AI is no longer just a supporting tool — it’s becoming a semi-autonomous actor. AI agents are now automatically accessing systems, interacting with data, making decisions, and taking actions with little or no human interaction. But, as agentic AI adoption accelerates, identity and access management related challenges become critical. Misbehaving AI agents can do as much or more damage as individual human “agents”.
A recent survey shows that 91% of organizations already use AI agents, yet 44% lack any formal governance. This creates blind spots, compliance risks, and an entirely new class of security and identity threats.
Agentic AI introduces unique challenges that traditional identity systems were not built to handle: weak authentication practices, stale permissions, unauthorized data access, malware agents, and lack of visibility, to name just a few. And of course, attackers are now using AI not just to assist — but as central components of their attacks.
Securing this new AI agent ecosystem requires a unified, identity-centric approach: managing agents as first-class entities within your identity fabric, enforcing lifecycle controls, and integrating governance directly into how agents are built, deployed, and monitored.
Matthew Gardiner, Analyst at KuppingerCole, will examine the rise of AI agents and how AI is changing the nature of both general security and identity specific threats, the governance challenges of agentic systems, and the emerging best practices for secure AI adoption.
Arkadiusz Krowczynski, Principal Product Acceleration Specialist at Okta, and Michael Pattison, Senior Solutions Engineer at Okta will present how Okta’s cross-platform approach extends identity protection to AI agents. They’ll demonstrate how Okta helps organizations secure agents throughout their lifecycle across four critical phases — Detect & Discover, Provision & Register, Authorize & Protect, and Govern & Monitor — integrating seamlessly into existing identity and security frameworks.
Hello, everyone. Welcome to this webinar, where we're going to talk about artificial intelligence, probably a topic you haven't been hearing much about these days. Just kidding. And specifically, drilling in more into the agentic side of artificial intelligence and tying that to the security challenges and specifically, even more specifically, the identity management challenges related to agents.
So, just to help you find the chat button, why don't you go ahead and chat in where you're dialing in from, so we can entertain ourselves and see how big a reach we have for this webinar. And so, before I introduce my co-presenters or have them introduce themselves, I'll introduce myself. I am Matthew Gardiner. I am a fellow analyst here at KuppingerCole Analysts and a relatively new analyst, but I've been in industry, in the cybersecurity industry, for more than 20 years in the product side and in security strategy side.
So, hopefully, I can combine those two worlds, and you'll get some value from the conversation that I'm going to kick off. So, if you go to the next slide, I'm going to do a – oh, before we go to the next slide, let me let Arkadiusz and Michael introduce themselves. They're going to come back after my initial session.
Yeah, thanks, Matthew. My name is Arkadiusz Kulczynski. I'm part of the product organization here at Oktober and working as a principal product acceleration specialist and now with Oktober for about three years and already attended a lot of KuppingerCole webinars and live events and, yeah, looking forward to this one. Thank you.
Hi, I'm Michael Patterson. I'm a senior science solution consultant and I'm working for four and a half, five years now with the identity space and I'm going to show you a little bit more later on the building side. Excellent. We'll see you guys back in a bit.
So, if you want to go to the next slide, just some housekeeping items, typical housekeeping items. You're welcome to mute or unmute yourself, but it won't matter. You are muted centrally.
So, hopefully, by now you've found the chat button and right next to it the questions button. So, that's really where we would like you to drop in questions and comments as you go. It will pick up in the Q&A section. There also will be some polls. There'll be specifically two polls related to the topic to hear your perspective and what's happening in your organization and we'll go through the results of those, which you can see as you answer, but we'll go through the results of them as part of the Q&A in the last 10 minutes or so.
As I mentioned, questions, comments, compliments, whatever you think would make sense, please drop them into the question box and we'll try to work those in at the end part. Hopefully, the discussions we have between now and then will help prompt some of your thoughts and ask your questions. And then this webinar itself is being recorded so you can, you know, watch it again, if you want, or refer to your friends and colleagues and also the slides themselves will be made available.
So, you know, you don't have to worry about taking notes or anything like that. So, my section is about basically laying the groundwork, laying the groundwork, getting a little bit about the growth of AI, but specifically around enterprise. We're going to spend most of our time around agents because those are really the, in some ways, the trickiest thing from a security and governance point of view. And so let's get into it. Next slide.
So, just some stats. I wanted to find some stats specifically related to enterprise AI as opposed to AI more generally.
And, you know, again, no secret. It's like the biggest thing out there these days.
You know, some people are arguing it's as big as the internet ever was. But as its impact to the enterprise, which is really where the security and governance issues come up, again, it's up to the right.
