Episode 1

The Identity Uncertainty Principle: A Security Leader's Take on Securing AI

EPISODE SUMMARY

In the debut episode of Grounds for Access, host John Martinez sits down with Rohit Agnihotri, VP of Identity & Access Management at Northwestern Mutual, to explore how agentic AI is upending traditional identity security. Rohit unpacks his "Identity Uncertainty Principle," the idea that as an agent's autonomy grows, the certainty of its identity shrinks, and what that means for zero standing privilege, just-in-time access, and securing non-human identities. Grab a cup and press play.

Subscribe or listen now:  YouTube   Spotify

Host: John Martinez (Delinea) · Guest: Rohit Agnihotri, VP of Identity and Access Management, Northwestern Mutual

John

What happens when that autonomous agent you gave standing access to orders a thousand pizzas? Good morning, everybody. This is John Martinez, technical evangelist at Delinea, and this is the Grounds for Access podcast. I'm joined today by Rohit Agnihotri. Welcome, Rohit. How are you today?

Rohit

Thank you, John. I'm very well. Thank you for having me on the show.

John

So, a little bit later on, I want to talk about the identity uncertainty principle. I definitely want to stab

Rohit

Absolutely.

John

That one. Let's get that one right up front, because I absolutely love that. So, welcome today. Rohit is the VP of Identity and Access Management at Northwest Mutual, I believe. Awesome.

Rohit

Northwestern Mutual, yeah.

John

Awesome. I got that right. And he's been in IM for a very long time, much longer than I have. So, I'm very excited to have you today, Rohit, on our podcast, on our introductory podcast. So, thank you again for coming on. So, Rohit, tell us a little bit about yourself and kind of what you do and what's a day in the life of Rohit and most importantly, because this is the Grounds for Access podcast. We do believe in,drinking coffee, tea, et cetera. What's in your cup?

Rohit

I am glad that you asked, John. And first of all, thank you for having me. I know that you are rebooting this podcast. I've heard some of your older ones. So, congratulations and I wish you a lot of success.

John

Awesome, thank you. Thank you. Thank you.

Rohit

In my cup today, there fortunately isn't any coffee because, dude, I already have as many jitters, especially working in IAM for such a long time. Yeah. I have a bit of paranoia now.

John

I get that for sure.

Rohit

Now on this new kick, my wife actually introduced me to the coconut water. I absolutely love it. It's very refreshing during the day. So, yeah, that is what is in my cup.

John

Nice. Nice. Nice. Nice. I love that. I absolutely love that. So, tell us, Rohit, about your time as an identity leader. What's that like? Give us a little bit of the background view of a day in the life of number one, you, Rohit. And I'll just preface the this part of the discussion with a little bit. I listened to a two-year-old podcast that you mentioned on your LinkedIn. And I really loved your cold open back then, which was, Hey, everybody, be kind to yourself, believe in yourself. So, I absolutely love that aspect of it. Because I'm a huge believer in that. I absolutely I remind myself, well, not maybe every day, but I try to remind myself about being kind to myself. I think we're talking about paranoia — too much coffee and all that stuff.

Rohit

That's nice.

John

It's a thing that those of us that are in this business, especially on the practitioner side, which I've been, we can definitely let that bog us down in the daily life of reaction to, incidents or something else broke or some we got breached, stuff like that. So, tell us a little bit from your seat, like what it's like to be an identity leader, identity security leader in large organizations like you've been.

Rohit

Well it's pretty awesome, John. I can send emails like please fix. So, yeah. I wasn't consulting for the longest time and the partners used to send

John

I love that.

Rohit

Me emails like, Please fix R A, please fix D L I was like, I would do it when I become the leader. So, I do it now as well. But it's a very interesting field to be in and especially in the seed that I am. I feel a lot of gratitude. And I'm not just saying this for the sake of saying this, but, I really feel that there are a couple of things. A, I get to lead a very, very good and an awesome team. Leading people is definitely something that I really enjoy. But most importantly, identity is something that is based in first principle. So, even though my job doesn't require me to be hands-on every day, but I can still break down the problem into simple things that I can understand from my vantage point. So, I really love that aspect of it. And then sometimes a technologist in a bigger organization, especially when you are in the industry, you might feel like you have been you are like a back office or you have been sidelined where the business takes front and center. And identity is something that business understands, business cares about. They have to deal with the identity leaders. So, identity leaders actually interact so much with the business leader that I do not see myself as a technical leader anymore. I am part of — no more or less — I'm a business leader who also has a technical or engineering team to learn. So, all these aspects — being a business leader, being able to understand my space because everything and identity is based on first principle, leading principle. I think that's pretty interesting. Obviously there is a lot of chaos that happens, John, but that is just part of the job.

