Hello, hello, hello. Good morning, Berlin. Good morning and welcome. My name is Henrique Teixeira. I'm the Senior Vice President of Strategy at Saviynt. I'm super glad to be here. I know it's early, so congratulations for you all for making it here. I'm happy because I'm with my best friend, Jonathan Neal.
Hey, good morning, everyone. I'm Jonathan Neal. I'm the SVP of Solutions Engineering at Saviynt. And just to echo what Eduardo said, thanks very much for making an effort for getting here early this morning. We're very much looking forward to sharing our perspective on a riveting story around non-human identity.
Yeah, I'm looking for our clicker. That's a very good point. It's over there. And I want to say something. It's my first time in Berlin, in Germany for that matter. And I was born in Brazil. I have one thing I want to say to the German people, right? And one characteristic of Germans that I appreciate, perhaps the number one thing I like about German people, which is mercifulness. Germans are very merciful. If you remember the football World Cup in Brazil, okay, that was the punchline.
Germany, when they saw seven is enough, I say thank you. Thank you, Germany. Thank you. Thank you for not making it even more miserable for us. So I appreciate it.
Again, we're going to be talking about machines. And something that it makes me think a lot, that I'm getting old. Not Jonathan. He's always young. But by the show of hands, how many of you remember the movie Blade Runner? Right? It's a very interesting movie. And this is not the box office of that thing. Any guesses, Jonathan, what that number is? It's not my sales quota for this year, by any chance? Not your sales quota, no.
Okay, I'm good. But this is a very interesting thing. It was the first time in history, I remember, that a company used profitability number to define technology. So if you're familiar with AGI, or artificial general intelligence, that was the definition that Microsoft and open AI used to define what this AGI thing is. And they also had a more traditional definition of what AGI meant. It's when machines, this artificial intelligent being, becomes smarter than us. Scary thoughts, but also a lot of opportunities that we can harvest. A lot of opportunities that you can also take advantage of.
One of the things that I want you to remember from this session, and I know it's a lot of things, especially this early in the morning, is the correlation about three things. The correlation between this AI, what is identity, and machines. What those three elements had to do together. And when we think about machines, we're talking about two types of machines. The software type of machines and devices. The hardware type of machines, like autonomous cars and smart fridges and stuff like that.
There are, of course, for each of those elements, they need an identifier, a machine identity to identify those devices and workloads. And several types of workloads that you may be familiar with, like an AI agent. I'm sure you heard about this terminology here in this conference at Carpenter Coal. RPA agents, which would be perhaps the grandfather of AI agents. But services, an EC2 instance in AWS. Those are all types of machines and their respective identities. But I want to bring to your attention this first one here. The AI agent.
And this company, Carpenter Coal, they published research saying that the market for AI agents today is already $5 billion. To put that in perspective, that is more than what the entire market for access management is. So if you combine Okta, Microsoft, Ping Identity, all those companies together, this market, which was basically born last year, is already bigger than that. Which is crazy. And estimated to grow to $75 or $74 billion. That puts us in perspective when we think about identification of those AI agents. This is going to be bigger than cloud if we think about this.
They need identities. They need these accounts to represent themselves.
But also, just like humans, the credentials is the way they authenticate. And the entitlements that tell them what are they authorized to do. Just to line out the journey that we went through and just to put that into perspective. So if you're doing identity for as long as Jonathan and I have been doing identity, you may remember this. The whole journey that we went through from mainframes in the 80s and what happened with decentralized computing is that we need now to create accounts. Not one central place, but several target systems. So user provisioning was born.
Very much workforce-centric and workforce-oriented. But then what happened in the year 2000? A very interesting correlation of two things. So cloud was invented in the year 2000. Salesforce was created in the year 2000. And a couple years later, AWS. So if you think about cloud, it's already 25 years old. Cloud is old. And in that sense, the same year, one American company decided to do something. It was Enron, if you guys remember. Enron decided to commit fraud. They decided to cook the books. And a law was created. Sarbanes-Oxley. SOX was created because of that.
So on top of everything companies were already doing in terms of efficiency and provisioning and creating users and automating user lifecycle management, now on top of that, they had to do what? Compliance certification campaigns, role engineering, SOD and this kind of stuff. So it compounds on top of whatever they're already doing. Then what happened perhaps two or three years ago? What happened was my mom gives me a call. And she's not in IT. She's a doctor.
And say, Enrique, have you seen this thing called chat GPT? I say, yeah, it's pretty interesting stuff. And she was amazed by that. And she was using.
My mom, a non-IT person, healthcare industry type of person, she was using artificial intelligence. So that year, it became mainstream. And same with cloud. AI is not new. But that year, it breakthrough mainstream adoption. At the same year, if you all read the Verizon data breach report, it was a continuum of attacks that were, number one, driven by credential misuse.
