Thank you very much, thank you. Greetings everybody, thanks to KuppingerCole for hosting us today. I hope you've had a great four days, nearly at the end. This session we're going to be talking about dreams, right? So my name is Paul, I work for Omada Identity. This is not a software pitch, this is not a demo. The purpose of this conversation is to enable you guys, you may not already need it, you may need it, I don't really know everybody in the room, to have a more meaningful conversation with your suppliers and with your sponsors and business about what AI can actually do.
And I know we've heard a lot about it, and this week's been full of topics on AI. I've had quite a long background in identity, so I predate Active Directory, you know, I was product owner of Netscape Meta Directory, if that means anything to you, Netscape, you know, the old browsers, mid-90s. I've been doing this for some time, and Benoit Granger, in the front row here, he's one of our executives at Omada Identity over in Denmark, and his team asked me to present to them what I would do, my personal dream for AI, to our developers.
And they really found it useful, so then our marketing organization asked me to present the same material back to you at this conference. So, you know, I do believe AI is going to be useful. I know there's a lot of hype, I know there's a lot of concern about regulations and security, confidentiality, et cetera, but, you know, I do believe we can get through it. There are regulations from the EU coming out, there is technology as well. It's a fast-moving market, but I am positive about the outcomes that this AI can bring.
And what I'm going to show you in the next, I don't know, 10, 15 minutes is my journey of 30 years doing this, and what I would personally do. It may be different to what you would do if you're an auditor, or a developer, or an end-user, or a business owner, or any of the personas around identity governance, but this is my personal journey, and it may resonate with some of you, and we'd love to have that conversation. So this is really about enabling you, right? And this is a tangible walkthrough of what I did.
So don't try this at home, there's a lot of text on that slide, you don't have to read it all. It basically says, don't go and put your own company data into a public GPT.
I didn't, I asked the GPT to generate a data set, right? This is my data set, and then I spent maybe five or six hours in a prompt, and I was giving it all of my knowledge, saying this is what I am looking for, here are examples using this data. And then I modified the data set, so I knew exactly how many instances of issues there were in the data. So when folks say AI is non-deterministic, and it hallucinates, yeah, it does.
But I was blown away by this particular public GPT engine, and how accurate it was, because I know I asked it to create this data set, random data, I then spent hours prompting, and all the challenges that I've done projects, I've been a developer, I've been a product owner, you know, I'm like one of the field CTOs here at Armada. So I think I know this market, and I'm like, companies struggle with answering questions like without IGA, who's the riskiest user in this room, right? All people in this room, who's got the excessive permissions?
And ask yourself, how long would it take for your IT department to answer that question, right? You may not be able to answer it, might take you months or years, you may give up. And this is where AI, I was like, I was really impressed by this. So I generated data, like a lot of data using GPT, so it creates Python in the browser, I then modified it by hand, right? You see the permissions on the right hand side?
I said, just generate permissions that are suitable, similar for a department in your business, give me a list of departments, and it built this data set for me. I then asked it the first question. So this is, I know this is slides, but this was copy and pasted directly from chat GPT. And I'm like, this is just how clever it is.
And, you know, people over the years have paid a lot of money to have clever people implement identity systems. And I was like, wow, right?
You know, if an AI brain like GPT-4 can have access to your data, what can it do? So I was like, explain the data set. I've got this big data set, I'm doing a proof of concept at your company, you give me a data set in Excel. And I'm like, I don't even want to look at it. I know what to look for, because I've been a developer. But I'm like, tell me, tell me how bad this is, because it's always going to be bad. Data is always bad, right? So the first thing the AI said to me was, you know, it told me descriptions. I didn't tell it that, it told me descriptions.
So my first question to you as a customer would be, what's the semantic meaning of these fields, right? And it knew it.
I'm like, okay, that's pretty cool, right? Just some examples on the screen there. I then said to it, what are the problems with the data? And it gave me this, right? So when you're processing data, bad in, bad out, right? You need to know what's going to break the workflow, what's going to break the logic and the controls you put in the IGA. So it said, there are people that have left the company that are marked as active, classic. Your HR department, maybe having a bad day, right? Somebody's left, but they've not been disabled by IT. So they still have access.
This is a real problem that exists in many, many companies. It's told me how many there are, there are four, right? The next one, people that don't have a manager. Anybody implemented identity here from a practitioner perspective? You build a control, an approval control, an access review, segregation of duty control, a workflow, and it says, send it to the manager. If we process this data set that I created, what's going to break? What's the scope of failure?
