The Blueprint for Managing AI Agent Access and the NHI Lifecycle

View Show Notes and Transcript

AI agents are being adopted at an unprecedented pace, bringing unique but solvable access management challenges to the enterprise. Because agents require programmatic access to internal tools, relying solely on LLM prompt filters is rarely sufficient; instead, organizations must prioritize robust identity and access controls.  In this episode, Ashish sits down with Ido Shlomo, Co-Founder & CTO of Token Security, to discuss how Identity and Access Management (IAM) teams are stepping up to govern Non-Human Identities (NHI). Ido shares practical solutions for transitioning to a "secure by design" approach, where identity teams provide safe, pre-configured access templates for developers spinning up new AI agents.  We explore the full NHI lifecycle from large-scale discovery and analysis to safe decommissioning and how teams are finally bringing single-sign-on-style centralization to the fragmented world of service accounts and API keys. Ido also explains how modern security teams are leveraging agentic application builders to create customized, policy-driven identity workflows using natural language.

Questions asked:
‍00:00 Introduction to Non-Human Identity (NHI) and AI Agents
‍01:30 Ido Shlomo’s Background: From Offensive Security to Token Security
‍03:30 Defining Non-Human Identity and the Rapid Scale of AI Agent Access
‍06:50 How IAM Teams Are Successfully Adapting to AI Agent Sprawl
‍11:00 Why Centralized Identity Is a More Reliable Control Than Prompt Filtering
‍14:30 Implementing Secure-by-Design Access Templates for Developers
‍18:20 The Challenges of Relying Solely on Native Cloud Provider Controls
‍21:00 Managing the Full NHI Lifecycle at Cloud Scale
‍28:30 Addressing the Lack of a Traditional Identity Provider (SSO) for Agents
‍33:20 A Practical IAM Approach: Discovery, Analysis, and Remediation
‍35:50 Empowering Security Teams with Agentic Application Builders
‍39:40 The "You Laugh, You Lose" Cybersecurity Joke Challenge

Ido Shlomo: [00:00:00] Guardrails don't work. For every human identity, that there are 25 non-human identities. Today, people are talking about 110 multiplier.

Ashish Rajan: We felt it was going too fast, but it was taking years for adoption. Over here, we're talking weeks and months over here, and sometimes even days for adoption. For

Ido Shlomo: AI agents, there is no identity provider.

Ido Shlomo: There's no- not a single sign-on for them. You are bringing in a two-year-old technology to dominate extremely wide parts of your business, and you want it to be secure by design, agents managing agents' identities.

Ashish Rajan: How does one separate the signal from the noise? Non-human identity and AI agent identity can be confusing, especially if you work in the cloud world.

Ashish Rajan: Because there are cloud identities, there are connections to different kinds of tools. I'm talking about the AI agent life cycle. I had a great conversation with Ido from Token Security about agent permissions, agent lifecycle management. How do you manage agent identity, especially the non-human identity, the [00:01:00] AI agent identity, across a large-scale environment?

Ashish Rajan: And what is he seeing around his customers on how the identity teams across the board are dealing with NHI and agent identities? All that and a lot more in this episode of the AI Podcast. If you're here for a second or third time, I would really appreciate if you take a quick second to hit the follow or subscribe button, whichever podcast platform you listen to us on.

Ashish Rajan: We are on Apple, Spotify, YouTube, and LinkedIn. I hope you enjoy this episode with Ido, and talk to you soon. Peace. Hello, and welcome to the episode of "What I'd Do." Hey, man, thanks for coming on the show.

Ido Shlomo: Happy to be here. Thank you for having me.

Ashish Rajan: I'm excited for this conversation. Maybe to kick things off, if you could share a bit about yourself and what your professional background is.

Ido Shlomo: Sure. No problem. I'm Ido. I started Token Security about three years ago. I'm the luckiest person in the world. I have the best partner a great friend of mine that we've been friends for almost 18 years.

Ashish Rajan: Wow.

Ido Shlomo: And we decided at a certain point to start Token because my personal background, I started...

Ido Shlomo: Oh, most of my career was in offensive cybersecurity- ... [00:02:00] as a long-term military officer and commander of large organizations there.

Ashish Rajan: Yeah.

Ido Shlomo: So I specialized myself in vulnerability research, implant development cyber operations but then decided to go to put an end to it, and to go civilian, to go defensive, commercial.

Ido Shlomo: And we l- I can talk ab- a lot about Token, but if, in terms of background, I think that's me.

Ashish Rajan: Cool. Yeah. And maybe obviously Ido, we are talking about identity as a topic today.

Ido Shlomo: Yes.

Ashish Rajan: And I'm curious as to what-- Obviously, you've had years in cybersecurity, in the- ... military background as well.

Ashish Rajan: Why identity? Yeah. And wh- what part of identity are you trying to tackle at the moment, and why?

Ido Shlomo: Yeah. All right. So jumping into it, I think that- Our superpower when we started was infrastructure security. But, when founders start companies, they are looking for what's called a founder-market fit.

Ido Shlomo: Founder-market fit is where you are the best at solving a specific problem, but that, that problem also matters a lot. And back then, I think that there were already ample amount of [00:03:00] cloud security products protecting workloads, application security, and so on. And we noticed that infrastructure security i- in terms of identity, hasn't been reinvented for a really long time.

