Skip to content
PodcastsTechnologyIdentity at the Center

Identity at the Center

Identity at the Center
Identity at the Center
Latest episode

443 episodes

  • Identity at the Center

    #443 - Ghosts in the Machine with John Huyette and Omer Arshed

    2026/08/24 | 1h 13 mins.
    Jeff and Jim are joined by John Huyette, AI Risk Leader at RSM, and Omer Arshed, North American Digital Identity Leader at RSM, to explore how identity controls can help organizations manage the growing risks of AI agents. John introduces five laws for managing AI risk: governability, lineage and integrity, trust boundaries, authority containment, and human impact. The conversation connects those ideas to familiar IAM principles including ownership, auditability, zero trust, least privilege, just-in-time access, privileged access management, and continuous monitoring. They also discuss prompt injection, shadow AI, human accountability, and why organizations should start by building an honest inventory of the AI capabilities already operating in their environments.

    5 Laws of AI Risk: https://www.linkedin.com/feed/update/urn:li:activity:7487942457075257344/
    Connect with John: https://www.linkedin.com/in/john-huyette-1373906/
    Connect with Omer: https://www.linkedin.com/in/omerarshed/

    Connect with us on LinkedIn:

    Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/

    Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/

    Visit the show on the web at http://idacpodcast.com

    Timestamps

    00:00 Introduction, 3D printing, and conference updates
    06:58 Introducing John Huyette and Omer Arshed
    07:52 John’s path from technology risk to AI risk
    12:11 Omer’s identity origin story
    13:43 The five laws for managing AI risk
    18:00 What “ghosts in the machine” means for identity
    20:17 Governability and ownership of AI identities
    25:17 Do you know what has access to what?
    29:43 Applying decades of IAM lessons to AI
    32:35 Lineage and integrity
    35:20 Building an AI bill of materials
    37:12 Trust boundaries and external data
    38:36 Prompt injection and untrusted content
    42:48 Applying zero trust principles to AI agents
    47:26 Authority containment
    49:56 PAM, least privilege, and just-in-time agent access
    56:22 Human impact and accountability
    58:41 Is agentic AI really a new identity problem?
    01:02:35 Starting with lower-risk AI use cases
    01:04:21 Where organizations should start
    01:05:07 Shadow AI and zombie accounts
    01:07:09 What excuses would an AI give during an access review?
    01:12:20 Wrap-up

    Keywords

    IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, John Huyette, Omer Arshed, RSM, AI risk, AI agents, agentic AI, AI governance, governability, lineage and integrity, trust boundaries, authority containment, human impact, shadow AI, identity governance, IAM, zero trust, privileged access management, PAM, least privilege, just-in-time access, non-human identity, NHI, prompt injection, AI identity, access governance, continuous monitoring
  • Identity at the Center

    #442 - Identiverse 2026 - Identity After Dark with Bravura Security

    2026/08/19 | 1h 29 mins.
    Recorded live at Identiverse 2026 in Las Vegas on June 17, Jeff and Jim are joined by Bart Allan, General Manager at Bravura Security, for a live recording with a studio audience. In a late-night talk show format, the three host an open Q&A driven by IAM practitioners in the room. From securing AI identities to whether access reviews are headed the way of the password, this is an unscripted conversation driven by practitioners for practitioners. Topics include identity as a business enabler, zero standing privilege, agentic authentication, standards for AI agents, vendor relationships, the captive customer problem, community, and hiring IAM talent. Thanks to Bravura Security for supporting the Identity at the Center podcast.

