Season 1, Episode 5

Beyond the vault: Why AI agents force us to rethink Privileged Access Management (PAM)

Of the three identity types—humans, non-humans, and AI agents—only one is truly non-deterministic. A human is predictable: Instagram can guess what you’ll buy before you do, and your calendar can tell me when you take your coffee break. A service account is deterministic by design—same server, same window, every time. But an AI agent? As VP, IAM at Northwestern Mutual Rohit Agnihotri argues, “If you are 100% certain of what your agent is doing, you might not have an agent. You might just have a very advanced RPA script.”

That unpredictability is exactly why the concept of “privileged” is breaking down. Every organization defines it differently, and with an autonomous agent, you can’t reliably put a stake in the ground about what it’s doing and accessing. When you can’t control what an identity is or does, vaulting credentials falls apart, too. The vaulting-only model is dead—making PAM as a discipline matter more than ever before.

In this episode, Rohit gets candid with Identity Decoded co-hosts Roy Akerman and Rob Ainscough on a simple truth that’s hard to ignore: the more autonomy an agent has, the more controls you need to put in place.

Key takeaways include:

  • Why “Which identities are privileged?” is the wrong question to ask in the age of AI and non-human identity dominance
  • Understanding the Identity Uncertainty Principle and how to build your risk strategy around it
  • Why outcomes, not tools, should define modern privileged access as the discipline keeps evolving

[00:00:00] Rohit Agnihotri:
All of us have heard some stats around machine identities will outnumber human identities by 82ish to 1. There is one undeniable fact here that there would be too many machine identities to manage. That's just a fact.

[00:00:12] Rob. A:
Rohit Agnihotri has spent nearly two decades helping organizations rethink identity. He's seen what it takes to make identity scale and get the attention it deserves, by building and leading IAM programs to advising executives on strategy.

[00:00:25] Rob. A:
He's also the founder and host of the widely listened to Identity Navigator podcast.

[00:00:30] Rohit Agnihotri:
We have all heard about this castle and moat architecture then went into identities the new perimeter. And identity is not the new perimeter. It was always the decision control plane that evolved beyond moat and castle architecture.

[00:00:42] Roy A.:
The word privilege is not serving us anymore in order to answer this question, not to mention even to control that new reality that we're at. Identity isn't just an operational problem, it's a security one. And most teams are figuring out in real time.

[00:00:56] Rob. A:
This is the podcast where we reverse engineer the meaning of identity security, sharing candid conversations about the people building, fixing, and rethinking identity security from the inside.

[00:01:07] Roy A.:
I'm Roy Akerman. And

[00:01:08] Rob. A:
I'm Rob Ainscough.

[00:01:09] Roy A.:
Let's dive in.

[00:01:10] Rob. A:
Let's do it.

[00:01:17] Rob. A:
Welcome Rohit to the show today, the identity navigator himself. We're very pleased to have you on the show. It's a great honor for us to have you on. So we thought we'd kick off, you know, just a bit of background. Everyone's got their own identity journey. And obviously you've got a really interesting one, so it'd be great if you could just take us through that identity journey.

[00:01:34] Rohit Agnihotri:
Thank you for invite. I'm very excited to be here. Uh, my identity journey, it's not as dramatic as some of the other people's journey honestly. Straight out of the college, I got a job. It was a, it was a cool gig. I used to write code for the back end systems and whatnot. It got repetitive really soon. I like to code but then, you know, one of my college seniors offered me more money to work for a startup,

[00:02:11] Rohit Agnihotri:
And one of my tech leads showed me to implement single sign-on using an older tool which was called Oracle Identity Federation.

[00:02:19] Rob. A:
Oh, wow

[00:02:19] Rohit Agnihotri:
And single sign-on for, for me that time just felt magical, right? Like, using my enterprise identity credentials to log in into something else, and I don't even have to provide my passwords.

[00:02:29] Rohit Agnihotri:
So that is where I got interested in identity and then, you know, continued to, uh, lean into it. Got relatively okay at it and then, you know, I started enjoying it when, when financial rewards and, and accolades started coming in, then I really started, uh, loving identity. Obviously there is more to it, but yeah, that is, that is more or less my journey into identity.

