Identity at the Center

Identity at the Center

Identity at the Center is a weekly podcast all about identity security in the context of identity and access management (IAM). With decades of real-world IAM experience, hosts Jim McDonald and Jeff Steadman bring you conversations with news, topics, and guests from the identity management industry. Do you know who has access to what? Visit us on the web at idacpodcast.com

  1. 7h ago

    #447 - Authenticate 2026 Preview with Andi Hindle

    Jeff Steadman sits down with Andi Hindle, conference chair for Authenticate 2026, for a preview of this year's event. Making his seventh appearance on the show, Andi walks through how Authenticate has evolved since its founding alongside Identiverse and outlines six major topic areas shaping the 2026 agenda, including passkeys in practice, regulatory pressures, security and standards architecture, digital identity wallets, and non-human authentication. The conversation moves into hardware-based identity for retail and industrial settings, age verification challenges, and a detour into 3D printing and supply chain assurance. Jeff and Andi dig into continuous identity and zero standing privilege, the shift toward non-human traffic dominating infrastructure requests, and how agentic AI is forcing organizations to rethink authorization and human-in-the-loop decisions. They close with privacy and consent questions for non-human identities, thoughts on where authentication and authorization standards are headed, and a lighter look at Authenticate team traditions and sci-fi recommendations. Connect with Andi: https://www.linkedin.com/in/ahindle/ Impact of GDPR on Identity and Access Management by Andi Hindle: https://bok.idpro.org/article/id/24/ Learn more about FIDO Authenticate 2026: https://authenticatecon.com/event/authenticate-u-s-2026/ Non-FIDO members can use the code IDAC15 to save 15% on their in-person conference pass. Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com 00:10 - Introduction and discount code rundown for upcoming conferences 01:10 - Andi Hindle returns for his seventh appearance 01:29 - Favorite episode banter and the running Andrew Shikiar joke 03:08 - Origins of Authenticate and its relationship with Identiverse 09:01 - Passkeys are solved, so what comes next 09:53 - Lessons learned building the Authenticate agenda 12:59 - The scale of effort behind running Authenticate 15:29 - Adjacent topics expanding beyond the core passkeys mission 16:09 - Six major topic areas planned for Authenticate 2026 22:13 - Identity as the foundation for everything digital 23:14 - Hardware identity and non-human authentication 24:53 - Retail tokens, badges, and age verification use cases 28:36 - Replacing things only when the replacement is actually better 29:41 - A detour into 3D printing and personal satisfaction 31:39 - 3D printing, supply chain assurance, and identity problems 36:38 - Introducing continuous identity 37:28 - Zero standing privilege and why it matters now 40:46 - The human user as the infrastructure edge case 45:16 - Speed, scale, and the limits of human in the loop 46:11 - Setting red lines for agentic risk 50:56 - Privacy and consent questions for non-human identities 56:51 - Anonymization, data logging, and GDPR parallels 59:51 - A GDPR and IAM resource from the IDPro Body of Knowledge 1:00:26 - What Authenticate topics might look like three years out 1:04:59 - Why accounts may not make sense for agents 1:06:49 - Authorization as the next hard problem to solve 1:08:20 - Inside jokes from the Authenticate organizing team 1:09:30 - The story behind Andi's favorite Britishism 1:10:38 - Book and media recommendations 1:14:39 - Closing thoughts and sign-off IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Andi Hindle, Authenticate 2026, FIDO Alliance, passkeys, identity verification, identity wallets, continuous identity, zero standing privilege, agentic identity, non-human identity, authorization, shared signals, GDPR, IDPro, Identiverse, age verification, hardware authentication

  2. Sep 7

    #446 - Rethinking Identity for AI Agents with Rick Scot

    Rick Scot, Global CIO and CISO at Elevate Textiles, joins Jim and Jeff to talk about how he went from leading a data team to holding both the CIO and CISO seats at a global manufacturing company. Rick shares the moment that pulled him into security, how his tight-knit Charlotte cyber community shapes his thinking, and how he balances speed and control when the two roles pull in different directions. The conversation moves into identity for the age of AI agents: whether an agent is a human or non-human identity (Rick argues it's neither), who should own accountability when something goes wrong, and how session termination has to extend beyond turning off an account. Rick also digs into shadow AI, the real cost of tokens versus flat-rate licenses, and how he evaluates new identity technology against his organization's size and risk appetite. The episode closes with what excites and concerns him most about AI over the next three to five years, his advice for identity practitioners, and a lighter look at hobbies people wouldn't expect. Connect with Rick: https://www.linkedin.com/in/rickscot/ Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com 00:00 - Intro and community shoutouts 07:06 - Introducing Rick Scot, Global CIO and CISO at Elevate Textiles 07:46 - How Rick got into cybersecurity 09:22 - Charlotte's tight-knit cyber community 11:18 - The moment that made security the focus 13:06 - Balancing the CIO and CISO roles 16:17 - What "Identity at the Center" means to Rick 19:26 - Where to start when building an IAM program 23:29 - Balancing risk and innovation with AI 27:46 - Who should own accountability for an AI agent 29:38 - A hierarchy for agent identities 33:31 - Terminating access and sessions, not just accounts 36:25 - Dealing with shadow AI 41:37 - Standing up a governance process for new AI projects 43:19 - Evaluating new identity technology and token costs 48:51 - Training and governance around AI usage 52:22 - Established vendors versus disruptive startups 56:56 - Looking three to five years ahead 1:00:20 - Advice for identity practitioners 1:01:41 - Lightning round: hobbies and surprises 1:08:40 - Closing and where to find Rick IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Rick Scot, Elevate Textiles, CIO, CISO, identity and access management, IAM program, identity governance, AI agents, non-human identity, agentic identity, shadow AI, session management, offboarding, token costs, Charlotte cybersecurity community, identity leadership