You know, this is data, the first one's data from Menlo Ventures, specifically talking about this being the fastest scaling software category in history. So, again, you know, I don't know, $37 billion, knocks your socks off, but the fact that it's, you know, gone from essentially zero to $37 billion in just a few years, you know, shows the fast growth. Specifically around agentic AI, in this PagerDuty survey, more than half of organizations claim that they already have AI agents deployed.
So, it's gone from very little to a fair bit. And if you look at the bars down below, which, granted, are a little bit small, only about 14% of organizations have no immediate plans, you know, sort of off the horizon is about 14%.
So, they're either doing it or about to do it or planning to do it, other than, you know, 14%, so 86% of organizations. So, we're going to ask you this question when we get to the poll to find out what you're doing in your organization.
But, you know, suffice to say, it's happening, and it's happening big time in enterprises. Next slide.
And, of course, any change that happens that relates to data and applications and users and business processes raises cybersecurity concerns, and I think this one is no different. The headline I grabbed here, maybe a little bit of hyperbole, it's a ticking time bomb, which, you know, that's not really the way I would talk about it, per se, but it does get the point across that things are changing and security and governance practices, no doubt, will absolutely have to change with it. But the question is, will we get ahead of it this time as an industry? Can we?
Will this lead to increased security investment? And so, that's one question that I have. And if you go to the next slide, you'll sort of see what, when I asked ChatsyPT, what it might look like. The security, the prompt was, can security teams get ahead of the AI trend? From this picture, it looks like the answer is probably get ahead might be a little bit too optimistic. It's a little unrealistic that all the security people are wearing ties. That's one thing that probably didn't get right. And three men, and they're running with a magnifying glass, for some reason.
But the point is, will we get ahead of it this time? The point is, this is the next big challenge. It's coming down the pike. We can all see it's coming. We have enough experience to know that, unless things are different this time, we'll be playing catch up. And obviously, it's on us, the vendors, the analysts, etc.,
to, you know, if not catch up, but be ready as best as possible for when, you know, when the tide really turns, and have a plan to better secure and govern AI when it really hits, as it's hitting right now. So, next slide.
So, just one, I have a few sort of high level comments before I dig in in detail. One of the sort of amusing ways to think about AI, I pulled from a show that perhaps many of you have seen. Silicon Valley, the short answer is a comedy about Silicon Valley. And it's funny, because it's so close to home. In this case, the still is pulled from, and it's basically a show, part of the show, where the AI engine at this company, the fictional company, was told to buy inexpensive hamburger. But it wasn't really guided very well. The guardrails were not so awesome.
And so, it found inexpensive hamburger and delivered 4000 pounds of it to the office. And so, I raised this to be funny, but also to get across the point that I think there's a blurring happening right now of who's responsible for essentially what I would call bad engineering, not a security issue.
I mean, there was really no security issue here. It's just that, you know, they said get the cheapest hamburger and it did. They didn't put the guardrails, but maybe they only want 20 pounds maximum or whatever they wanted for the cookout.
So, the question I have, and something to think about, is how much of this bad engineering can security own? And the world is complicated right now.
So, we're sort of trying to sort through who's responsible for what in the security and governance of AI and genetic AI in particular. So, if you go to the next slide.
So, what I like to do during any complicated transition like this is go back to basic principles. And the most basic principle in security is CIA, confidentiality, integrity, and availability. Those are the three parts of security that really does fall largely with the security team. You could argue that availability is broader than security, but at the end of the day, this is the lens from which we should evaluate security controls.
And so, I'm going to use this CIA triangle as kind of a reference point as I go through the rest of my section. So, if you go to the next slide.
So, the question is, you know, before we get into, like, how do you secure agents, we should probably agree on what an agent is. So, I have two definitions.
One, I put the super simple one here. It's an agent is a software worker. And I like the fact that they said worker because that's sort of a model that, you know, ties back to identity, really, and how you secure your workers. In this case, it's a software worker, but it can perceive, reason, and act on your behalf.
Now, that your could be a person, it could be an organization, a business unit, but towards some goal. If you go to the next slide, you'll see a little bit more of an academic definition where they're powered by large language models, which is sort of generally part of the solution.
So, they act as sort of the brain of the agent. But, and the agent is endowed with planning, tool use, memory, autonomy, and automation. And it's able to autonomously, in many cases, or at least semi-autonomously, which we'll talk about, execute tasks across the web, software, and physical environments. And it creates a sort of a new flavor of risks that are similar in some ways, but dissimilar in other ways from security risks that we've, you know, been working on for many years like identity.
So, if you go to the next slide, it will be the first poll. And this is basically mirroring the stat I did at the top. I want to know about your organizations. Does your organization have AI agents currently deployed in production?