    Connect with Bart: https://www.linkedin.com/in/bartholomewallan/
    Learn more about Bravura Security: http://bravurasecurity.com/idac

    Connect with us on LinkedIn:
    Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
    Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
    Visit the show on the web at http://idacpodcast.com

    00:00:00 Welcome and Introduction
    00:03:00 AI Identities: Should IAM Teams Panic?
    00:07:30 Identity as a Business Enabler vs. Cost Center
    00:24:00 Continuous Identity and the Future of Access Reviews
    00:35:00 Zero Standing Privilege and JIT Access
    00:38:00 Standards for Agentic AI
    00:46:00 Vendor Relationships and the Captive Customer Problem
    00:55:56 Normalizing Rip and Replace
    01:01:00 IDPro, Identity Beers, and Building Community
    01:11:00 Agentic Authentication and Non-Human Identities
    01:18:00 Hiring IAM Talent
    01:26:00 Team Diversity and Multiple Perspectives
    01:27:00 Closing

    Identity at the Center, IDAC, Jeff Steadman, Jim McDonald, Bart Allan, Bravura Security, Identiverse 2026, Identiverse, IAM, identity and access management, identity security, AI identities, agentic identity, agentic authentication, non-human identities, NHI, access reviews, zero standing privilege, JIT access, continuous identity, IGA, vendor selection, identity community, IDPro, IdentiBeer, live podcast
  • Identity at the Center

    #441 - Identiverse 2026 - Sachini Siriwardene and Ian Glazer

    2026/08/17 | 37 mins.
    Live from Identiverse 2026 in Las Vegas, Jeff and Jim sit down with Sachini Siriwardene, winner of this year's Kim Cameron Award, along with Ian Glazer of the Digital Identity Advancement Foundation (DIAF). Sachini shares how she moved from open banking API security into consumer identity work at a bank, and what led her to apply for the award named after identity pioneer Kim Cameron. Ian explains DIAF's mission to remove financial barriers to industry participation and previews the upcoming Vittorio Bertocci award for standards contributors. The conversation covers agentic AI and non-human identity governance, the AuthZen specification, continuous access management, and how practitioners can separate real AI capability from marketing hype. The group also swaps favorite hallway conversations from the show floor, including a discussion on extending the shared signals framework beyond RISC and CAPE, before wrapping with some very Vegas talk about the Sphere.Connect with Sachini: https://www.linkedin.com/in/sachini-siriwardene/Connect with Ian: https://www.linkedin.com/in/iglazer/Learn more about the Digital Identity Advancement Foundation: https://diaf.org/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com00:00 - Cold open and conference banter01:35 - Jim's origin story with identity and Kim Cameron03:22 - Welcoming Sachini Siriwardene and Ian Glazer04:02 - Ian explains the Digital Identity Advancement Foundation05:54 - How Sachini got into identity through open banking08:46 - The moment identity clicked as mission critical09:47 - Agentic AI and non-human identity governance11:25 - Optimist or pessimist on AI and the job market14:45 - Applying for and winning the Kim Cameron Award15:41 - How DIAF selects award recipients17:21 - Standout sessions and the AuthZen specification18:36 - First impressions of Identiverse20:01 - Advice for future award applicants22:03 - Managing agentic identity in practice23:16 - Separating AI hype from real capability24:32 - Where the identity industry can improve27:08 - Acting fast without chasing hype28:05 - Favorite hallway conversations29:23 - Extending the shared signals framework30:39 - A D&D themed conference talk31:08 - Vegas talk and the Sphere experience34:19 - Wrap up and how to support DIAFIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Sachini Siriwardene, Ian Glazer, Identiverse 2026, Kim Cameron Award, Vittorio Bertocci Award, Digital Identity Advancement Foundation, DIAF, agentic AI, non-human identity, AuthZen, continuous access management, open banking, OAuth2, FAPI, shared signals framework
  • Identity at the Center

    #440 - Identiverse 2026 - Mike Kiser

    2026/08/10 | 52 mins.
    Recorded live at Identiverse 2026, Jeff and Jim sit down with returning guest Mike Kiser, Director of Strategy and Standards at SailPoint, for a wide-ranging conversation that spans two of the standards world's most active frontiers. The first half breaks down C2PA, the Coalition for Content Provenance and Authenticity, explaining how it differs from digital watermarking, how metadata and cryptographic signatures build a chain of custody for media, and why this work connects directly back to identity. The conversation then shifts to AI agents and the challenge of defining and governing intent, with Mike drawing an extended analogy to the early, under-regulated days of space exploration. The episode closes with reflections on the value of hallway conversations and community at Identiverse.

