The presentation focuses on IAMONES, a company innovating in the identity governance space by utilizing advanced AI technologies such as agentic AI and large language models (LLM) to simplify identity and security management. IAMONES aims to bridge the gap between security and identity management through a platform that seamlessly integrates traditional identity data with AI-driven processes, offering conversational user interfaces and natural language configuration. This approach minimizes the complexity and time associated with traditional identity management systems, offering rapid, conversational interactions to manage identity and security operations efficiently. The IAMONES platform employs a temporal identity graph enriched with time-stamped data and a collection of specialized AI tasks known as the "identity brain," offering functionalities such as automated workflow processes and segregation of duties checks. The presentation highlighted a demo focusing on use cases like security investigation and remediation, showcasing the platform’s capability to perform tasks efficiently using natural language instructions without needing in-depth coding or lengthy configuration processes. The integration of structured and unstructured data from various identity and security sources positions IAMONES as a solution for enhancing identity-related processes, potentially reducing the reliance on legacy systems and fostering more harmonious relationships between cybersecurity and identity teams.
All right. Can you hear me? Good.
Thank you, John. Good morning, everybody.
So, quickly about us. For those of you that don't know us, the name IAMONES is the pronunciation because it's a combination of IAM and the Ramones band. I created a funky name just to be not memorable, but everybody's asking questions on how to pronounce it.
Last year, we had our first out-of-stealth presentation here at IDC. So, the company is slightly older than one year. And we also have a nice report by Martin describing us as a rising star.
So, if you really want to hear what generative AI can contribute to make identity simpler, you should skip my presentation and go to this guy's presentation in little over than one hour. He'll be delivering a client presentation. Quad is an American company, and they will be talking about the use of conversational AI.
So, today, the title of my presentation is Identity & Security. My brother is no longer an only child, and I want to pinpoint some specific use cases where what we make is useful not just for identity people, but also for security people. And I'll be running a little demo, recorded one, just for the sake of today.
So, we're going to make it very visual. So, first of all, just a little reminder of what are the pain points that we addressed. First and foremost, Yamon was built to bring simplicity into the identity governance tech primarily, okay? Because the users are typically lost in translation when using the traditional products. The second reason why Yamon started is to make sense of a lot of natural language knowledge that is sitting in documents that now, with the new AI ingredients, can be resonated upon.
And last but not least, that's the purpose of today, I wanted to get rid of my cyber friends telling me, you identity guys are useless to us. And so, the presentation today, it's really trying to make sense of what we do for security people.
So, the change ingredient, it's always the same. You might have seen this before.
But, you know, the change ingredient, which is really allowing us and other vendors to reshape the software stack, it's agentic AI and large language model. Because that is essentially what they are very good at doing. They can interact with natural language and they can resonate on the natural language you provide.
So, in structured natural language. I say that the large language model is the new operating system. You can use the reasoning capability of this engine in lieu of, you know, thousands of line of codes and configuration and rules engine that you had in the past. When we started the company, we had a very simple mission.
So, today, if you want to take a look at the product or you want to look at the product, the user experience is fully conversational and you'll be seeing that during the demo. But the interesting part that we do and all of the vendors that are born on the AI can do, it's the configuration of the system happens in natural language.
So, whether it's a workflow, SOD policy, access restrictions, natural language that takes one hour to configure rather than weeks of development. We gave it a name. We call what we do conversational IM. And I have to pay credit to a partner, a good friend of ours, Mr. Sami Makela out of Sweden. He came up with this name.
So, I always give credit to partners, even from contributing to the name creation. So, a little insight on how the platform is built. The platform, Yamon, is built, first of all, with a very non-AI component. You need to take the oil out of the wells. And oil is a bunch of legacy traditional IGA identity data sitting in on-prem, obscure, siloed environment and move them into a standardized format that we call temporal identity graph. The reason why we call it temporal is because we enrich the data with temporal information, time stamps, timeline.
Graph, because, you know, we live in a world where the data representation and connection, it's essentially a graph of identity, users, account permission. And there is a lot of intelligence you can derive out of that graph, not graphical information. On top of that, we develop, and that's the real, I would say, IP, what we call the identity brain, which is essentially a collection of AI tasks, each one specific for a given task.
So, within the brain, there is the part that takes care of SOD checks. One part is taking care of automating the workflow process, starting from natural language instruction. Another one, for example, it's the LLM firewall. Once you have a conversational UI, you need to be sure that there is no attempt of being, to have a privilege escalation within the chatbot, something like, pretend I'm the manager. I want to do everything. And on top of that, we have two visual components. We call it the consigliere.
It's the ask and task, where you ask things, and the maestro component, which is where you configure the product. The product, it's SAS for the upper part, but we give a lot of credit where your data, as a company, are stored, are sitting in a private tenant database, which includes structured data, like your IGA traditional data, as well as unstructured data, like company knowledge you might want to upload.
