Skip to content
PodcastsTechnologyIdentity at the Center

Identity at the Center

Identity at the Center
Identity at the Center
Latest episode

444 episodes

  • Identity at the Center

    #444 - August 2026 Mailbag

    08/31/2026 | 49 mins.
    Jeff and Jim open with the unavoidable topic of AI agents and the tension between enabling innovation and governing agent permissions, then run through a packed fall conference schedule. The August mailbag pulls questions from Singapore, Toronto, Prague, Johannesburg, Helsinki, and Seoul. They discuss when externalized authorization makes sense, why passkey recovery can become the weak link in phishing-resistant authentication, what EU digital identity wallets may mean for enterprises, how continuous access evaluation changes the meaning of terminating access, and how to build resilience around a centralized identity provider without creating a second full-scale IdP. The episode closes with a lighter question: if every IAM product needed a giant warning label, what should it say?

    Connect with us on LinkedIn:

    Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/

    Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/

    Visit the show on the web at http://idacpodcast.com

    00:10 - Welcome and have we talked about AI too much?
    01:32 - Governing AI agents without becoming the progress prevention department
    03:50 - Fall conference season and IDPro
    04:40 - Cybersecurity Summits in Chicago and Atlanta
    06:40 - SailPoint Navigate, InfoSec World, FIDO Authenticate, and Identiverse DC
    10:40 - 3D printing, challenge coins, and superfan status
    11:56 - August mailbag begins
    12:19 - Singapore: Is externalized authorization ready for mainstream IAM?
    20:30 - Toronto: Passkeys, account recovery, and help desk social engineering
    25:55 - Prague: What should enterprises do about EU digital identity wallets?
    31:44 - Johannesburg: Continuous session revocation and what “terminate access” really means
    38:04 - Helsinki: Designing identity resilience around a centralized IdP
    45:23 - Seoul: What warning label should every IAM product have?
    48:26 - Wrap-up and how to send future mailbag questions

    IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, IAM, identity and access management, August 2026 mailbag, externalized authorization, authorization, policy-based access control, passkeys, account recovery, phishing-resistant authentication, identity verification, EU digital identity wallet, continuous access evaluation, shared signals, session revocation, token revocation, identity resilience, identity provider, disaster recovery, business continuity, AI agents, agentic identity, IDPro, FIDO Authenticate, Identiverse DC, InfoSec World, SailPoint Navigate
  • Identity at the Center

    #443 - Ghosts in the Machine with John Huyette and Omer Arshed

    08/24/2026 | 1h 13 mins.
    Jeff and Jim are joined by John Huyette, AI Risk Leader at RSM, and Omer Arshed, North American Digital Identity Leader at RSM, to explore how identity controls can help organizations manage the growing risks of AI agents. John introduces five laws for managing AI risk: governability, lineage and integrity, trust boundaries, authority containment, and human impact. The conversation connects those ideas to familiar IAM principles including ownership, auditability, zero trust, least privilege, just-in-time access, privileged access management, and continuous monitoring. They also discuss prompt injection, shadow AI, human accountability, and why organizations should start by building an honest inventory of the AI capabilities already operating in their environments.

    5 Laws of AI Risk: https://www.linkedin.com/feed/update/urn:li:activity:7487942457075257344/
    Connect with John: https://www.linkedin.com/in/john-huyette-1373906/
    Connect with Omer: https://www.linkedin.com/in/omerarshed/

    Connect with us on LinkedIn:

    Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/

    Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/

    Visit the show on the web at http://idacpodcast.com

    Timestamps

    00:00 Introduction, 3D printing, and conference updates
    06:58 Introducing John Huyette and Omer Arshed
    07:52 John’s path from technology risk to AI risk
    12:11 Omer’s identity origin story
    13:43 The five laws for managing AI risk
    18:00 What “ghosts in the machine” means for identity
    20:17 Governability and ownership of AI identities
    25:17 Do you know what has access to what?
    29:43 Applying decades of IAM lessons to AI
    32:35 Lineage and integrity
    35:20 Building an AI bill of materials
    37:12 Trust boundaries and external data
    38:36 Prompt injection and untrusted content
    42:48 Applying zero trust principles to AI agents
    47:26 Authority containment
    49:56 PAM, least privilege, and just-in-time agent access
    56:22 Human impact and accountability
    58:41 Is agentic AI really a new identity problem?
    01:02:35 Starting with lower-risk AI use cases
    01:04:21 Where organizations should start
    01:05:07 Shadow AI and zombie accounts
    01:07:09 What excuses would an AI give during an access review?
    01:12:20 Wrap-up

    Keywords

    IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, John Huyette, Omer Arshed, RSM, AI risk, AI agents, agentic AI, AI governance, governability, lineage and integrity, trust boundaries, authority containment, human impact, shadow AI, identity governance, IAM, zero trust, privileged access management, PAM, least privilege, just-in-time access, non-human identity, NHI, prompt injection, AI identity, access governance, continuous monitoring
  • Identity at the Center

    #442 - Identiverse 2026 - Identity After Dark with Bravura Security

    08/19/2026 | 1h 29 mins.
    Recorded live at Identiverse 2026 in Las Vegas on June 17, Jeff and Jim are joined by Bart Allan, General Manager at Bravura Security, for a live recording with a studio audience. In a late-night talk show format, the three host an open Q&A driven by IAM practitioners in the room. From securing AI identities to whether access reviews are headed the way of the password, this is an unscripted conversation driven by practitioners for practitioners. Topics include identity as a business enabler, zero standing privilege, agentic authentication, standards for AI agents, vendor relationships, the captive customer problem, community, and hiring IAM talent. Thanks to Bravura Security for supporting the Identity at the Center podcast.

    Connect with Bart: https://www.linkedin.com/in/bartholomewallan/
    Learn more about Bravura Security: http://bravurasecurity.com/idac

    Connect with us on LinkedIn:
    Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
    Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
    Visit the show on the web at http://idacpodcast.com

    00:00:00 Welcome and Introduction
    00:03:00 AI Identities: Should IAM Teams Panic?
    00:07:30 Identity as a Business Enabler vs. Cost Center
    00:24:00 Continuous Identity and the Future of Access Reviews
    00:35:00 Zero Standing Privilege and JIT Access
    00:38:00 Standards for Agentic AI
    00:46:00 Vendor Relationships and the Captive Customer Problem
    00:55:56 Normalizing Rip and Replace
    01:01:00 IDPro, Identity Beers, and Building Community
    01:11:00 Agentic Authentication and Non-Human Identities
    01:18:00 Hiring IAM Talent
    01:26:00 Team Diversity and Multiple Perspectives
    01:27:00 Closing

    Identity at the Center, IDAC, Jeff Steadman, Jim McDonald, Bart Allan, Bravura Security, Identiverse 2026, Identiverse, IAM, identity and access management, identity security, AI identities, agentic identity, agentic authentication, non-human identities, NHI, access reviews, zero standing privilege, JIT access, continuous identity, IGA, vendor selection, identity community, IDPro, IdentiBeer, live podcast
  • Identity at the Center