So, basically, the answers are pretty straightforward. Now, go back. I just want to just say yes, no.
Yes, no, don't know. So, hopefully, everyone on this call probably will know if you have some agents deployed. But I guess I couldn't assume that.
So, to go on. So, I'm going to give you a few models to think about that, you know, sort of translate a world that, you know, we all know better to this sort of new world of AI and agents. Are agents digital versions of people?
So, the answer is kind of, in some ways, often, but not always. So, if you think about what a person can do, they search for information. They communicate. They access data. I'm talking about, you know, in the enterprise sense. They make decisions.
You know, they set up their environment in a certain way. You know, those are all things that an agent would do.
So, you can kind of use, you know, we're talking about identity and agents here. So, to some extent, the model does hold, although not perfectly. If you go to the next slide, I give you a model of kind of the identity management world as we've known it up until, you know, free agents.
Certainly, in the world of, you know, the late 90s and early 2000s, we started to get people accessing online web applications and that sort of complexity of, you know, authorization, authentication, entitlement management, permissioning, all those sorts of things that as an industry we've been working on for you know, 20 years or more, 30 really. So, we've created this whole environment of people, processes, and technologies like identity and access management systems and governance systems and TAMs, etc.
to try to put a better handle on the human and their appropriate access to corporate resources. So, again, this model, if you go to the next slide, does apply, but not perfectly, to the world of agents.
So, you could think of perhaps having as many or many more agents than you have people, you know, that's coming down the road. And you still need to securely authenticate, connect the agents to applications and data, but it gets starts to get more complicated because, for example, you need to agents might use the services of other agents.
So, it's sort of there's sort of a transitive property going on there. So, it's similar, but not the same as human-based security and governance and identity. If you go to the next slide, you get a little bit more realistic view of the world of agents that, you know, are arriving right now into the world of users, applications, and data.
In fact, this graphic is probably a little bit out of whack percentage-wise in that you could have many more agents than people, but, you know, you can only fit so many on a screen. So, the bottom line is we need to get ready for this, you know, much more complicated management and governance and security now the world of agents.
So, let me give you on the next slide, I'll give you another model to think of, you know, it's getting closer and closer to the kind of the real problems here, but again, I want to give you a reference point. Perfect reference point for agents in the software world are, quote, agents in the physical world.
So, the most classic one that we've probably all experienced and maybe even written in is, you know, the self-driving car. So, that's what I'm pointing to here, you know, autonomous agents can be modeled on the levels of self-driving of cars.
And so, on the next slide, I've created a grid that basically shows, you know, from zero automation to some driver assistance, to partial automation, all the way to full automation and the sort of the autonomous driving, you know, bullets in the middle column, and then the sort of the analogous enterprise agents, AI agents, and the analogy of, you know, how much human is in the loop, so to speak, and we're going to talk about human in the loop quite a bit for the rest of this session, from none at all, you know, at the zero level to, you know, very, very little at the bottom.
So, for example, for full automation, the human might define the goals, policies, and handle rare edge cases. But other than that, it's not really in the loop.
And so, if you excuse the fact that humans are generally fairly risky, and so probably shouldn't be at the low risk side of the equation, but from one to five, basically, the model to think about is the more autonomy and the more action ability you have of these agents, the more risk in general. So, you combine those two sort of independent autonomy and actionability, and you get sort of just the combination of these two. You can think of an XY chart, I guess, you know, is where the risk goes up.
And so, following from that, if you go to the next slide, what's in green here is essentially where the automated security controls need to play a part. Now, where the human is highly involved, obviously, the controls are somewhat semi-automatic in that, you know, the part of the governance where the human is in the loop is the human needs to be in the loop to make a decision about, yes, that's okay.
Go ahead, order 4,000 pounds of hamburger because, you know, we're feeding a football stadium versus an office. That kind of decision.
So, this, but as you get more down towards the full automation, the human is not so much in the loop. The system itself needs to be governed and secured and managed more automatically.
So now, the final model I'm going to go through is on the next slide, where we get into real security issues that are really raised by AI in general and agents in particular. And the point I was trying to make here is those are putting together this four by three matrix or 12 sort of areas of security concern. First of all, they have impact to the CIA, confidentiality, integrity, and availability of the systems in different ways. But in other ways, this is just another new paradigm.
A lot of these security controls or security issues like, you know, sensitive data leakage has nothing in particular to do with agents. It could happen in many different ways. And actually, if you go through and, for example, look at you know, for example, the threat actor created malicious agents as a form of malware. This happens to be a particularly potentially quite bad form of malware that has a lot of epitome so that the threat actor themselves can scale. And then the third one I'll make a comment on is overprivileged agents.