  3. Sep 2

    #445 - Sponsor Spotlight - Twine Security

    Jim McDonald hosts this Sponsor Spotlight episode of Identity at the Center, made possible with support from Twine Security. Jim is joined by Benny Porat, co-founder and CEO of Twine Security and previously co-founder and CTO of Claroty. Benny shares how his cybersecurity background led him into identity and explains the concept of the "execution gap," the space where identity teams are accountable for outcomes but lack the full business context to act on their own. The conversation explores Twine Security's AI digital employee, Alex, and how it differs from traditional automation and RPA, where AI-driven execution fits best within identity operations today, and the balance between the parts of a task AI can handle easily versus the harder remaining work. Benny and Jim also dig into governance and trust, including why least privilege matters even more for AI agents and non-human identities, how organizations typically start with read-only access before expanding permissions, and how access reviews and recertification could evolve as AI takes on more of the process. They close with reflections on measuring success, how the identity practitioner's role changes as more execution shifts to AI, and a lighter round on what a personal AI digital employee might look like. Connect with Benny: https://www.linkedin.com/in/bennyporat/ Learn more about Twine Security: https://www.twinesecurity.com/ Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at idacpodcast.com 00:00 - Introduction and welcoming Benny Porat, co-founder and CEO of Twine Security 00:52 - How Benny found his way into identity and access management 02:21 - The origin of the name Twine 03:28 - Defining the IAM execution gap 05:53 - AI digital employees versus RPA and automation 08:07 - Where AI digital employees are best suited today 09:45 - Why AI is strong at eighty percent and what makes the rest difficult 14:45 - Where a digital employee like Alex fits within identity operations 18:43 - Trust, governance, and giving AI agents the right permissions 21:42 - Applying least privilege to AI agents and non-human identities 25:19 - How organizations start using Alex, from read-only to full execution 30:27 - Rethinking the role of access reviews with AI involved 33:14 - Measuring efficiency gains and revocation rate improvements 36:00 - Addressing concerns about AI replacing IAM practitioners 39:12 - How customers define and measure success 44:15 - How the practitioner's day-to-day role changes with AI agents 47:12 - Closing thoughts and where to learn more 47:37 - Lighter note: imagining a personal AI digital employee Keywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Benny Porat, Twine Security, Sponsor Spotlight, AI digital employee, Alex, identity and access management, IAM, execution gap, least privilege, access reviews, recertification, agentic AI, non-human identity, NHI, Claroty, IGA, PAM, governance, human in the loop

  4. Aug 31

    #444 - August 2026 Mailbag

    Jeff and Jim open with the unavoidable topic of AI agents and the tension between enabling innovation and governing agent permissions, then run through a packed fall conference schedule. The August mailbag pulls questions from Singapore, Toronto, Prague, Johannesburg, Helsinki, and Seoul. They discuss when externalized authorization makes sense, why passkey recovery can become the weak link in phishing-resistant authentication, what EU digital identity wallets may mean for enterprises, how continuous access evaluation changes the meaning of terminating access, and how to build resilience around a centralized identity provider without creating a second full-scale IdP. The episode closes with a lighter question: if every IAM product needed a giant warning label, what should it say? Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com 00:10 - Welcome and have we talked about AI too much? 01:32 - Governing AI agents without becoming the progress prevention department 03:50 - Fall conference season and IDPro 04:40 - Cybersecurity Summits in Chicago and Atlanta 06:40 - SailPoint Navigate, InfoSec World, FIDO Authenticate, and Identiverse DC 10:40 - 3D printing, challenge coins, and superfan status 11:56 - August mailbag begins 12:19 - Singapore: Is externalized authorization ready for mainstream IAM? 20:30 - Toronto: Passkeys, account recovery, and help desk social engineering 25:55 - Prague: What should enterprises do about EU digital identity wallets? 31:44 - Johannesburg: Continuous session revocation and what “terminate access” really means 38:04 - Helsinki: Designing identity resilience around a centralized IdP 45:23 - Seoul: What warning label should every IAM product have? 48:26 - Wrap-up and how to send future mailbag questions IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, IAM, identity and access management, August 2026 mailbag, externalized authorization, authorization, policy-based access control, passkeys, account recovery, phishing-resistant authentication, identity verification, EU digital identity wallet, continuous access evaluation, shared signals, session revocation, token revocation, identity resilience, identity provider, disaster recovery, business continuity, AI agents, agentic identity, IDPro, FIDO Authenticate, Identiverse DC, InfoSec World, SailPoint Navigate