Ido Shlomo: Back then, there were all sorts of product doing a part of it, a bit like secrets management, a bit of privileged access management. And we saw that even though those product existed-

Ashish Rajan: Yeah ...

Ido Shlomo: there has been such a huge gap around identity and access management for workload. And we said, "Okay, we are really good at that.

Ido Shlomo: Let's try to tackle it. Maybe it would be interesting for the market, maybe it wouldn't."

Ido Shlomo: We started working on that, and that was going really well. It ended up in a category called non-human identity security.

Ashish Rajan: Yeah.

Ido Shlomo: A category that's, there was something very exciting about building something over a couple of years and then seeing it materialize into a category that companies get acquired in, that's talked about as the next thing in security.

Ido Shlomo: Our biggest luck, I think, was that this neglected tech stack that we were trying to build a solution for [00:04:00] ended up being the tames- same tech stack as what agents use to access resources.

Ido Shlomo: So when an agent comes to read a file, to send an email, to query a CRM record, or delete a database, God forbid they use the same technology of non-human identities that's facilitating programmatic access.

Ido Shlomo: So that's service accounts, API keys, tokens, and so on. That's why we are called Token Security. We were the OGs starting before it was cool- ... protecting these ki- types of identities. And I think that's like people investing in GPUs when it was used for computer games. Yeah. Ending up being super rich because it's already not used for computer games, but used for AI.

Ashish Rajan: Yeah.

Ido Shlomo: That's a, a bit of how we ended up where we are today.

Ashish Rajan: What's the reality? 'Cause I find it also fascinating. You started in the cloud infrastructure space. What's the reality of NHI today? To what you said, it's very common. A lot of people perhaps are still not introduced to it. What's the shift you've seen in what people assume they have as an AWS [00:05:00] foot- footprint for identity-

Ido Shlomo: Yeah

Ashish Rajan: versus the non-human identity? And how has that changed with

Ido Shlomo: AI? Yeah. So sometimes I find myself sitting near one of my... I lead product research and engineering in Token, so I sit and I'm discussing something with my engineer, and they have 20 to 40 agents running in the same time.

Ashish Rajan: Yeah.

Ido Shlomo: Each and every agent uses, or piggybacks, on their own human credentials to make an action on our CICD pipeline or, On our code repos or make changes to, to production on specific events. These are sometimes manual, but also people are using agents more and more in that area. Now, that area has exploded in terms of the amount of interaction.

Ido Shlomo: When we were talking about applications, then it had a specific pace, which was still very large. Infrastructure as code and the ability to manufacture software has been around for quite a while, but I truly haven't seen [00:06:00] something as quick and as wide as adoption for AI in software development- in my entire professional career. So that's that kind of describes a bit... And I f- I feel that everybody that listening to it- Yeah ... would agree that we've never seen this unprecedented pace.

Ashish Rajan: Yeah.

Ido Shlomo: Yeah.

Ashish Rajan: I don't think anyone has. Yeah. It's come out-- come around so quickly as well, and I'm sure when you saw the cloud ecosystem as well, we felt it was going too fast.

Ashish Rajan: But it was taking years for adoption.

Ido Shlomo: Yes.

Ashish Rajan: Over here, we're talking weeks and months over here. Sometimes even days for adoption. Which kind of leads me to the next question as well. A lot of people obviously feel they have control over the identity in cloud. They have SAML or if you have the AWS example, you have the IAM user.

Ashish Rajan: You-- People feel they have control over the identity piece in... what specifically about the ag- AI agent space or agent specifically-

...

Ashish Rajan: Is that something that you're finding unique that this changed the conversation with most customers you work with?

Ido Shlomo: Yeah. That, so as [00:07:00] I said sometimes lucks come knocking on the door, first of all let me g- give a big shout-out to my customers, like, identity access management teams. They have been teams that have been, for the last 25, 30 years, building a very strong practice of human identity management. So that's the SAML federation piece- Yeah ... the single sign-on, being able to do identity govern- governance and administration.

Ashish Rajan: Yeah.

Ido Shlomo: Now they were the first to say, "Wait, we have this other type of identity that we need to take care of." Putting a password manager in order to fix your identity problem, which is like the secret, the equivalent is the secret manager for workloads, would not be enough. We need governance, we need process, and we need the ability to manage it.

Ido Shlomo: And for a really long while, nobody gave it them. Sorry for the language. Nobody was really interested in that, so no budgets were diverted to that. Now, then started the cloud explosion, and more and more organizations started to understand that identity teams also needed to help in governance [00:08:00] of non-human identities.

Ido Shlomo: Back then, mainly workloads. Still a bit slow cleaning up tech debt of 15 years is not easy.

Ashish Rajan: Yeah.

Ido Shlomo: But we started to see major movement there. Then- People got to know the the AI space, which started from LLM and model consumption, and still, there was still something like a big delay.

Ido Shlomo: They said, "Wait, I should protect it with maybe guardrails. I should put some kind of model filtering." This is not an identity problem. Now, this is the, like the peak the climax. When people start discussing agentic application, they don't care about model consumption anymore. They don't really understand what tokens does the agent consume, how its internal reasoning process works.

Ido Shlomo: They just know that they gave it the most important part that distincts between agents and just LLM applications are the tools.

Ido Shlomo: The ability of an agent to take an action.

Ashish Rajan: Yeah.

Ido Shlomo: That's where you've seen unplanned [00:09:00] budg- budgets being poured into identity teams to try to find the right tool to manage those agents' identities, and today, this is completely exploding.

