Agentic AI is Forcing a Reckoning in Enterprise Permissions
It is no secret that the tech landscape is moving at lightspeed, but handing autonomous AI agents the keys to a grossly over-permissioned enterprise kingdom is an absolute recipe for disaster. Alan Shimel sits down with Oso CEO Graham Neray to unpack a staggering new joint study with Cyera, revealing that a massive 96% of assigned user permissions go completely unused and are still largely managed by hand. In this candid conversation, they break down why this mountain of security debt is the true “canary in the coal mine” for the agentic era, and how solving the historically unsexy problem of authorization has suddenly become the C-suite’s most critical mandate.
Transcript
Hey, everyone. Welcome back here to Techstrong TV. Let me introduce you to our next guest.
He's been on here before. It's Graham Nogueria. Graham is the CEO of Oso.
Graham, it's great to have you on, man. How are you? Hey, I'm doing great.
Thanks for having me. Took us a little while to get going, but we're going, Graham. Um, as I mentioned, you've been on here before.
Um, you know, you're in business long enough, you get to-- I-- We have this family connection with your dad, and, it was really-- I got a kick out of seeing you achieving success in starting a company like this and, and... But give people a sense. I know, you know, this is where you are now, but you've actually had a-- quite a career.
Give people a sense of kinda where you've been, how you got here. Sure. So before starting Oso, I worked at a company called MongoDB.
Um, when I joined there, we were still pretty early on, so doing about a million in revenue. Um, by the time I left, we were doing about two hundred and fifty million in revenue. Um, it was really cool to play, you know, a small part even in that, in that story.
I sort of spent the first half of my time there building out the go-to-market side of the business, so first marketing, and then a function to scale the sales org. And then I spent the second half of my time there working as chief of staff to the CEO, a guy named Dev Ittycheria. He and I kinda made a trade.
I told him that he could have my life for, like, two to three years, as my wife will attest, and he took... You know, he definitely had it. Um, but in exchange for that, I wanted to learn all the things about building and running a company, and that, and that's what we did.
So in that period of time, we launched MongoDB Atlas, which is now the company's main revenue driver, helped take the company public in twenty seventeen, built the first product growth team, and then when I left, to start Oso, he became the first investor. So Graham, that brings us to founding Oso, right? Yeah.
I've, I've founded four or five venture-backed companies, I've co-founded. I've been involved in it. For anyone-- If anyone who's ever founded a company knows that it's not something you just, like, wake up in the middle of the night and decide on a whim that you're gonna start a company.
It's something where you've gotta have a passion f-for what you're doing, that you believe the mission is important. Y-y-maybe you gotta be a little crazy. But talk to us about what drove you here to, to start Oso.
Yeah. I mean, to be totally honest, like, I, I love infrastructure, I love security, and I love developers. And we were working on a different product at the time, actually.
But it was through conversations with our customers, that it became clear that there was this area of the stack that was kind of untouched, hadn't really been worked on in, like, fifty years, and that's permissions. So just, like, to step back, right? So for those who are, you know, not as, familiar with the domain, you know, you have, authentication.
You can think about that as, like, the login screen to your app. But permissions are sort of the behind-the-scenes machinery that decide, you know, if you wanna click a button, if you wanna pull up a page, if you wanna pull some data, are you allowed to do that or not? And it turns out that for the last fifty years, that's all been done custom, and increasingly now, companies like, you know, 1Password, Brex, Vanta, ZoomInfo, Productboard, and tons of others are using Oso to do that instead.
Um, and now look, I've been spending almost seven years working on this domain, and if I can be honest, like, I remember going for a walk with my friend once, during COVID in the Arnold Arboretum, Park in Boston, and I was explaining to him what we do, and he finally got it and he goes to me, "Oh, permissions. " Uh- And I kind of feel like I've been in this, like, pseudo unsexy domain for the last six or seven years. But now, but now with the shift to agents, all of a sudden, everyone wants to talk about permissions.
Here we are, Aaron Levie tweeting about permissions. Dharmesh, CTO of HubSpot, posting about permissions. And I feel like everything that we've been doing has kind of prepared us for this moment, which is, which is kind of cool.