You know, the concept of overprivileged users is not a new concept. It's now you just have the corollary overprivileged agents. And so each one of these sort of areas of concern have you know, potential impact either to the confidentiality or perhaps all three of the CIA triad because it's hard to know what exactly the next step of the attack is. So it could impact you know, any aspect of confidentiality or availability.
So I'll use this as a reference, but again, I'll pivot on the next slide to say here are the things that I said, you know, here are the security issues that I think directly relate to the identity management problem of agents. And so you can see that the vast majority of security issues are really kind of a new flavor of identity and access management issues now applied to agents. So let me go to the next slide, which is the poll before I hand off to my co-presenters.
So this poll is when do you expect agentic AI identity and access management governance to become a top priority in your organization? Is it already a top priority, so number one, or are you sort of it's bubbling up now and you expect it to become a top priority in the next six months? Is it more than six, you know, in the six to twelve months time window at your organization or more than a year into the future? So as you're answering that, I'll ask that the slides be taken down and we'll hand off the presentation to Fabio. Over to you. Thank you again, Matthew.
So this was a very insightful look at the current situation of the strategy. So we are super happy and excited to be here today and have the privilege to share with you an update on what Okta is doing strategically to drive the future of safe AI adoption. So safe ABBA, as always, please make always purchase decision based on what's available today and an additional disclaimer about just informations and personas that maybe will be used in the presentation.
Again, my name is Akhildas Kopczynski. I'm part of the product organization at Okta and working as a principle product acceleration specialist. So last year at our flagship event, we talked about our journey to become one of the most secure companies on earth. And this year we want to share what we've learned about how the most secure companies innovate with AI.
So for us, this means building everything on a foundation of security that you can trust. We've heard it today and many of you also read in the news and nothing new. AI is really the biggest platform shift we've seen since the internet. But this one feels a little bit different. So we all see the headlines. AI is reshaping entire industries and we feel definitely the pressure to add AI to our products and use it to get better, faster and for sure more competitive. But we also see other headlines where the ones about the security risk, right?
So we know we can't innovate at the cost of security and there is the tension that we all face every day. And you know it because yeah, we've been saying it for years. So to get security right, you have to get an energy right and as this big AI topic is the biggest platform shift, you really can't be successful in one without the other. So that's why AI security is really identity security. And it's easy to really get ambitious about hey, what's next, right? But finding the right balance between moving fast and staying secure is super super hard.
So we're hearing the same from you, from our customers, from our prospects. You want to really innovate and you need to be secure and in overall every company struggles with this and the stakes have never been higher to achieve this and we have to figure out how to do both the best case, right? So how we do, so how so how do we do both? So at Okta our foundation is really Okta Security Identity Commitment. So we launched this almost two years ago and it's with our four pillars.
So first building secure by the default products, second hardening our own corporate infrastructure, third really championing best practices that are easy for you to adopt and finally elevating the entire industry in the fight against identity attacks. At that time we've invested more than lots of hours across these four pillars and we are super proud of the progress and this is how we innovate without compromise. So we all know this and we all heard different stories. So chatbot we all laughed at moving towards really true autonomy.
In other words, specifically we come from the deterministic machine behavior to probabilistic machine behavior. So in the deterministic world, you know exactly what a machine is going to do. You know the developer. You have your change you have your change control process. Those processes likely even include for example, vulnerability scanning and threat analysis. The bottom line is that machines in the deterministic world are highly trusted and may have a higher level of success than a real human.
None of this is the case for an AI agent and therefore we cannot have the same level of trust in the behavior of an AI agent that we have with a deterministically written piece of maybe sometimes small code. And that pace is only accelerating. So the more powerful these AI agents become the more access they need to your systems and your data and the more access they need the more critical it is that they have a secure identity.
This means that without identity security AI security collapses and again AI security is identity security and to understand why consider the complexity you are already maybe facing today. Coming back to this agent. So these ones are really connected to everything just like yeah, just like the people do. They connect to machines computers and APIs and they connect to other agents across the globe. They connect to your data and sometimes to your customer data that results in a massive increase in complexity across the entire environment.
But we notice that complexity isn't the only challenge as of today really AI agents are invisible, overprivileged and unmanaged. So this is a huge risk to your business. So the big question is what can we do and how we from Okta can help. So when talking about securing AI agents there are two areas of concern.
First, we need to have to ensure that AI agents are built in a secure fashion and that they are built in such a way that enterprises can adopt them in a secure way. Second, we need to ensure that enterprises have really full visibility, control and governance over the agents within their environments and working with the problem of this scale really requires a holistic approach and to get this right you really need to get an identity security fabric.
