O TYM ODCINKU
The thing that makes an agent useful is the exact thing that makes it dangerous. Keycard co-founder Ian Livingstone breaks down why non-determinism is both the feature and the bug, and why identity, not model quality, is what really gates how much autonomy you can hand an agent. If you have ever clicked "always allow" without reading it, this one is about you.
What we cover:
– Why authentication was enough in the cloud era and stops being enough with agents
– The background check you can't run on an agent, and what has to replace it
– Mission identity: who is acting, on whose behalf, and for what purpose
– Cross App Access, Agent Auth and the protocols trying to fix OAuth
– Consent fatigue, LLM as a judge, and where hard boundaries still belong
– Why MCP ships with an auth story and CLI tools don't
Chapters:
00:00:00 - Introduction
00:03:43 - Why every wave of computing rewrites identity
00:04:50 - The feature and the bug are the same thing
00:10:23 - Why shared secrets break for agents
00:13:36 - The background check you can't run on an agent
00:19:42 - Chargebacks, delegation and proving intent
00:22:16 - Mission identity: a new layer
00:28:07 - Cross App Access, Agent Auth and emerging protocols
00:33:02 - MCP vs CLI, and how Keycard works
00:43:22 - Identity three years from now
🌐 Tessl: https://tessl.io
🔔 Subscribe for weekly episodes on AI-native development
Where do you draw the hard line for your own agents? Tell us in the comments.
POKAŻ NOTATKI 🔗
TRANSKRYPCJA 🔗
00:00:00.080 --> 00:00:07.360
Ultimately, the identity question is, how do I ensure when an agent does make a mistake, it doesn't do something catastrophic I didn't intend?
00:00:07.519 --> 00:00:10.080
This thing is built on like a probistic distribution.
00:00:10.240 --> 00:00:14.320
The feature is that it can reason and it can guess over large amounts of data, right?
00:00:14.480 --> 00:00:17.359
Um, and that it is non-deterministic, that's a feature.
00:00:17.440 --> 00:00:17.600
Right.
00:00:17.760 --> 00:00:21.039
The bug from a security perspective is that it's non-deterministic.
00:00:21.120 --> 00:00:23.120
Yeah, because the feature and the bug are the same.
00:00:23.199 --> 00:00:31.440
And the final question is how do I know that an agent is performing actions aligned with the intent of whoever set the agent to do something?
00:00:32.640 --> 00:00:39.280
The AI Native Dev is a podcast with developers and engineering leads at the cutting edge of AI and agentic coding.
00:00:39.520 --> 00:00:49.679
Join your host, Glyfer Johnny, and me, Simon Mayfor, every week as we chat with the most exciting voices in AI and tackle the biggest questions facing developers today.
00:00:50.320 --> 00:00:52.479
This is the AI Native Dev.
00:00:55.119 --> 00:00:58.799
We just wrapped up two amazing days at AI DevCon in London.
00:00:58.960 --> 00:01:03.520
But the great thing is that we get to do it all over again in New York City 5th November.
00:01:03.840 --> 00:01:04.879
You're absolutely right.
00:01:05.040 --> 00:01:14.000
We're gonna be back in a city that never sleeps on November 3rd and 4th for more amazing sessions, really engaging, hands-on workshops, and much more.
00:01:14.239 --> 00:01:20.000
Yep, all that great networking, partying, eating and drinking that you've come to expect from AIDEF CON.
00:01:20.400 --> 00:01:27.439
We think we have one of the best hallway tracks in the business, and it's the perfect compliment to our incredible speakers and presenters.
00:01:27.760 --> 00:01:33.359
We'll both be in person and virtual with live-streamed access to all mainstage keynotes and talks.
00:01:33.680 --> 00:01:39.359
Sign up right now for our Super Blind Bird ticket for just$100, only available for a limited time.
00:01:39.680 --> 00:01:42.719
We're really excited to be headed back to the big app.
00:01:42.959 --> 00:01:44.239
We hope to see you all there.
00:01:50.159 --> 00:01:52.879
Hello everyone, welcome back to the AI Native Dev.
00:01:53.040 --> 00:02:08.159
We are in uh kind of an ad hoc office over here, you know, actually sort of in uh hometown or like a home base, home base at the moment, uh here in San Francisco as part of the AI Engineer event, uh, and really you know, kind of enjoying a lot of AI conversations on it.
00:02:08.240 --> 00:02:11.120
And today we're gonna dive into identity.
00:02:11.199 --> 00:02:20.639
You know, identity if you've been sort of exploring the security realm of agentic uh anything really uh has been you know the top uh topic of it.
00:02:20.719 --> 00:02:28.960
You know, everybody appreciates that it is a foundational aspect of how do you get these agents to actually be secure and kind of work and give them some autonomy.
00:02:29.120 --> 00:02:37.120
And so to kind of demystify this whole domain and understand how to tackle that, we've got Ian Livingstone, who is the co-founder of Key Card.
00:02:37.280 --> 00:02:37.520
Yeah.
00:02:37.759 --> 00:02:43.439
Uh uh that is uh a sort of a really exciting kind of company in the identity space.
00:02:43.520 --> 00:02:50.319
Uh, but also really Ian is really sharp and deep around explaining things as a whole, and specifically identity.
00:02:50.400 --> 00:02:54.800
Uh, I've known him from uh sneak days and his sort of past uh companies that is founded on it.
00:02:54.960 --> 00:03:02.479
So we'll uh we'll learn about identity, we'll learn about what you can do, and we uh we'll hear a little bit about Keycard in the process of it as well.
00:03:02.719 --> 00:03:04.000
Yeah, thanks for coming on.
00:03:04.240 --> 00:03:04.879
Thanks for having me.
00:03:04.960 --> 00:03:20.719
I'm super excited to talk about identity and agent and security and this whole bundle of things together today, and uh really help people understand sort of how one is like what's the problem, um, why is this a hot topic, like why is identity, like identity is like kind of boring, it's snooze fest, it's been for years, you know.
00:03:20.960 --> 00:03:29.840
But why is this hot again and why are people thinking about it and how that actually changes the way that we actually think about the way we build systems and also how autonomous these systems can become.
00:03:30.000 --> 00:03:30.240
Yeah, yeah.
00:03:30.400 --> 00:03:31.919
So well, let's unpack over here.
00:03:32.080 --> 00:03:33.280
So let's let's get started.
00:03:33.439 --> 00:03:41.199
Just tell us a little bit about what what are the uh the problems or sort of the you know, give us a bit of a structure for thinking about identity and agents.
00:03:41.520 --> 00:03:41.759
Absolutely.
00:03:41.840 --> 00:03:46.000
So I think I think the first step we have to think about is like why is identity even a thing we talk about?
00:03:46.080 --> 00:03:50.560
Like if we were to step back, and like identity has been a part of computing for as long as it existed, right?
00:03:50.639 --> 00:04:04.560
The minute you had a mainframe and then I wanted to have multiple users, now you have an identity problem, which is like what files or programs on the system are guy's programs and files, and what files and systems are Ian's, and how does Guy have access to all of Ian stuff, or does Ian have access to all of Guy?
00:04:04.719 --> 00:04:10.080
Like it's been like every wave of computing introduces this question of well, who can do what, when, and where?
00:04:10.319 --> 00:04:10.719
And who can access.
00:04:11.120 --> 00:04:11.360
Exactly.
00:04:11.599 --> 00:04:16.879
I remember like uh high school sort of mini hacking, getting into all sorts of information systems that I was not supposed to be about.
00:04:17.519 --> 00:04:17.839
Exactly.
00:04:18.079 --> 00:04:33.519
And you know, in the rise of the internet brought about, like when we uh you know, initially it was like TLS brought about commerce, and so every wave of computing is comes with that net new security challenges that we have to solve because it changed, like the interaction patterns change when we introduce like new paradigms of the rise of the cloud, and then etc.
00:04:33.759 --> 00:04:40.399
You know, with IAM and identity for for cloud vendors like an AWS and GCP and secrets for all, we've always had these problems.
00:04:40.639 --> 00:04:48.160
And so agents, like many things, as we introduce new functionality and capability like platform shift, we have to reassess our security model.
00:04:48.560 --> 00:04:55.839
And I and you know, the core crux of the identity problem when it comes to agents is this thing is built on like a probabilistic distribution.
00:04:56.000 --> 00:04:57.920
It's a statistical training, right?
00:04:58.000 --> 00:04:58.800
It's beautiful.
