While the panel is coming up, please head on up. We're not going to take any questions because I'm going to need some help from the audience. I don't have some, but as the panelists are coming up, the thought I was thinking about is I'm heading to the airport later this afternoon, and it seems like this whole space is like I'm going to get on the train at Alexanderplatz, but the train's not going to stop. It's going to be going 100 kilometers an hour, and somehow I have to get on it. Do people feel like that with this space? How are we going to secure and govern this?
My first question, basically, to the panel, and those who hadn't just presented can introduce themselves when they answer a question, is this the biggest, most important challenge we've ever experienced in our professional lives? It feels like it to me, but do you agree, disagree? I already said, for me, as an analyst, it's easy. It's the most fascinating intellectual challenge I've faced in business in the past 35 years, or more than 35 years since I'm doing identity and security, so I would agree. But for me, it's easier because I'm the analyst. I don't have to solve it.
You just leave that to the vendors. You're supposed to provide the direction for solving it. Aren't we all?
Agree, disagree? Biggest you've ever seen? Absolutely. I think the thing that really makes it such a challenge is the non-deterministic attributes of an agent. Non-human identities are pretty simple. They're processes. They can only do X, Y, and Z. An agent can do whatever you allow it to do. It's how do you secure an agent but not strip its ability to be non-deterministic because that's what gives it its power. I look at it like how do I put guardrails on a highway so that you can do 150 miles an hour down the autobahn and not go through the corner? That's kind of how I look at it.
Everyone generally agree? It's the only technological revolution where there wasn't a clear end point in sight that was self-improving and self-accelerating.
Matthias, do you agree? Have you ever experienced anything like this in your career? Actually not. If you think back five years at EIC, yeah, identity was interesting. But was it challenging, sexy? I don't know. But we are really in a phase where identity management is really changing and that is really mainly for me speed, velocity, size. And that is something that we are not yet used to. We need to adapt and didn't expect that to happen. So it's good. So it's challenging times. Maybe one point and you also mentioned the non-deterministic aspect.
I think what we really have, and this is super important for the entire community, we need to think in or to understand this is really about tectonic shifts. So it is a very different playing field. And I very, very much disagree with the thesis that this is just basically the same type of problems in a different format. It's different problems now. And we need to do a lot of things different. And solutions we built for the, so to speak, old world approaches, a lot of standards, a lot of other things may be helpful in the interim, but not on the long run.
That's a perfect segue to my next question. I wrote down the words we need, we need, we need, we need about five times just to remind myself. Even you just said we need. And so we have tremendous amount of need, but we are where we are. And we've done it a certain way to get where we are. But if we keep doing it that way, are we going to solve the problem? We haven't solved the past problems that well. All of you have said that before. So do we need to change how we're doing this? Or are we going to just repeat, get into the same position we are now for the pre-AI world?
So I think that's a really good question. And I think we always talk about security by design. We always say you've got to design security in the front. And everybody goes, yeah, yeah, yeah, you have to do that. No one does that. Didn't do it when the web came out. Didn't do it when we went to mobile. We're not doing it with AI. It's going to really, really bite us. But I think, Martin, you're right. We need new tools. I think everybody in the identity space right now is saying I have a tool, and this is how I solve AI with my tool.
I have a hammer, and I'm just going to say this is what you need to solve AI. We need to start thinking how do we morph those tools to be better for AI as opposed to I'm going to take what I'm doing now and wrap it around AI. I'd say one thing. My personal interest has always been authorization. And in the IGA and identity space, authorization has always been the neglected stepchild, basically. It's hard. All the money went to authentication. All the money went to IGA lifecycle. And now it's flipped completely. Authorization is the only thing that's really going to protect us.
And real-time authorization. Everyone always said you should do it, and everyone thought it was a good idea. And those projects never really went anywhere. It's hard.
Yeah, fine-grained authorization. How do you do it? Yeah. Matthias? Yeah. Then the sentence needs to start with we need. I think we need standards and interoperability. We need to make sure that we not build siloed solutions. We don't trust in one single vendor but have an ecosystem that works closely together. I'm old enough to remember that sentence. Standards are a good way to get the worst people out of the office for a few days. But I think we need the standards, and we need them right now. And if we continue doing it like we do right now, we need to understand.