[00:02:49] Rob. A:
Classic pivot into identity there, and learning to love identity. We were doing our research. We were thinking about what the, you know, the important things we could talk about, uh, in this podcast were that, that our viewers would love to hear about. And something you talked about on one of your recent podcasts really came to life, which was privileged access management, right?

[00:03:07] Rob. A:
One of the most interesting and probably feared, I'd say, disciplines within identity. It's certainly something I feared, uh, when I did it. But could you talk us through a bit about, you know, privileged access management? W- where are we going with it? What's it all about? How is it gonna deal with the challenges of the future?

[00:03:24] Rohit Agnihotri:
Absolutely, and I, and I find that- It is really a fascinating space right now, not just because of all of us know this, this pri- you know, stores the keys to the kingdom, so we are storing that and, and preventing that. But more than that, how the space is evolving really fascinates me. So all of us have heard some stats around machine identities will outnumber human identities by 82ish to 1 or 144ish to 1, depending on which research that we look at.

[00:03:52] Rohit Agnihotri:
But there is one undeniable fact here that there would be too many machine identities to manage. That's, that's just a fact. We have also come to know that vaulting all of these credentials might not be logical, just because, you know, A, the licensing cost would be too much, and B, uh, these identities by itself are very non-deterministic in nature, so if something spins up, does its job, and then doesn't exist, what are you really vaulting?

[00:04:19] Rohit Agnihotri:
And the third thing that we have identified is just the access reviews that has to go into all of these vaulted credentials. That is not fun for anybody and brings so much bad reviews or bad publicity for identity and access management team. So just with all of this, we had to move towards something which is more secure, which is more safer, right?

[00:04:40] Rohit Agnihotri:
All of us understand that, you know, these credentials out there, these standing privileges that are out there are potentially, if not the number one attack vector, they are definitely one of the major attack vectors in the enterprise, right? Everybody, when they are trying to navigate vertically or laterally or horizontally, all of these attackers are trying to find an unused credential that they can leverage and then do privilege escalation based upon that.

[00:05:06] Rohit Agnihotri:
So we identified a few things here. Access reviews for these number of identities is not going to work. Licensing is going to be a big pain in the neck if we are trying to manage this. Standing privileges do not work, and everybody's trying to find an identity that they can leverage. So that is where we are moving towards, and we all have heard this.

[00:05:23] Rohit Agnihotri:
It's not a new concept anymore. But everybody in the industry is trying to move towards, first, from vaulting to just in time, and then ideally from just in time to zero standing privileges. That solves so much of our, so much of our problems. And also, you know, with agentic AI coming into this, this gets a new dimension in itself, where this decision control plane is actually shifting.

[00:05:47] Rohit Agnihotri:
So a lot of good things happening out there, and I'm very interested to see how this space evolves in the next few years.

[00:05:53] Roy A.:
I think the title of th- that podcast was, like, fairly bold, right? It was PAM is dead or, or something around that, right? So, like, what is it that you're trying to, to push through? Is it that the traditional way of doing PAM cannot really stand against the new reality?

[00:06:10] Roy A.:
What has changed? Or what's the reality checkpoint that you had?

[00:06:14] Rohit Agnihotri:
So, A, I grew up watching Bollywood movies. I absolutely like tearjerkers and whatever drama. I love drama movies, right? So I have this penchant of naming my podcast episodes, which is just a little bit too dramatic. But yeah, PAM, I think if we go to…

[00:06:29] Rohit Agnihotri:
If we continue doing what we have been doing for last so many years, uh, just vaulting domain credentials, trying to vault everything, and just identifying our success as to how many credentials are vaulting, that's not going to work. And I think that model or that sole model is definitely dead. I'll give you an example, right?

[00:06:49] Rohit Agnihotri:
Even in terms of when we are talking about non-human identity management, and everybody in the industry is talking about it, but we are trying to classify or we are trying to put too many nomenclature on this. This is type of identity A, this is identity B, this is identity C. Now, I as a developer am being prompted for MFA all the time.

