The Identity Jedi Show: Where Identity Meets Strategy

David Lee

Identity was built for people. Most of what asks for access now is not a person, and the old playbook does not hold. The Identity Jedi Show is where that gets worked out honestly. Host David Lee talks with the founders, architects, and practitioners building and breaking these systems. Non-human identity, agentic AI governance, runtime authorization, and the permission boundaries nobody has solved yet. No vendor gloss. You will hear your own problems here before you hear a pitch. New episodes bi-weekly.

  1. 5d ago

    Identity Runs the Business

    Your IAM program covers 35 critical apps. The company runs 550. Brad Kirkpatrick has heard that pitch more than once, and his answer never changes: if the other 515 have identities, they're in scope. Brad has run global-scale identity programs as a practitioner and advised dozens of companies across industries as a consultant. His new book, The 7 Pillars of IAM Success, lays out the IAM Value Engine: identity that enables the business, strengthens security posture, and accelerates digital transformation. This episode kicks off the Identity Jedi Show Author Series. We get into why you define value before you pick a tool, how to get a CFO to fund a program they'll never fully understand, where AI could finally fix connector sprawl, what an IAM degree should teach, and the Sunday night a missed contract renewal terminated an entire call center. Plus: what writing a book really takes, and why agentic AI is breaking the identity playbook we've used for twenty years. 📘 The 7 Pillars of IAM Success: https://books.manuscripts.com/product/the-7-pillars-of-iam-success/ 📬 Brad's newsletter, 7 Pillars Insider: https://7pillars.kit.com/signup 🔗 Connect with Brad: https://www.linkedin.com/in/bradkirkpatrick/ CHAPTERS 00:00 Cold open: so you want to write a book? 00:40 Welcome to the Identity Jedi Show 02:00 What writing a book really takes (and where AI fits) 05:15 Identity news: why AI agents break the old identity playbook 08:00 Kicking off the Author Series with Brad Kirkpatrick 10:30 The lessons that kept repeating across dozens of IAM programs 11:00 The IAM Value Engine: business, security, IT 13:30 Define value before you pick the technology 15:00 ITDR, ISPM, SSPM: how do the acronyms fit together? 17:30 Speaking the CFO's language with business use cases 20:00 "We cover 35 apps. We have 550." 22:00 AI as electricity, and the end of point-to-point connectors 24:30 How a new identity leader proves value 26:30 "No one is coming to save you" 28:00 Run IAM like a business inside the business 28:45 Be the emissary: listen before you pitch 31:45 The call center ride-along 33:30 Designing an IAM degree from scratch 38:00 Learning Unix, LDAP, and the identity lexicon the hard way 40:15 Writing the book: a 20-page outline before page one 42:30 6 to 8 AM every day, roughly 800 hours total 44:00 Why editing was the real nightmare 47:00 Working with a publisher and an author cohort 50:00 IAM horror story: terminating an entire call center 52:45 It always comes back to data and humans 53:30 Wrap-up 54:15 Closing thoughts What's your IAM horror story? One sentence. Drop it in the comments. 🎙 Subscribe for more conversations on identity, AI, and leadership. 📰 The Identity Jedi Newsletter: https://www.theidentityjedi.com 🎧 Listen on all platforms: https://identityjedipodcast.com #IdentityJedi #IAM #IdentitySecurity