We need to understand that if we continue the way we do it right now, we are in for disaster. And maybe to add a few very short points. The first thing is we need to work on a few standards collaboratively, no standards for. The second thing is I trust to quote Yves Maler and what you said. We need to do things like security properly. And Yves said DS and MCP stands for security. That's what we must avoid, things like that. So bring up things without security. The third thing is, and this goes into all of that.
I think what we really observe now is everything which we didn't solve bites back now. Dynamic authorization. We didn't do data security properly. All the other things that we failed, right now we would need them. When I hear the word standard, I think plus five years. That's how my mind goes. In the AI world, they don't do standard. They just drop code, like MCP being a perfect. So maybe we need to shift away from, I mean standards are great in concept. But we need to build specs and put them in open source and make it happen. Because we don't have plus five years, I don't think.
No, we don't have five weeks. I mean the way AI is working, I was talking to a customer.
Yeah, I'm going to deal with AI in 2028. I was like, no, you're not. We're going to deal with that this fall, this autumn. I agree. We can't take the time to come to a standard. But look how MCP got adopted, just like that. Somebody put it out there. Now it's de facto standard. Then ACP came out with Stripe. How do we accept card payments? So we have to make sure that we continue to evolve this. One of the standards I know that we're working on as an industry in the spec is the intent claims.
Patrick, you talked about it. I talked about it. I think Martin, you talked about it. We talked about fine-grained authorization. But how do we know? How do we transfer what you told an LLM agent, what you typed in, to the attribute it needs in the database to have that fine-grained authorization? So we need a standard for that. You mean a spec, not a standard.
Yeah, a spec. We need something that everybody can work to. But AI probably can come up. Just ask AI how this would look like. So AI asks AI, asks AI. Since we're at an analyst conference and there's vendors here, what are the controls that you expect to come out of existing products that will extend into AI? And then what controls will have to be sort of greenfield specifically for AI? Do you have some ideas for either of those? Either of you? Any of you?
Yeah, maybe. We are talking about structuring a future AI identity, NHI market. And I think one thing that is really missing and that is different from what we know right now is what we call ATDR, so Agent Threat Detection and Response, because this is not just ITDR with a different starting letter. This is really something understanding how can we guardrail and understand what an agent does at runtime. Will an ITDR system extend into that or will it have to be built from scratch? Maybe it's just an extension. I don't think so.
There will be additional mechanisms required when it comes to understanding intent and what that actually means in current actions of an agent. Behavior analytics is not new. It is not. But it's different now. It's multidimensional. I think it's closer to raising children than watching a standard process doing something on behalf of a regular technical user. What I think is we really need to also be very pragmatic. We don't have time, so we must use what we have to at least fix the biggest problems as much as we can.
When we move forward, and this is really the call to the vendors, don't stop by just extending ITDR to ATDR, but then it's really where you need to think about the tectonic shifts and rethink the solutions. Build them for really the bigger challenge, the very different challenge we are facing now. I think there are two things. What can we do now versus the strategic? We really need to re-architect, rethink, rebuild. If you were hearing Martin's presentation, you had all these categories with new acronyms. I guess a whole new industry could be forming to fill some of those spots or not.
I don't think you can boil the ocean to try to solve. They're not all equally necessary at this moment in time. I think if you only solved one spot, it would be the point of execution, the execution broker, the policy enforcement point, and the PDP that makes the authorization decisions. If at that point you had something like a PDP with off-sen, a standard, and it captured the context or it would not reject execution, then you have a control point.
If the execution engine could output some receipt that might become a standard for downstream consumption reporting, then you've moved the ball quite a bit. I think you were the one who said that an agent that exists that can't do anything is still not risky. If you control what it can do. I want to follow up on that. I agree 100%. You have customers out there, especially our identity customers, the people that I talk to, the identity practitioners that come to this conference, they're not involved in the agents being built, but they're being told, we built this agent, go make it work.