John

Course, that comes with it. And I think one aspect of it — and I, as part of my day job, talk to a lot of identity leaders, a lot of identity practitioners. And it's still a mix, from what I hear out there, in the sense that, some identity teams are kind of like I was a Sys-admin, many years ago. And I remember that identity security grew out of the IT organization. But I think, a few major incidents about fifteen or twenty years ago, like a lot of that mind shift happened, but I still see some organizations, where identity is it an IT organization? Is it a security organization? Organizationally, where does it report? How does that even change the sort of the operations, if you will, of identity security. Being an IT versus being in a security team as an example. How do number one, how do you view it and what are the differences of those two reporting structures?

Rohit

Yeah. Absolutely. Honestly, there isn't much. You can call it water, you can call it H2O, you can call it aqua. That doesn't change the nature of the water itself. It doesn't change the nature of the work, whether I'm reporting to the CISO, whether I'm reporting to the CIO, whether I'm reporting to the head of infrastructure. I still need to have that same balance. My part is my or my job is to look after user experience, to make sure security is in place, to make sure business is getting it at this pace speed that business wants. So, all of these factors remain consistent. Now, how does it change? Managing up is an art. It just doesn't matter if you're reporting to a CIO or a CISO or somebody else. It also depends upon, you might report to one CISO who is very different, very technology or technology focused, you might report to another CISO who is very business focused. So, it's all the art of managing up and then managing down itself. Like if I get reorganized today, I will still continue to manage in the way that I do. So, I think identity leaders specifically have to find that balance for themselves and irrespective of where they sit in the organization, they have to find that balance between security, usability, and business velocity, and then just learn the art of managing up.

John

I like what you mentioned a little bit earlier about at the end of the day, your role is more of a business role. So, and I did catch this in one of your podcast episodes, is the aspect of making sure that the business leaders, your board of directors, let's say, is bought into, the whole aspect of securing identities within an organization. And you talk about that and it's important. And at the end of the day, 100% of the users of an organization use your service. Everybody logs in 100%. So, talk to us a little bit about that. How important is it for having your business leadership bought into, your role and your team's role within the function of the organization?

Rohit

Yeah, absolutely. So, we cannot succeed unless you have a buy-in and a great relationship with those business leaders. So, you absolutely have to make it happen. And to have a great relationship, there are like every relationship, it needs work. It needs work like A, you have to stop talking in terms of verified ID or technical constructs or just in time or ZSPs, which you and I both know are super important, but they don't care about it. So, we have to speak to them in the language that they understand.

And second thing that I really believe in is trust is not built during the crisis. When there is an outage, they aren't going to trust me. So, I have to go out there and build those relationships and try to understand their pain point. And at the end of the day, John, you, I, all of us at the workplace are trying to do the best that we can, are in it for the right reasons and then just want to shut down and go back and spend time with our families. People are people. They don't have a bad streak with them. If you speak to them in a rational manner. They would do it. Because our customers today are very security aware as well. They are asking for security.

Like, for example, would you ever put your money in a bank that does not have a secure MFA? No. And that is why the business leader who owns the website on the bank is very aware of MFA. It's just that we have to meet them where they are. And most importantly, and I think this is where some identity leaders make this a mistake. They believe identity is important, and that's an important thing. And that's not it. Business is not in the business of identity and access management. An insurance company wants to sell insurance.

A retail company wants to sell more product. And identity is a part of it, like platform is a part of it, or any other technology team is a part of it. So, we need to understand that. We need to understand risk and risk acceptance and risk tolerance and all of those things and have that conversation with business. We cannot just come in and say this is what identity team wants. Who cares, man?

John

Yeah.

Rohit

So, it's all about the business. It's all about the bottom line and doing right by our customers.

John

Absolutely. Although I will say, as both obviously as a consumer of insurance products. I have insurance for stuff, house and cars and all that stuff. I think this is more just me being a security nerd more than anything. It's just like I appreciate when my insurance company a few years ago sent an email out and said, Hey, we're turning on MFA for all of your stuff. And I'm like, Okay, that makes me feel but I'm sure I'm not the norm. Most people are like, my God, now what? What do I need to do? And it's what a hassle.

Rohit

That's absolutely fair, it's such a big responsibility. But, from my perspective, John, and especially working for a company which is hundred and sixty, hundred and seventy years old, it does put a lot of responsibility on me as well. Like why does my company exist? My company exists for, and I'm simplifying it, I'm not the CEO or the board of directors, but my company exists for two basic reasons. A to provide financial security to the Americans today. And be relevant enough so that we exist in the next forty years because you are putting in your money, hopefully, you will not need for the next forty years. So, you are trusting in us that we would be here for the next 40 years, hopefully for the next 160 years. So, that puts a big responsibility on me because trust is built over time. So, yeah.