So a unified approach that simplifies control while strength is protection and this really helps you to ensure that all of your identities, human, non-human identities and nowadays AI agents can be safely secured before, during and after authentication. So a really unified approach to identity security. So what does an identity security fabric look like in practice? So the most important thing is that it has to be really comprehensive.
No gaps, no badges for an attacker to sneak through. This means it must cover every identity type, every identity use case and every resource and we are starting with a unified approach for every identity type. This includes your employees, customers, partners, contractors and all of your non-human identities. That's why we are making AI agents a really first class identity in our Okta platform. And as mentioned it has to cover every identity use case.
Converged of identity access management, privilege access management, identity access management, also identity security posture management and last but not least threat detection and response. And this fabric has really to integrate across every of your resources. So your apps, your infrastructure, your databases and your IPIs, everything. And not only your cloud applications, but also your on-premise applications, because we know a lot of our customers are leveraging on-prem environments and having a kind of hybrid model.
So this whole identity security fabric really allows you to orchestrate security across, as mentioned, the entire fabric. The left hand knows what the right hand is doing. So this is definitely important. So you can share risk signals for a coordinated defense and really automate actions like, hey, a universal lockout the moment a threat emerges. And when we are talking about infrastructure, this really expansive network includes our biggest crucial partners.
A single platform really offers seamless orchestration from, again, before authentication, during authentication and after authentication. So security is really orchestrated across the entire fabric. To sum this up, AI agents are now treated equally to humans. So once you bring an AI agent into the platform, you can easily manage it in our meta directory. So from that single point, you can see and control the agent's access, its connections and all of its activity, which is super important. You manage them like any other identity, and it's super and just simple.
And this overall unified approach enables you to maintain a strong security posture and be free to use AI to meet your business objectives. So to bring this in the whole identity security fabric, again, it's all about, number one, visibility, seeing all the identities in one place, control, really to ability to control what apps, what data these agents have access to, both modern and traditional ways, and governance. So giving IT and security teams the ability to audit and secure agent identities over time.
So to sum this up, before I will hand off to Michael, the Okta platform is really the best, fastest and easiest path for building an identity security fabric. So it is first and only modern, fully integrated and scalable cloud platform properly built for both IT and security. Individually, our products are best class, but when you bring them all together, so before, during and after authentication, they deliver this massive outcomes. And of course, a key feature platform of the Okta platform is that it continues to evolve as new technologies emerge. So stay tuned.
So in a world that's changing this fast, you really need a partner who can help you to innovate safely. And our job is to focus on identity, which frees you to choose the AI technologies you need for your business. You decide what and how to deploy. And by providing a really consistent identity security layer, we from Okta have insulated a future proof your organization from the constant churn of the whole AI market. And to give us a deeper dive into the auxiliary side of the house, I'm joined by Michael today. So Michael, the floor is yours.
Thank you, Aki. As mentioned before, we saw a lot of how we can build things with, sorry, how we can manage and secure AI agents in the enterprise. And now let's change pace a little bit. Next slide, please. To see how we can actually build this AI agent, this experience. And as we all know, identity isn't just a locking box anymore. It's getting mission critical. It's how you secure your business and how you personalize every digital experience. And most importantly, it's how you earn trust. Next slide, please. And now we were entering this new AI area where AI is built into everything.
Everybody wants it, but it is also very important to when you build systems, when you build AI integrations, to have security in mind. Next slide, please. So we believe that AI will unlock a lot of new opportunities, but it also introduces a lot of new risks. And what I want to show you today is how we can utilize identity to help solve some of these issues we identified. Next slide, please.
Sorry, one back. So what we heard a few times already today is to get AI right, you have to get identity right. And what that means is that we really, really need to have this topic on the top of our minds when we start building it. It cannot be bolted on later on after we have our first version or second version of an agent running. It needs to be there right from the beginning. So next slide, please. And that's where OSIRU comes in. So we always help builders to manage human identities. And now we can do the same for AI agents.
So we need to ensure that these complex requirements can be solved as easily and as efficiently as possible so you can stay secure and keep building what's next for you. So let's look at the next slide and how we can do that. So first of all, we need to ensure that when we bring AI into products, it's not just a feature, but it's actually an experience that allows people to interact with agents, with internal co-pilots, with smart workflows. And next slide, please. That brings us to the challenge that we heard before already, that AI agents are not predictable. They are non-deterministic.
So it means they accept open-ended input, which might be fine if we summarize public data and we just rely on their trained data models. But handing sensitive data or taking actions on their own, that is a significant risk, and we need to manage that. Next slide, please. So it means that it also reshapes your internal architecture. We are moving away from this classical three-tier data model where you have a presentation layer, you have your business logic, and you have your data somewhere protected by two levels. Next slide, please.