So same, it happened 20 years ago. Now this new wave of things happening with AI being front and center. But at the same time, when you think about cybersecurity, identity is front and center.
Now, I want to make you a promise. And a prediction which is a promise. I can guarantee you. I can guarantee you two things. Or we can guarantee you.
So, Jonathan, you keep me straight. This next wave is not going to take 20 years. That's the first promise I'll make you. And the second one is that this is not the last wave. I can guarantee you after genetic AI, we're going to see something different. But this is a very interesting thing when we think about this timeline where things are happening faster and faster. That the general or what we call singularity, machines becoming more intelligent than humans. There was this person called Ray Kurzweil. He's been researching AI for 60 years. Which is crazy to think about.
And he said that he had this prediction that AI would achieve singularity by 2045. And then he said, no, scratch that. It's happening in five years, 2029. So I was actually going to make a point. If you go back to that slide. I was actually going to make a point in the actual sort of growth in identities that we see. Under typical governance with an organization. There's also increased linearly as we've seen these trends progress. And I was going to use the pun around the rise of the machines. But I realized that was a different movie franchise altogether.
But what you will actually see is, you know, the problem is compounding. It's getting bigger and bigger. And if you guys aren't already in a position where you have formalized or at least starting to formalize your strategy around how you manage non-human identities. Then you've got to start. Because this isn't going to take long. This is already here. This is a new paradigm. So if you're not already doing it, the next best time to do it, if you're not already doing it, is today. Exactly. And it's already happening. It's not this year that started.
If you look at Internet traffic, all that kind of stuff is already more machines than humans. But also, one of the biggest challenges, Jonathan and I, when we speak to our clients and then we see is that it's very hard to justify or making companies to look at the problem of this hidden, almost like time ticking bomb of non-humans. So the good news is, if you're familiar with OWASP and the top ten risks they have, they have released this year a top ten risks for NHI. Which I think it's a beginning to that. We don't have a specific compliance regulation like SOX for NHI.
But I think if I could predict something, maybe coming up soon. So for this first part, I think that the big takeaway is that we are already a minority here. So if you think about the number of transactions happening on the Internet today, almost two-thirds of that is already machine to machine. It's not humans to machines. So we are the minority. And Jonathan, how can we even list what challenges bring us to manage here today? There are a lot of challenges. Unfortunately, we don't have that much time to cover everything. But I want to just really address a couple of key points.
And even though as part of our roles, we've learned a lot in terms of putting together processes and strategies for managing human identities. Some of the tools and some of the techniques that we've become familiar with and we also rely upon for protecting our identities just simply don't work when we're talking about non-human or machine identities. Let me give you a couple of examples. First and foremost, MFA does not exist if you are machines. A machine cannot pull an iPhone out of their pocket and use an authenticator app or an OTP. So you've got to get that out of your mind.
Secondly, if you're a fan of conditional access policies, guess what? Impossible travel just became completely possible if you're a machine. So really we've got to start rethinking, re-baselining how we approach the problem of managing non-humans. I wanted to ask a very quick show of hands, just in the interest of time. How many out there of you or your organizations are already standardizing on a tool like AWS Bedrock or Microsoft Copilot Studio, SAP Jewel? Are you using it today? How many of you are using it? I would estimate perhaps 20% of you.
Yeah, but that's pretty good actually. Yeah, that's pretty good. So where we see democratized development of new applications, agentic applications, as really a big positive, and we'll cover some of those in a second, we've got to start thinking about the people who are developing those apps because a lot of the time they are not cyber security professionals. And they're damn well not identity professionals. So it's very easy for them to slip into making the same mistakes that we've seen in the past. And a really good example of that is hard-coded credentials.
Hard-coded, high-privileged credentials that exist in perpetuity, which is an open door. They're not cyber security guys. They're not even much less identity people, right? So how can we expect them from them?
Yeah, and early attempts to pull this in a CMDB. Yeah, we got all this recorded in a CMDB. This isn't working. This is not a solution. It's failing. And I'll touch on one other thing because, and we'll come back to this as well. We all know the processes. We're all familiar with the level of assurance we get from onboarding a human. We go through an interview process, a background check, identity verification. You don't have any help. There is no HR when it comes to onboarding machine or non-human identities. True.
Now, there are some great solutions out there. There are some opportunities, but you've got to start rethinking, re-baselining some of the things. And this means going back to basics a little bit in terms of cyber security principles. We've already discussed this sort of non-linear effect or the non-linear approach that machine identities have. We've got to start thinking about how we manage this at scale.
If we're doing this at scale, really the only viable option for finding AI, because security starts with visibility, you've got to go and find this stuff, is by using AI itself, using AI to find AI. Because once you've got visibility, you can then start to pivot towards protecting control. Maybe putting these secrets, these credentials in a vault, at least getting some kind of security wrapper around those. And then finally, and I think this is probably one of the most difficult things, but also one of the most important things, is getting or just defining ownership for machine identities.