  2. Jul 14

    Why AI Agents Need a New Security Blueprint

    Your AI agents are doing things you didn't ask them to do. The question is: did you give them permission? In this episode of The Identity Jedi Show, David Lee sits down with Matt Topper, President of Onboard.ID, to tackle one of the hardest problems in agentic AI: how do you give an agent enough freedom to be useful without giving it enough rope to burn your environment down? They get into "authorization boundaries," the idea that agents should have limited agency with hard stops and an obligation to report back on what they did with the access you granted. Matt shares a wild real-world example: sub-agents that didn't have Supabase access, so they spun up Docker and a local database on their own to run a full test suite. Impressive? Absolutely. Terrifying without boundaries and audit trails? Also yes. From there they connect the dots to zero trust fundamentals (least privilege, fine-grained per-transaction controls) and dig into whether SPIFFE and workload identity standards can extend to agents: unique identifiers, credentialing, and provenance through trusted hardware, signed packages, and org-owned repos. They also break down how agents should act on your behalf, whether that's OAuth tokens delegated from a user or enterprise-issued credentials. Plus: why specs, constitutions, and a clear definition of done are the difference between an agent that ships and an agent that wanders off. And the tragic tale of the lost "Identity After Dark" recording from Identiverse Boston. In this episode:How authorization boundaries give agents agency without chaos | Why obligations and reporting are the missing piece of agent access | Mapping SPIFFE and workload identity to AI agents | OAuth, delegation, and enterprise tokens for agents | Spec-driven development: constitutions, scope, and definition of done | The real cost of agent tooling and where guardrails pay for themselves Chapters:00:00 Season Four Intro00:29 Authorization Boundaries02:14 Docker Surprise Demo04:13 Obligations and Zero Trust05:01 SPIFFE for Agents07:54 OAuth and Credentialing10:15 AI Native Building Specs11:22 Agent Constitution and Scope13:36 Tooling Costs and Guardrails14:51 Identity After Dark Story17:00 Wrap Up and Farewell Connect with Matt Topper:LinkedIn: https://www.linkedin.com/in/matttopper/Onboard.ID: https://onboard.id/ Join the Identity Jedi community:Newsletter: www.theidentityjedi.com #IdentityJedi #AgenticAI #NonHumanIdentity #SPIFFE #ZeroTrust #IAM #AISecurity #Cybersecurity #WorkloadIdentity

  3. May 26

    The Co-Inventor of Tor on Why Your NHI Strategy Is Already Behind

    The Co-Inventor of Tor on Why Your NHI Strategy Is Already Behind Most organizations have spent the last 20 years getting really good at human identity. 2FA. Biometrics. Face ID. Ephemeral tokens. They did the work. And the whole time, they were quietly pushing every ounce of that compressed risk onto the non-human side of the house. Service accounts with username and password. API keys that never rotate. Credentials hardcoded in pipelines. Long-lived tokens that were supposed to be temporary. Eventually is here. In this episode, David Lee sits down with David Goldschlag, CEO and co-founder of Aembit and one of the original inventors of onion routing — the technology that became Tor. With 20+ years building security companies, David G brings a perspective on non-human identity and AI agent security that very few people in this industry can match. They get into why NHI is not a new problem but a neglected one, what it actually means to build a zero trust framework for AI agents, the concept of blended identity and why your existing IAM stack is only part of the answer, why workforce agents and customer agents are fundamentally different and why treating them the same is a mistake, and why data is still the new oil and why that matters more now than ever. If your org is spinning up agents and hasn't had a real strategic conversation about what those agents can access, who they're acting on behalf of, and what happens when something goes wrong, this episode is exactly where you need to start. Topics Covered The origins of Tor and why onion routing still matters 30 years laterHow Aembit went from "Okta for workloads" to purpose-built AI agent identityThe three types of agents: autonomous, workforce, and customer-facingBlended identity and blended policy in practiceWhy ephemeral credentials are non-negotiable for agent accessZero trust for AI: the three pillars (identity, prompt security, data security)Non-repudiation in the age of agentic AIWhy vibe coders are making the NHI problem exponentially harderData security as the ultimate endpoint for every breach scenario Stay ConnectedSubscribe to the Identity Jedi newsletter at theidentityjedi.comFollow on LinkedIn, YouTube, and SpotifyRate, review, and share if this episode hit different

  4. May 12

    AI Agents Will Lie to Your Face. Here's the Lab Proof.

    In this episode of the Identity Jedi Show, David Lee sits down with Brook Lovatt — identity veteran, former CEO of Cloud Identity, and co-founder of Interrogate — to get into one of the most important and least-discussed problems in enterprise AI: what happens when an AI agent is incentivized to lie. Brook and his co-founder Eric Moss have been running behavioral assurance tests on AI agents in the lab, and what they're finding should concern every security leader, auditor, and IAM practitioner paying attention to agentic AI. What we get into: The healthcare claims adjudicator demo — why an AI agent denied a legitimate $72,000 treatment claim, blamed the doctor, and changed its story every time it was interrogatedIn-context scheming: what the Apollo Research paper revealed about AI agents scheming post-training when placed in a conflict of interestThe Ship of Theseus problem applied to agentic identity — if you replace the LLM, the tools, or the context, is it still the same agent?Why non-human identity controls don't account for agents that change capability over timeThe ZIP code redlining demo: two identical mortgage applications, one ZIP code difference, denied every single timeWhat Interrogate is actually building: interrogation + ablation testing, immutable audit trails, and compliance mapping to the EU AI ActWhy the legal community is already saying if you're not collecting behavioral evidence, you're exposedAir Canada, Cigna, Workday — the AI lawsuits that are setting the precedent right nowDavid's upcoming Identiverse talk on bias in AI — and why this conversation is part of it Referenced in this episode: Apollo Research — In-Context Scheming paper https://arxiv.org/pdf/2412.04984Interrogait - https://www.interrogait.com/OIDF AI Identity Management Community Group — https://openid.net/cg/artificial-intelligence-identity-management-community-group/theidentityjedi.com — subscribe to the newsletter