  5. Aug 24

    #443 - Ghosts in the Machine with John Huyette and Omer Arshed

    Jeff and Jim are joined by John Huyette, AI Risk Leader at RSM, and Omer Arshed, North American Digital Identity Leader at RSM, to explore how identity controls can help organizations manage the growing risks of AI agents. John introduces five laws for managing AI risk: governability, lineage and integrity, trust boundaries, authority containment, and human impact. The conversation connects those ideas to familiar IAM principles including ownership, auditability, zero trust, least privilege, just-in-time access, privileged access management, and continuous monitoring. They also discuss prompt injection, shadow AI, human accountability, and why organizations should start by building an honest inventory of the AI capabilities already operating in their environments. 5 Laws of AI Risk: https://www.linkedin.com/feed/update/urn:li:activity:7487942457075257344/ Connect with John: https://www.linkedin.com/in/john-huyette-1373906/ Connect with Omer: https://www.linkedin.com/in/omerarshed/ Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com Timestamps 00:00 Introduction, 3D printing, and conference updates 06:58 Introducing John Huyette and Omer Arshed 07:52 John’s path from technology risk to AI risk 12:11 Omer’s identity origin story 13:43 The five laws for managing AI risk 18:00 What “ghosts in the machine” means for identity 20:17 Governability and ownership of AI identities 25:17 Do you know what has access to what? 29:43 Applying decades of IAM lessons to AI 32:35 Lineage and integrity 35:20 Building an AI bill of materials 37:12 Trust boundaries and external data 38:36 Prompt injection and untrusted content 42:48 Applying zero trust principles to AI agents 47:26 Authority containment 49:56 PAM, least privilege, and just-in-time agent access 56:22 Human impact and accountability 58:41 Is agentic AI really a new identity problem? 01:02:35 Starting with lower-risk AI use cases 01:04:21 Where organizations should start 01:05:07 Shadow AI and zombie accounts 01:07:09 What excuses would an AI give during an access review? 01:12:20 Wrap-up Keywords IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, John Huyette, Omer Arshed, RSM, AI risk, AI agents, agentic AI, AI governance, governability, lineage and integrity, trust boundaries, authority containment, human impact, shadow AI, identity governance, IAM, zero trust, privileged access management, PAM, least privilege, just-in-time access, non-human identity, NHI, prompt injection, AI identity, access governance, continuous monitoring

  6. Aug 19

    #442 - Identiverse 2026 - Identity After Dark with Bravura Security

    Recorded live at Identiverse 2026 in Las Vegas on June 17, Jeff and Jim are joined by Bart Allan, General Manager at Bravura Security, for a live recording with a studio audience. In a late-night talk show format, the three host an open Q&A driven by IAM practitioners in the room. From securing AI identities to whether access reviews are headed the way of the password, this is an unscripted conversation driven by practitioners for practitioners. Topics include identity as a business enabler, zero standing privilege, agentic authentication, standards for AI agents, vendor relationships, the captive customer problem, community, and hiring IAM talent. Thanks to Bravura Security for supporting the Identity at the Center podcast. Connect with Bart: https://www.linkedin.com/in/bartholomewallan/ Learn more about Bravura Security: http://bravurasecurity.com/idac Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com 00:00:00 Welcome and Introduction 00:03:00 AI Identities: Should IAM Teams Panic? 00:07:30 Identity as a Business Enabler vs. Cost Center 00:24:00 Continuous Identity and the Future of Access Reviews 00:35:00 Zero Standing Privilege and JIT Access 00:38:00 Standards for Agentic AI 00:46:00 Vendor Relationships and the Captive Customer Problem 00:55:56 Normalizing Rip and Replace 01:01:00 IDPro, Identity Beers, and Building Community 01:11:00 Agentic Authentication and Non-Human Identities 01:18:00 Hiring IAM Talent 01:26:00 Team Diversity and Multiple Perspectives 01:27:00 Closing Identity at the Center, IDAC, Jeff Steadman, Jim McDonald, Bart Allan, Bravura Security, Identiverse 2026, Identiverse, IAM, identity and access management, identity security, AI identities, agentic identity, agentic authentication, non-human identities, NHI, access reviews, zero standing privilege, JIT access, continuous identity, IGA, vendor selection, identity community, IDPro, IdentiBeer, live podcast