Ido Shlomo: And those teams that have been, like, working there a- and trying to get the budget to fix non-human identity ended up as being the most important teams in the orga- enterprise's AI security strategy. And that creates something that's very unique because I think that today, when people are talking about AI security, they're talking about agentic security.

Ido Shlomo: Yeah. And that specifically is solved only by identity and not by model filtering.

Ashish Rajan: To reduce your blast radius as well for what could go wrong.

Ido Shlomo: It's not only to reduce your bl- blast radius. It's to have a central point of control about what an agent is doing.

Ido Shlomo: You are already accepting... I think that, like when people are talking, and, like, when they are discussing, they are accepting that agents have their own roles in the organization, right?

Ido Shlomo: Yeah. They are talking about my analyst agent, my code reviewer, my... and this and that. So they are accepting that this is an identity [00:10:00] problem and that they should give these like virtual semi-human processes identities.

Ashish Rajan: Yeah.

Ido Shlomo: And so right now that's like the, the main topic of conversation for all those teams.

Ashish Rajan: Do you find that with many people already going down the path of building identity access management with agentic AI as, and agentic AI, but by, I think I need to be careful 'cause I think sometimes it just means so many different things. So I'll just say agents, let's just say for this conversation.

Ashish Rajan: Yes. Agents and identity in the cloud context versus on-premise, the ones that you're seeing as customers who are quite advanced in how, and this is to your point, people have been trying to do this for some time, but now it's like a mainstream problem, so there's a budget for it as well. A lot of people try their AI security journey with solving prompt injection and all the- Yes

Ashish Rajan: other things that came up. What's the justification for... 'Cause obviously we are at BlackHat, people are trying to figure out, "Hey, what my- Yeah ... security program looks like."

Ashish Rajan: What's the justification for instead of pouring money into prompt [00:11:00] injection and LLM firewalls and stuff, what have you found that you're seeing in these customers who are quite forward-

Ashish Rajan: That makes them go, it's better to put money and budget and effort into- Yeah ... IAM instead of all the other ones?

Ido Shlomo: Yeah. Th- that's a good question that, that confronts us with a hard reality.

Ido Shlomo: AI technology is hard to explain. I don't think that everybody really acknowledges what a large language model is.

Ido Shlomo: Because what as models evolved they became more and more complex. What's a thinking model versus a non-thinking model? Most, most security teams would have a hard time explaining that because it's really complex. Eventually, when customers choose to go with an identity access management solution for AI agents is because of two reasons.

Ido Shlomo: One is that model protection doesn't really work. When we say that Fable or Mythos or the, in the Hugging Face incident or all of the incidents that right now everybody's speaking about that the [00:12:00] model broke through-

Ashish Rajan: Yeah ...

Ido Shlomo: or that it didn't have guardrails, it means that models are b- are such an advanced technology that security, and i- in a lot of terms, it's very hard to build good guardrails to the point that people that have spent years, like there's this pod- podcast of an AI red teamer that says, "That's not going to work."

Ido Shlomo: Guardrails don't work because the ability to predict the input of a large language model or the output is the ability to understand each and every part of the English language, as an example. Yeah. And it's almost impossible to build good guardrails today. Also let's say the truth, the frontier model labs are investing tons of money in order to do that.

Ido Shlomo: So when people consume AI models today, engineering teams assume that the model is unbreakable or that has the right guardrails. So on one end, it's very hard to do. On the other end, like the security teams that we are working with, since we moved from model inference to really AI agents-

...

Ido Shlomo: I am [00:13:00] taking your advice to use that term.

Ashish Rajan: Yeah.

Ido Shlomo: They understand that it doesn't really matter. Yeah. I don't really care what inputs and outputs are in the model. Yeah. What I care is what the agent is doing.

Ashish Rajan: Yeah.

Ido Shlomo: Once I treat a thing as an agent, and I understand that it could connect to my AWS environment, that it could change CRM records in my Salesforce, that it could send an email or get an email o- in my behalf, then I start to understand that this is an access problem.

Ido Shlomo: Yeah. And the, the real thing that matters is what the agent is doing, not necessarily how the mind process is working. So when we build zero trust, for example, it wasn't because security training wasn't working, it's that nobody would tell you, "Yeah, but I got such a great security training program." "Why do I need to do identity access management?" It does- it didn't make sense to them.

Ashish Rajan: Yeah.

Ido Shlomo: So I think that, that answers the question- I think, yeah ... of why it doesn't work and why maybe guardrails

Ashish Rajan: really matter. It's a great answer as well, 'cause also it highlights the point where if the concern that you have is what an agent can do in the first place, that truly just comes down to identity.

Ashish Rajan: It's not an LLM firewall. [00:14:00] It-- you're probably trying to predict what could happen when instead if you limit the access of identity, you probably have-- You're attacking it from a different perspective, is you're going to the source in a way. Ultimately, the AI agent has to use some permissions, either your own or something they, something it assumes.

Ashish Rajan: And if you manage that, limit that, that kind of goes a long way as well.

Ido Shlomo: Yeah. And ju-just to add on top of that, it's not only post-factum identity limitations restrictions, and so on. It's also a safe provisioning process. Token is one of the leading companies in the idea that we can provide a marketplace of secure agen-agentic templates.

Ido Shlomo: That the agentic templates doesn't necessarily mean the safest prompt. I don't even think that's a thing. Agents feed themselves prompts and respond to things that is in their internal thinking process. They interact with other agents, and so on.