00:04:59.040 --> 00:05:03.519
The the feature is that it can reason and it can guess over large amounts of data, right?
00:05:03.680 --> 00:05:06.480
Um, and that it is non-deterministic, that's the feature.
00:05:06.639 --> 00:05:06.720
Right.
00:05:06.959 --> 00:05:12.000
The bug from a security perspective is that it's non-deterministic and that it's still a feature.
00:05:12.079 --> 00:05:13.439
So the feature and the bug are the same.
00:05:13.600 --> 00:05:22.879
And so the fundamental question is how do I know that an agent is performing actions aligned with the intent of whoever set that agent to do something, right?
00:05:23.360 --> 00:05:29.839
Which um is like the fundamental question of sick of this generation, is it and there's many different hacks of that, right?
00:05:29.920 --> 00:05:39.120
You got supply chain security is a part of it, you know, data security is a part of it, uh, but identity is very foundational in thinking through how do I have a secure agent.
00:05:39.279 --> 00:05:44.000
And it's also foundational to think through how do I enable an agent to be autonomous, right?
00:05:44.319 --> 00:05:53.199
Um, and the more autonomous an agent becomes, or the more autonomous you want an agent to be, the security equation becomes much more difficult to solve.
00:05:53.360 --> 00:05:59.279
And the systems that used to work in last last era start stop working as much in the new era, right?
00:05:59.360 --> 00:06:02.079
And that's I think that's a fundamental sort of like thing to understand.
00:06:02.319 --> 00:06:12.000
And then ultimately the identity question is how do I ensure that when an agent does make a mistake, it doesn't do something catastrophic, I didn't intend, right?
00:06:12.160 --> 00:06:20.079
And so today, if you've you know have paid attention or have read, there's lots of different agentic problems associated with identity that people talk about.
00:06:20.240 --> 00:06:32.560
One of them would be you have supply chain attacks that result in database passwords and keys being leaked, like the most recent Light LM and attacks, that the actual attack factor was how do I take long-lived API keys off of disk and use those to exfiltrate data.
00:06:32.720 --> 00:06:49.519
But there's other problems of um how do I, you know, when I use an agent, if I ask an agent to do something, this is very common six months ago, was I asked the agent to optimize a database, a potential path to optimizing a database, it would actually be overright.
00:06:49.920 --> 00:06:50.319
Exactly, right?
00:06:50.480 --> 00:06:51.680
And so it's snappy.
00:06:51.839 --> 00:06:56.160
It makes it snappy, but that would be deeply unaligned with what the actual user wants that agent to do.
00:06:56.240 --> 00:07:01.120
And so that's finally a question of um of a Danian access.
00:07:01.199 --> 00:07:01.360
Yeah.
00:07:01.759 --> 00:07:12.079
And the difference between what we've had and what with agents is I actually want to give agents access to different things depending upon the job I've assigned them to do or the task I've assigned them to do.
00:07:12.160 --> 00:07:14.000
And that's a very different model than we've had previously.
00:07:14.079 --> 00:07:14.240
Yeah.
00:07:14.720 --> 00:07:18.560
So I think there's there's basically a few aspects that you that you outlined over there.
00:07:18.639 --> 00:07:23.920
So one aspect of it is is um is the the non-determinism, right?
00:07:24.079 --> 00:07:33.600
Or the safeties, like how likely is the agent to uh sort of choose to do a thing that is not a thing that you would have otherwise kind of reasoned and is allowed on it.
00:07:33.759 --> 00:07:44.000
So I guess there's sort of a broader safety element, and some of that comes down to you know harnesses and context and all that of trying to sort of steer the agent to understand the lines are.
00:07:44.319 --> 00:07:47.839
And I guess that's that's not really identity, those are like agentic workflows.
00:07:48.000 --> 00:07:52.319
But then next to that, I think we have sort of two aspects of identity that you touch on there.
00:07:52.639 --> 00:08:03.680
One is uh, you know, who is the agent, you know, what is what is the sort of entity, right, that I'm signing it, and and the second is the the uh permissions, you know.
00:08:03.920 --> 00:08:07.519
I guess we talk about authentication and authorization in identity.
00:08:07.680 --> 00:08:14.560
Um so I I guess how do you am I kind of dividing that correctly uh over here?
00:08:14.639 --> 00:08:18.639
And maybe if we put safety is a massively interesting topic on its own.
00:08:18.800 --> 00:08:23.759
Yeah, but do you think they're intertwined or the and or do you just need to worry about all of them?
00:08:24.480 --> 00:08:29.600
I think I think it when if when a business, when you step back and ask, is it safe?
00:08:29.839 --> 00:08:34.559
Yeah, or another way to think is do I trust an agent be able to have perform this action?
00:08:34.720 --> 00:08:41.919
Yeah, it you know, identity and access, uh delegation, uh all these things are fundamental components of that, as they are in every other era of computing.
00:08:42.080 --> 00:08:42.320
Yeah.
00:08:42.559 --> 00:08:52.879
And you know, to a certain extent, you when it comes to identity and access, there you'll have deterministic controls around what agents can do, and you'll have non-deterministic controls.
00:08:52.960 --> 00:09:02.720
And like a good example is like safety work, often is about how do I bias a model into ensuring that it is it is not affected or has you know does the outcome I want.
00:09:02.799 --> 00:09:06.080
So it's not gonna do the bad thing or has less probability to do the bad thing.
00:09:06.240 --> 00:09:10.879
But from a security equation, you want to say, well, there's a set of things I just want to never happen.
00:09:11.039 --> 00:09:15.600
I want to guard, like I don't want a guard rule, I want to I want a hard boundary around what it can do.
00:09:15.679 --> 00:09:18.960
And it's part of this is also the reason why things like sandbox is very popular right now.
00:09:19.120 --> 00:09:23.440
It's like I can never 100% know the model may not do this.
00:09:23.600 --> 00:09:23.759
Right.
00:09:24.000 --> 00:09:32.240
So, but I need in order for me to put this in production for this type of workload or perform this type of task, I need to ensure that it has a hard boundary so it can never happen.
00:09:32.320 --> 00:09:41.679
So I can say as a business that yes, you know, the worst case scenarios that I worry about have actually been removed from the equation, and then the rest of the things that are left, it's like kind of okay if that happens.
00:09:41.840 --> 00:09:48.480
Like it's not great if it does something weird, but it's not gonna destroy the business or result in lost customer data or on and on and on it goes.
00:09:49.039 --> 00:09:51.919
So you there's uh one aspect of it is defining the sandbox.
00:09:52.159 --> 00:09:55.039
So you're saying I know that these things won't happen.
00:09:55.279 --> 00:09:55.519
Exactly.
00:09:55.679 --> 00:10:01.360
And you know, if I want the agent to do useful things, like if it might not delete all of my inbox, but I'm still getting it to send emails, exactly.
00:10:01.519 --> 00:10:03.279
But it can still do unsafe things over there.
00:10:03.360 --> 00:10:08.240
Yeah, but if it doesn't have access to my AI records, it's not gonna send those AI records uh outside.
00:10:08.480 --> 00:10:12.399
Okay, so so there's we're we're talking now a little bit more about that sort of boundary zone.
00:10:12.720 --> 00:10:12.960
Exactly.
00:10:13.120 --> 00:10:17.279
So what are the types of agent uh identity conversation that we have?
00:10:17.519 --> 00:10:20.720
Yeah, I think I think there's one is like sort of where we're coming from, right?
00:10:20.799 --> 00:10:27.360
And if you look at sort of the identity systems of last generation, like the way I would give a piece of software access to something is I would give it an API key.
00:10:28.000 --> 00:10:34.960
It would maybe, you know, service account would represent a service account potentially, it would maybe represent a user because it was a user's API key or personal access token.
00:10:35.120 --> 00:10:38.320
It was like we built a world based on shared secrets.
00:10:38.480 --> 00:10:38.639
Right.
00:10:38.799 --> 00:10:49.679
And and the issue with shared secrets is they often bound strictly to a specific identity, and they bound specifically strictly to a set of permissions associated with that long-lived secret.
00:10:49.759 --> 00:10:56.240
And the more important thing is if that secret were leaked, anyone who got access to that shared password also could do that thing.
00:10:56.480 --> 00:11:14.080
And now the the fundamental challenge is okay, knowing that that's where we came from, how do we move to a world where I want, you know, I'm guide the journey, I want really want this agent to operate in a very long period of time on my behalf, because it's gonna have access to my Gmail or I have access to my Google Drive.