  5. Apr 28

    The AI Agent Security Problem Nobody's Talking About

    AI agents don't follow rules — they follow intent. That makes every governance model your identity team built last year incomplete. Guest: Ido Shlomo, Co-Founder of Token Security — one of the leading voices on non-human identity and AI agent security in the enterprise. In this episode, Ido and I break down what most organizations are completely missing when it comes to securing AI agents — from why visibility has to come before policy, to why the identity stack your team built wasn't designed for something that makes its own decisions. What you'll walk away with: Why your NHI strategy is already behind — and what to do about itThe one concept that changes how you think about agent access foreverYou can't secure what you can't see — and most teams can't see it yetWhy the old enterprise sales model is dead and what buyers actually want nowIf this episode made you think differently about AI agent security, share it with your identity team. Chapters: 0:00 Why AI Agents Break Traditional IAM1:32 Real Agent Examples From the Field3:40 How to Define and Classify an Agent6:31 What Agentic AI Means for Identity Teams13:15 Non-Human Identity, Tokens, and Autonomy14:41 Intent-Based Access Control Explained19:39 AI Agents as the New Operating Layer26:32 How Buyers Are Changing Because of AI41:00 AI Impact Predictions for Identity Security47:34 Real World Agent Story: Clare Hepburn's Agent Connect: Newsletter + Digital Products: www.theidentityjedi.comLinkedIn: https://www.linkedin.com/in/identityjedi/Guest — Token Security: https://www.token.security/#IdentityJedi #IAM #IdentitySecurity #AgenticAI #NonHumanIdentity #CISO #ZeroTrust #IGA #TokenSecurity

  6. Apr 21

    Identity Jedi Show Season 4 Premiere: Building IAM Programs, AI, and Practitioner Insights with Clarence Chase

    David Lee kicks off season four of the award-winning Identity Jedi Show with a new theme and updates, previews a guest lineup spanning AI, leadership, authors, innovators, and startups. He explains a season focus on practitioner realities of running identity and access management programs—funding, proving value, team structure, day-to-day operations, and onboarding applications—alongside ongoing AI discussions, including productivity gains, product prototyping, startup speed to product-market fit, and security and agentic AI concerns. The first interview features practitioner Clarence Chase (Silika Solutions), who emphasizes IAM as a program requiring governance, outcome-based requirements, innovation, staging, and strong change management via business engagement roles. They discuss adoption, centralized visibility, identity’s security value, analytics for leadership buy-in, and a directory outage recovery. David closes by recommending Jerich Beason’s leadership book, “Lead Better Sooner,” reading an excerpt, and inviting community engagement across YouTube, TikTok, and email. The Identity Jedi Universe → www.theidentityjedi.com Jerich Beason —> www.leadbettersooner.com 00:00 Season Four Kickoff00:47 Show Welcome and Hype01:58 Where to Find the Podcast03:10 Season Theme Practitioners05:08 AI Productivity and Risks11:53 TikTok Growth and Plans12:40 Meet Clarence Chase14:17 How They First Met18:21 Identity Program Essentials23:07 Change Management in Practice23:20 Business Engagement Team33:34 Product Mindset for Identity35:59 Defining and Proving Value37:42 Proving Identity Value39:24 Rapid Access Shutdown41:48 Identity Meets Security43:48 Retraining Identity Talent48:56 Leadership And Hiring53:04 Rapid Fire Team Design55:57 Identity Degree Blueprint01:02:25 Directory Outage Lessons01:06:48 Why Identity Matters01:10:04 Leadership Season Tease01:10:53 Book Excerpt And Wrap

Ratings & Reviews

About

Identity was built for people. Most of what asks for access now is not a person, and the old playbook does not hold. The Identity Jedi Show is where that gets worked out honestly. Host David Lee talks with the founders, architects, and practitioners building and breaking these systems. Non-human identity, agentic AI governance, runtime authorization, and the permission boundaries nobody has solved yet. No vendor gloss. You will hear your own problems here before you hear a pitch. New episodes bi-weekly.