John

Yeah, absolutely.

Rohit

But I completely agree. This is just something that we continue doing it. Sometimes the user base is very security aware and it becomes easier for them to adopt it. Sometimes you have to coach them through it and that is a part of job.

John

A little bit of a switch here on your experience. I see that you've obviously been a practitioner before; you've been a developer before. What have all of those experiences taught you about where you are today? Especially for those that are watching us today and are thinking of like, Hey, I would like to become at some point a VP of IAM. What is being a practitioner taught you now that you're a leader?

Rohit

Absolutely. So, my only piece of advice, and it is not going to be a super insight Buddha-level advice, but my only piece of advice would be everybody's job is difficult. Just understand that. And I've got this respect because of different vantage points that I've had, as a product developer, as an implementation engineer, as a support engineer, then a mid-level manager, and now the VP of this company.

Everybody's job is difficult. So, when somebody comes to me and says, Hey, onboard this application. This is just a connector. I know there is nothing like just a connector. Or when somebody comes to me and says, " Switch on just-in-time, I know there is nothing called " switch on just-in-time " access. So, I have a lot of respect. I do believe things are not just binary and it just nothing is just a something. So, that does give me a leg up because I have a lot of respect for people who are in the weeds, who are in the messy middle. And I need to give them the respect and the bandwidth so that they can do their job.

John

Let's switch, let's switch topics completely. I, the elephant in the room here is AI. We can't go five minutes without talking about AI. And that's.

Rohit

Good.

John

We were talking a little bit earlier. AI is here to stay. It's a reality of our life today. And in contrast, or not in contrast, but I've shown AI against the identity uncertainty principle. And we can get into what that means. So, for the audience, I'd love for you to explain what that means. But it there's a lot of uncertainty, obviously. AI agents are they there's a lot of trust in their inference models. And that and we actually, I've used Claude code, I've had it generate code for me, I've had it do things that yeah, this is great. Go ahead and do it. But there's a lot of uncertainty there on how it's going to react. I mean, there's recent incidents.

With OpenAI, Hugging Face. Is this like, hey, it hacked me. It's like, but here's the great reason for it. And here's why that's a good thing. There's a lot of uncertainty there. And so, with that contrast of, the identity uncertainty principle in AI, let's kind of delve into the AI topic. Talking about that. I don't know if you want to, introduce us to the identity uncertainty principle first and then kinda go into AI from there or, what do you think? What does Rohit think?

Rohit

Absolutely, absolutely. So, simply put, AI is here to stay, and we all have to adapt to it. People like you and me, John, without aging ourselves too much — we are not AI native. So, we'll have to scale up. The younger generation that is going to come up will going to be AI native. I'm glad Gen X now or whatever they are called now, Gen Z, they were all digital native, so they were showing us. Like, hey, yeah. Exactly. Yeah.

John

Gen Z, yeah. I've got two Gen Z kids, yeah, absolutely. Yep.

Rohit

So, the Gen Z kids were showing us every day, and now the next Gen Alpha who is going to be AI native is going to show them something as well. But yeah, AI is here to stay. There is going to be no company of the future that is not using AI. That company will not exist. But in the next two or three years, or at least four years, there would be two types of companies that would emerge. One of the companies would be using AI the right way, and the other companies would be using AI the wrong way, and it would be very clear and apparent.

And this is where I think identity uncertainty principle comes in, because what I've tried to do with while crafting this is we cannot use the same old models to define the agentic AI as an identity. What that means is let's say if you are into the privileged access management space and you are thinking about vault everything, you will never come to a concept of just-in-time. Sometimes you have to stop doing the old to start doing something new. You cannot put Agentic AI in the same category as human AI. So, now my thesis or the identity uncertainty principle is very simple. As the autonomy of the agent increases, the certainty of its identity decreases. So, the more you are increasing the autonomy of the agent, the certainty of whether it is the same agent is actually decaying. Because, see, human beings like you and me. Our identity evolves over many years. I'm pretty sure John what with the John that logged in at nine o'clock was the same John that was in there at nine o' five. And it is not just because of biological exactly. And it yeah, and it is not just because of the biological reasons.