00:11:14.159 --> 00:11:20.240
Um, but if it at any point it needs to perform a right action, so send an email on my behalf, I should probably approve it, right?
00:11:20.320 --> 00:11:43.440
And how like fundamentally the process we're going through is as we go up the autonomy curve, so we go from I love to use like self-driving car analogy, as we go from level zero, which is you know to terms six off for pre-chat GPT, to you know, co-pilots, which is like you know, level one, yeah, to something that's like slightly or tab complete from cursor, to sort of like cursor agents and claude code agents, which are like level two, is a human still involved.
00:11:43.600 --> 00:11:50.480
How do we actually go from a world where like as we go up that autonomy ladder, I'm retaining security over what that thing's doing?
00:11:50.639 --> 00:11:59.840
And if you know, currently, if you were to use cursor or claude, when it goes into a tool call, oftentimes they're saying, Hey guy, sure you want to do that?
00:11:59.919 --> 00:12:01.200
Yeah, you'll always want to do that?
00:12:01.279 --> 00:12:03.440
Yeah, no, you don't want to do it in on everything.
00:12:03.519 --> 00:12:23.360
And so the question is you can't have autonomy when the human has to constantly be in the loop, which is where these access systems come in, which is saying, as I go up the autonomy ladder, so as we want to get to this sort of self-driving car analogy, there's a trust and safety equation then associated with that, which is how do I keep this thing driving on the road instead of like driving off the road off the cliff or whatever has to be done.
00:12:23.519 --> 00:12:26.320
Yeah, and that's at the crux of it what we're actually all talking about.
00:12:26.480 --> 00:12:26.639
Right.
00:12:26.799 --> 00:12:26.960
Yeah.
00:12:27.279 --> 00:12:31.360
So I I feel like uh uh the word identity is like uh can be a little bit confusing here, right?
00:12:31.600 --> 00:12:35.200
Because there's like one question is I've got this agent, it's running on my behalf.
00:12:35.279 --> 00:12:38.240
Uh can I know that it is the agent?
00:12:38.399 --> 00:12:38.480
Yeah.
00:12:38.639 --> 00:12:42.639
So like I feel when I hear identity, I I think primarily about who is it that is acting.
00:12:42.799 --> 00:12:46.879
And that might be uh, you know, is it me talking or is it my agents talking?
00:12:47.039 --> 00:12:48.960
So a system can separate the two of us.
00:12:49.120 --> 00:12:53.200
It might be, is my agent talking to another agent to perform actions on its behalf?
00:12:53.360 --> 00:12:55.279
So it's kind of you know, agents all the way down, right?
00:12:55.360 --> 00:12:56.960
They uh they cascade down.
00:12:57.120 --> 00:12:58.320
So that's one aspect.
00:12:58.399 --> 00:13:05.039
But a lot of the attention you draw is actually to uh to the uh kind of to its decisions almost, right?
00:13:05.120 --> 00:13:20.399
Like you know, as it as it comes along, um it might be it's around the communication of when I delegate a task, what is not just the uh the knowledge that it is my agent, but rather what is its scoped permissions right now within this world.
00:13:20.480 --> 00:13:24.320
Like you can compose the email, but you are not allowed to send the email.
00:13:24.799 --> 00:13:25.120
Exactly.
00:13:25.279 --> 00:13:29.360
So is that I guess people like again, the word identity is used for the market on it.
00:13:29.600 --> 00:13:29.759
Exactly.
00:13:30.000 --> 00:13:33.120
How do you separate this sort of authentication from authorization?
00:13:33.279 --> 00:13:33.440
Yeah.
00:13:34.240 --> 00:13:35.120
So this is interesting, right?
00:13:35.200 --> 00:13:46.080
Because if you look at in the identity world, the cloud when we getting to the cloud was really about can I identify, so authenticate that guy Pajurney is in fact guy Pajerney when Guy goes to Google Drive?
00:13:46.240 --> 00:13:52.320
Like that, the basis of cloud is really focused on that, and authorization didn't really fall into the problem space.
00:13:52.399 --> 00:13:56.000
And that's because at the time we didn't really have to solve authorization.
00:13:56.159 --> 00:14:09.600
And we didn't have to solve authorization because if I could identify that it's Guy and I trust Guy, um, then I can give Guy really broad base access because implicitly we've he's we've done the background check, right?
00:14:09.759 --> 00:14:11.360
We called all the references, yeah.
00:14:11.759 --> 00:14:15.440
He you know isn't uh isn't a sociopath, right?
00:14:15.600 --> 00:14:18.720
Like it turns out well.
00:14:19.039 --> 00:14:26.240
It turns out that Guy really you know cares about how people think about him and he wants to do a good job, and it turns out if he got fired from the job, that'd be devastating.
00:14:26.320 --> 00:14:31.519
So that implicitly we can we can trust that guy is going to operate with high intent and not be malicious, right?
00:14:31.759 --> 00:14:38.879
And part is because it's the same guy that will sort of come into the next task and then S that things in the next task while the agents are basically a brand new creature every time.
00:14:39.279 --> 00:14:46.000
Exactly, a brand new creature every time, a completely different context, and they're they don't have um they have no sense of is this good or wrong.
00:14:46.159 --> 00:14:47.840
Like they're not malicious, yeah.
00:14:48.000 --> 00:14:48.240
Right?
00:14:48.399 --> 00:14:53.039
They they just don't know, and there isn't a way for them to say it, do I know or do I not know, right?
00:14:53.120 --> 00:14:55.519
Um that's authoritative in a way that a human can be.
00:14:55.679 --> 00:15:06.879
And so from that perspective, agents really change that equation where it used to be that, okay, if I just know it's a human and I trust that human, once it's all configured, it kind of works.
00:15:07.120 --> 00:15:16.480
Now it's based on the thing that I've assigned them and the data they have about that thing, I'm going to give them different levels of access based on what's in that context window.
00:15:16.639 --> 00:15:26.639
And so much about this next generation is it is about authorization, which is how what things can this do, but it's also about what things has this agent seen or done.
00:15:26.799 --> 00:15:30.879
So I know that it is in a well-bounded box on whether it should have access to that.
00:15:30.960 --> 00:15:36.080
And if I can't call that judge, if I can't make a decision, like a system can't make the decision, system can also be like, hey, you know what?
00:15:36.159 --> 00:15:41.360
Actually, maybe I need to go talk to Guy and be like, hey guy, can you review this thing that the agent wants to do before it goes and does it?
00:15:41.440 --> 00:15:54.320
And so much of if we're if what we're trying to do is to basically turn software into the Waymo experience, so much of it is like, how do we, as the models improve, how do we over time give them more autonomy, but with the same substrate system?
00:15:54.480 --> 00:16:03.120
Because there's gonna be certain tasks that you assign an agent that you're gonna say, you know what, it's totally summarization where I'm pulling in a bunch of context, I'm summarizing a document for you.
00:16:03.360 --> 00:16:05.600
You should have, it's okay, read access to everything.
00:16:05.679 --> 00:16:06.159
That's totally fine.
00:16:06.240 --> 00:16:22.159
But the minute you want to go and do a high, maybe a transaction with a cost of over$500, definitely that's a maybe that's when a human has to say, you know what, I don't trust agents to make decisions on my behalf over$500, or organization may say, I don't trust agents to have access to customer data at all.
00:16:22.399 --> 00:16:23.919
Like there are different trust equations.
00:16:24.000 --> 00:16:36.240
And every person and organization, depending upon the context of what the agent is, who's using it, and what things it's re-asking, will have a different equate trust equation about what they think is okay for them.
00:16:36.559 --> 00:16:37.120
Yeah, yeah.
00:16:37.360 --> 00:16:37.840
Interesting.
00:16:38.000 --> 00:16:50.080
So really what you want is you want the uh the identity, or really like this identity plus authorization bundle to be task-based, to be I'm performing a task, this task should have a set of permissions.
00:16:50.320 --> 00:16:50.559
Exactly.
00:16:50.720 --> 00:16:58.399
Um I think within that world, it feels there are two uh two simplifying a little bit, two ways in which sort of agents run.
00:16:58.879 --> 00:17:01.840
One is uh an agent as in an agentic workflow.
00:17:02.240 --> 00:17:04.079
And so I'm running it, and so you know, I can choose.
00:17:04.160 --> 00:17:06.960
Sometimes it's doing broad things, sometimes it's doing narrow things.