We actually have now these agents that are reshaping your entire stack. So they become the presentation layer, but they also become, in a way, your API. They have access to APIs, they have access to data. So this is already risky when it's just internal on your own agent. But it will get significantly worse when you actually expose this agent or this product you have to a third-party agent where you have even less control over. Next slide, please. So now if we're putting these two things together, then we have a quite serious risk to tackle.
So every API call, every permission check should be secure, and identity is the way to do that. Next slide, please. So here's the challenge. We still need to move fast, but we need to stay secure there as well. So we've been working with leaders who are building next-generation software, and we identified some of the biggest challenges. So next slide. So to build these AI agents, you need identity to be easy to integrate, it needs to be flexible, and it needs to be secure by design. And that's what Auth0 is. That's what we have been always from day one.
We made it easy to help secure identities in mobile apps, in web apps, and now we're doing it again for AI. So what are the pillars we identified? The first one is authentication, obviously. AI needs to know who I am, so I can build a user profile, I can get a user context, and also I can offer personalized content. So that means agents are not just answering prompts, they are making decisions that they call APIs, and context tells them who they represent, what they can access, and how cautious they should be. The next pillar is APIs and tool calling.
So the agent only really becomes useful if he can do something for a user that is more than just answering from his built-in training data. So that means, for example, accessing a Google calendar to schedule an event, send a message via Slack, or maybe purchase some stock. Then we also need, next slide please, to have a way that AI can perform async operations autonomously. So that means they do things without supervision, but to complete a critical action, like booking or purchasing something, it should still require proper human authorization.
So, for example, a travel agent AI that needs a user consent to approve before we book the actual travel, or flight, or hotel, or something. So that agent needs to have a way to actually reach that user, even if you're not sitting in front of a chat prompt. Next slide please. So that means that we also need to consider how AI can access data, and how we protect these different data sets from abuse.
So it means getting away from this, let's say, easy integration where you give your AI access to everything, and hope that a system prompt will protect you, to shift to a properly scoped integration where the agent can only actually act on behalf of the user. Next slide please. So it means that we actually have these four pillars, right?
So we have user authentication, which we've already done from day one, but we also allow easily integration into third-party systems by helping AI systems hold their permissions, hold tokens for third-party systems without the developer needing to build this by themselves.
So you can just use a simple SDK from us, that will also allow you to use asynchronous authorization to get user interaction, user approval if you need to, and then finally we will have a little closer look at how we can actually then scope user permissions on a data level to ensure that an agent can only ever access the data he should be able to. So next slide please. And that is actually a very crucial topic.
So we need to make sure that even in the worst case scenario, somebody becomes very creative with a prompt for an agent, that agent is never able to actually do any more harm than a user could do. For example, he can only access the patient's record that he's authorized to, or he cannot modify, for example, any data that he has no permissions to. But how do we enforce this at runtime? Next slide please.
So the way we can do this is by using FGA, which means a fine-grained authorization model that allows us to build, first of all, an authorization model in a simple textual description that we can use to actually build a relationship graph that allows us to then very quickly determine, based on the permission data we have in the system, what access a person or an agent can have to a specific set of data. So this could be like documents, it could be a role level permissions, however granular you actually need it. Next slide please.
That in turn allows us to integrate into this RAC pipeline, so the Retrieval Augmented Generation, which is a way to make AI answer more accurately and useful by allowing to combine the model reasoning with real data. So instead of relying only on what the model already learned during a training, you can put in documents from your own data and give them to the model as context to answer. And this obviously needs to be very controlled and run in a user context. So when a user sends a prompt, the AI chain kicks off a search to find documents that might help answer it.
It queries the vector store, a system that retrieves these documents based on how semantically similar they are to a user prompt, so that there's some pre-sorting in there. But then to make sure that only the data is considered that the user has access to, we need to actually filter these queries beforehand. And that's exactly what we can do with FGA and the SDKs we provide you. So Auth0FGA applies a post-retrieval application layer filter. Big mouthful. We are not filtering inside the vector store itself, and that's by design.
We manage to make sure that all the answers, all the data that's coming back, is properly authorized. And for example, the length chain retriever then pulls these documents out first, and we check that only the documents the user has access to are then used for the actual answer. Next slide please. So with that, we believe we have all the major components that you need to build AI agents securely.
So we have the authentication for GenAI, we have a token vault that can store secure tokens, we have the way to contact the user via asynchronous authorization, and finally, we can also restrict the data the agent can access based on FGA. Next slide please. And with that, we come to the end, I think, of this presentation. So we have this identity fabric, and we have the part where we actually run the platform, monitor everything, but we also look at how we can have a secure agent fabric that allows us to also build and maintain these agents. Excellent.
