OK. So we'll be having a panel discussion for around 20 minutes. And I think I would like this to be interactive. So if any of you have a question or a comment, just raise your hand, and then we can address that. But before we begin, maybe you guys can introduce yourselves. Sure. My name is Sanjay Nadimpalli, and I'm founder and CEO of Tuebora and another AI startup called Stimulate. Before Tuebora, I was one of the principals behind Avexa, which was one of the first IGA solutions in the market. And then I've been dabbling with other things prior to that, but that's what I've been doing.
I'm Benoit Grangé. I'm a CTPO for Omada. I've been working for Omada for the last three years. And before joining Omada, I was working for a company named OneSpan, focusing on multi-factor authentication and digital signatures. So really in the digital space and identity security for the last 20, 25 years. So happy to be with you today. Awesome.
Well, thank you so much. Maybe the first question, just to set the stage. We've been talking a lot about AI agents, chatbots, GPTs. It has been the main theme at the conference this year. How can we distinguish between real business value and industry hype when it comes to integrating these features into IGA or IAM solutions? Maybe we can start first with Sanjay. Sure.
I think, if you see the evolution itself from what has happened, is we did a lot of processes manually for some time, and then automation came in. And then people started looking at different kinds of automation. Now we are at a stage where automation by itself is not solving the problem, because the business changing, and there is a lot of data changes that are happening. And the decisions that you have to make are not static or something that you can figure out ahead of time. So they have to be done dynamically.
And that's where the agents have the ability to process that information, get you the context, do a reasonable amount of reasoning, and give some explainability to the choices and decisions they make. And at the end of the day, it allows you to have a system that is autonomous and is adapting to what's happening within your environment. So there is true value from that standpoint where you don't have to think ahead of time on how to manage your environment, and the system will guide you through a better structured way to manage your identity or access.
So I think there is a lot of business value from that standpoint. Of course, it comes with the questions that everybody raises.
Oh, can it do this? Can it do that? I think it will mature over a period of time. There are things unknown still in terms of how to manage tooling and security around that and make sure it doesn't go off and do things on its own. Yeah. Maybe to absolutely fully align on that, I think from my side, we have been dealing with AI, ML for the last five and maybe a longer time. But what we have seen with the emerging of LLM is the fact that the user experience has been completely transformed.
So the value and one of the feedback from the market has always been, how do we deliver a better user experience? And if we're talking about this agent, the first thing that they are delivering is obviously a better user experience. There is no need anymore to have long training to get the knowledge to execute some task. This kind of capability can really drive the user to execute some very complex tasks.
So removing the complexity, making things possible for the end user with limited education or education when they need accessible is really the turnkey, in my view, in terms of business value when leveraging this kind of tool. So that's where, for me, is becoming a trend and the expectation from the market that user experience should be this one. So ChatGPT is really making what should be tomorrow experience. And everywhere, especially as software vendor, we have to consider that the bench is there. If we don't deliver that, I think in two to three years, we will be out straight. Great.
You talked about the business value and the user experience. And Sanjay briefly mentioned about some of the challenges when it comes to making sure that these systems are not doing things that we are not aware of. But can you maybe tell us a little bit more about some of the challenges that you see, some of the things that organizations need to consider before deploying these systems? And maybe we can start with Benoit first.
I think the first point, to come back to Paul's presentation, whatever we want to do or that we can do, at least for me, is really execute or make sure that Paul's dream is coming reality. So that's my day-to-day work. So making sure that his dream is really present into the product.
Now, one of the point that we've seen is, indeed, this automation. There is a lot of things that can be done by this agent. But over-relying on them today can also represent a risk. How do we know that the decision that is going to be taken is a proper one? How do we validate that? So how do we prevent this black box effect and this behavior that can be introduced? So do we have today the expertise and knowledge of making sure that what is being proposed is the right thing? So I would say that, for me, the point is, to what level and to which extent should we rely on this model?
Where do we put the limit? From my side, I decided that we are delivering some guidance, some recommendation, but we still maintain the human decision factor into effect, especially for very sensitive decision. But that's one of the key point is, where do we put the limitation until we really have an understanding and clarity about the decision and making sure that all of this process about what is going to be executed by the agent is under control? I agree.