00:17:07.039 --> 00:17:07.279
Yes.
00:17:07.519 --> 00:17:13.839
But I think within that world, it feels quite kind of manageable to say I'm giving it authorization.
00:17:13.920 --> 00:17:17.039
We'll come back a little bit to how do I define which permissions it should have.
00:17:18.000 --> 00:17:19.759
You know, that is sort of a hard problem.
00:17:19.920 --> 00:17:30.640
But but at least I know like this bundle, this sort of this sort of this process here that is executing, it's it's kind of executing the same thing or like this assigned action again, again.
00:17:30.799 --> 00:17:35.920
Um, and then I've got like you know, my kind of Claude Code or Codex or Gemini that I'm sort of running locally.
00:17:36.160 --> 00:17:36.400
Yes.
00:17:36.640 --> 00:17:44.559
Uh and I don't know, like probably like in my in my reality or like claud that I'm running on my desktop, I I don't, it doesn't do one thing.
00:17:44.720 --> 00:17:52.640
Like I do one thing and then I come back, it's just like I've got this other one, and I oftentimes just sort of run it in like one long session that I walk around.
00:17:53.359 --> 00:17:59.519
And you know, if I just sort of approve a thing, it's like okay, I just performed an action and says, Can I delete this file and delete this file?
00:17:59.599 --> 00:18:06.480
And then it's like fine, okay, delete all, like yes, always approve, and then I come along and I do something else, and you know, that goes away.
00:18:06.799 --> 00:18:08.079
Is that a lost cause?
00:18:08.319 --> 00:18:19.279
Like, is that uh it's like, hey guy, you just stop using uh the agent like that, like use it in a more methodical fashion and delete that, or or or is there a better model for HUD to head?
00:18:19.519 --> 00:18:20.640
There's definitely a better model.
00:18:20.799 --> 00:18:34.640
Like what we want to get to is a world where agents, you can assign agent a task, a task maybe something, hey, do like survey the internet and every day come back to me, or survey all of my assets, all of my inbox, and come back to me and tell me what happened, right?
00:18:34.720 --> 00:18:40.799
And that's like that's a long-lived process where you definitely don't want to every morning wake up and have to click a consent screen, right?
00:18:40.880 --> 00:18:51.599
You you actually just like I've assigned you, I've given, I've delegated authority to you to perform things on my behalf and work in order for me to delegate to this agent, I and that agent actually, and this is where identity comes in.
00:18:51.680 --> 00:18:53.279
We have to be able to identify the agent, right?
00:18:53.440 --> 00:18:59.039
So it's like I've given FUBAR agent for the contact for this task, this authority.
00:18:59.200 --> 00:19:03.279
And when I sign a different task, I wanted to give it different authority, but that's the first basis.
00:19:03.359 --> 00:19:11.519
It's like this is why we talk about identity is okay, well, in order to give something your authority to do something on your behalf, you both have to be able to be able to identify that thing.
00:19:11.680 --> 00:19:17.599
And then the thing that the downstream systems that are saying, hey, is this random request that's coming into my system?
00:19:18.240 --> 00:19:19.920
Does it have the permissions?
00:19:20.079 --> 00:19:22.880
Like, has it been given the authority to do the thing it's asking to do?
00:19:23.119 --> 00:19:32.079
Well, I have to both know, well, oh, Guy did in fact give FUBAR access to do this thing, but I have to actually be able to identify both FUBAR and Guy.
00:19:32.480 --> 00:19:39.680
And certainly those systems want to treat an access request or a request based from Guy differently than they do from FUBAR.
00:19:40.079 --> 00:19:56.319
Because when you think of like, I love to give the example of um like credit card chargebacks here, because if you ask your agent to perform uh uh a transaction on your behalf, and then you say, hold off a second, I didn't give it access to do that.
00:19:56.480 --> 00:19:56.640
Yeah.
00:19:56.960 --> 00:20:24.079
How does the intermediary be like, well, actually, no, we have a record uh, in fact, that you did tell FUBAR to go and do this thing, and then you said it could spend up to$500, and it did do that thing, so we're actually not gonna process that chargeback because you did do it with today's identity systems, with what we built in the last generation, you can't differentiate between, well, did Guy give FUBAR that access for this specific task or a different task, or where's FUBAR in the mix?
00:20:24.160 --> 00:20:30.240
None of that, none of that existed because we actually didn't have to build that for last generation security posture, and now we we do.
00:20:30.480 --> 00:20:31.119
Yeah.
00:20:31.599 --> 00:20:35.359
So uh, I guess kind of echoing back a little bit, and we'll get a little bit to solutions.
00:20:35.519 --> 00:20:37.839
Uh I'm hearing three levels here.
00:20:38.160 --> 00:20:44.480
You know, one is uh separate kind of me from my agent and so use identities that are specific for that agent.
00:20:45.039 --> 00:20:53.200
Two is uh have a set of authorization that is um that is aligned to the task that you've just given uh the agent.
00:20:53.440 --> 00:21:04.400
Uh and I guess three, which relates a little bit to the two, is if you're within like the the second one is easy when you've defined the task up front and it's not a long-lived agent.
00:21:04.720 --> 00:21:18.400
But when it's a long-lived agent, uh am I right in understanding that uh you're saying there's another kind of bucket of like ephemeral entity, the sort of entity that comes along, which is what is the current task being done?
00:21:18.640 --> 00:21:18.960
Exactly.
00:21:19.279 --> 00:21:29.440
Uh, that is like kind of like gathered out of the moment in time, the last few messages, whatever it is, you know, the last message that the user has provided, whatever it is.
00:21:30.160 --> 00:21:38.319
Um, and I guess that type of activity, uh, you know, it really isn't a place in which the human will engage.
00:21:38.480 --> 00:21:42.799
So that probably needs to itself be more kind of inferred or decided.
00:21:42.880 --> 00:21:42.960
Yeah.
00:21:43.599 --> 00:21:44.000
Is that right?
00:21:44.079 --> 00:21:50.079
So the first one and the second one are a scale problem of a thing that we had before.
00:21:50.160 --> 00:21:55.759
We had a system, we gave the system a task, we had to give it an identity, we had to give it uh uh a permission set.
00:21:55.839 --> 00:21:57.279
But this third one, that's a new creature.
00:21:57.599 --> 00:21:57.920
Totally.
00:21:58.000 --> 00:21:59.759
And and and if you were to go it read.
00:22:00.319 --> 00:22:14.000
Current literature, you'll find that what you and I are talking about, like I think tasks is very understandable for us to think about is like, oh yeah, I assigned this thing a job or a task to go do, and I went and did it on behalf, and maybe that task is repeats every 30 days, or it takes a long time to do that task.
00:22:14.079 --> 00:22:15.839
Um, in literature, it's called a mission.
00:22:15.920 --> 00:22:19.279
Um, is like often in standards that are starting to emerge, there's that concept of a mission.
00:22:19.359 --> 00:22:31.920
And the mission is over time, as users or other people give assigned work for these things to do, you're going to think about here are the missions or the quests I've assigned to this thing.
00:22:32.400 --> 00:22:36.960
And I as a user will update what that mission is as we learn things.
00:22:37.039 --> 00:22:37.200
Right.
00:22:37.519 --> 00:22:44.079
And really, what that mission is is about describing the user's intent as a concrete thing.
00:22:44.160 --> 00:23:01.279
It's like I intend for this agent to be able to, you know, complete this type of task, and that allows another system, like an authorization system, to understand hey, this user or this company, right, somebody has assigned a mission to this agent.
00:23:01.519 --> 00:23:07.839
That mission is something I can measure their requ access requests against and say, is this aligned with human intent?
00:23:08.000 --> 00:23:17.839
So that gives us a way to like think about how the concept of uh an agent's identity and their and the task they're working on travels across systems, right?
00:23:18.160 --> 00:23:33.039
Which is the issue that doesn't exist at all today is if you go to ABOS and you ask your agent to talk to ABOS on your behalf, ABUS has actually no way to know whether you what the action that the agent is performing was aligned with what your initial request was at all.
00:23:33.279 --> 00:23:33.359
Right.
00:23:33.680 --> 00:23:49.119
And so part of this is like we have this new concept as in delegation is this what is it that this thing has been assigned to do so that I can then judge whether the thing it's asking to do is aligned with the thing it was assigned to do.
00:23:49.440 --> 00:23:49.519
Right.
00:23:49.759 --> 00:23:55.519
So this is like a so we have human identities, we have non-human identities, and is there now a mission identity?