But you have like employment contracts and you have like this moral compass and you have this social fabric that you have to adhere to. So, human identities changes very slowly. The same thing with service accounts. Service accounts today, what it does, it's going to exactly do the same thing tomorrow because at the end of the day, this is a script. And then we created this new class of entity, and change is the nature of that class. Like you are telling this AI agent that go out, learn and find new and innovative ways of doing it. So, change is its core behavior. And the difference between this change and the change that human goes through is it changes at machine speed that we cannot comprehend.

So, I'm saying it is taking decisions, it is learning, it is adopting, it is changing. So, as it is changing at the rate or the inverse rate of how much the autonomy is increasing. And to keep that as constant, you have to measure the frequency or behavioral change at the same rate at which it is changing. So, this is basically, in simple language, what the identity uncertainty principle is, so that our agents are autonomous with what we are comfortable with.

John

Yeah. And yeah, you have to adapt to that evolution of these agents. Because they're going to be

Rohit

Hundred percent.

John

They're going to be trying more stuff. So, I and I'm glad you brought up you preempted my next question. Which was a little you a little bit around the difference between AI agents and service accounts, and machine identities using those service accounts. Those are more deterministic, obviously. And I love the way you said it. A script is going to do the same thing today that it did yesterday. Yeah, unless you modified it. As an engineer modified it, have to do something

Rohit

Hundred percent. Yep.

John

Else. But yeah, we got into agentic identity security at the beginning, thinking of it in terms of non-human identities. Is it technically a non-human identity, or is it a hybrid? Is it a composite identity where the human kind of kick starts the agent and then it goes and does its own thing? And does that, does that spawn a new identity? Like how do you think about that. Because, I know, this is the uncertainty principle, but like how do you think about that? How do identities evolve and how do we adapt to that world?

Rohit

Yeah, absolutely. And there is so much to unpack. So, such a loaded question and such a great question there, John honestly. But, just breaking it down. So, we are thinking about agentic security as it is just a one thing. So, in comparison, what is human security. No, dude, there is no one thing as human security. You have your webs and network firewall, you have your MFA and then you have your email security and you have a step-up authentication. So, it's a bunch or a host of products. It's a suite of products. And similarly, anybody claiming that they are doing agentic security, they are doing a part of it, but they are not truly doing agentic security because there is nothing like human security per se.

And the second thing that it comes down to is it a part of non-human identity? So, non-human identity or NHIM, I struggle with this term a lot because of few reasons. It is a great instrument to get buy in. My team can come in and say, Hey Rohit, I need funding for a non-human identity initiative. Like, yeah, that's cool. Everybody's talking about it. So, it's a good tool. But this is a concept. And you cannot create architecture or engineering decisions based upon a concept. It has to be based upon an architecture. And what we are doing is we are talking about non-human identity as it is an architecture. And it is not because the service account is very different from an agent, is very different from an API key, is very different from an OAuth token.

So, at our level, or at least my level, it's a great instrument to get buying, to have a conversation without getting too much into the weeds. But non-human identity as an architectural concept is bad. AI agents could be termed as a non-human or a type of non-human identity, but then you have to understand that every type of this identity is different. Another problem that I have with this, John, is let's say I open a shop where I treat animals. Should I call it non-dog treatment and non-dog animal treatment center? That means I will treat both goldfish and lion. And I'm pretty sure treating goldfish and lion are two very different skills.

So, think about how we think about identity. We think about workforce identity. It is something. We think about privileged access management. It is something. And now we are saying non-human identity. So, we created a circle around the humans and said everything outside of it is non-human identity. And that is where I struggle with in architectural concepts.

John

No, great, great points. I love that. So, this is the next step. Is going to be the process purgatory. So, let's go. Yeah. Yeah.

Rohit

Yeah, process purgatory. Yes. And before that, John, if you don't mind, I think even on the topic of this AI agents, and I think there is so much confusion around what an agent truly is. So, by this channel or by this medium. I would like to test out this idea. How I look at this AI agent, it's a part of three things. Like these are three things that makes an agent. So, there is this LLM, which is called the brain, and then there is this context or which we call the memory. And then there is the tools, which we called as the hands. And these are the three components when they come together. It creates an agent. You take out any one component and it does it is not an agent anymore.

Let's say you take out hands or the tools that it connects to. So, it is now just a chatbot. It is not an agent. That is why ChatGPT is not an agent. If you let's say take out the brain, you take out the LLM, so now it has the context and it has the hands or the tools, it just becomes an automation script. So, that is why, brain plus memory plus hands, this is what makes an agent and all of us needs to be aware of it.