Ashish Rajan: Yeah.

Ido Shlomo: What we provide is safe access.

Ido Shlomo: So when you are creating safe access from the start I think that you are already getting to a secure by design approach [00:15:00] to AI agents, and that's really important.

Ashish Rajan: I love this. There's a concept called secure by design.

Ido Shlomo: Yeah.

Ashish Rajan: What does that look like when people approach this?

Ashish Rajan: Because I-- obviously going back to the people who are trying to uplift an existing program- ... perhaps they're from an identity background as well. What does it look like to do security by design for AI agents?

Ido Shlomo: Yeah. So in the risk of sounding repetitive when people thought about secure by design models, they thought that there is a model that couldn't be jailbroken- a model that couldn't be distilled. And so they decided maybe that the, the frontier model levels would provide the models that are safe enough. What we understood is that this is true for Our grandmas, our fathers, our siblings that are not working in the IT security.

Ashish Rajan: Yeah.

Ido Shlomo: So let's discuss enterprise security, right?

Ido Shlomo: When you're talking about secure-by-design enterprise security, you understand that you are bringing i- for immense business value.

Ashish Rajan: Yeah.

Ido Shlomo: Let's not underestimate how transformational this technology is. You are bringing in a two-year-old [00:16:00] technology to dominate e- extremely wide parts of your business, and you want it to be secure by design.

Ashish Rajan: Yeah.

Ido Shlomo: So you understand that the technology new, is new and might not be protectable on the modern endpoint itself. So now you're trying to understand what areas of the organization would be impacted by that. You are planning the lateral movement paths. You're trying to understand where, what the agent could or couldn't do, and how to create...

Ido Shlomo: the true guardrail for agents is identity.

Ido Shlomo: So what you do is that you need to reinvent your entire IAM identity access management discipline to not work in the pace of people. How many people are coming in and out of company at a certain month? Yeah. Dozens? Hundreds? Thousands? We're talking about me sitting by an engineer running, in parallel, 40 agents an hour, let's say.

Ido Shlomo: And then it multiply it by the amount of either engineering, IT, or even business end users that are [00:17:00] running ex- an extreme amount of agents. That needs a reinvention. The technology stack is not the same. The, the use cases are not the same. You need to rebuild, agents' identity access management from the ground up.

Ido Shlomo: But once you do that, you have like a marketplace of roles, of permissions, and of intent-

Ashish Rajan: Yeah ...

Ido Shlomo: that that kind of when you want to spawn a new agent, you have already a system of record that tells you how to do it safely. That's what we would call secure by design, is like having the roles, the credentials provisioning, the entire lifecycle management, and also the deprovisioning.

Ido Shlomo: Eventually, a lifecycle management ends when an agent need to be retired because it's lost its function.

Ido Shlomo: And today, this is something that we are pushing. There's not a lot. And we can talk about other business drivers like regulation, like compliance and so on. But I think that today, most teams are driven by risk management-

Ashish Rajan: Yeah

Ido Shlomo: and the ability to like shift left and allow people that want to spawn agents [00:18:00] to have safe identity templates for those agents.

Ashish Rajan: What about native controls? 'Cause a lot of people who are from the cloud background, they've obviously been told by AWS and- ... everyone else for a long time, "Hey, use short-lived tokens, session tokens, and use that as a way to limit your exposure to a, a breach."

Ashish Rajan: Where does, where is the balance between that and what you guys are building?

Ido Shlomo: Yeah. I don't know. There is like a, like I like to say, a $33 billion proof of the fact that people don't trust AWS with their cloud security, right? You... AWS is not incentivized to keep you secure. Yeah. It's incentivized for token maxing and for you to consume as much bedrock of the bedrock service that you can.

Ido Shlomo: I think that first of- security is a very important and big consideration for people, and I don't think that they would buy their identity security from a frontier model apps, if that makes sense. I would say that people or identity access [00:19:00] management teams understand that they need dedicated tooling, and that you need people that are coming from a security back- background to build it.

Ido Shlomo: I don't have a problem understanding how Anthropic ecosystem work.

Ashish Rajan: Yeah.

Ido Shlomo: I just am frustrated about the fact that their customers don't get what they need in order to ma- to do it securely, and I'm happy that I provide that service for them.

Ashish Rajan: Do you find that, So to your point, the frontier model doesn't have any incentive to build those guardrails themselves or even the cloud models to your point.

Ido Shlomo: You can talk about being a good citizen and maybe I'm sure that not the day of having a more established regulator framework around the use of AI. Most of the AI security frameworks that I saw, whether it's the ISO 42,000 something and AUCU1 and other compliance framework that people are trying to push like bottoms up- They talk a lot about access.

Ido Shlomo: Yeah, for sure they advise you to use the latest model version, but the moment the, the ink doesn't even [00:20:00] dry on the paper, there is a new model version that they need to update in their entire compliance framework. But when they set up identity controls, it's much much more stable and much more robust, much more resilient to real governance and and he- being really responsible.

Ido Shlomo: So I'm not saying that Anthropic is not really incentivized to-- They need to work with enterprise customers. It's the fact that what they aim for is for you to use as much token as you can, and not necessarily to do it as secure as possible. Yeah.

Ashish Rajan: And I guess the, the goals are very different at that point in time.