00:23:55.920 --> 00:23:56.640
There there is.
00:23:56.720 --> 00:24:05.119
And it's uh ta typically this is a s there's there's in it in you can think of these concepts of inside identity, there's been this concept of session for a long time, right?
00:24:05.200 --> 00:24:16.319
It's like I log into a website, that creates a session, often from you know 1990 to 2000 year web, it's a cookie in your browser, yeah, and that represents some session, and that session helps identify who you are.
00:24:16.640 --> 00:24:27.359
And now it's not just a session, isn't just um who you are, it's who are you acting on behalf of, yeah, and it is also for what purpose.
00:24:27.519 --> 00:24:34.960
Yeah, right, and that's the the three layers that we now have to think about, and for that purpose gives you access to do what things.
00:24:35.039 --> 00:24:35.359
Yes, yeah.
00:24:35.519 --> 00:24:37.359
And that's those are the layers of complexity.
00:24:37.440 --> 00:24:47.119
And if you if you think of it from that perspective, that's how the layer of the complexity of identity systems have are that that agents force for us to be able to solve a lot of these safety concerns across the system.
00:24:47.519 --> 00:24:48.160
Yeah, okay, cool.
00:24:48.240 --> 00:24:51.680
I love the session analogy because it's something you can kind of relate to on it.
00:24:51.839 --> 00:24:58.160
And sessions are interesting because sessions are things that they might get invalidated and require a new one for a variety of triggers.
00:24:58.240 --> 00:24:58.400
Yeah.
00:24:58.720 --> 00:25:03.519
Most common time, you know, like it's been idle for a while or maybe just you know, sort of sitting there.
00:25:03.680 --> 00:25:09.599
Sometimes it's uh an action that has been performed that kind of requires a reauthentication and a variety of those.
00:25:09.839 --> 00:25:13.680
So maybe let's sort of go into indeed a little bit of the solution landscape on it.
00:25:13.839 --> 00:25:17.279
So, what are what are the types of sort of tools or new capabilities that are out there?
00:25:17.440 --> 00:25:24.480
You know, I know Kickard is kind of one of those on it, but give us a little bit of the families of uh ways to tackle this sort of new challenge.
00:25:24.720 --> 00:25:32.480
Yeah, I think there's there are many different sort of solutions on on market that kind of message to this type of thing.
00:25:32.559 --> 00:25:40.240
But I think like let's step back and think about what are the new technologies or protocols that are emerging to start solving this, and then we can kind of discuss about like different ways.
00:25:40.400 --> 00:25:46.720
So I think there's there's really if I'm sitting in the chair as a security person, I'm thinking about two things.
00:25:46.799 --> 00:25:50.880
One, I'm thinking is about how do I find my shadow agents or my shadow entity?
00:25:51.039 --> 00:25:51.759
It's always a conversation.
00:25:52.079 --> 00:25:55.200
Security is what are the things that are happening that I don't know about, right?
00:25:55.440 --> 00:25:58.079
So I can quantify people are obsessed with shadows.
00:25:58.319 --> 00:26:00.319
Shadows is like, yeah, can I see a shadow?
00:26:00.480 --> 00:26:04.400
Is a user doing something I didn't intend, or is a system misconfigured, or whatever, right?
00:26:04.480 --> 00:26:10.640
This is this is governance, and there's a lot of money made in governance and security, which is quantifying effectively risk.
00:26:10.880 --> 00:26:13.119
And then there's the golden path, right?
00:26:13.200 --> 00:26:20.480
And in all security solutions, in all dynamics, you always have, hey, here is how we're gonna find all the risk.
00:26:20.720 --> 00:26:29.359
Well, once we've identified risk, because a lot of the risk is not people doing the wrong thing, like they don't have the wrong intention, they just don't know how to do the right thing that is like the secure pathway.
00:26:29.440 --> 00:26:32.160
And then you have your solutions that are what are the secure pathways, yeah.
00:26:32.319 --> 00:26:32.720
Exactly.
00:26:32.880 --> 00:26:40.480
And so you always in most markets and in most problem spaces, you have well, let's go find and quantify all the risk, and then you have, okay, here's a place we we go.
00:26:40.640 --> 00:26:43.359
And over time, as markets consolidate, they often tend to be the same thing.
00:26:43.599 --> 00:26:45.039
But move them from the shadow to the road.
00:26:45.440 --> 00:26:45.759
Exactly.
00:26:45.920 --> 00:26:48.960
But and and the road is typically the infrastructure part, right?
00:26:49.039 --> 00:27:00.960
And we saw that with the rise of social on the web, you know, with the rise of OAuth, you things like OSero come along and made it really easy for developers to build um social login on their website and user management, which turned out to be a really hard problem.
00:27:01.039 --> 00:27:02.960
And so a lot of people, that's why that market exists.
00:27:03.039 --> 00:27:10.160
And then, of course, we had for internal workflow, we had like things like Okta that rose, and it made it real easy to have a golden pathway for me to log into stuff.
00:27:10.319 --> 00:27:10.480
Right.
00:27:10.559 --> 00:27:13.279
Um, and then you, of course, had all your governance functionality that came as well.
00:27:13.440 --> 00:27:13.519
Right.
00:27:13.759 --> 00:27:23.359
These are all kind of examples of places where you would sort of centrally define your sort of identity, your authentication, like your system, but then you'd be able to kind of plug that in to many places.
00:27:23.839 --> 00:27:32.000
And and even with the rise of cloud, we had things like Hash and Corp Vault and Terraform that allowed me to configure IAM systems or put a place for me to store long-lived secrets.
00:27:32.160 --> 00:27:35.599
And so much of the last error was about where do I, where's the golden path.
00:27:35.759 --> 00:27:36.079
Right.
00:27:36.240 --> 00:27:48.240
Um now with the change to with the rise of agents, agents basically break a lot of assumptions of how all those things work together because they kind of work across different systems.
00:27:48.480 --> 00:27:59.119
They can work on behalf of your customers, they can work on behalf of yourself, they can work on, they can just be pieces of code that are running in your stack, you know, maintaining your software factory, deploying, debugging things.
00:27:59.519 --> 00:28:05.440
You have all these different interactions that are no longer human-driven, but they do exist, and how do you manage that?
00:28:05.599 --> 00:28:14.960
Um, but the fundamental issue is what are the new technologies or techniques that are coming out to help do the session mission per tasking?
00:28:15.119 --> 00:28:20.799
And so in OAuth, you have some movement there that's trying to trying to take over OAuth.
00:28:20.960 --> 00:28:23.359
Some of the stuff that Oxford just came out was called cross-app access.
00:28:23.519 --> 00:28:26.880
It solves some of the problem equation, but doesn't solve all things.
00:28:26.960 --> 00:28:29.359
So that's ID Jag for those who are watching.
00:28:29.599 --> 00:28:43.599
And then on um, there's a net new protocol called Agent Auth, written by Dick Hart, who um is a net new approach on a protocol to try and solve these quad these mission, session, orientation, and loop and move along with secrets.
00:28:43.759 --> 00:28:45.759
So those are some of the protocols that are emerging.
00:28:46.160 --> 00:29:06.240
And then the different approaches uh today are you're gonna is how do I find and quantify what risk I have, whether it's on my endpoint or my production stack or my cloud accounts, and then you sort of have your goal path things of how do I actually enable my developers or my customers or my employees to be able to find, build, and use agents uh successfully in sort of the golden path.
00:29:06.400 --> 00:29:06.480
Yeah.
00:29:06.720 --> 00:29:07.039
Okay.
00:29:07.279 --> 00:29:10.319
So let me kind of uh echo back some a little bit of that.
00:29:10.400 --> 00:29:13.359
So like the OAuth, so you have the sort of broader challenges.
00:29:13.519 --> 00:29:20.799
One of the projects around OAuth, it's about sort of allowing agents, identifying as agents, not sort of masquerading as humans to use OAuth.
00:29:21.440 --> 00:29:26.960
Today, you know, I guess we will have all seen, hey, it ran the login, it sort of opened up your browser, you're kind of clicking a thing on it.
00:29:27.039 --> 00:29:30.960
This is you authenticating as a human, then giving that key now to the agent.
00:29:31.119 --> 00:29:31.359
Exactly.
00:29:31.599 --> 00:29:39.359
Instead, can we sort of create a protocol that allow the agent allows the agents to sort of authenticate as it as an agent and sort of have the appropriate?
