agentic identity, zero standing privilege, non-human identity, authentication, authorization, IAM podcast
  • Identity at the Center

    #435 - Majority Rules: IDAC Live at Identiverse 2026

    2026/07/20 | 26 mins.
    Jim McDonald and Jeff Steadman took the Identity at the Center podcast live at Identiverse 2026 in Las Vegas for a crowd-sourced game show called Majority Rules. Identity professionals competed in real time, picking answers to IAM and conference questions in a race to predict the majority. With a prize pool of over $5,000 for the top ten scorers, the stakes were high and the honesty was brutal. The episode also marks a milestone: IDAC hitting two million downloads. Thanks to Shirley Han and the CyberRisk Alliance team, and to sponsors Hyper, Red Block, SlashId, Rubrik, Stratacity, FusionAuth, Nexus, CrowdStrike, Hush Security, PlainId, RSM, and CyberRisk Alliance.

    Connect with us on LinkedIn:
    Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
    Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
    Visit the show on the web at http://idacpodcast.com

    0:00 Introduction and Two Million Downloads Milestone
    1:00 Sponsor and Event Team Recognition
    3:00 How to Play Majority Rules
    4:00 Warm-Up Round Begins
    6:00 Battle Royale Mode Explained
    8:30 Decentralized Identity and the LDAP Reality
    10:30 Las Vegas Evening Entertainment
    11:30 Top Identity Trends at Identiverse 2026
    12:30 Access Certification and the 4:55 PM Click
    13:30 Classic Vegas and Expo Hall Favorites
    14:50 PAM Strategies and the Post-it Note
    16:00 Conference Navigation and Footwear Survival
    18:00 Identity Log Monitoring Chaos
    19:30 Hallway Track Conversations
    20:30 Cloud Entitlements and Everyone Gets Root
    21:00 Sleep Habits at a Security Conference
    22:00 Business Cards in 2026
    23:00 Legacy App Strategy and Thoughts and Prayers
    24:45 Las Vegas Dining Preferences
    25:30 Winners Announced and Closing

    Keywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Identiverse, Identiverse 2026, Majority Rules, live event, game show, IAM, identity and access management, decentralized identity, LDAP, SSO, PAM, privileged access management, cloud entitlements, ISPM, access certification, Las Vegas, cybersecurity, conference
More Technology podcasts
About Identity at the Center
Identity at the Center is a weekly podcast all about identity security in the context of identity and access management (IAM). With decades of real-world IAM experience, hosts Jim McDonald and Jeff Steadman bring you conversations with news, topics, and guests from the identity management industry. Do you know who has access to what? Visit us on the web at idacpodcast.com
Podcast website

Listen to Identity at the Center, Acquired and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features
Identity at the Center: Podcasts in Family