So we have plenty of time to do some Q&A, but before we get into the actual questions, I'll go through the polls. And actually, I think the poll results actually highlight the challenge we have quite well, even from just the audience here. So the first question, if you recall, was does your organization have AI agents currently deployed in production? And 63% of respondents said yes, 25% said no, and 13% said they didn't know. But obviously, the significant majority of yes is the answer.
But when you go to the question of when do you expect agentic AI, IAM, basically the topic of this webinar, governance to become a top priority in your organization, the only 15% said it's already a top priority. So 85% is obviously implying it's in the future. And the number one answer of when this sort of governance model that we've just been talking about becomes a top priority is a year in the future. So it's sort of somewhat off the horizon.
So that is probably the problem that we're not surprised we're going to be in the midst of as an industry, but we're doing it, the industry, you know, the company is doing it, in this case, agentic AI in spades, but not so much around governance. So we'll do our best to try to close that gap, but clearly there's a gap. Now I'll go over to, do you guys have any comments on that while I pull up the actual questions? Or is it a surprise? No surprise. No surprise, right? Yeah. You're telling me that the security industry is going to be behind a major transition in applications and data?
Who could see that coming? So first question is a straightforward one from Sebastian. It's about shadow AI. So I had that as one of my, in my grid, as one of the problems. So how do you, how does Okta detect, you know, the deployment of AI and AI agents that your system or your team, the script team wasn't involved in, and they're just being rolled out? What's the secret sauce for that? Yeah. So as mentioned, everything starts with visibility. So we can't protect what we don't see. So getting this visibility via, for example, identity security, posture management.
So to collect and check all the different identities, especially the agents and check, hey, who are they and where they are connected to. So this is the first, first important point. To really gain this visibility, keep your one-stop shop dashboard and then check, check potential risk scenarios, et cetera.
So yeah, visibility. What's the best source for that visibility? Directories or where are you looking?
So we are, we are looking across different identity providers, not only, not only Okta. So here we are IDP agnostic. And we also are checking across, across different applications. So like the big ones on the market, you know, the Google is the safe for us and, and many, many more. So we are not only checking different IDPs, but also specific applications with, you know. That might be hosting AI services. Yeah. Okay. So a number of the other questions are around sort of like, how do you do it?
So I think most of them that I've been looking at today will be over to you guys, but there's sort of like the concept of human in the loop that we both talked about. And you know, at a theoretical level, it makes sense. Like if you have a tricky authorization to grant, you know, bring a human in the loop, but it raises a number of questions like, well, you can't have a human in the loop a hundred times a second. The human may be asleep.
You know, how do you guys try to address the reality, the mismatch between how agents operate and how humans operate? And, you know, if they need to be in the loop, how do you deal with that?
So, I mean, there's two aspects to this, right? If the human is sleeping, the human is sleeping, so the agent has to be patient and wait. And I think that's the easy part. The pause. Yeah. And the tricky part really is to ensure we can reach the human on a channel that he's actually checking, right? So it could be a push notification to ask for approval, or it could be an email. It could be some kind of instant messaging system that he is utilizing. But also there is obviously the other big important question is how do we actually make sure it's the right person, right?
I think that is one of the questions here as well. So how can we do something like a step up or a two-factor verification of some critical interaction to make sure it's not somebody left his phone unlocked and there is a toddler playing with it and approving the sale of the company or something like that.
So, yeah, we need to do step up. We need to make sure that critical operations are protected accordingly and not just by a simple yes, no prompt maybe. And that's something we need to consider. And does it, you know, in most approval processes, you know, human approval processes, like if Matthew not available in, you know, three hours, then go to somebody else.
I mean, is that the kind of logic you'd expect where you go to their boss or you go to someone at peer or is it, you know, how do you handle them? Yes, to a degree. So there is two ways of thinking, right? One is it's like a personal interaction, then probably there should be nobody else. But you can also look at it from the perspective of like approval chains.
And that's something we can also very easily model with fine grained access, where we can have these logical hierarchies that says, okay, maybe this is the user, that's the manager of that user, that's the manager of the manager, and so on. And we can go that chain up that tree up to till we get an answer. So it really depends on the context, but, you know, if it's a personal purchase, I don't want my boss to decide. But if it's a business decision, you know, that may be perfectly reasonable. Okay. All right.
So now there's a question on, again, like, how do you do it where, you know, say, an agent would like to leak private data? How do you, how does, you know, centralized security systems like what you provide, stop them from doing that? Is there a way?