    Connect with Mike: https://www.linkedin.com/in/mike-kiser/

    Connect with us on LinkedIn:

    Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/

    Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/

    Visit the show on the web at http://idacpodcast.com

    00:00 Introduction from Identiverse 2026
    01:00 Mike previews his two Identiverse talks
    01:35 What C2PA is and how chain of custody works
    06:51 Watermarks versus C2PA explained
    10:06 Why content provenance matters for identity
    14:22 Is C2PA a standard or a working group
    16:23 The SpaceX and space debris analogy for agent intent
    20:13 Governing agent publishing without stifling innovation
    22:00 Action Identification Theory and the how versus the why
    27:47 Can an AI actually have intent
    32:34 Why people humanize and fall in love with chatbots
    38:37 The case for locking down intent early
    39:39 Does intent change, or is it a new intent
    46:19 Favorite hallway conversations at Identiverse
    51:03 Wrap up and where to find Mike

    IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Mike Kiser, SailPoint, C2PA, Content Provenance and Authenticity, Identiverse 2026, Shared Signals Framework, AI Agents, Agentic Identity, Digital Watermarking, Decentralized Identity Foundation, Intent-Based Access Control
  • Identity at the Center

    #439 - Sponsor Spotlight - Tuebora

    2026/08/05 | 54 mins.
    This Sponsor Spotlight episode, made possible with support from Tuebora, features Jim McDonald in conversation with Sanjay Nadimpalli, CEO and founder of Tuebora. Sanjay shares his path into identity beginning as one of the first engineers at Aveksa, then discusses how intelligence is reshaping identity governance and administration by replacing static configuration with continuous, context-aware decision making. The conversation covers the concept of governance debt, how AI can interpret organizational intent expressed in natural language, and where human oversight remains essential. The discussion also explores governance of agentic identities, including how they differ from traditional service accounts, the challenges posed by their ephemeral and dynamic nature, and the policy-driven frameworks needed to manage them. Sanjay closes with a reflection on what identity practitioners should be thinking about for the next few years.

    Connect with Sanjay: https://www.linkedin.com/in/sanjaynadimpalli/

    Learn more about Tuebora: https://www.tuebora.com/idac

    Connect with us on LinkedIn:

    Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/

    Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/

    Visit the show on the web at http://idacpodcast.com

    00:00:00 - Introduction and welcome
    00:00:56 - How Sanjay got into identity
    00:02:40 - Full circle moment with Deepak Taneja and Zilla
    00:03:05 - What Tuebora does
    00:04:14 - The story behind the name Tuebora
    00:05:20 - Can intelligence replace configuration
    00:10:05 - Why static configuration falls short today
    00:14:52 - Customer frustrations with legacy environments
    00:21:09 - Comparing this to everyday AI tool use
    00:23:31 - How intelligence drives outcomes
    00:28:42 - Maintaining security control alongside AI
    00:32:38 - The orchestra analogy for AI and human roles
    00:35:28 - Introducing agentic identity governance
    00:36:10 - Why agentic identities differ from service accounts
    00:42:20 - The scale problem of agentic identities
    00:44:00 - Building a framework for agent governance
    00:47:35 - Closing advice for identity practitioners
    00:52:06 - Where to find Tuebora next

    IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Sanjay Nadimpalli, Tuebora, Sponsor Spotlight, identity governance, IGA, agentic identity, AI agents, governance debt, explainability, IAM, access governance, non-human identity, Aveksa, continuous governance, identity governance and administration
More Technology podcasts
About Identity at the Center
Identity at the Center is a weekly podcast all about identity security in the context of identity and access management (IAM). With decades of real-world IAM experience, hosts Jim McDonald and Jeff Steadman bring you conversations with news, topics, and guests from the identity management industry. Do you know who has access to what? Visit us on the web at idacpodcast.com
Podcast website

Listen to Identity at the Center, Dwarkesh Podcast and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features
Identity at the Center: Podcasts in Family