00:29:39.839 --> 00:29:40.640
Okay, so that makes sense.
00:29:40.720 --> 00:29:51.279
And that's like a a bit more of a uh uh sort of like a technical path with sort of the correct identity, but it doesn't solve the sort of the the uh the mission sort of identity like problem that we talked about before.
00:29:51.599 --> 00:29:54.240
I guess the sort of the second bucket is more around that sort of mission identity.
00:29:54.480 --> 00:29:54.720
Exactly.
00:29:55.200 --> 00:30:09.759
And for the mission identity, like where is the point in time in which and and and like who is involved in saying, fine, there's a mission, you've done it, but like what are the permissions that are allowed over here?
00:30:09.920 --> 00:30:23.359
It seems untenable that that would be a human uh that will come along every time and say, okay, fine, I figured out that what you're trying to do is compose an email, you'll have these permissions versus you know you're optimizing a database, so maybe you are allowed to modify an index.
00:30:23.680 --> 00:30:24.079
Exactly.
00:30:24.319 --> 00:30:26.880
I think there's there's two parts to this.
00:30:27.119 --> 00:30:36.880
One is everybody, individuals and companies, more companies and individuals, are going to have things that you say, you know, no agent can do this without me being involved, right?
00:30:37.039 --> 00:30:41.039
For me personally, it's probably spending over a certain amount of money or deleting data, right?
00:30:41.119 --> 00:30:44.160
Like those are like if you're deleting, I want to I want to make that decision, right?
00:30:44.240 --> 00:30:44.720
Because I care.
00:30:44.799 --> 00:30:47.359
Or if you're sending an email, I I actually do care deeply.
00:30:47.839 --> 00:30:52.079
And those are easy, because those are like not mission decisions, those are like just ground wide decisions.
00:30:52.319 --> 00:30:53.599
Yeah, they're just ground rules.
00:30:53.839 --> 00:30:59.759
Now, when it comes to mission decisions, this is really where fit patterns like Elm as a judge start to start to emerge.
00:30:59.839 --> 00:31:08.720
Because you're you're using you know a reasoning engine to reason about whether something's reasonable, and then ostensibly you basically based on does the system think this is reasonable?
00:31:08.960 --> 00:31:12.319
Okay, if it's not reasonable, now who decides what we do as a result?
00:31:12.640 --> 00:31:15.920
Is that no, absolutely not, because it's hit some determinants of guard rule.
00:31:16.079 --> 00:31:17.359
We say no, we'd never let delete.
00:31:17.519 --> 00:31:19.359
Oh, it's trying to do X, right?
00:31:19.519 --> 00:31:20.960
Should this go to the security team?
00:31:21.119 --> 00:31:29.839
The security team then has like a system that reviews it, or should it actually go back to you know the person that's operating on behalf of and says, hey, does Agent try to do this thing?
00:31:29.920 --> 00:31:32.640
Yeah, is this aligned with your what you were trying to get done?
00:31:32.799 --> 00:31:33.119
Right?
00:31:33.440 --> 00:31:39.599
And the biggest challenge we have today when it comes to age genetic security is how do we actually not end up with consent fatigue, right?
00:31:39.680 --> 00:31:46.720
Like the worst part about the yes, no allow always product dialogue is you just click yes because I'm not gonna read it.
00:31:46.880 --> 00:31:47.359
Yep, right?
00:31:47.519 --> 00:31:55.440
And that's always been one of the biggest challenges in security is how do I have a security system that is only sounds the alarm when a program is relevant.
00:31:55.680 --> 00:31:56.000
Exactly.
00:31:56.160 --> 00:31:57.680
Otherwise you lose all the signal.
00:31:57.839 --> 00:32:09.599
So the mission componentry, one part of it is getting all the protocols and the functionality in place so that you can sort of federate out what is it that this person said this thing's actually supposed to be doing.
00:32:09.759 --> 00:32:14.160
Um, and then the second component is the system around that that can actually make judgment calls.
00:32:14.240 --> 00:32:14.480
Yeah.
00:32:14.720 --> 00:32:27.759
And the better the system around it is at making judgment calls, um the more like the less interrupts the users will have, yeah, right, and a lower risk profile decision we made, and thus more trust and a pathway to higher autonomy.
00:32:27.920 --> 00:32:28.240
Yeah, yeah.
00:32:28.559 --> 00:32:28.960
Makes sense.
00:32:29.119 --> 00:32:30.240
Okay, so you have to do that.
00:32:30.319 --> 00:32:32.960
So again, agents all the way down, you know, something into it.
00:32:33.119 --> 00:32:37.680
So you need though the infrastructure, we have these two open protocols that I guess are forming, right?
00:32:37.839 --> 00:32:39.200
Like standards take a moment.
00:32:39.279 --> 00:32:39.599
Yes.
00:32:39.920 --> 00:32:58.960
Uh, and uh and then you have uh uh I guess kind of this sort of new concept, which is you have these missions, you have to give them an identity, which is already like a little bit hard to sort of uh identify where that is, but then also you need to figure out what is the authorization to give them, what are the permissions, which will be a subset of your overall agent identity permissions.
00:32:59.599 --> 00:33:04.160
So what are the the let's sort of get down then to the tools themselves that are available, right?
00:33:04.240 --> 00:33:11.839
If I am you know building agents and I'm I'm I'm sold, you know, like this is a problem, this is a concern, I have this.
00:33:12.079 --> 00:33:13.519
What are the tools available to me?
00:33:13.839 --> 00:33:19.599
Yeah, you know, today there you there's this big battle in the ecosystem that I'm sure Guy has talked to about somewhere.
00:33:19.759 --> 00:33:22.559
There's this battle between CLI versus MCP, right?
00:33:22.720 --> 00:33:33.839
And so we kind of have you know, you have CLI tools which very much have not don't have any really off system built into them, and then you have MCP, which the nice thing about MCP is it comes out of the box with like OAuth support.
00:33:33.920 --> 00:33:44.480
So in order to be an MCP, you have to have OAuth support, and that OAuth support um gives a pathway for saying is does this thing actually support some of the concepts that we talked about, right?
00:33:44.960 --> 00:33:52.160
And there's there's two broad ecosystems where there's solutions that only work for MCP, and then there's some solutions that only work for CLIs.
00:33:52.319 --> 00:33:52.480
Yeah.
00:33:52.799 --> 00:33:55.519
And the question really is is that sufficient?
00:33:55.680 --> 00:34:02.960
Because what we know is there's a set of agents, computer use agents, specifically coding agents, that CLI tools are their bread and butter, right?
00:34:03.119 --> 00:34:04.160
They're just really good at it.
00:34:04.480 --> 00:34:14.800
And that makes them fast, and it's one of the reasons that like Opus and GPT-5.2, Opus 4.5, GPT 5.2 really were the were breakthrough models on these computer use things and led us to a new level of autonomy.
00:34:15.039 --> 00:34:17.199
Um, and then you have sort of MCP only.
00:34:17.440 --> 00:34:36.960
And the question um is to think about what is the agent, what type of tools is the agent need to have access to and what type of agent should I have running in my ecosystem to do that, and how do I integrate that if it's an agent that is operating inside my company, I probably want that to integrate with my IDP.
00:34:37.440 --> 00:34:46.800
Um and I want it, but I want to think about the IDP slightly differently for agents and for users because they're actually slightly different problem statements uh broadly speaking.
00:34:47.280 --> 00:34:52.000
And then the tools on the market tend to be um like an agentic IDP solution.
00:34:52.159 --> 00:34:59.519
You there's some tools on the market that look like an MCP gateway, which is a common topic, very much designed for MCPs, it's a giant proxy.
00:34:59.760 --> 00:35:05.679
Um, and there's other things that are designed uh specifically for solving this sort of agent-to-agent communication in a federated manner.
00:35:05.760 --> 00:35:08.079
And those are the two like landscape solutions at the moment.
00:35:08.239 --> 00:35:16.320
And then, of course, you have your traditional um last generation sort of uh vendors, like your privilege access management, that was very, very hot topic.
00:35:16.400 --> 00:35:21.599
So how do I give a human access to like a Postgres running in my Amazon or my GCP?
00:35:22.000 --> 00:35:23.280
Very big important problem.
00:35:23.519 --> 00:35:27.599
Um, things like a cyber arc, you know, that was bought by Palo is a good example of that.
00:35:27.760 --> 00:35:29.519
Uh and those are sort of the buckets.