I mean, it's sort of like my 4000 pounds of hamburger problem, basically, like, you know, it's operating, it makes the wrong decision. But it's not really a security issue.
Or, but in this case, it is a security issue, because it's sensitive data going out the door. Yeah, so, oh, sorry, Michael, continue.
Yeah, I mean, it's a two sided problem, right? One side, it needs to be the need to be guardrails right from the beginning from from the development point of view, you need to have like a strong system point, you need to have strong authorization for for things maybe even like different approval levels for different amounts of spend, for example, but then there's also what what I had over to Arcadius, the governance side of things that you need to have a look at. Exactly. So as mentioned, so we covered the visibility part a second for sure is hey, it's all about control.
So what apps and data can they really access and as permissions change and creep over time, we have to keep them and secure and the access secure over time. So the governance part is definitely the number number three pillar and resist visibility, control and governance. So we have to, we have to keep an eye on all the fancy AI agents that are spinning so fast, right?
That is a question on basically, maybe you could develop a little more of the fine grained authorization that you talked about, Michael, you talked about it toward the end of your session, where like, how do you like with all these AI frameworks? How do you embed the fine grain authorization? And how do you kind of divide the, you know, the responsibility?
Like, this is what does the security team need to do on the back end? And what does the developer need to do on the front end to sort of externalize a pretty granular like, I don't know, is it a control about ordering hamburger, you know, maximum amount equals, you know, 20 pounds?
Or, you know, how do you how do you get the fine grain authorization into the different AI frame? Yeah, good question. So I think it all starts with the authorization model, right? You need to think about what do you actually want to authorize? And that can be abstract to a certain degree. So you can also include context into that, that system. So it doesn't need to be something like a fixed rule. But you can also provide context to the query itself. There's only 20 people eating hamburger. So assume accordingly, you don't need 4000 pounds.
Yeah, exactly. And you can also have things like, for example, you could model an approval that says, okay, if you spend, let's say, $500, go for it, right. But if you maybe spend $501, we want to have a human looking at that and verifying it. So you can find the balance, but it doesn't come by itself. You need to think about what you're trying to protect, and how you can, you can put in proper guardrails. The other question is around a lot of the entitlements seem to be explicitly mapped to individuals.
You know, so kind of like, Matthew has his entitlements, his accounts, and thus my agent should have the presumption that the agents have the same, no more, no less. That presumes that my identities are being well managed, my accounts are being well managed. And the question is, is that, you know, is that a fair assumption? Or does it, or is this going to put more light on the issue that a lot of organizations have sort of poor user identity management, sort of build agents on top of it will make the problem more tricky?
Yeah, I mean, absolutely. It's the same story everywhere. If you have bad data, you make bad decisions, right? So there is no magical tool that will make your bad data into good data. Maybe you can use an AI agent to make it sound like it's good data, but that's probably not what you really want.
So yes, you could, and you should, for an agent, run it in a user context, but it does not necessarily mean that he has exactly the same permissions. It could be less, right?
Again, it depends on how you model this, because I think the key difference is, or the important point is that an agent should not impersonate a user. He should always be an agent, but he's acting on behalf of the user, which seems like a small difference, but it's an important difference.
Yeah, yeah, I mean, it's true in the real world, like your spouse may act on your behalf, but not in every way. Like maybe you don't have signature authority, unless they have your power of attorney, for example.
So, all right, well, I think we have time for maybe one more question. Excuse me.
Ah, here's one more I don't think we've answered. It's also that transitive issue that I mentioned, where you have agents, and then agents need to get services from another agent, and now you have, like, how does that other agent authenticate the agent that's asking it to do something? What you're thinking about, sort of that agent to agent authentication, how is that done?
So, again, it's a good question. At the moment, I think everything is still a little bit in flow. On a technical level, it is, at the end of the day, there is a lot of API authorization, and that's something we can do very well. There is also something new we're trying to introduce, which is cross-app access, that allows us to also manage these permissions on an enterprise level, not on a user level, right?
So, again, it brings the control plane back for the IT, also for governance. And I guess at the moment, it's still a mix of a few different technologies, agent to agent being one of them. And hopefully, it will consolidate soon that we can have an easier standard for everybody to work together.
Now, we are on the front lines of this issue, so it makes sense that not every possibility is easy yet. But thank you very much. Thanks very much to the audience. We've gone a minute over. Arki and Michael, thank you very much for taking part in this.
Hopefully, the audience got some valuable information. And please, you know, pass along the recording and the slides to your colleagues. And we look forward to having you into new webinars for technical analysts in the new year. And you guys have a great time. Thanks for having us. See you next time. Yep. Bye-bye.
See All Locations
See All Locations