[00:07:08] Rohit Agnihotri:
If I create a service account, by definition, service accounts might not have MFA. I have just prevented a control. I do not have to do MFA anymore because that is a service account and I can share that identity across my team, right? And, and nobody's prompted. So there are things like this. There are shortcuts like this that are coming out from the older PAM model, and we have to be more intelligent about it, I would say, or more intentional about it as to how I would say it.

[00:07:35] Rohit Agnihotri:
So don't, don't just focus on vaulting. Focus on behavior-based identity nomenclature rather than just attribute-based identity nomenclature. Think about just in time and zero standing privileges. But I think most important thing which is coming out of the new PAM is creation of that authorization plane, right?

[00:07:54] Rohit Agnihotri:
That account broker or service broker where you never have access to the account. It's just a broker layer or the authorization layer that is sitting in between. And I think this is where new PAM is moving towards it.

[00:08:07] Rob. A:
I'm very much in the same boat because I, I think, I think when we say PAM, though, we have to be a little bit careful, right?

[00:08:12] Rob. A:
Because I think there's this jump that a lot of people I see as I talk to people in industry make, which is P- PAM equals vaults, vaults equals PAM But PAM as a, is a discipline, right? It's a discipline about risk and risk reduction and risk containment and managing risk. And I think PAM as a discipline, certainly not dead, probably more important as we move into agentic future than it's ever been.

[00:08:40] Rob. A:
But vaulting as the application of how to do that in the enterprise, now that's a different story, right? I talk to people who are really, really struggling with that. I think it's probably the default for people to struggle with implementing that and, and controlling that risk with it. So I think you're completely right, because we, we've gotta get this right, haven't we?

[00:08:59] Rob. A:
Yeah. Like, we've gotta get this right. We've gotta work out how we're gonna control this privileged risk.

[00:09:03] Roy A.:
Gents, you just, like, shifted the security control point from who has access to the vault, and if they have access to the vault, we can trust them to do whatever they want, which, whatever key that they have access to, to someplace else, right?

[00:09:17] Roy A.:
I don't know if it's real time-ish or, like, but definitely someplace else, because you've just realized that you need to do this for machines as well.

[00:09:24] Rohit Agnihotri:
As practitioners, we have to be very intentional, very smart, and we have to look at things that best reduces the risk. Rob, as you were mentioning, uh, doing PAM is not the objective here.

[00:09:34] Rohit Agnihotri:
Reducing the risk is objective, and whatever gets us there is the right answer.

[00:09:39] Rob. A:
It's not a tool answer, right? It's a discipline of containing risk, and there's gonna be multiple aspects to that across, you know, human, non-human, agentic. There's gonna be different aspects to that that we need to think about.

[00:09:50] Rob. A:
But I think you've talked about it before, Rohit. It's like outcomes matter. It's the outcome that matters, right? How are we protecting what really matters to the business is the key thing.

[00:10:01] Roy A.:
What Rob just said, like, brings me to wonder how privileged the, uh, AI agents in your organization are, right? It's like a highly financial and, like, healthcare that you're dealing with and other, other places, like…

[00:10:12] Roy A.:
So, so the data is very sensitive. The infrastructure is super complex, but you need to progress How privileged are they?

[00:10:20] Rohit Agnihotri:
That's a great question, and actually almost impossible to answer, right? Because at any company that I work for, there is always a very different definition of privileged, right? So anytime I walk into a meeting with my executives, this company, previous companies, companies before that, even when I was consulting, everybody was like, "Define privileged."

[00:10:39] Rohit Agnihotri:
And there is no one answer that fits, so everybody was defining privileged in their own manner. So to answer how privileged are our identities really, or, or agents, is a very, very hard question for me to answer. I'm also looking at what my agents can do. That's number one. But most importantly, how much aware am, I that my agents are doing something at this time?

[00:11:02] Roy A.:
The word privilege is not serving us anymore in an- i- in order to answer this question, not to mention even to control that new reality that we're at. So privileges and outcomes, there's a distance between them when it comes to an AI agent, right? And I think you both answered the question. I mean, I'm looking at this from the perspective of, of the security lens, which is It's not the right question to ask how privileged they are, it's how free are they in doing things with– on those business outcomes, or like strive to arrive to those business as- uh, outcomes.