John

And that's a great way to look at it: look at agents. Because one analogy I've heard for chatbots is it's like a very well-spoken parrot. It's basically it sounds human even. But it really is just kind of parroting back. No, I love that. And I think one aspect of these agents. It's especially once we get into the autonomous world. The agents are out there because, we've commissioned them to. We've commissioned them to go out and do these tasks on my behalf, on our behalf as an organization, as a team, et cetera. Do these things. And they're out there and they're inferring. They're learning, they're adding to knowledge. And they're learning how to do you the tasks that you want them to do in a more efficient way. It's like we talked about earlier: they're no longer deterministic. It's not a script that goes, from top down and it does exactly all of the things that I tell it to do. We allow it to learn and do things better or do things a little bit different.

It's like when you prompt, ChatGPT to create an image for you, a lot of people get frustrated, as do I. It's like, it didn't create the same image the next time. I just want you to edit this little piece, but now you gave me a whole new thing. And so it's like that aspect of it. Is like that non-deterministic part. Now that you've, you've explained to us, how you view an agent. And the parts of it, like the brain aspect of it. Is that the or better asked. As identity security people, how do we adapt to that? How do we think about securing the identities that these AI agents use.

Rohit

Yeah, absolutely. So, first of all, we'll have to get rid of old constructs here. We cannot think about agentic security in the same vein or in the same lane as we thought about human security. These are new concepts and we'll just have to be comfortable with it. But to answer your question very directly, John, like as you mentioned, this is non-deterministic by nature. You can provide it the same input twice and it will give you two different outputs. It creates its own path. So, it you would see it logging into applications which you haven't thought about just because it is the right thing to do. So, you have to be and you have to be get you have to be comfortable with that. Of how you create your policies.

But a couple of things that definitely should stand out when you are securing your AI agents is definitely think about the delegation chain model and not in a theoretical concept, but, think about how can you add the identity data in your observability tool. So, that's number one. Second, there are great RFCs out there like RFC 8693, in which this is about token exchange, in which when the token is exchanged, you can use claims like ACT claims so that where it came from and where it is going.

So, definitely there are some development constructs that you could use. So, that A, you have the observability data, and B, you also have, this RFC 8693. So, you can create a delegated team. Second thing is thing about the fidelity as well. Fidelity in terms of what was the intent and what is the true behavior, and not in a sort of I will look into the logs and find it out. This has to be done during the runtime itself, because that is the difference between an autopsy and a pulse. So, as and that is why attestation is not logging. Irrespective of what the vendors tell us attestation is not logging. So, the next thing that we can do is look into that fidelity. Is the fidelity deviating.

So, what that means is you will hear a lot of concepts about intent-based authorization or behavior-based authorization, and that is where the future is, and it will continue to go that way. So, basically you have your intent, which is what it was supposed to do. And then you have your behavior and then you have this uncertainty principle. All these three things will actually help you secure your agentic AI. And then there is definitely another portion of it, your IGA, your PAM, your just-in-time, your authorization layer. Those concepts are pretty mature right now and they will continue to mature as we go along.

John

And I'd love your answer. I mean, I love the aspect of intent-based authorization. And now as somebody who works at a vendor, where we are we're taking our stance on how to do security of these agents. And how to help organizations solve this problem for people. It brings about an interesting twist, I think, to how we as a security industry have reacted to security trends over the years. And just a little bit, based on my own background — like I mentioned earlier, I came from the cloud security side of the world. And just like a lot of traditional security, although back, 15 years ago we didn't call it traditional security because the cloud was a new thing back then. But we took, I would say, a very traditional approach, which is like we put discovery of issues ahead of controlling and management of those issues. And that's a very typical sort of reaction to these security trends and these new technologies as they come out. Discover, control. Does that

Rohit

Hundred percent. Hundred percent.

John

Does that work in the AI world though, when there's uncertainty. Then I think this is kind of where we'll segue into, some of your other topics. But ha does that still work? Or do we kind of flip it around a little bit, do some control first and then do some discovery or, talk to me a little bit about your thoughts around that part of the industry.

Rohit

Yeah, absolutely. So, exactly as you said, it's a new way of thinking, honestly. So, when we went from data center to cloud, people who wanted to do role based access control in the same manner, that didn't work out so well in the cloud. But most importantly, what's the number one problem the people who have in their workloads in the data center face? It's the discovery part of it. It is the easiest thing to solve in cloud. I can tell you exactly how many workloads are running, how many service accounts are. So, see? Two different words.