  7. Aug 17

    #441 - Identiverse 2026 - Sachini Siriwardene and Ian Glazer

    Live from Identiverse 2026 in Las Vegas, Jeff and Jim sit down with Sachini Siriwardene, winner of this year's Kim Cameron Award, along with Ian Glazer of the Digital Identity Advancement Foundation (DIAF). Sachini shares how she moved from open banking API security into consumer identity work at a bank, and what led her to apply for the award named after identity pioneer Kim Cameron. Ian explains DIAF's mission to remove financial barriers to industry participation and previews the upcoming Vittorio Bertocci award for standards contributors. The conversation covers agentic AI and non-human identity governance, the AuthZen specification, continuous access management, and how practitioners can separate real AI capability from marketing hype. The group also swaps favorite hallway conversations from the show floor, including a discussion on extending the shared signals framework beyond RISC and CAPE, before wrapping with some very Vegas talk about the Sphere.Connect with Sachini: https://www.linkedin.com/in/sachini-siriwardene/Connect with Ian: https://www.linkedin.com/in/iglazer/Learn more about the Digital Identity Advancement Foundation: https://diaf.org/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com00:00 - Cold open and conference banter01:35 - Jim's origin story with identity and Kim Cameron03:22 - Welcoming Sachini Siriwardene and Ian Glazer04:02 - Ian explains the Digital Identity Advancement Foundation05:54 - How Sachini got into identity through open banking08:46 - The moment identity clicked as mission critical09:47 - Agentic AI and non-human identity governance11:25 - Optimist or pessimist on AI and the job market14:45 - Applying for and winning the Kim Cameron Award15:41 - How DIAF selects award recipients17:21 - Standout sessions and the AuthZen specification18:36 - First impressions of Identiverse20:01 - Advice for future award applicants22:03 - Managing agentic identity in practice23:16 - Separating AI hype from real capability24:32 - Where the identity industry can improve27:08 - Acting fast without chasing hype28:05 - Favorite hallway conversations29:23 - Extending the shared signals framework30:39 - A D&D themed conference talk31:08 - Vegas talk and the Sphere experience34:19 - Wrap up and how to support DIAFIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Sachini Siriwardene, Ian Glazer, Identiverse 2026, Kim Cameron Award, Vittorio Bertocci Award, Digital Identity Advancement Foundation, DIAF, agentic AI, non-human identity, AuthZen, continuous access management, open banking, OAuth2, FAPI, shared signals framework

  8. Aug 10

    #440 - Identiverse 2026 - Mike Kiser

    Recorded live at Identiverse 2026, Jeff and Jim sit down with returning guest Mike Kiser, Director of Strategy and Standards at SailPoint, for a wide-ranging conversation that spans two of the standards world's most active frontiers. The first half breaks down C2PA, the Coalition for Content Provenance and Authenticity, explaining how it differs from digital watermarking, how metadata and cryptographic signatures build a chain of custody for media, and why this work connects directly back to identity. The conversation then shifts to AI agents and the challenge of defining and governing intent, with Mike drawing an extended analogy to the early, under-regulated days of space exploration. The episode closes with reflections on the value of hallway conversations and community at Identiverse. Connect with Mike: https://www.linkedin.com/in/mike-kiser/ Connect with us on LinkedIn: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show on the web at http://idacpodcast.com 00:00 Introduction from Identiverse 2026 01:00 Mike previews his two Identiverse talks 01:35 What C2PA is and how chain of custody works 06:51 Watermarks versus C2PA explained 10:06 Why content provenance matters for identity 14:22 Is C2PA a standard or a working group 16:23 The SpaceX and space debris analogy for agent intent 20:13 Governing agent publishing without stifling innovation 22:00 Action Identification Theory and the how versus the why 27:47 Can an AI actually have intent 32:34 Why people humanize and fall in love with chatbots 38:37 The case for locking down intent early 39:39 Does intent change, or is it a new intent 46:19 Favorite hallway conversations at Identiverse 51:03 Wrap up and where to find Mike IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Mike Kiser, SailPoint, C2PA, Content Provenance and Authenticity, Identiverse 2026, Shared Signals Framework, AI Agents, Agentic Identity, Digital Watermarking, Decentralized Identity Foundation, Intent-Based Access Control

4.9
out of 5
39 Ratings

About

Identity at the Center is a weekly podcast all about identity security in the context of identity and access management (IAM). With decades of real-world IAM experience, hosts Jim McDonald and Jeff Steadman bring you conversations with news, topics, and guests from the identity management industry. Do you know who has access to what? Visit us on the web at idacpodcast.com

You Might Also Like