[00:11:37] Roy A.:
It kind of like the means are not really relevant anymore, but the results are. So we want to control the results. The results are the risks and vice versa.

[00:11:45] Rob. A:
And it's, it's a really difficult one when it comes down to it, 'cause, 'cause my feeling on this is there's some real shaky identity foundations out there which are really, I think, vulnerable to the types of things that agents are able to do, right?

[00:12:01] Rob. A:
We already know through what Anthropic talked about last year, you know, agents can be subverted and used to complete reconnaissance and leverage identity to achieve nefarious goals, right? We know that's already there, and that's way before Mythos and all the developments this year, right? Which probably only make it scarier.

[00:12:18] Rob. A:
I think given that we know that, what, what's it really gonna expose about identity that we're probably not that proud of? Because, you know, we're talking about NHI like that's a new thing and a new problem, right? In various formats, that's been around, what, 15 years, 20 years. The cloud transition probably accelerated that process.

[00:12:38] Rob. A:
Some big numbers there in terms of NHIs. We're always kind of playing catch up, and there's this real like almost debt in identity that I really think about with agentic that could be exposed.

[00:12:49] Roy A.:
When we've had our first talks, you've mentioned that you have a way to look at identities or AI agents in a different way, right?

[00:12:55] Roy A.:
To the– what some kind of formula that will allow us to, to have a framework. Be very happy if you can explain it a little bit better.

[00:13:01] Rohit Agnihotri:
So this is where it stemmed from. As we were think– as we were thinking and talking about it, we established this criteria of defining privilege is a hard thing to do, or at least it is pretty subjective, right?

[00:13:11] Rohit Agnihotri:
And then we moved over to there is an excellent research, so there are many frameworks out there today, uh, which have a lot of merit about, okay, then what are the type of agents that you are want– you want to create? Do you want to create a like an intern or an observer agent? Do you want to create a chatbot?

[00:13:26] Rohit Agnihotri:
Do you want to create an agent who acts like a senior engineer, a principal engineer, or maybe like a CEO? And then you can see, okay, what is the risk appetite associated with each of those personas if you are associating agents with a principal engineer can do much more damage than potentially a senior engineer or an intern, right?

[00:13:45] Rohit Agnihotri:
And, and there is a flaw to that logic as well. We are trying to extend the same human concepts to agents as well, right? What I mean by that is we all like to believe that we have free will, a- and maybe some of us do, but not all of us do. We are very pattern-driven, behavior-driven people as, as a whole, right?

[00:14:05] Rohit Agnihotri:
Rob, like Instagram can potentially predict what are you going to buy next, even if they don't tell you, but they're going to predict, right? I can look at your schedule for maybe a couple of years and, and exactly tell you the time, what time do you get out for a coffee or what time do you go out for a walk.

[00:14:21] Rohit Agnihotri:
So we are very predictable by nature, right? Then we have these human emotions like guilt or shame or being employable and things like this. And this is where agents are free. They have no guilt, they have no shame. Uh, they don't need to keep their job. Uh, they are by nature unpredictable, right? And sometimes it is a very black box, so we cannot say by certainty what is an agent going to do.

[00:14:47] Rohit Agnihotri:
It can piece together tools or it can piece together pathways that we might have never thought about, right? So this is where this uncertainty is coming from. And that is where, where I believe was identity uncertainty principle that I have proposed. What this is, is basically the fundamental law of agentic AI security, okay?

[00:15:06] Rohit Agnihotri:
It's very simple by nature. What it says is, as the autonomy increases of an agent, the certainty that it is the same agent that you started with exponentially decreases, right? So more autonomous your agent is, the, the certainty of that agent was the one that you started will, will decay, right? So it's an inverse relationship simply.

[00:15:29] Rohit Agnihotri:
And to counteract that, you will have to put more controls in place. You will have to identify your dynamic risk scoring. You will have to identify your behavioral analytics, and those behavior analytics would be very different from human behavior analytics. But this is where I was coming from an identity uncertainty principle, because look at this, right?