And I think the issue comes from the situation where you have these capabilities that you want to leverage because it simplifies and reduces the manpower in the process. But what's important is you have to make sure that things like prompt injection can become a problem for you if you don't take care of things. And essentially, agents are nothing but some collated set of tools that you provide for executing some tasks. And every output of a tool and the input to the next tool that you execute, you have to make sure that a certain amount of guardrails are put in place.
Some amount of authentication is put in place in that chaining. If you don't do that, you don't know what you are going to empower the system. So drive it through policies. That's the best way to manage some of these things to see whether the tool is really empowered to do what it is supposed to do. And drive it through policy. And policy-based access, everybody has talked about. I think policy-based even tooling becomes very critical. And so you embed policies, make sure you have the tool to give you the reasoning of what it is doing.
So once you have a certain amount of explainability, things make it easier. You know the rationale behind the decision of the tool and why it is doing that. So authentication, some reasoning capability, policies, embed all of that into your strategy. Great. I was hoping that maybe you could share a case study from your own experience that maybe could be beneficial for the audience. But before that, again, if you have any question, please raise your hand and we can keep this engaging. So no? And Sanjay? Sure.
So one thing that comes to mind is we see that the industry is plagued with one of the biggest tasks of application onboarding. That just seems to be a problem. Irrespective of what solution you use, everybody has their own mechanism of, I'm going to give you this user interface. I'm going to give you this template. I'm going to have this SCIM connector. I'm going to do all this magic for you. But it all assumes that people know what they should do.
But most of the time, if you look at applications, especially some of these homegrown applications, people who have built it, they probably have left the organization. There is no documentation. And there is so much integration that has been done. So IT has one view of the system. They know how it is laid out and all that. Business has a view of what users are given and why they are given. So you have to bring in both IT and business into application onboarding. And there is no better mechanism to solve this than AI agents, because they give you enough information.
If you give enough information, they know how to operate on what your application is and what you need to do for onboarding. So you can actually have a textual description of your application. You don't really need to go look at the application or get data out of it. And sometimes, just a CSV extract is good enough. Analyze that and say, OK, this is what I need to do to integrate the shape of the data and what is being managed. So application onboarding, we find that a great use case. And simplifying that whole process, especially for your homegrown applications.
That's absolutely a critical use case and very valuable. The second one that I think of that is quite interesting with this kind of solution is, as an administrator, it would be good that on Monday or every morning, I can just ask, what happened to me and what should I do today? So just getting this agent, just delivering you some feedback about what happened during the night, what are the tasks that should be proceeded during the day in a very simple, synthetic way, and getting this kind of report. So really changing the way you are going to manage identities as an administrator.
It would be, again, something that would change the way it's being addressed on a day-to-day basis. Are there any, let's say, misconceptions when it comes to doing these things that maybe you think it's important to address? At that point, I think the point where we need really to analyze is, we start to see agent everywhere. That's one of the challenges that we're going to face. So we're talking about this agentic AI.
But today, how are we going to make sure that your agent is, in fact, being used in a proper way? So I think there will be some aggregators. So as a user, I think it's important that, as a user, what is a tool that I'm using on a daily basis? Is that Slack? Is that Teams? So functionality that are provided by this agent should be distributed across the tools that are being used based on your user personnel on a daily basis. So making sure that you don't start to create 20 different agents, because as an administrator, I don't want to manage 20 agents. Or as a user, I just want to manage one.
So the conception that already has to be considered is, how do we deliver this agent in a way that they can be embedded into super agent that we manage from a large organization? Just one topic I have currently on my mind coming from a government perspective and these two topics are going to be arising. When you use agents for identity topics in the organization, we need to ensure the traceability and the government structure. Let's call it explainable AI, which we had a lot of times.
So that external organizations want to have a look at the complexity of what you can explain and what happens to the identity of this agent. And that's probably something I'm not getting to. I think that your point is absolutely interesting, but is also, in my view, a very strong value from this LLM. So they can guide you taking a decision. At the end, it was my point, leaving the decision at the human level, at the manager, but delivering necessary background regarding why you should take this decision, guiding the user into a decision.
Where I see a massive value is that most of, and also basic use case. I'm just going to give you a very basic use case that you will recognize. The entitlement that have to be recertified almost once a year or twice a year. Most of the time, this entitlement, nobody really understand what it is about. Nobody really understand. So there is a long list of questions. And the manager, just because you get hundreds of questions, is just saying yes to everything. Leveraging this large language model, where there can be first a proper definition and naming of a different entitlement.