And yeah, I could write a macro to do it. I could write some scripts. I could write some shell script to do it, but it told me straight away, 105 people.
Next one, people with no cost center. So the AI went through this.
Yes, it took a few minutes. It took about five minutes to go through these thousands of lines, but it gave me the impact of what would happen if I processed this data. And importantly, it gave me a description. It didn't just give me, if I wrote a script to do this, it would give me a number, right? An integer.
Oh yeah, there were seven records with duplicate user IDs, but the AI told me this text here. So those expensive services people, those SMEs that we're using in the industry, the AI said, they should be unique. They're duplicates. If you import this data from your HR system, bad things are going to happen. And that's from my experience implementing IGA over the last 30 years. No matter what technology you use, it's about the data. So this is like, to me, this is like a pre-flight check.
It's like, you're on the airplane, the crew are going through the check. And I'm like, well, how can AI help me? So this is my dream. Because I've been a practitioner and I'm like, the data's crap. It's breaking every time. And we iteratively have to go through, clean the data, clean the data, clean the data. So this is my personal dream, right? So I'm like, next question. Using that data, who's got the highest risk? So I've done no controls. I've just told it what I'm looking for. My definition of risk. Maybe not yours, but mine. And it said, this guy, the application developer.
And I'm like, wow, okay. So the GPT engine's just given me a risk score of 13. Where's it got that from? Just made it up, right? So I'm like, okay, why? Why?
So what, right? These are the risks that it gave me. The reason I'm telling you this is that these AI engines are really smart. The industry, the identity industry is catching up. If you look at the different vendors, including ourselves, right? We have AI initiatives. We're on the stand. You can see the demo today. From different personas.
You know, we, just like many other vendors in the market, we're talking about AI. But I'm just wondering if the consumers of our technology, like you guys, if you're aware of how smart it is. Because I know everyone's used it in their personal life.
But, you know, it sounds like a great identity consultant to me. And I'm like, what would it mean to you if the identity software that you use on a daily basis could actually be this smart, right? And the purpose of this talk today is about encouraging conversation. It's not to demo software. It's to say to you guys, this stuff's really clever, right? So what should I do? It should be reviewed immediately, right? This is the AI telling me to review it.
Of course, the AI can't review it. That's what you need an IGA product for. Next question.
Right, we've heard of role mining. We've heard of RBAC. It's generally been quite a difficult, manual, expensive, slow process to do using old technology. I said to it, using the data set, using unsupervised machine learning, are there any patterns that I need to be aware of? So imagine if I walk into your company, I'm like, well, who are the communities of users? And what are their access rights? Most people wouldn't really know where to start, okay? Unless you have one of these technologies like IGA in place. It gave me four clusters. It took like 10 minutes to run.
I had to wait a bit, go get coffee. But it gave me four clusters. And what was interesting is all the advice in the following slides came from these clusters of people. It told me there were job titles, departments, and permissions. So you see cluster zero has got 10, cluster one has got 14. And it grouped them. And I was like, okay, that's interesting. Give me more insights into the clusters. Told me clusters one and two are the biggest groups, meaning automating these would have the biggest impact for the business. So what problem am I solving? Access reviews.
The more questions people have, the less attention they pay, the more likely they are to select or approve. That's just human nature. So using cluster analysis, I can build roles, I can build patterns, I can make my life easier, get my work done quicker, get back to something else, right? I asked it to look at all the clusters.
And again, it told me this. This is just copy and paste straight from ChatGPT. Next point, give me a list of anomalies from security and group them by risk. If you went to your IT department and asked them this, do you think they could tell you this in two minutes? I bet my life they could not, right? It ran some Python code and it gave me this.
Okay, I have an aggregate count. 26, 21, 25, that's interesting. Because that's the data set that I did. Those are the changes that I made manually, and it adds up. Who are those people?
Okay, there are 30. What should I look for? Here's some examples of the anomalies. Anybody that's been in identity, this would mean something to you, right? People with the wrong assignments, they're in the wrong departments. And these are the anomalies in the data that I introduced, so I know it's not hallucinating. I made these mistakes in the data set. But imagine if your technology you're using could just give you this in the morning.
Hey, Paul, what happened overnight, Javi? Oh, we found some anomalies in the data, so we didn't process them, because we know things would break, right?
Uh, yeah, these are, well, whatever. They may require manual investigation or additional access reviews. But it knew about least privilege and zero trust because I told it to look for data on the web. I pointed it to NIST. I pointed it to the blogs that you guys write.
I'm like, this is what's important to me. Help me answer these questions.