The traditional deployment model that we offer, it's very simple, and Diego will present about the way they're using the product, but it is essentially, there is a bunch of traditional IGA, SailPoint IQ, One Identity, even Micro Focus and other stuff, that it's sitting on-prem, and clients don't want to move to the cloud for a number of reasons. And today, from a lot of vendors, the innovation on the AI comes if you move to their cloud version.
Now, we say, you can stay where you are. You're good with your provisioning stuff, and you have spent blood, sweat, and tears to do that. We augment, essentially, and we come on top, providing two things. The conversational capabilities that you will be seeing briefly during the demo.
But again, the real USP from us, it's not a conversational UI. That's a commodity. It will become a commodity. If you don't have it, you're out of the market. It's the configuration of the system in natural language, and I'll provide a glimpse into that.
So, in order to make life of you, partners, and clients simpler, we are building a set of pre-canned integrations. So, the one above are the one we have. The one below are the one that we are building. And it's essentially a plug-and-play into your oil, so you can consume it. The identity gateway can be connected to anything. This is something that we pre-built in order to make your life faster.
Now, we're getting into a bit of the visual part that is going to at least try to explain on our side what we mean by bridging the gap between security and identity. But first of all, when we run our demo and presentation, we have no longer use cases. We say we have different conversation.
So, if you want to see one of our demos, maybe some of you have already seen it, it's all about the type of question that, for example, the business users at large can ask, trying to remove the lost in translation syndrome, and ask things as they express them. English, German, Swabian, any language available on earth. This is another interesting one.
So, even the application owners in this domain, they are suffering a lot, and I would like to contribute to make attachments better, but it's a pain to get my data into the system. So, a very specific use case, it's just making description of entitlement readable, allowing application owner to say, help me generate a description, maybe out of a 25 years old Dutch document that described that legacy application.
And now, last but not least, our tool is particularly favored also by auditors, or by clients that want to give auditors a bit of freedom into sort of navigating the IGA data without being lost in providing reports. Now, I want to go a bit behind the scene in how we make that magic of integrating different sources of data.
And if we look at essentially the data that we mesh, we mesh your IGA data that you might be taking from, say, point one identity or other platform, enriched with the timeline, then we allow you to add documents, your corporate knowledge, and that example of the security integration is going to basically use a Word document that could be coming like bit site or security scorecard type of information. And last but not least, enriched and instructed by our instructions. Our instructions are nothing more than prompts.
But here, it's a powerful part of large language model. If you give a natural language prompt, it replaces millions of lines or maybe thousands of lines that used to be scripted in the business code.
So, now I want to show you the visual part of today. And it's what I call a security investigation and remediation use case.
So, you have your IGA data. Say they are coming from SailPoint. You have your documents. Fictionally here, we use a report. A report like coming from bit site that says that's a security scorecard of your company and typically includes also the data link. That's a Word file.
For us, it's a data source. And then what we do, we provide our instruction that can be a separation of duty policy as well as workflow instruction.
So, now let's get into a bit of a visual demo. I didn't want to run the demo here, but it's been taken yesterday live from the platform that you might experience in yourself subscribing and trying.
So, I let it go and I will be commenting briefly during the run. So, let's see if this works. Okay. It doesn't or does. I need to see where to start it. All right.
So, that was me yesterday. So, let's get into the system.
Of course, here it's me, but let's start with a very simple question. Is there anyone who has been granted a revoking permission in less than two hours? Okay. And I don't write hours. I say hour. H-R-S.
So, now what the system is doing, it's going behind the scene and say, where is this data? So, it thinks and it picks up all the users that have been assigned a permission for the last short period of time. Why? Because the privilege escalation typically is granted and revoked very quickly. And then you might say, all right, tell me, have any of these users been involved in the leak?
Again, it was a mistype. I did it on purpose. We don't care. Okay.
And so, now the system says, all right, you're referring to these guys. Oh, yeah. Andrea Rossi. Look at it. You've got a data leak. And that's what it is. It's also providing other information. And then I say, all right, so probably that guy.
So, think of it as not asked. Think of it as automated. Now I'm just scripting it for your sake. And give me a full perspective of his entitlements.
Again, another error. Replying German. And then the system says, all right, we're talking about give me a full perspective of his. It must be Andrea. We're talking about Andrea.
So, this contextual conversation is like talking to a human. And now we go.
So, we get the report, which is in German, and you could distribute it. So, one of the benefits. Forget about multi-language support. This is coming out of free. And then I say, all right, I don't like Andrea. Suspend him. That's the part that is triggering the workflow.
So, you don't have to know it. It's the system understanding. If you say suspend it, suspend it, something.