The biggest problem just becomes, I know this, it is in cloud. So, this is the same thing with Agentic AI as well. We think differently, we think differently about it. Some of the concepts will still hold, like it is still an identity, it will still need an identifier, it will, bring up I don't know if you want to call it joiner, mover, leaver or something else, but it will be brought in the word or it will start living and then it will do its work and at some point it will die. So, those things will continue to happen, and we just have to be smart about it. So, say for example, an OAuth token that is valid for you for an hour, that's fine. For a human, one hour OAuth token makes absolute sense. But agents can do a lot of these things within an hour, and that is where the uncertainty principle comes in.

Let's say your agent is making 20 decisions per second, John. An agent can do it. So, imagine how many decisions can it take in an hour. So, let's say by the time it is on 500 decision, it could have transformed into something else. It was very different from what it started. So, by the minute five, you will have an agent that is very different from the agent that you had when your token lifetime started. This is what uncertainty brings in. You do not know anymore. That the agent that you started with and the agent that you have is at minute five are the same agents and then you have fifty-five more minutes before that token expires and it has to reauthenticate. So, that token lifetime could be very different from a human user versus a an agent because they operate at a different speed. And that is why you hear a lot of these things about runtime authorization. But this runtime authorization also has to be at machine speed and it has to bring in intent and behavior to understand the fidelity of the agent.

John

I love that. So, for our next topic here, I do want to hit up the aspect of organizations being stuck in Gen 1 problems. And certainly I I've seen that in my past experiences too. We joked a little bit earlier before the podcast. That, I've seen where organizations even to this day are fighting Gen 1 cloud security problems. After all of this time, after all of this preaching that we've done, they're still fighting some of those problems. Does agentic security break that? Does it reinforce that? Talk to us a little bit about your aspect.

I think you've called it maybe I'm getting you wrong, so correct me please. But like the tool hopping tango and and process purgatory, so but you're but it's all like under the same kind of realm from what I've been reading your stuff. Where it's like organizations are on Gen 1 problems, those of us on the vendor side are solving gen three problems, but does, just like we've talked about AI agents, now living in a in an authorization scoped world where things happen in five minutes versus one hour. Does that leapflog? Does it speed it up? How does that work, Rohit? Guide us.

Rohit

Yeah, I don't know if I'd be able to guide you, but we can obviously talk it through, John.

John

Yeah, yeah, let's talk it through. Let's go.

Rohit

And I don't know if your listeners found out by my accent so far or not, but I grew up watching a lot of Bollywood movies, John. So, I have this penchant for drama. That is why I write these serious papers on serious stuff, but I call it something very fancy and very dramatic and stuff like that. So, tool hopping.

John

I love it.

Rohit

Tango and process purgatory is this part of Bollywood that lives within me. But

John

Love it.

Rohit

It's a great point. And I have a lot of respect for the vendors, not just out of the goodness of my heart, but also because vendors who are the ones who are investing in this industry to take us forward. If there was no vendors, there wasn't not going to be any shared service framework or no conditional access evaluation profile or maybe no just-in-time or zero standing privileges. So, vendors are actually driving this industry forward. So, I have a lot of respect for them.

Vendors — when they evangelize a term, and you are an evangelist, John, so this. When you evangelize a term, then my bosses hear about it and then they are ready to give me money and fund my program because of that. So, I have a lot of respect for that. But then also at the same, identity leaders are always in this chaos where vendors are also telling us, like, you both you and I know zero standing privileges is the future. Or if it is not the present, it has to be the future. But I also understand that not everything can be zero standing privileges, that you understand as well.

But I'm also struggling, or the companies are also struggling with vaulting their current accounts, the companies are struggling still struggling with orphaned accounts, companies are still struggling with role-based access control, the same things that they were struggling with in two thousand and eight. So, there is a disconnect between vendors and the ground realities sometimes, and it is not a bad thing, but it makes sometimes an identity leader's job hard because then we hear things like turn on zero standing privileges and I'm like, there is no button there. So, yeah. So, that's good thing.

The other thing that, and it's not on all on the vendor side as well, I also blame identity leaders for it as well. And this is something that I feel strongly. This is called tool hopping tango. In which it's easier for me to not mature the processes but migrate to a different tool. So, if I migrate from tool A to tool B, it is possibly going to take three years or two years or whatever. And then all my KPIs would look green. Migration is green at forty percent. But what is it getting behind the scenes? Nothing. And I've seen too many identity or at least a few identity and business and tech leaders guilty of this. This tool hopping tango — they get into migration, they move on while the migration is happening.

Everything was green when they were here, but the organization achieved nothing. So, this is tool hopping tango, and then process purgatory is sometimes. Sometimes the process itself becomes the defining factor and then the objective is lost. So, how many roles do you have in the ecosystem becomes a KPI. It doesn't matter if your roles are over-provisioned or under-provisioned. So, that is a thing that we have to be very cautious about.