[00:15:48] Rohit Agnihotri:
If you are 100% certain of what your agent is doing, you might not have an agent. You just might have a very advanced RPA scripts that is using an LLM model, and that is going to cost you a ton of money, right? So this is where identity uncertainty principle is coming from. You know, with the certainty, it decreases as the autonomy of the agent increases.

[00:16:10] Rob. A:
And do you think that feels like just the endpoint is probably not the endpoint, but of a long trend in identity of increasing uncertainty of the identity of what it's there for, of what it's intended for, that we've seen expressed through NHIs into agentic now. It feels like a long-term trend, right?

[00:16:29] Rob. A:
This isn't gonna stop. This isn't gonna change. This is just a new reality that we're, we're dealing with as defenders, right?

[00:16:36] Rohit Agnihotri:
That is absolutely true, Rob, right? And I have been challenged. You know, when I came up with this principle, I tried to peer review it with many of the identity experts, and they had a very rightful question.

[00:16:46] Rohit Agnihotri:
How is this any different from humans, right? We are at a company for a long time, and we accumulate permissions, right, and that is why certifications and all such type of things exist. Also, you know, I could be malicious, and that is why I have insider threat team that is working to identify if there is anything that I'm doing that I shouldn't be doing.

[00:17:05] Rohit Agnihotri:
But the difference is not just the speed and scale at which the agents can function, right? The difference is everything else that we just spoke about, that, you know, they have no shame. They have no guilt. They can identify pathways. So it's more than just the speed and scale. There are other things as well.

[00:17:21] Rohit Agnihotri:
There are maybe no legal ramifications for an agent to go rogue. As the owner of the agent, Rob, you might have legal ramifications, right? But not the agent in itself, right? Yeah. So, so that is where it differentiates from the human concepts to a non-human concepts.

[00:17:34] Rob. A:
But it is interesting. We, we talked about that, right?

[00:17:37] Rob. A:
We talked about coming back to it, PAM and vaults, right, and the games that we create, right? I'm gonna vault your credential. I'm gonna put that in the way. I'm gonna make that a bit annoying for you to use every day. I'm gonna use my service account that I've got access to, I've got the credential for instead, right?

[00:17:51] Rob. A:
It's all goal-seeking behavior. Ultimately, human or agent, you wanna get the job done, and they're gonna be creative about that. Uh, but I think all of this, for me, and I'd be interested in hearing your view, it leads us to a new way of thinking about identity, what's important, and what it's there for, right?

[00:18:10] Roy A.:
While you guys are- kind of like describing a new way to use, um, microscopic visibility into the behavioral aspect of like a non-deterministic thing, or it can be an NHI that is well-crafted but changed, like, uh, frequently. Um, trying to think as with a security mindset, how would I break it, right? And the first things that comes to mind is that, okay, you'll figure out the behavior.

[00:18:36] Roy A.:
You'll have a few control, a few visibility points, a few stabs across the way that will tell you with a high level of confidence what this specific behavior means, what's gonna be the output or, like, several outputs, right? But then an attacker can be faster than your realism or insight systems. And until you figure out if it's bad or, or legit, until you connect the dots, I'll be in.

[00:19:02] Roy A.:
I'll do my gig, then I'll get out. I'm trying to figure out, like, we, you, you solved the broken PAM for visibility. You shifted the focus to the behavioral stabs or, like, visibility points, but what's next? PAM could revoke your access. Count can… PAM can snitched on you and tell, "Oh, uh, somebody, um, um, I don't know, compromised the access to the vault.

[00:19:25] Roy A.:
Let's do, uh, you know, rotation. Let's make this and that." What are you guys are going to do when you see that this behavior becomes malicious?

[00:19:31] Rob. A:
For me, I, I think it's really interesting when, when we… And you've seen a lot of kind of incident response type of situations, right? And when we see, you know, SOC teams respond, we often see the kind of sledgehammer approach of, you know, mass reset of credits 'cause we don't quite know what went on.