Ashish Rajan: Do you find that in the conversations that I have with agents, how does it work at a scale? 'Cause obviously you can talk about one agent, one session to- one temporary session token. How does it work across the scale? 'Cause most organizations, especially enterprise, have, let's just say over 200 AWS accounts- Yeah

Ashish Rajan: and huge teams of developers, like 10,000, 20,000 people. They all have identity, they're all creating agents as well in their cloud environment, whatever. So the the life cycle [00:21:00] that you mentioned earlier, where for all the way from provisioning to deprovisioning and everything in between, how does that scale across a large organization?

Ashish Rajan: Like- Yeah ... what are we looking at as a, as an organization that I should be expecting would change- ... when I try doing this at scale?

Ido Shlomo: It's a g- great question because, when we started the workload identity security, anonymized identity category, There, there were quotes of like for every human identity, th- there are 25 non-human identities.

Ido Shlomo: Today, people are talking about like 110 multiplier. Yes, that was one of the reasons that we built Token4. We-- The me- the mechanics of non-human identity work differently.

Ido Shlomo: People are thinking in scale from day one- Yeah ... and they are looking for a security partner that works in that scale.

Ido Shlomo: So trying to harness a human identity provider to do agentic identity is useless. It's impossible because the entire techn-- [00:22:00] underlying technology works differently. For example, people are provisioning agents using Terraform.

Ido Shlomo: It's a-- It almost doesn't have any human identity because it's not worth the investment in scale, and they do multiple cloud environments for testing, staging, production.

Ido Shlomo: You have usually one p- one identity provider. So Token was built for that cloud scale because we started actually to scale with applications, with workloads back then. That means that we've built like novel solutions like a infrastructure as code ownership or the ability to s- to do secrets management in scale and so on, and that really adapted well to the scale of AI agents.

Ido Shlomo: But it was because it was purpose-built for that scale of environments.

Ashish Rajan: So to your point then you're able to scale, So the life cycle management that you're talking about, you're able to scale that across a fairly large cloud environment at ease-

Ido Shlomo: Very

Ashish Rajan: much ... if you have a layer to manage that.

Ido Shlomo: Yes. Yes, and it would be futile [00:23:00] to try to adapt your SailPoint to do the same. I'm talking with the customers. They are really trying. They are, like, being sold on the idea that their identity governance and administration solution, like SailPoint, Saviynt, and other fun, other products- Yeah

Ido Shlomo: Are trying to create products in our category and they say, "Okay, yeah, it's gon- only gonna take me three years to make it work." And I was like, "Yo, we need to move faster than that," and I think that everybody agrees with us.

Ashish Rajan: So what's the-- And I'm glad you mentioned this because a lot of questions that people have especially the ones in the IAM space, they're all being told the same thing, right?

Ashish Rajan: There- i'm sure there are other vendors out there who are claiming the fact that, "Hey, we've done identity for X number of years." Yes. "We got you. Don't worry about this. It's just in the roadmap," or perhaps it's already there. How does one separate the signal from the noise?

Ido Shlomo: I think that luckily- We are at the point that performance matters already, like that there are established projects with budgets to do what we do.

Ido Shlomo: , I think that one of the well-known fact is that we did [00:24:00] everything that we can to centralize human identity.

Ido Shlomo: And to put one place that we manage human identities, and for non-hu-human identities, we didn't do that. So it's very hard to... it's very, sorry, easy to even see that fragmentation where you have one human identity provider and that agents, they access identities from a ton of different services.

Ashish Rajan: Yeah.

Ido Shlomo: So for example, we built this integration strategy that allows us to cover over 850 different products. That was something that was purposely done in order to answer for AI agent identities that are by design fragmented.

Ashish Rajan: This is also an interesting point to also ask about just before AI kind of took off and non-human identity was just being spoken about, there was a category called CIEM came across- Yes

Ashish Rajan: in between. Some people clearly invested in that as well. Then there is a whole, I think hey, manage your permissions, manage your access. There's a lot of that conversation conversation as well. There's the whole governance with admin [00:25:00] users, agent and AI what we're talking about here, and just to be where is the role for...

Ashish Rajan: Is CIEM should still continue being a thing?

Ido Shlomo: That's a great question.

Ido Shlomo: The CIEM category suffered a like a premature death.

Ido Shlomo: Okay. Eventually when non-human identity became a category, and I'll explain the difference in- Yeah ... in one moment. But when non-human identity became a category, we did have a we did the postmortem on CIEM- Yeah ... and why it was consolidated into CNAPPs, like Wiz and Lacework and Okta and- Yeah

Ido Shlomo: I don't know other cloud security products. And back then, I think that the entrepreneurs that were building companies like Ermetic and Sonrai and Brightive, they did see a real gap in the market. They did see that workload identity-driven attacks were on the rise, and that workloads had this blast radius that was from their entitlements.

Ido Shlomo: CIEM is like cloud infrastructure entitlements management. Yeah. It's one of the hardest parts of identity access management for [00:26:00] workloads. But back then, I don't think that there was the urgency because there was no emerging technology that gave a tailwind to, to them as vendors. Yes. And when we started, we first of all took a much larger approach.

Ido Shlomo: We didn't treat the entitlement as the problem. We saw an identity lifecycle problem.

Ido Shlomo: And we tried to solve that. And identity lifecycle, y- it has a lot of different types, like w- from key rotation to safe provisioning, to decommissioning of inactive identities, and also rightsizing, meaning that I think that we saw the need to reinvent IAM and not only focus on entitlements.