00:35:29.599 --> 00:35:40.159
And then of course you have your I'm building an agent that someone uses, and how does my agent or my MCP or whatever allow users to authenticate so it can carry down identity and access?
00:35:40.239 --> 00:35:41.920
And those are the broad buckets of different problems.
00:35:42.239 --> 00:35:46.320
So like everything that you describe right now is very like enterprise solutions uh for it, right?
00:35:46.400 --> 00:35:51.280
So you in the organization you figure out how do I represent agent identities in my IDP?
00:35:51.440 --> 00:35:51.599
Yes.
00:35:51.840 --> 00:36:07.920
How do I sort of systematically control access to my systems by routing kind of a you know, blessing some sort of access grantor uh somewhere uh in it and then having it be accessed via CLI or MCP and run along?
00:36:08.079 --> 00:36:10.639
Um so like those are very like enterprise-wide.
00:36:11.119 --> 00:36:25.119
Are the solutions all like some of the problems that you've described are things that I might as an individual or as a team also say, well, within within my sort of processes that I'm running here, I want some sort of mission identity, mission permission definitions on it.
00:36:25.280 --> 00:36:29.280
Are there solutions that are also like uh working within uh within that resolution?
00:36:29.519 --> 00:36:31.599
I mean, certainly that's something we're trying to do with Key Card.
00:36:31.760 --> 00:36:40.480
It's trying to empower teams to be able to just quickly and easily pick up agents, but also quickly and easily build their own agents where they're not constrained, whether it's MCP or CLI or a specific scale.
00:36:40.719 --> 00:36:42.320
We're trying to build it across.
00:36:42.400 --> 00:36:52.159
And so we sort of look at it's it's actually not MCP and CLI, it's both, but it's also not PAM, it's all three combined.
00:36:52.239 --> 00:37:01.760
And how you bring these different identities, these different postures into one system that's really easy to adopt and build with is how we think about the problem, and that's where we're coming from.
00:37:01.840 --> 00:37:09.039
And you know, I think the challenge tell us a little bit more about that, which is the how would you so if you were to use Keycard, you know, what what what does that entail?
00:37:09.119 --> 00:37:12.719
You know, if I'm uh and if you well, I guess you sort of choose, right?
00:37:12.800 --> 00:37:18.000
Whether that's sort of like if I'm uh you know the big boss kind of uh CTO kind of in the system or if I'm a developer.
00:37:18.880 --> 00:37:22.400
But you know, what what does it sort of look feel like, you know, like what am I doing?
00:37:22.639 --> 00:37:23.360
Yeah, absolutely.
00:37:23.519 --> 00:37:58.320
So with the way that we've architected our solution is if I'm you know using cloud code and we give access to some things, I download the keycard CLI, I cut run uh claude or cursor or pie or insert your your harness of choice, keycard, we integrated with the hook system, we then you basically tell keycard, hey, this agent can access these things, and it could be a set of MCPs or it could be a set of CLI tools or tool calls on my behalf, and then we make the from that point on, no longer do you actually have to yes, no, allow always consent dialogue.
00:37:58.400 --> 00:38:04.639
Key card can make those determinations for you, and then you get to say, you know what, if it's a delete, I should probably review.
00:38:04.719 --> 00:38:18.880
And that thing, whether that thing's running on my local device or if it's running um in a sandbox someplace or it's cloud, it works the same way across all so one insertion point to allow your to allow your agent to be evolved into a software factory and have autonomy.
00:38:19.119 --> 00:38:32.800
And then if you're on the flip side, I'm trying to build a service, I'm trying to build an agent or a tool that agents can talk to with the latest, greatest protocols without having to be a denity expert, you can use your SDKs, which then allow you to build those types of things that your agents can interact with.
00:38:33.920 --> 00:38:43.199
And and so in that context, you are providing uh a means of some sort of central definition of logic, I guess, or sort of like the decision making.
00:38:43.280 --> 00:38:43.760
Yeah.
00:38:43.840 --> 00:38:47.679
Uh and then you are uh connecting that to different accesses.
00:38:47.840 --> 00:38:55.599
Like the two the two value propositions are one, hey, here's like a smart engine that can make good decisions around who should approach what and is able to take your input.
00:38:56.159 --> 00:38:59.440
And the second is uh, hey, I can handle the proliferation of agents.
00:38:59.519 --> 00:39:04.559
You have many, many agents who want the same kind of logic applied uh at various places, exactly.
00:39:05.280 --> 00:39:18.320
And then I'm uh and from there connect that up to like some the parent system of you know how does a how does sort of a central platform team convey down some of those decisions into sort of individual developer desktops.
00:39:18.559 --> 00:39:18.880
Exactly.
00:39:18.960 --> 00:39:30.000
So how does, you know, we we really are focused on how do we enable that individual developer to find lots of success, then how we let them graduate from like that to a team of people going together across independent of the harness, right?
00:39:30.159 --> 00:39:30.480
Yeah.
00:39:30.639 --> 00:39:50.639
Um access what resources and what circumstance and over time, how does that give sort of that centralized security team and the platform team both the enablement function of how do I roll this out across the entire organization, but also how does that security team get the confidence to say, you know what, we can say yes to this high high degrees of autonomy because we feel like we have the security in place that we require to do it.
00:39:50.719 --> 00:39:50.880
Yeah.
00:39:51.679 --> 00:39:54.480
Hey everyone, hope you're enjoying the episode so far.
00:39:54.719 --> 00:40:02.880
Our team is working really hard behind the scenes to bring you the best guests so we can have the most informative conversations about agentic development.
00:40:03.039 --> 00:40:08.480
Whether that's talking about the latest tools, the most efficient workflows, or defining best practices.
00:40:08.639 --> 00:40:12.239
But for whatever reason, many of you have yet to subscribe to the channel.
00:40:12.480 --> 00:40:19.199
If you're enjoying the podcast and want us to continue to bring you the very best content, please do us a favour and hit that subscribe button.
00:40:19.360 --> 00:40:26.719
It really does make a difference and lets us continue to improve the quality of our guests and build an even better product for you.
00:40:27.039 --> 00:40:28.880
Alright, back to the episode.
00:40:29.199 --> 00:40:30.079
And so cool.
00:40:30.159 --> 00:40:34.480
So I love that, and I love the sort of the dev taste of sort of a bunch of the sort of the key card uh stuff on it.
00:40:34.559 --> 00:40:46.480
And it is, you know, like I'm a believer in the bottom-up, although with the, it's not necessarily bottom-up, but in that sort of developer experience, clearly also the world has a lot of sort of uh uh uh passion for for central control systems that come along.
00:40:46.559 --> 00:40:48.400
And I guess that's the tension that sort of plays out.
00:40:48.719 --> 00:40:50.000
Neither is like right or wrong.
00:40:50.079 --> 00:40:57.039
Yeah, it's just about what is the emphasis at a different time, how much do you indeed kind of define the guardrails uh in a broad uh broad sense.
00:40:57.199 --> 00:41:04.800
But I think a key a key takeaway, uh, you know, there are many, many, many kind of interesting things in kind of all this description, and thanks for outlining that.
00:41:04.880 --> 00:41:14.000
But this notion of these mission identities uh and uh uh uh agentically decided uh uh uh permission set for that.
00:41:14.320 --> 00:41:20.000
And then from there the ability to define those, enforce them, probably observe them, improve them over time, right?
00:41:20.159 --> 00:41:25.519
Look around them, uh enforce them, all of those are uh are probably evolutions of system over time.
00:41:25.840 --> 00:41:29.679
But that core new mission identity and permissions are sort of a uh a new entity to create.
00:41:30.000 --> 00:41:30.239
Exactly.
00:41:30.400 --> 00:41:35.760
That's the final thing that we're focused on at Keycard is how do how do you understand what agents are doing?
00:41:35.840 --> 00:41:41.840
Yeah, how do you allow agents to do things without having to artisanally define all this strict long-lived policy?
00:41:42.159 --> 00:41:50.719
Um, and that's by we do you get there by being able to describe high-level, yeah, like you know what, these are the situations where I'm really not okay with an agent doing something.
00:41:50.880 --> 00:41:52.239
For me, it's a lot about deletion.
00:41:52.320 --> 00:41:52.559
Yeah.
00:41:52.719 --> 00:41:58.719
Um and in all other circumstances, I'm okay with a system making the judgment call on my behalf, but whether it's allowed.