    #441 - Identiverse 2026 - Sachini Siriwardene and Ian Glazer

    08/17/2026 | 37 mins.
    Live from Identiverse 2026 in Las Vegas, Jeff and Jim sit down with Sachini Siriwardene, winner of this year's Kim Cameron Award, along with Ian Glazer of the Digital Identity Advancement Foundation (DIAF). Sachini shares how she moved from open banking API security into consumer identity work at a bank, and what led her to apply for the award named after identity pioneer Kim Cameron. Ian explains DIAF's mission to remove financial barriers to industry participation and previews the upcoming Vittorio Bertocci award for standards contributors. The conversation covers agentic AI and non-human identity governance, the AuthZen specification, continuous access management, and how practitioners can separate real AI capability from marketing hype. The group also swaps favorite hallway conversations from the show floor, including a discussion on extending the shared signals framework beyond RISC and CAPE, before wrapping with some very Vegas talk about the Sphere.Connect with Sachini: https://www.linkedin.com/in/sachini-siriwardene/Connect with Ian: https://www.linkedin.com/in/iglazer/Learn more about the Digital Identity Advancement Foundation: https://diaf.org/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com00:00 - Cold open and conference banter01:35 - Jim's origin story with identity and Kim Cameron03:22 - Welcoming Sachini Siriwardene and Ian Glazer04:02 - Ian explains the Digital Identity Advancement Foundation05:54 - How Sachini got into identity through open banking08:46 - The moment identity clicked as mission critical09:47 - Agentic AI and non-human identity governance11:25 - Optimist or pessimist on AI and the job market14:45 - Applying for and winning the Kim Cameron Award15:41 - How DIAF selects award recipients17:21 - Standout sessions and the AuthZen specification18:36 - First impressions of Identiverse20:01 - Advice for future award applicants22:03 - Managing agentic identity in practice23:16 - Separating AI hype from real capability24:32 - Where the identity industry can improve27:08 - Acting fast without chasing hype28:05 - Favorite hallway conversations29:23 - Extending the shared signals framework30:39 - A D&D themed conference talk31:08 - Vegas talk and the Sphere experience34:19 - Wrap up and how to support DIAFIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Sachini Siriwardene, Ian Glazer, Identiverse 2026, Kim Cameron Award, Vittorio Bertocci Award, Digital Identity Advancement Foundation, DIAF, agentic AI, non-human identity, AuthZen, continuous access management, open banking, OAuth2, FAPI, shared signals framework
  • Identity at the Center

    #440 - Identiverse 2026 - Mike Kiser

    08/10/2026 | 52 mins.
    Recorded live at Identiverse 2026, Jeff and Jim sit down with returning guest Mike Kiser, Director of Strategy and Standards at SailPoint, for a wide-ranging conversation that spans two of the standards world's most active frontiers. The first half breaks down C2PA, the Coalition for Content Provenance and Authenticity, explaining how it differs from digital watermarking, how metadata and cryptographic signatures build a chain of custody for media, and why this work connects directly back to identity. The conversation then shifts to AI agents and the challenge of defining and governing intent, with Mike drawing an extended analogy to the early, under-regulated days of space exploration. The episode closes with reflections on the value of hallway conversations and community at Identiverse.

    Connect with Mike: https://www.linkedin.com/in/mike-kiser/

    Connect with us on LinkedIn:

    Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/

    Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/

    Visit the show on the web at http://idacpodcast.com

    00:00 Introduction from Identiverse 2026
    01:00 Mike previews his two Identiverse talks
    01:35 What C2PA is and how chain of custody works
    06:51 Watermarks versus C2PA explained
    10:06 Why content provenance matters for identity
    14:22 Is C2PA a standard or a working group
    16:23 The SpaceX and space debris analogy for agent intent
    20:13 Governing agent publishing without stifling innovation
    22:00 Action Identification Theory and the how versus the why
    27:47 Can an AI actually have intent
    32:34 Why people humanize and fall in love with chatbots
    38:37 The case for locking down intent early
    39:39 Does intent change, or is it a new intent
    46:19 Favorite hallway conversations at Identiverse
    51:03 Wrap up and where to find Mike

    IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Mike Kiser, SailPoint, C2PA, Content Provenance and Authenticity, Identiverse 2026, Shared Signals Framework, AI Agents, Agentic Identity, Digital Watermarking, Decentralized Identity Foundation, Intent-Based Access Control
More Technology podcasts
About Identity at the Center
Identity at the Center is a weekly podcast all about identity security in the context of identity and access management (IAM). With decades of real-world IAM experience, hosts Jim McDonald and Jeff Steadman bring you conversations with news, topics, and guests from the identity management industry. Do you know who has access to what? Visit us on the web at idacpodcast.com
Podcast website

Listen to Identity at the Center, Hard Fork and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features
Identity at the Center: Podcasts in Family