So, here I'm submitting the request to suspend access to Andrea. And that was a bit of the demo that is sort of highlighting a set of capabilities, like timeline investigation, cross-correlation with data, that have been added. And I'll show you from where, if I can. I don't know where my glasses have gone, but I think it's here.
So, just to give a bit of behind the scenes. We still have eight minutes, so we're well on time. This is right from the system that workflow is behaving according to an instruction, which is this. We're not moving this stuff into code. This is what the AI agent is reasoning upon. This is the code. Another source of information that was actioned upon during the demo is this fictional cybersecurity rating report.
So, we have partnership with the company to incorporate leaked credential information, because they are a useful source of data. And sometimes that integration process is very cumbersome. In our case, if you have a subscription with security scorecard, bit site, or panarays, this guy managing sort of scoring mechanism, they can provide data leak information. And you can meld or mesh this data in a Word document with the database information. The user doesn't care. And you don't care either, because it's just uploaded into that.
So, that's the behind the scene that I built. So, that was a very simple use case that I want to highlight, moving away from the traditional IAM utilization of these two, but also trying to make my cyber friends happier that, one, we make sense of their data.
Because, imagine, these data could come in also from a security operation center or an XDR system. That's the easiest way to incorporate security data in the reasoning process.
And, you know, probably now, with that UI, they don't have to submit the JIRA ticket and wait three weeks to know the timeline history for a given security incident. They can do it themselves.
So, that was my genuine attempt to get our cyber friends that typically hate us, identity people, to be more meaningful. All right, that is it. There is one interesting more case study that I'm not going to show you the demo. We are building it with Nexus that probably most of you know. It's about helping, using this mechanism of meshing structured data, documents. In this specific case, it could be the authorization concept template that, if you live in Germany, your beloved buffing authority is asking you dramatically to produce. And with natural language instruction.
So, this is a different use case where you sort of use the engine to populate documents that might be taking weeks to manually produce. And here, you get a lot of suggestion with the same mechanism that you might have deducted from the previous demo.
So, and again, every use case we built, it's essentially a combination of structured data, typically coming from IGA platform, documents. There are just manuals, knowledge that you give to our brain and instructions. Our instruction is something that our brain takes more seriously than the attached documents because it's basically the way we tell them to behave.
All right, that was it. I think I'm doing it even less than 20 minutes. Two takeaways, very simple. Whatever the way I summarize what we do at Yamonis, again, Yamonis, not IM1s, it's we're moving long hours of developing configuration into moments. It looks like a bit of a BS. It looks like a bit of a magic. That's why I put the demo to visualize it. It's really a game changing, and it's not only us. We had one luxury, though. We started fresh. And as we started foundationally with LLM, we don't have a technical depth of years of software development we need to exist to.
And last but not least takeaway, hey-o, let's go, conversational, quoting my favorite band, the Ramones. Thank you very much, and I give you back three minutes of your life. Thank you. Thank you. And I take my computer back as well. Does anybody have any questions?
So, first of all, who told your AI that Dostoevsky books are boring? They are not.
No, you're right. We should change that statement. We should change that statement. All kidding aside, you're sitting on top of the technologies, and I saw that you had a number of large names on it. How does that integration actually work, I'm interested in? With the LLMs? Between the IGA platforms that you had shown as logos and your solution. And how long does it take you to develop such an integration?
Well, first of all, the integration between your legacy data and our normalized database has no AI in between. Okay, that's a traditional stream data capture. The only thing that we do is that we normalize data from different sources into our normalized data set. Because only in our normalized data set we can single-train our identity brain to understand any question. Okay?
So, what does it take to put the data of one identity or same point into our system if it's a standard platform? One hour, and then off you go. There is no learning here. That's very important. This is AI. This is not machine learning. We don't have to wait six months to get a baseline of behavior from each client data.
No, no, no. You just put your data, and then it's like having an expert that knows your business of identity with some instructions in natural language.
And, again, I know it's a bit of a paradigm shift, but that's a new way of building software stacks. So, we might look unique now. It's going to be the standard three years down the road. Okay?
So, I'm not saying that we are unique. We just have the luxury to start fresh. When it comes to the integration with the LLMs, we do it two ways. One is behind the scenes we orchestrate the best LLMs, so we are LLM agnostic. Our brain is composed of mini brains, each doing a specific task. And based on the task, we pick the smartest, cheapest, and fastest engine. That could be Google Gemini or Anthropic or OpenAI. We have developed now the possibility for if any of you is running a GPU. I was talking to clients last night. They have their own GPUs.
They have installed their own large language model that doesn't know identity, but it's sort of an horizontal new operating system. Now we can infuse that knowledge into your LLM. That works specifically nicely for large clients that are deploying self-hosted LLMs are part of their initiatives.
Well, great. Thank you, Andrea. Thank you very much.
See All Locations
See All Locations