Ido Shlomo: Yeah. And so the only thing that I can say is that they were, they had a good problem, but they are far too early in where they were back then. I wouldn't reinvent it- ... right now, though, just to say that.

Ashish Rajan: What about authentication authorization? Traditionally, identity teams, the reason we were talking about SAML, MFA, all that is authentication.

Ashish Rajan: Authorization used to be something that we used to hand [00:27:00] over to the application team, because it made sense to be closer to the environment because you knew what you were doing. What does that look like at scale when you talk about NHI, especially specifically AI agents?

Ashish Rajan: An agent may have access to five different tools- Yes ...

Ashish Rajan: six different tools. The, and the, the whole thing expands.

Ashish Rajan: Initially, a lot of people used to, at least in the identity space, people were always like: Hey, I know I know Ashish has access to, let's say, Salesforce.

Ido Shlomo: Yes.

Ashish Rajan: But the authorization of what Ashish can do in Salesforce is authorization, quote-unquote.

Ashish Rajan: And that is what was managed by our identity team. In the non-NHI team and you were talking about this earlier as well, in terms of, hey, the tool access and everything, what does that look like in the scale of cloud context, multi-cloud context?

Ashish Rajan: Because authorization is no longer now to what you say, if I pull back the layers- Yeah ... AI agent is an identity, but that identity is across my multiple clouds- ... on premise. MCP included, this list goes on, whatever. So how is, how do you see authorization [00:28:00] in the, in a scale world from that?

Ido Shlomo: Yeah. Small detour from that question. We can go, I will go back to it in a moment. So my small detour is that I can't, it's very hard to, for me to hear a, an AI agent is an identity.

Ashish Rajan: Oh, okay.

Ido Shlomo: Yeah. Yes. Like you're not an identity, right? We are consumers. We are consumers of identities that represents us in like digital world.

Ashish Rajan: Ah,

Ido Shlomo: yeah. Actually, yeah. Meaning that when an AI agent accesses something, it accesses on behalf. Sometimes it uses your human identity- Yeah ... or the identity that represents you as a human. But on its own, it's not an identity.

Ido Shlomo: Yeah. And then let's go back to the question itself. What's different?

Ido Shlomo: Or how do you build for that scale? So human identity is very centralized. We did everything that we could in order to manage human identity in one place. That when I, as an individual, come to consume that identity, I log into my single sign-on. That's what [00:29:00] it... I do biometric authentication.

Ido Shlomo: I have identity verification and proof, and my entire identity life cycle is managed in one place.

Ashish Rajan: Yeah.

Ido Shlomo: My groups, my roles, and that's federated across a lot of different products. And that's how human identity work. For AI agents, there is no identity provider. There's no, not a single sign-on for them.

Ido Shlomo: And so Each agent, in order to access real resources, it needs access through non-human identities, API keys, auth-based integrations, service accounts and passwords, private and public keys, keepers that allows it access into the specific target repo. So what Token needed to do when we started is to centralize all of that into one place because the-- since there is no single source of truth, we needed to normalize the data across a lot of different types of of different identity providers, and that took [00:30:00] a lot a really long time.

Ido Shlomo: But now that we are leading in terms of coverage as, as I said hundreds, like eight hundred and fifty different data sources, I think that we are at the place that we can safely say there's only a very small long tail that we don't cover for you today. And I think that's super important when you are coming to evaluate how we are going to solve a AI agent identity to not think that there is only one place that you need to look into.

Ashish Rajan: And I think I like this. Also, maybe just to clarify for people who-- 'cause you mentioned there is no identity provider for AI agents.

Ido Shlomo: Yes.

Ashish Rajan: What is-- So is it the... Am I-- By what's an ex-- H-how-- What am I tying it back to, to manage? Is it the fact that I have a quote, unquote, "service account"-

Ashish Rajan: That's been given access? And this is to have the identity people understand okay, if it's not my SAML provider- ... what is the entity, let's just say that as a word- Yeah ... what does it tie to as a [00:31:00] service or function or whatever in cloud? What is it? Is it an IAM user?

Ido Shlomo: By the way, there, there are, like, also business incentives of why there's not a single identity provider.

Ido Shlomo: I think that technology providers create vendor locking when they create a dedicated identity access management scheme. SAML was, like, like a, a regulatory need.

Ashish Rajan: Yeah.

Ido Shlomo: And I think that that was groundbreaking technology, and also a groundbreaking move of all of us acting like adults.

Ido Shlomo: Yeah. Go us. But now that you want, for example, an agent to only use your CRM surface as a CRM you are incentivized to create your own identity access management model that is not replaceable with other CRM providers. So each and every system implements it in a different way, but usually it's a programmatic interface, an API that an agent authenticates to.

Ido Shlomo: And the-- it also represents the, that, that back end also represents your permission model. So when you talk about [00:32:00] integrating with a third-party service, that's usually the, the surface that that an AI agent ties to when it- ... tries to take action on a specific resource.

Ashish Rajan: So if I make an API call to, say, OpenAI or Anthropic, that, that is my AI, quote unquote, "AI agent"

Ido Shlomo: in that context?

Ido Shlomo: Yes, that's w- that's the consumption moment. Yeah. But then you're interacting, like integrating with OpenAI or Anthropic in order to utilize the model, right? Yeah. But then the second act of that play- yeah ... is when an agent got the instruction from a model to call a tool and to take an action.