00:41:58.800 --> 00:42:05.840
And that's how we can have the sort of high degree of atomic, how we can move towards high degree, higher degrees of autonomy without bad downstream things happening.
00:42:06.159 --> 00:42:13.840
And you know, one of the biggest challenges with that talking to a lot of in the enterprise, or even individual devs, is this is great.
00:42:14.400 --> 00:42:16.559
Like conceptually it's great, but like how do I roll this out?
00:42:16.639 --> 00:42:31.119
And that's where like high-level policy combined with like the LM as a judge feature helps people to see, oh, okay, so I'm not sitting there artistically defining hundreds and hundreds and hundreds a line of no policy files, which was you know what we learned.
00:42:31.199 --> 00:42:35.440
I think a lot of security tools in the last generation is that that's where deployment went and failed.
00:42:35.679 --> 00:42:36.480
Yeah, yeah, yeah.
00:42:36.800 --> 00:42:39.599
Because it's not like when it came to humans, we were good.
00:42:39.920 --> 00:42:40.239
Exactly.
00:42:41.199 --> 00:42:44.239
It's like a general this was like a bad problem.
00:42:44.320 --> 00:42:57.360
Uh you know, and I think the reality of uh uh of of kind of many many aspects of technology is that problems that were a nuisance, but we can kind of kind of get by with uh in the pre-agent era, but they were not great.
00:42:57.440 --> 00:43:02.239
The best teams handle them, and all those are now intolerable in the agent era.
00:43:02.480 --> 00:43:12.639
I often I often say to people the the best practices of cloud are now base requirements for agents, and we've certainly seen those sandboxes and cloud environments and everything, and that's still true about that.
00:43:12.880 --> 00:43:16.000
They were good before, but uh the same was true for like waterfall to to cloud.
00:43:16.239 --> 00:43:16.719
Yeah, true as well.
00:43:18.320 --> 00:43:18.639
Yes.
00:43:18.880 --> 00:43:23.440
So uh I guess kind of before we close off here, I'll ask you to do one foolish thing, which is predict the future.
00:43:23.519 --> 00:43:24.239
Uh I love it.
00:43:24.320 --> 00:43:25.360
I love to predict the future.
00:43:25.440 --> 00:43:26.159
I do this all the time.
00:43:26.239 --> 00:43:26.559
Yeah.
00:43:27.119 --> 00:43:34.639
So uh I mean one aspect of it is with all this identity and evolutions of it, you know, what is the transition periods to it and what is immediately carrying and all that.
00:43:34.719 --> 00:43:41.679
But if we if we leapfrog all of that and we say like three years from now, feels like a lifetime away, kind of in AI timelines.
00:43:41.840 --> 00:43:47.840
What do you think will be the sort of the state of the ecosystem when it comes to how do we define these identities?
00:43:48.079 --> 00:43:49.519
Yeah, I think I think there's a couple things.
00:43:49.679 --> 00:43:55.119
One is um first and foremost, new protocols will actually have been deployed, right?
00:43:55.199 --> 00:43:59.840
And so right now we're really sitting on last generations like OAuth like implementations, and it turns out most of them were.
00:44:00.079 --> 00:44:04.960
Not very good, and we're seeing a lot of that when you know you go use an MCP from some of your favorite providers.
00:44:05.039 --> 00:44:08.159
You're like, well, why does this not work the way that I actually thought it would work?
00:44:08.239 --> 00:44:09.199
Why does this require all this cost?
00:44:09.519 --> 00:44:16.800
I think I think the future of the internet and and and such, agents will make everything feel pluggable, and interoperability will be incredibly important.
00:44:16.880 --> 00:44:32.079
And you'll see lots of companies really want to, because they want to have an agent forward experience, they'll really make interoperability across agent clients like a hive story, which means that like most people will be focused on actually building up net new auth components to support this.
00:44:32.320 --> 00:44:38.320
And that will then, from an engineer perspective, make actually pulling a bunch of tools together so much easier and so much better.
00:44:38.639 --> 00:44:53.760
I think that on the flip side, what we'll see is specifically in the enterprise, we're gonna see people move where where there used to be a lot of silos, and those silos are driven by how hard it was to write policy to less silos and higher degrees of productivity and higher degrees of contact sharing.
00:44:54.159 --> 00:45:12.880
Both because like there's huge promise, but also because the identity and access systems will upgrade to the point where it allows that interoperability in the enterprise will allow these things to communicate to each other while the security team will have like the things that they need to say uh to keep the company secure, which has often been part of the reason that those systems didn't connect, is because they didn't have a good way to actually manage information sharing.
00:45:13.039 --> 00:45:13.119
Yeah.
00:45:14.000 --> 00:45:15.440
That's like a very optimistic view of the future.
00:45:15.760 --> 00:45:21.760
It's like, you know, the protocols will be like it's not a given that standards will be defined in three years on it uh and that sort of the system will doing it.
00:45:21.920 --> 00:45:25.360
So that is definitely sort of the aspiration, which is these systems will will evolve.
00:45:25.519 --> 00:45:33.679
And I guess, I guess kind of the the twist the uh the driver is the belief that it's just like agents are making a sufficiently enforcing function that we have no option but to solve it.
00:45:33.920 --> 00:45:34.320
Exactly.
00:45:34.559 --> 00:45:38.159
And that's certainly been the history of identity and access for the last 30 years.
00:45:38.320 --> 00:45:50.159
It's like it's not the consumer that has really forced the evolution, it's it's excluding online shopping with TLS, it really has been the enterprise that has driven the requirement because what they want is a productivity gain.
00:45:50.239 --> 00:45:56.159
So they have the security requirements, and they go out and say to all their buyers, you really need you have to implement this.
00:45:56.239 --> 00:45:56.480
Yeah.
00:45:56.719 --> 00:46:00.000
Like for me to keep spending my 25 million dollars with you.
00:46:00.320 --> 00:46:05.360
And of course the vendors say, Well, we're not turning that money away, we really need that revenue, so we're gonna go implement it.
00:46:05.599 --> 00:46:07.679
And also because all of our enterprise schools are asking for it.
00:46:07.920 --> 00:46:20.719
And I think what's unique about this era of agents specifically is we're seeing agents at work be adopted much faster with much higher degrees of ROI than agents at home.
00:46:20.880 --> 00:46:26.400
And you know, that's an inversion of some things we've seen previously, um, but it's certainly true now.
00:46:26.559 --> 00:46:36.000
And so I think as a result of that, that will force like the uh the uh security stack, the next generation security stack to evolve much faster than I would have typically suggested.
00:46:36.400 --> 00:46:39.119
Yeah, I think that's a good uh like I I think I relate to that.
00:46:39.199 --> 00:46:44.320
Maybe it's like a little bit optimistic on it, but I think nothing is better, like it's a strong forcing function to do that.
00:46:44.480 --> 00:46:51.119
It is definitely well fueled from a VC uh domain of it in terms of like uh funding the transition, probably because of this sort of urgency.
00:46:51.360 --> 00:46:51.599
Exactly.
00:46:51.760 --> 00:46:51.920
Yeah.
00:46:52.239 --> 00:46:58.400
Ian, thanks a lot for coming in, you know, kind of demystifying, kind of like helping us uh understand identity uh on it.
00:46:58.559 --> 00:47:03.920
Uh looking forward to seeing you know key card and uh and in general kind of this world uh mature for it.
00:47:04.239 --> 00:47:05.360
So thanks a lot for coming in.
00:47:05.599 --> 00:47:06.079
Thanks for having me.
00:47:06.159 --> 00:47:13.840
And if you're interested in keycard, you can find us at keycard.ai, and we'd happy to show you a demo on LPC how you can adopt coding agents and build your own agents at scale.
00:47:14.239 --> 00:47:14.880
Very cool.
00:47:14.960 --> 00:47:18.639
Uh and thanks everybody for tuning in, and I hope you join us for the next one.
00:47:19.360 --> 00:47:24.239
The AI Native Dev is brought to you by Tesla, the package manager for skills and context.
00:47:24.320 --> 00:47:27.360
Your hosts are Guy Pajani and me, Simon Maple.
00:47:27.440 --> 00:47:29.119
Our producer is Tom Dowler.
00:47:29.280 --> 00:47:32.559
The AI Native Dev is not just a podcast, it's a community.
00:47:32.639 --> 00:47:36.159
And we host monthly meetups at the Tesla offices in central London.
00:47:36.320 --> 00:47:41.360
Visit Tesle.io forward slash community to learn more, and I hope to see you there.