[00:19:48] Rob. A:
So we've got this behavioral insight, fantastic. Mm-hmm. But what's the so what? What stands in the way? I heard Martin Sandrin call it speed bumps. What are the speed bumps that are in the way? Mm-hmm. Mm-hmm. Yeah. And that's a really good way of thinking about it. But we've gotta be more, more proactive, particularly in that privileged access area where it really matters.

[00:20:05] Rohit Agnihotri:
That was a great way of putting it, right. And, and you asked, like, what could I do in that situation? So I will polish up my resume. That's number one.

[00:20:16] Rohit Agnihotri:
But most importantly, that is where, you know… And I think the technology now has started to evolve, right? That is why we have this shared signal framework or this continuous access evaluation protocol or paradigm, right? So we have these things. So an agentic AI security, especially if agents are highly autonomous in nature, it cannot be session based.

[00:20:36] Rohit Agnihotri:
Let's say somebody, an employee is fired or an employee is terminated or employee is fined doing something rogue, it is session based. You revoke the token. The token, let's say, will live for 15 minutes or 30 minutes or an hour, and that is where their session can live, right? An agent can do so much damage during that time.

[00:20:55] Rohit Agnihotri:
That is why you need to have a big red kill switch for every agent in your ecosystem.

[00:20:59] Rob. A:
I think that's the important point for me, is having that mindset of identity's the lever And I need the ability to act on that facet. I need the ability to have a kill switch

[00:21:11] Roy A.:
So you guys are going to break the session, so Vault will not be the way to get access or to start a session, and you're gonna put every action under a magnifier and maybe make the access decision on the grand access decision in a fraction of a second every time over and over again.

[00:21:31] Roy A.:
Now, as a security person, I'm getting concerned. I mean, no, as, as from the hacking side, it actually brings like a new reality to IAM in general. I mean, I, I wonder, Rohit, so like if, if you recruit now for a position in your team, and you already face a massive adoption of AI agents What is the top quality that we'll look for from a technical or, like, mindset, what it will be?

[00:21:56] Rohit Agnihotri:
I think the biggest thing for me is first principle thinking, right? Can you break down the problem into its most basic building blocks and go from there, right? Because there is so much information out there, and I wouldn't say there is misinformation because all of us are learning about it. Whatever I'm saying could be absolutely incorrect in next six months.

[00:22:16] Rohit Agnihotri:
I don't know, right? So all of us are learning together. So I think breaking that down, and this is what I love about identity. What I would hire for is first principle thinking. Can you look at the agent and can tell me what does it really mean? Why does this identity uncertainty principle make sense to me?

[00:22:32] Rohit Agnihotri:
Whatever I'm hiring for, I think learning agility and first principle thinking would probably be the two, two things that I would hire for.

[00:22:39] Rob. A:
I completely agree. So I was kind of doing this for 10 years, right? Threat landscape changed radically. That was before agentic, right? There was such change in terms of what was out there, what we were worried about, what we were trying to do, that you need that flexibility.

[00:22:56] Rob. A:
You need that, those changes in thinking, that, that curiosity to think differently and to think about outcomes, as you said before. That's, I think, really useful advice. What we really like to do for our viewers is, like, what's the takeaway? What are the practical things, you know, we've talked about a lot.

[00:23:12] Rob. A:
You've got some tremendous experience you shared and we've discussed. What can they take away? What can they go in on a Monday morning, think differently, do differently for some of the challenges that they're seeing based on what we talked about?

[00:23:25] Rohit Agnihotri:
I was a developer for quite some time, and now so much of the development is black box ex- abstraction.

[00:23:31] Rohit Agnihotri:
I just use the tools that have been created by these geniuses and just have to use them without understanding them. We have been using this line for almost 10 years now, that identity is the new perimeter, right? And now we are moving beyond it, saying with agentic AI that might not be true. But we have to understand that was always a metaphor.

[00:23:50] Rohit Agnihotri:
It was never a true statement, but none of us wanted to admit it because it was just simple for us to sell identity to our bosses and people who were signing the checks. Identity was never the perimeter. The decision control plane was basically the new network, right? And, and identity was the strongest signal.