John

So, yeah, that I thank you for that. I love that. I really like and by the way, I'm here for the Bollywood explanation of things of hard security topics. I love it. Absolutely love it. But you're right. It's like, as you talk to business leaders about these concepts that we come up with. It's just like, but as an ex-practitioner myself. It's like I understand that it's not a switch. It's not a switch you could just move to day one. There's a path to get there.

But from your perspective. How do you explain to these leaders that hey, these concepts are real concepts, they're real security concepts. Meaning — you talked about this a little bit — but if you could expand on it. How do you explain these hard security concepts as values to leadership that we need to strive to? And so that's the easy part of the question.

But the hard part of the question is then I'm sure they're going to be asking you the follow-up. Which is like, okay, Rohit, well, now give us the roadmap to get there since we're going to invest in this thing that you told me to go invest in. How do you take us there? So, it's a loaded question, but, walk us through it, please.

Rohit

But it's an excellent question. And honestly, that is the job. That is the job, and that is why I said, first trust is not built during the crisis. So, you have to go out and make these relationships yourself. You have to stay on top of your own game. So, learning and relationship should be a key component of your job, as much as it should take ten to twenty or thirty percent of your time when you are creating this relationship and also upskilling yourself, which sometimes takes the back seat because there is always a P1 or a P2 or a P3. So, John, if you respect my knowledge enough and if you like me, if both these conditions are true, you will potentially hear what I'm going to tell you without dismissing it.

Now if either of those two things were not true, if you didn't like me, or if I don't know what I was talking about, you would probably dismiss a novel idea that I come up with. So, earn their trust and be educated. That's number one. Number two, what you do is communication is an art. Everybody tells us, you have to break it down from the technical terms to the business terms and stuff like that. It's not science. It is an art. It's easier said than done. But you have to practice about it. And how you practice is by reaching out from the bottom rung of the organization. You don't go to the top and start saying zero standing privileges. You have to create that community. People have their trusted advisors, who are maybe very technical in nature, and you have to earn the trust of your those advisors and help them understand it.

So, that is an art in itself. How do you communicate these topics? And how do you communicate these topics is by speaking in the language that they speak. So, if they are worried about how many clients are logging into the application, how many clients are leaving midway during the MFA process and stuff like that. And that is how you try to communicate. So, first understand their language. It's easier said than done. Don't talk in terms of technology, talk in terms of business. But business is no language. Speak in the language that they hear every day. If they are hearing client authentication, or maybe not client authentication, but if they are hearing about the reach of marketing or how CRM works or stuff like that, speak in that language and they will understand you. And regarding the roadmap as well. I think it has to start with inventory first. You cannot control what you cannot see.

Start with an inventory, break it down, and most importantly, show them small wins. Don't have a big bang approach of the win is going to come two years down the line. When you have big wins along the way, then it happens for two things. A, you have the time to match your roadmap, because your roadmap is fluid, and you continue to earn their trust and hopefully dollars along the way as well. So, two or three things. It really depends upon exact use case, but, as the guiding principles this would really help anybody out.

John

And that's I was going to say, that's exactly where that trust building comes in. For sure.

Rohit

Mm-hmm. Yeah, John, I do have a question for you though. You have been asking me so many questions. What's the difference between an influencer and an evangelist?

John

I think with an influencer it's scope. An influencer strives to have the million followers on YouTube. Or whatever social media platform or is whereas an evangelist, I'm here to, number one, talk about my company solutions. Of course. They pay me to do this, but also, use everything I learned, either over the years. Or having great conversations with somebody like you. I'm learning today.

Using that to formulate kind of my thoughts and my message. At the end of the day, it's being a messenger. At the end of the day. It's being able to talk. If you ask my dad, though — if you ask my dad, who's also a talker, by the way — it's, you have to have the gift that you and I have, which is the gift of gab, being able to talk. If you ask my dad, it's

Rohit

Dude.

John

The dream job. Just talking. I think that's in my view, that's the difference. That's a difference.

Rohit

That's funny. No, that's very insightful and definitely looks rehearsed. But to anybody listening or watching, this was not rehearsed. I was just trying to put John on the spot because not that I'm calling you old John, but I always felt like, influencers are young people and evangelists are not so young people. But you explained it much better.

John

There is that too. There is that too. Although my daughter has, several times, tried to turn me into an influencer in certain things. Great, great question. I love that question. I hadn't thought about it that way, so that's good. Now let's switch a little bit. Early retirement jar. What's the most in your view, what's the most overused acronym that goes into the early retirement jar?