Right, so this was like a different problem I'm solving here. So Ben was my executive, and I'd say he wants a report. He wants it quick, like a few slides, and he wants to know what's the outcome for the business, the scope, and what to do, and the priority. So then I'm a different persona now. So then I was a consultant. Now I'm kind of a business analyst. This is exactly the format, the look and feel it gave me, right, five things to do. So you compare this against keeping a cold analysis or some of the other industry analysts. It's exactly spot on.
So this is like my analyst in my pocket, right, or my consultant in my pocket. It said I need to do access reviews, and I'm like, why?
Right, first two points there. I'm not gonna read it. Why should I do it? Who should I do it on? And you see it's identified the people in the clusters, one and three, the role mining that we did, or it did it for me, right? So why should I do it? They have excessive permissions, and it violates least privilege, and I need to do it regularly, right? And this is one of the features of IJTools. That was number one. I'm running out of time. Number two, I should look at RBAC, right? RBAC makes things easier to request and easier to review by removing the complexity in permission. Why?
It tells me down the bottom. Helps enforce least privilege again. Number three or five, I should look at PAM for high-risk users. I should look at just-in-time access. Told me who to look at. Clusters one and three, the security admins, the finance people. And at this point, I'm like, okay, do we have jobs in the future? Because this thing's quite clever, actually. Privileged users are high-risk targets for attacks.
I'm like, yeah, they are, actually. Number four, need to clean up the data.
Examples, and these three bullet points are examples from the datasets. People in IT have HR descriptions. You see it everywhere. Not necessarily in HR, but you see it in data. People's data is messy. Look at the 30 outliers. So outliers are important. So can your supplier give you the outliers? Can they do the role mining in the cloud easily with one click, give me a list of outliers, and then make me recommendations on what to do? Because this is what, in my interactions with our prospects, they're looking for. Number five, look at SOD, segregation of duty.
You shouldn't be able to sign off your own work, for example, as a developer. And again, it told me the targets. Look at clusters one and three. There are outliers who hold conflicting permissions. I don't need to pay 180 days of services for this. I don't need to. It just did it for me. And this has always been my dream with IGA, is to make it easy and make it accessible and not to see projects that last five years, right? And you can never get rid of the contractors. Next question, next slide. The summary, okay? So on the left, we have the activity.
We have the target population in the middle. And look how useful the cluster analysis was. So this is the results of the role mining, which is why role mining, if it's done well, can be really, really useful. And the security benefits on the right-hand side for my executive. That's what they're interested in. And this is the order. And look at the last question. Would you like me to generate a detailed plan?
No, I'm not gonna put you to sleep with that. But it's this kind of recommendation and the speed and accessibility of what it can do, which really interested me. And I'm like, if you attached this brain, which is from OpenAI, which is the brain we use at Armada, to the hands that do the work from an IGA product, then you've got something, I think, that can really add a different perspective. And finally, changing persona again, we're looking at users, end users, right? The business users and their interactions with IGA. What do they care about? They care about not bothering with it.
That's why we have shadow IT. Friction and points of use. They want it to be easy. Tell me what I need. I'm a joiner. You know I work for Benoit. Why should I hunt for things in an access catalog? Why should I create tickets? I want to do it in Teams or Slack, the tools I have. Just give me the right access. You know I'm in this team. You know everybody else in the team. Why do I have to spend all this time looking for stuff? Look at the benefits to the business. Fewer tickets, better decisions, less friction, time saved.
The problem that security products have by making it hard and boring and difficult is people go to their admins, they use shadow IT, and they only got real compliance problems. And you don't know about the problems because people are just going around the side. So if we can use AI in tools like Teams to make it easy, so you can talk in the language that you know, whatever language, Dutch, French, German, you know it knows all those languages. And it's pretty smart. So looking to the future, I'm out of time. I realize that. What's next? You know the vendors, we're releasing AI.
You know check out Armada. Next few days there'll be some big announcements. But imagine a future where AIs are talking to each other and ask yourself, this is going to happen in our career, so we can't ignore it. Who's going to govern the interaction and data flow between those AIs? When we're asleep and your instant responder AI is talking to your identity governance AI, saying give me Benoit's accounts, give me the risk, disable them, remove those permissions, his account's been breached, what visibility and control are you going to have? And that personally to me is a very interesting area.
So thanks for listening. I hope that was useful. And I said, let's just continue the conversation because it's a very interesting space. And I hope you get home well and have an enjoyable rest of the day. Thank you.
Thank you, Bob.