They're sitting there going, whoa, whoa, whoa, how do I secure that? What we're starting to understand with our customers, if we say, put in that authorization checkpoint. This is step one. This allows the identity team to be the runway, not the red light. It allows them to be the enabler, not Dr. No. I think we need to think about where can we get a grip on the entire thing now. We can get a grip.
Obviously, all these agents pass the authorization layer. This is the one thing they want to go to resources. Everything we can put in front of the resources, obviously, is where we can get a grip on it. It's much more difficult to get a grip on this mesh of agents. On this edge of this mesh. The same is, I think, starting, where does it start? We need discovery across everything, including starting with the browser, starting with the endpoint.
Not just assuming everything we see on whatever, an intra-agent thing or whatever, is what we need to know, because it's ubiquitous everywhere happening, and people bypass the standard tools anyway. But these are the edges where we can start and where we must start. Like a cloud gateway, we need an AI. Gateway is such a bad term. I know. Sorry. We call our product gateway, and I hate it. Why? Because it's not a gateway. Someone once said, gateways are the loser's way. But that's always what we've done, right? Yes. I think gateways are always what we do when we haven't solved the problem well.
I think if we would have had proper end-to-end security, we wouldn't need a security gateway in between. It's good to have them. No doubt. It's the backstop, right? But it's always an indicator for not having the perfect solution. The worst solution is human in the loop. Just put the human, the fine-grained authorization system, the human net.
Yes, the human net. I loved your line about humans and agents when I heard you speak two weeks ago.
You said, if I was an AI agent, I would really think humans are the slowest creatures on the planet. Which leads to Terminator. Which leads to Terminator, but it also leads to agents aren't going to wait all the time. If they're non-deterministic, they'll find a way around it. Any questions from the audience? So the question is, is that a question or a comment? Authorization is deterministic if it's enforced at the gateway? Is that what you're saying? But if it's talking about... Defining the rules, then it becomes deterministic. It becomes...
And you shouldn't assume all agentic processes are going to be completely non-deterministic. Because that's inefficient. If I give the agent... First of all, an agent shouldn't be multipurpose, where it has all the tools. Because it overwhelms the context window. It makes it dumb.
Basically, if I give you an entire library and I ask you how to fix a bicycle, that's not the right way to do it. So you limit the context. You don't give it that many tools. You have special purpose agents.
And then, if that agent handles certain processes, like onboarding a contractor, you don't want it to reinvent the wheel every time. You want to have the agent automate a deterministic process.
Alright, so the classic... We have two minutes, so each of you have 30 seconds or 45 seconds. What's the thing that you would suggest this audience do to get the first step or take a good step towards where they need to be for agent security and governance? Give us one thing. Be pragmatic now and collaborate for the future. Or for building the future.
Yeah, I would say the two things they need to do is find out who's building agents in their organization and what they want them to do. Discover. Discover the projects, so you see them coming and try to insert yourself in. We did an AI panel, like a remote panel for a customer. And our identity guy said, we had people dialing into this that we didn't even know who they were.
So, I mean, that's a great way to discover what projects are going on. They did work for the company? Pretty sure?
Yeah, well, we're pretty sure they weren't North Korean spies. I'd say shut the doors and windows, lock the door, and wait for the agent to come knocking to access your resources. Let them identify themselves. Okay. If they can't do anything, then it doesn't matter. Exactly. I'm a boring governance guy. Assign ownership to agents. Just do it. It won't work everywhere, but whenever you can, you have somebody who's responsible.
So, actually, since we have a minute, I wrote down a question. Is Microsoft going to be the ubiquitous registry for agents like it has been for humans? Active directory? Enter ID? No. There is not going to be one? There's going to be many? It's not going to be one.
So, simple answer, no. I think it will be a bit more nuanced. It won't even be one within one organization. They've notoriously neglected sign-grade authorization since As-Man, which was an abandoned organization. We're going to have the real federated directory. Is that right? I think we are well advised when it comes to these types of registries, CMDBs, directories, whatever, to well differentiate between the physical and the logical perspectives.
So, from a logical perspective, we need to ideally have a unified view to be able to create it, but it will be different places we need to bring together, always. That's why we had meta-directories.
Wow, that's a term I haven't heard for a while. Thank you very much.
Well, we are now out of time, so let's thank the panel.