[00:24:10] Rohit Agnihotri:
Identity was like the drawbridge that was actually leading that charge against, you know, how the decisions are being made.

[00:24:17] Roy A.:
I'm hearing, you know, like, that from excelling from a process perspective in order to be an IM person, now is the time for gloves on. Like, from so many angles, right? With the AI excellency and effectiveness, like, program with a company, we need to be there.

[00:24:32] Roy A.:
With the, like, the decision-making process that we're having for granting access, IM should become much more active, much more real time-ish and maybe much more important person in the security room.

[00:24:46] Rob. A:
I think just to, to add to what you said, Rohit, 'cause I completely agree with what you're saying. I think it's such great advice for people out there.

[00:24:53] Rob. A:
It's a difficult discipline. There are a lot of people out there struggling with what identity means, what it's there for, what it needs to do for the organization. I think it was absolutely fantastic advice.

[00:25:03] Roy A.:
I think that this is a great time, gentlemen, to go to the last part of our show today. Let's put Rohit a little bit under time pressure with our rapid fire questions.

[00:25:13] Rob. A:
We've got four of them. So the first one, what's one identity myth?

[00:25:18] Rohit Agnihotri:
Identity is the new perimeter. That has always been a myth for me. Decision control plane is where the real decisions are made, and identity is the strongest signal. So continue using that on your slides, continue using that in your conversations, but when it comes down to architecture, understand that difference, that identity is not the new perimeter.

[00:25:36] Rohit Agnihotri:
It was always the decision control plane that evolved beyond moat-and-castle architecture.

[00:25:41] Rob. A:
Agreed. Great answer. So we'll move on to the second one. What's one thing that leaders get wrong?

[00:25:47] Rohit Agnihotri:
Identity cannot be bolted on. There has to be more intention around it, and I think a lot of people understand this, but they do not grasp the concept of how to get identity team involved, right?

[00:25:58] Rohit Agnihotri:
And that is where I think a lot of companies are struggling with either the adoption or the right architecture because identity team was invited too late in the game.

[00:26:07] Rob. A:
I completely agree. The next one, I think an even tougher question. What's one hard truth?

[00:26:12] Rohit Agnihotri:
What's one hard truth? All right. So the more money your agent makes, the faster you should be ready to kill it.

[00:26:17] Rohit Agnihotri:
It's not about autonomy. It's not about it… Once you start building agents for your company and it starts making money for you, the more money it makes, be ready to kill it at an instant notice, right? That is how you lean into that agentic AI,

[00:26:32] Rob. A:
AI architecture. That's a big one. That's a big one.

[00:26:33] Roy A.:
I wanna take the next one, if you wouldn't mind.

[00:26:35] Roy A.:
You

[00:26:35] Rob. A:
always steal this one. Yeah.

[00:26:36] Roy A.:
What's the one over-hyped term or belief? that you're sensing? You know, the ones that you're sick of hearing and you know that it's probably not that thing, but that's the wave right now, that's the trend?

[00:26:50] Rohit Agnihotri:
I would be real controversial here and offend some of my friends in the industry, non-human identity management, right?

[00:26:56] Rohit Agnihotri:
I just believe that is too large a term to be grouped into a singular thing, right? You cannot have a non-human identity management program. Your API keys work very differently from your agents, work very differently from your OAuth tokens. So we are trying to oversimplifying a concept which is not as simple.

[00:27:14] Roy A.:
Yeah. I think that's the, the poison in trying to categorize something too soon, right? While it's still evolving. I, I couldn't agree more. Rohit, thank you for being a perfect guest. It was truly interesting to have this discussion, and I bet that our audience took a lot of it.

[00:27:28] Rohit Agnihotri:
Thank you, gents. It was a pleasure to be here.

[00:27:30] Rob. A:
That's it for this episode of Identity Decoded.

[00:27:33] Roy A.:
If this conversation changed anything that you thought about identity security, share it with someone who's working through the same challenges.

[00:27:39] Rob. A:
And don't forget to follow the show so you don't miss what's

[00:27:43] Rob. A:
next

Identity Decoded

with Roy Akerman & Rob Ainscough

Subscribe so you never miss a new episode.