Rohit

Dude, that's interesting. I will call NHI. And I have so much respect for it because I think this is

John

NHI.

Rohit

The corner store of security. I really believe this is for the future because agents are type of NHI. But I told you earlier. Like we have drawn the circle around humans and everything outside is non-human. This just makes my job impossible because that undefined universe needs to be secured. So, I think non-human identity, but again I think this is very important. I think these conversations are very timely, but just something the terms that I never felt in love with.

John

Next one along the same lines. What is the one accepted industry best practice that we still do that should be put to rest and no longer used anymore?

Rohit

User access reviews. It's time for standing privileges to be minimized aggressively. It's time for us to go towards just in time and zero standing privileges. It will not happen in one hundred percent of the cases.

John

All right. And here's the future prediction question for Rohit. Where do you see agentic access in three years?

Rohit

I think it would be part of the fabric of everything that we do. Business RPOCing and piloting right now. Some workloads are running into production and as we are maturing, we are creating that scaffolding along the way. So, people like me are getting ready with everything that is needed to reasonably secure agents. I think within the next year, year and a half we will be there. And actual production workloads would be running. So, I think in the next three years, agents would be in the very fabric of the way that we do work, very much like computers are today for us.

John

Yep. That would be a natural part of us.

Rohit

Hundred percent.

John

So, last question in this quick hit part of the episode. When you're talking to your peers at the round tables, industry round tables, your industry peers. And they secretly come to you with, like concerns about what we're going through in the industry, how do you advise your peers? Especially with AI.

Rohit

Absolutely. Yeah, absolutely. And I completely forgot that you call this a rapid fire, John. I'll tell you something personal. My wife tells me that I'm the worst rapid-fire player ever because I love talking so much I can never answer in one word. Like I have to create and leave a story and things like this. So, sorry for messing up your rapid fire.

John

I love it. Love it. Yep. All good.

Rohit

I have a very generic piece of advice to all the peers that come up to me. Continue; we have to learn. We have to forget everything that we have learned so far and we have to relearn and get in the habit of forgetting and relearning at a much faster rate. Fortunately for people like me or us, John, we are blessed because we are in an industry that is based upon first principles.

Let’s say if I was a developer, I could have written the code and could have never understood how Kubernetes really works behind the scenes. I could have deployed my code and everything; that's fine, but I would not have survived without understanding it. But in identity, if I want to understand anything, I can understand that. That is what I talk on my podcast as well. If I want to understand a token, I can understand everything in it. It's really just a file. What can a file contain? It can contain your name and your identifier and those are attributes.

I feel like learning for us is so much simpler, especially now with AI. That everything can be broken down into first principle. So, just continue learning, be adaptable. And then there are controllables and un-controllables in life, John. There are some things that are out of our control and you can either stress about it or it is what it is.

John

Yep. Very insightful. Thank you, Rohit. So, where can folks find you? I know you have we talked about The Identity Navigator podcast, but tell us about where we can find you and we could hear more and read more from Rohit.

Rohit

Yeah, absolutely. You can always reach out to me via the podcast. It's called The Identity Navigator. I'm very active on LinkedIn as well. So, anybody can reach out to me on LinkedIn. The email with the navigator is the identitynavigator@gmail.com. I'm normally very responsive on that email as well. Always happy to nerd out. I always have these bold ideas and I'm never afraid of being corrected because that's how I learn. So, reach out to me via any social media platform, I would be there. So, yeah, I'm really looking forward to hearing the feedback from your listeners, John.

John

Awesome. And that's it, everybody. Thank you for watching today's episode of the Grounds for Access podcast. Please, like a lot of these podcasts, we definitely would ask that you like this episode. So, click the like button down there and you subscribe to our channels so you can continue following us wherever those channels are, YouTube, Spotify, et cetera. We absolutely appreciate that. And we thank you. And I've also finished my drink that's in the cup. I don't know if you have any more coconut water left in your cup, but I don't have any more coffee left in my cup.

Rohit

I have a couple of sips, John, but I'm just very grateful that I did not choke or say and had taken a wrong sip and, you embarrassed myself on your podcast. So, I will take that as a win.

John

We would have used that for something anyway.

Rohit

Thank you.

John

I'm glad you didn't choke either. So, thank you. And thank you, Rohit. I totally appreciate you being on our podcast episode today for Grounds for Access. So, again, thank you. Any parting words that you have for us?

Rohit

Yes, it was a pleasure being here, John, and I wish you a lot of success in all the evangelizing that you are doing and with this new podcast of yours.

John

Thank you, Rohit. All right, that's it. Thank you, everybody. We appreciate you. See you next time. Bye.