Ido Shlomo: Yeah. That goes directly to the service's API-

Ashish Rajan: Yes ... API service. That's right. Yeah. Okay, and that's where you're able to kinda say to your point about the authorization- Yes. Okay, awesome. The thing is, with NHI, what do you th- think is a level of maturity, or in terms of what's an easiest place to start to address this problem?

Ashish Rajan: 'Cause obviously, I imagine with enterprise, who had identity access management for a long time, huge environment they've gone, "Yep, okay I think this is a good idea, man. I think [00:33:00] I agree with Ido that, hey, this is the NHI." I'm n- Are there any-- Like where do you see your customers start with?

Ashish Rajan: Are they starting with the fact-- Like, are there easy agents to start with so they can show ROI? Or what's an easy place to start for people to start showing ROI?

Ido Shlomo: So first of all, it's a lot of fun to see my customers become the celebrities of the security team. "Oh, yeah, that, this is our time.

Ido Shlomo: This is our moment. We are having a non-human identity project. Where do we start?" And most of them are all- have already started to bash their head against the wall of "How am I going to centralize that many applications into one normalized model?" Th- everybody understands that governance without discovery is just theater, right?

Ido Shlomo: Yeah. It's just like kidding ourselves that, "Oh, if we look at one place and avoid the rest w- we would get it sorted, and then we would move to the second one." They need... So the first thing that ev- that our customers start with is very li- large scale discovery of the ability to inventory the non- non-human identities, identify what you have what what identities do you [00:34:00] have, how do they authenticate, and what's their permissions.

Ido Shlomo: And then you start to understand, like, where are all my gateways? Basically, identity replaced network as the real boundary in the world, so a lot of the discovery ends up as being, like, tying that, those non-hu- human identities discovered to AA agents. Now you have a complete or a...

Ido Shlomo: Let's imagine a graph of the access that an agent can take. An agent has three to 20 different API keys, and those API keys can give access to different areas of the organization. So you started with discovery, now you're going through analysis.

Ido Shlomo: Analysis of what's my crown jewels? Where shouldn't the agent access?

Ido Shlomo: What's my policy? Trying to define how the life cycle management of these agents is going to look like. How do we retire decommissioned agents or agents that are not in use? How do we monitor for new agents being created, and how do we discover for risky behavior using agents? So [00:35:00] you did discovery, then now you have that understanding phase or analysis phase of figuring out what exactly do I want to tackle, what campaign am I taking.

Ido Shlomo: Like hardening my Snowflake, like getting to zero trust for agents in production and more. And then the last part is a remediation. B- basically applying those management practices of delegating, changes to agents' identities to internal teams, working with my internal engineering in order to make to create the right, right sizing for those agent.

Ido Shlomo: How do I eventually even take active action or active remediation action against agents that are very risky, or that I can safely say that I'm not hurting any business process? So that's basically the, that entire journey in one go. And the nicest thing is that all used to be managed by people.

Ashish Rajan: Yeah.

Ido Shlomo: Today, a lot of that is managed by agents. Agents managing agents' identities. Basically, our MCP server was one of our best [00:36:00] sellers that we ever... one of the features that were the best sellers of the o- of the company because it allowed agents to manage agents' identity.

Ido Shlomo: But basically, it allowed identity access management teams to extend our product and to use it using agentic technology. Wow. So that's pretty cool, and that led us to also building more agentic interfaces, like an agentic application builder, and all sorts of cool stuff that you can see on our website.

Ido Shlomo: Enzo, our agentic application builder, is our take on do you know platforms like base44- yeah ... Lavabel, Replit? We built the same, but for identity teams.

Ashish Rajan: Oh. Yes. So I can have an identity application through prompts?

Ido Shlomo: A custom... Yes, a customized identity application hosted on our identity graph, allowing you to manage identities in your own internal workflow.

Ashish Rajan: Oh, and people were asking for it? I think people wanted to do that. Oh, to your point, because then you can customize it to your organization.

Ido Shlomo: Yeah. I think, yes, exactly. I think that everybody today in, by the way, in all technol- all the areas of technology are [00:37:00] contemplating between build and buy.

Ido Shlomo: Yeah. So you either build something that's very customized, but you pay the total cost of ownership, or you buy something, but it's a one-size fist- fits all.

Ashish Rajan: Yeah.

Ido Shlomo: And there's no product that one-size- ... fits all. So how do you combine those two? You build an application builder that allows you to build on top of a very strong data graph.

Ashish Rajan: Oh, okay. So it still plugs into your existing data graphs. Yes. It still s- plugs into all the identity information you have, but it's based on what you want it to be rather than- Yes. So you're almost going away from that whole one dashboard to rule them all. It's your- Absolutely ... dashboard-

Ido Shlomo: Yes

Ashish Rajan: for what you want it to be.

Ido Shlomo: Exactly. So you have an interface for your agents. That's the MCP server that you- Yeah ... and you can also build your own application over our graph-

Ashish Rajan: Yeah ...

Ido Shlomo: using our agentic builder, and by that you are like, you're not going to build 850 integrations. Let's agree.

Ido Shlomo: Yeah.

Ido Shlomo: I agree. Let's not play that game. Let's not kid ourself. But if someone has built it for you, you don't want to be tied to their

Ashish Rajan: UI.

Ido Shlomo: So you have [00:38:00] the ability to build your own.