Having a clear definition, if necessary, about this entitlement. Delivering, as well, some guidance about the one that should be really checked in detail, the one that represent the risk. That's where I think in terms of governance and logging and auditing everything and making sure that when it comes to the compliance, there is clear validation from a manager is something that is even going to help company to be in a better way compliant. And make that more efficient than just to be compliant.
Because the challenge we have today is that company are being compliant, but from a security standpoint, I mean, nothing is being done. Because just people, they just want to check the box, we are compliant. Compliance normally is based to enforce security and not the opposite. So.
Yeah, I think the important thing here is that you bring in decision making with verification, right, in the process. And you embed that. Some people talk about auditing and stuff like that. Auditing to an extent where you can infer some things from the audit as well, right? And you bring in human intervention and certain amount of auditing that happens in this process. So then it gives people a lot more confidence with these systems. I think that if you don't bring in that into the process, you are always doubting what the system is gonna do. All right. There was another question in the back.
Yes? Yeah, I have a quick question. I want to follow up to what the gentleman talked about. So when we talk about agents, we are really talking about agents. And I think the gentleman there talked about that. And my question to you has to do with the fact that we're going to delegate some kind of domain to agents. And they have agents. So they have choices. And they also have access to knowledge that even we humans do not know. And human decision-making, some of that is not only driven by the agent. It can be that even that we humans do not know.
So is there a framework that is going to help agents make effective decisions? Or deliver decisions that can be very impactful? And we experience this real world. So when we make decisions, even if it's based on fact we don't know, it has to do with what is the potential impact of that decision that drives the decision that we make. But agents, they are not going to know. They may not be aware of the actual impact of the decision. So we may need a framework in terms of how agents are going to make decisions. Are you aware of any such frameworks?
Or is there something that is impactful in itself? Yeah, see, it's a good observation.
See, the thing is, we are not embedding agents just to bring in automation or autonomous activities, right? The fundamental thing is, if you see, your traditional AI, it did based on patterns and everything else, right?
You know, a bunch of things. And then you had gen AI, primarily interpreting tests and giving you meaningful inferences and all that. And then you have agentic stuff, which is actually taking actions based on reasoning, right? And that reasoning, where does the reasoning come from, right? The reasoning comes from you providing certain guidance in terms of the policies that I was referring to, right? So if you say, for example, if somebody gets privileged access, you know, if your policy is, we want to quickly compute the risk score.
And if risk score is greater than some number, we want access review to be done for that particular user. Let's say that's what you want to do. So you typically would have coded all of this, right? Or you would have gotten hours of SMEs to come and build this. But if you describe your policies, like this is a policy for me, right? If this happens, this is how I want to manage it. And you give this, you know, sort of a framework to your agents so that it's working within sort of a box, if you will, in which it operates, right?
So in some ways, think of it as like an execution sandbox in which you perform these activities. And that execution sandbox is defined through policies. And in fact, we are talking about situations where people are building operating systems just for agents that gives you a lot more control about what's happening in that execution flow, right? So you harden system, and then you bring in policies, you know, and then helps you, you know, operate within that environment. Yeah.
And I think the point is the vendor like us today are really integrating and extending the product to support the governance of this agent. That's really something that we're working on at the moment. One other point that would be interesting is that each time there is an agent that has some right, we should get another agent to validate that the decision has been taken according to the right. So it's a chain of agent, but this would be the ideal solution where the agent would be control each other. So there is not a single line of failure. Okay.
I believe we're almost out of time, but if there's one more question, we can take it. Yeah. Do you think NCP will become the de facto standard for the agent to participate? I think it's too early to say that, but I think there is a lot of interest for sure.
And, you know, people have been expressing good outcomes so far, you know, with what it is. But I think the whole agent to care stuff is still too early to even call out as, you know, here is a path which will work for people. I think you just have to see where this goes, but yeah.
I also, I'm hearing a lot about it for the last few weeks, but I'm curious if we discuss in a month what would be the outcome. It's moving so fast, but yeah, there is a chance, but it really is moving so fast, it's absolutely unbelievable. Okay.
Well, thank you so much, guys. Thank you very much. Thank you. Enjoy your rest day. Thank you. Thank you.