Without ownership, you don't have accountability. And without accountability, you cannot effectively govern.
So, these are really some of the things that you should be thinking about. And AI actually gives you a leading edge when it comes to rethinking some of this. Yeah.
So, Jonathan, finding them, vaulting them, governing them, and ownership. And I hope machines cannot learn how to travel in time, go back and kill us. But I'm going to say something that might be controversial into the future, which is, people, we must own machines. We own machines and humans. And that's the reality. That's a big challenge that we have today in governance for agentic AI, is that it's very hard to establish that ownership.
So, the NVIDIA guy, and his name actually is Jason Huang, he said this. That you, you are going to be the human resources of those machines. It's a very interesting concept to think about because, yeah, the CMDB model is broken, but maybe because are we prioritizing the right things to put into that database, in that CMDB, this configuration database? If I had to make a suggestion, yes, if you have a prioritization of a way of projects in CMDB, use that to store your machines. I may be even more controversial than that. Please. And I think this is, I actually think this is going to evolve.
I think this statement is 100% true for right now. But if you think only back five years ago, the burden of managing non-employee identities fell on IT. IT had to create them in AD. They had to create service tickets or respond to service tickets and do a whole bunch of manual stuff. That has completely shifted left. That's shifted to the business. The business now takes responsibility, ownership, and accountability for managing supply chain users, franchises, externals, contractors.
At some point in the time, the business will have to be responsible for picking up the burden for managing non-human as well. And what are the benefits of getting there, too?
So, yes, number one, agentic AI, an agent is a machine. I want we all to be on the same page about that. But also a lot of good stuff, right, that this could be bringing us in terms of opportunities. There is a lot of good stuff. Just a couple of examples, in fact. I was with a really large group a couple of weeks ago, and it was mainly an SAP audience. And we were talking about what the future is with SAP Jewel and being able to build agentic applications. And that's really kind of signaling the death of applications as we know it.
People are not going to be building big, monolithic applications anymore. It's going to be fast. It's going to be agile. It's going to be agent-based. And this is going to take care of a lot of the boring stuff and mundane operations. And it's going to be much more efficient, right? We're going to multitask and do things much more efficiently.
Really, think about it. It's going to be much more powerful than when we first introduced single sign-on.
Yes, and I remember that. I think we are old enough to remember. And maybe some of you remember when we all proposed single sign-on to organizations.
Jonathan, you're crazy. The single sign-on thing, right?
So, one password gives you access to everything. So, it is also very risky, right?
So, it's going to be more dangerous than SSO. If you think of an AI agent, the way it will be interacting with other apps, it's going to be more dangerous than SSO.
Now, it's not the first time it happened. And we are very good in building controls for those things.
For SSO, we invented MFA. Not Jonathan and I, but you guys did, right?
So, the industry invented MFA. We invented pass keys. We invented all these additional controls to make sure that single sign-on was a pretty cool idea and was also safe to use.
So, I don't think it's going to be different here for agents. So, recapping what we just walked through here, which was an electric way of presenting this topic in 20 minutes, I want to give you like three very actionable but also easy to remember steps.
So, how can you strategize this whole machine identity, this whole identity security plans for 2025 and beyond, right? Number one, we got to think about those two areas of our landscape together.
Humans, non-humans, bring everything together. Number two, what Jonathan told us about, right?
So, you got to find them, vault them, govern them. The three steps that are very, very easy, but also to start and give you a head start to that ownership or solving that ownership problem.
And last, prepare for AGI, this singularity which sounds scary, by doing things that are already familiar to us. So, they all use secrets. They use certificates. They use those things that we already have perhaps a good grasp on.
So, we start with those low-hanging fruits. And if I have an ask to make, right? One ask is let's talk about this elephant in the room. Let's talk about the non-human identity in the room.
So, just by initiating that conversation, we are closer to the solution. If you want to stop by Savant, so we're both Savant employees, we are already showcasing stuff that looks pretty cool. But more interesting than this, I want to invite you for dinner. Okay?
So, join us at Spago 7 p.m. tonight.
And guys, you're being amazing for this early time in the morning. Thank you.
Thank you, Jon. Thank you, guys. Thank you. Thank you. Thank you.
So, we have one quick question or comment from the audience. I think this is a slight pushback. An AI agent is not a machine, guys. Agentic AI is a service just like an app. Wow. I think you're right. And let me say this. And I forgot to mention. I've been working at Savant. I was a garden analyst for more than five years. And let's not get distracted by taxonomy and terminology. As long as we're talking, I think we're talking about the same thing. The name we call it, it doesn't matter. That's my answer. Okay. Great. Thanks. Thomas and Neil, I'll make it fair. Bye. Bye.