Ashish Rajan: So people would be able to build an application because they would be working on the token app builder.

Ashish Rajan: They would-- It would already have the MCP capability with all the 150 integration you guys have?

Ido Shlomo: Yes.

Ashish Rajan: Ah.

Ido Shlomo: And think about security team coming, uploading the AI security policy. The application is built based on that document. They are describing what they want- Yeah ... like, how they want the organization to be managed, and the second part is they get an application that's tailored to their processes and their language, and their know-how.

Ashish Rajan: Is this more-- Are, are you finding that pe- people who are using your app builder capability, are they on the more advanced side or are they just people starting off as well? I think I'm curious as to what are you finding as a maturity of people adopting this. Clearly, you've built it as a feature- Of course

Ashish Rajan: and everything.

Ido Shlomo: It's not really the adoption is it is on the end of people that are more engineering savvy or that are more like tinkerers.

Ashish Rajan: Yeah.

Ido Shlomo: But it's actually liberating a lot of people. I think that a lot of people used to rely on engineering teams to [00:39:00] build their own internal dashboards and so on.

Ashish Rajan: Yeah.

Ido Shlomo: Now, we've liberated them to be, like, as business users- To write code, and that code is really tightly fit to AI agents' identities. I think it works. I think that l- a lot of my customers are enjoying some kind of like a renovation of their career and seeing something new happening in their life.

Ido Shlomo: It's

Ashish Rajan: a great evolution coming in.

Ido Shlomo: Yes. Yes,

Ashish Rajan: absolutely. Oh, wow. Awesome. Dude, this is awesome. Thank you so much. I... That, that was most of the technical questions I had. I have the last section. You may wanna... you may want your phone as well.

Ido Shlomo: Yes.

Ashish Rajan: This is la- You laugh, you lose. I'll say a joke, and if you laugh for... if you react in the first five seconds, you lose. If I react in the first five, five seconds, I lose. So I can start first- You lose ... and see your reaction. All right? So I'll start my joke first, and then I'll see your reaction. So my joke to you is Well, I'm already laughing without-

Ido Shlomo: Yeah.

Ashish Rajan: You know what's funny about service accounts?

Ido Shlomo: What's funny about service accounts?

Ashish Rajan: They're like that guy in the office nobody's spoken to in five years. The day [00:40:00] you try to get rid of him, suddenly he's mission-critical.

Ido Shlomo: That was pretty good.

Ashish Rajan: Yeah.

Ido Shlomo: I loved it. All right. Let me give it a try. I think that you had like a good start there, but let me also give it a try. A CISO walks into his CEO office and says, "I've got two pieces of bad news." So the CEO says, "Okay, sit down. When you are coming to me with bad news, we are really screwed."

Ido Shlomo: So the CISO sits down and says, "Look, the first one, one of our AI agents just transferred $20 million to an offshore account." And the CEO says, "Jesus, $20 million? That's a lot of money. I can't believe it we are, like, in a bad situation. But what's the second news?" So the CISO says, "It's using your credentials."

Ido Shlomo: So the CEO exhales and says, "Oh, thank God, I thought we've been hacked."

Ashish Rajan: [00:41:00] Oh. That was fu- that was good, man. Wait, did you think of this yourself?

Ido Shlomo: Yes.

Ashish Rajan: Oh, wow. Well done, man.

Ido Shlomo: I I took my, my day-to-day go-to joke and adapted it to AI agents' identities.

Ashish Rajan: Oh. So that's where I get- I'm gonna use this.

Ashish Rajan: I think that- that's a good one.

Ido Shlomo: I'll send it over.

Ashish Rajan: Yeah. I'll take that one. Where can people learn more about Token Security and the work you guys are doing? Yeah. What's the websites?

Ido Shlomo: We are really trying to be evangelists of our field. My re- big shout-out to my product research engineering and marketing team that is doing God's work in spreading the word.

Ido Shlomo: Our website is www.token.security.

Ashish Rajan: Yeah.

Ido Shlomo: Surprisingly. You can find the blog there, the resources. We give talks in conferences. I really recommend seeing what the research team is buil- is doing and putting out there because it's really novel stuff.

Ashish Rajan: I'll, and I'll put your LinkedIn link into the show notes as well, so people connect with you as well.

Ido Shlomo: Yeah, appreciate it. But

Ashish Rajan: thank you so much for coming on the show, Ido.

Ido Shlomo: Thank

Ashish Rajan: you. I had a great time. Dude, it was amazing. Thank you so much.

Ido Shlomo: Yeah.

Ashish Rajan: And thank you, everyone, for tuning in as well. See you next time. Thank you for listening or watching this episode of [00:42:00] Cloud Security Podcast. This was brought to you by techriot.io.

Ashish Rajan: If you are enjoying episodes on cloud security, you can find more episodes like these on cloudsecuritypodcast.tv, our website, or on social media platforms like YouTube, LinkedIn, and Apple, Spotify. In case you are interested in learning about AI security as well, do check out our sister podcast called AI Security Podcast, which is available on YouTube, LinkedIn, Spotify, Apple as well, where we talk to other CISOs and practitioners about what's the latest in the world of AI security.

Ashish Rajan: Finally, if you are after a newsletter, it just gives you top news and insight from all the experts we talk to at Cloud Security Podcast. You can check that out on cloudsecuritynewsletter.com. I'll see you next episode.

Peace.

‍

No items found.
More Videos