Well, you know what they say, the wheel of karma goes round and round, right? And the wheel's come around to you now. So good for you, man.
That's, that's-- It's true, though. I, I, I will tell you, I had a moment... So I spent the weekend digging in a Perplexity computer.
Uh-huh. Just agentically redefining Techstrong. And yeah, I could tell you all about permissions, you know, 'cause I-- hooking into WordPress and hooking into this and using that and, and it's all about the permissions, right?
'Cause it can hook into anything, but you need the permissions and authentication to do it. And yeah, I get, I get that. Um, Oso.
Give us the website. O-S-O dot... com.
com. Okay. Yeah.
com is owned by someone in China, and they want a lot of money for it, so I said no. com. The guy, the guy wanted about seven million dollars.
Yeah. And, uh- Not happening. Yeah, no.
com. Um, but yeah, a long story. Anyway, so Graham, how-- Give us a little-- So, so you've been at Oso now, what?
Would-- Is it three years? Four? No, we- Two?
We-- No, no, no. This is-- We're coming into our seventh year. Um- Seventh.
I knew it was like the fourth. And so this is what I mean. Look, I've, I've met with over two thousand engineering teams over the last several years to talk to them about this one problem.
And, you know, in, in the domain of, like, just B2B SaaS applications, that problem was one thing. But the shift to agents has dramatically shifted this. Uh, it has dramatically sort of, like, changed the dynamic.
Um, we all know that apps are over-permissioned. What do I mean by that? Like, you have more permissions than you need.
This is like everyone has experienced this. It's like, oh, just, you know, give them that role. Just make them an admin, whatever, so they can get their job done.
And this is a kind of a bargain that we've accepted, this like gross over-permissioning because, it was in the name of user productivity. We don't want to get in people's way, and fundamentally, we could get away with it because, one, we're trusting users whether or not we should. We say, okay, users have judgment.
They, you know, they want to keep their jobs. They're fundamentally accountable. Um, and two, there's, an upper balance the amount of damage that, you know, you or I, Alan, can do before the security team notices.
The problem is agents break this bargain, so agents don't have these constraints. Agents are not trustworthy. They can be tricked.
They can do silly things. They can hallucinate. Uh, even when they think they're doing the right thing, it might be the wrong thing.
And two, they operate at machine speed. They could do way more damage in five minutes than you and I could imagine doing in a span of, you know, five days. And we see this already happening with incidents popping up.
You know, there's an incident from AWS a few weeks ago where their coding agent decided that the fastest path to, resolving the developer's issue was to destroy and recreate the environment, which created a thirteen-hour outage. I don't-- I'm not blaming AWS. I'm not pointing fingers at anyone.
This is a, a problem that's endemic in our industry, and we view those kinds of incidents as the canaries in the coal mine, and that's sort of what, what-- why we think this is an exciting time and sort of why we think the, the research that we're publishing is relevant today. I love it. Excellent.
Excellent. So speaking of research we're publishing, you guys recently, I guess, in partnership or in conjunction with Cyera, another company we follow a lot, released this study of how enterprise permissions are actually used or being used- Yes ... you know, now in this new agentic age.
Um, and, and some of the, the, you know... I, I mean, I didn't read the whole report yet under embargo, but I got the highlights, and some of it, I mean, kind of raised an eyebrow or two, right? But, you know, I didn't see that coming.
But tell us, Graham, you know, what, what, what, what for you are the key findings? Okay. Well, in some respects, it's like it's saying what everyone already knows.
It's like saying to dentists that not everyone flosses enough. Like, anyone in security is intuitively gonna know and understand the findings of the report, but it is quantifying something that I, to the best of my knowledge, no one has ever done before. I've seen it in surveys.
I've seen it in, you know, anec- so the, the anecdata sense. But what we did that's different is we analyzed production permissions usage over two point four million users, and what we show, which won't surprise anyone in the security industry, but shines a light on a problem that we really need to address now, is that ninety-six percent of permissions that people have, they don't actually use. Said differently, people have ten X more permissions than they actually use on a day-to-day basis.
And again, this was fine for humans because we had the trust, and we had the time constraints, but now you imagine taking an agent like Claude Code or Cowork or whatever and exposing it to this grossly over-permissioned surface area, and you could be in for a world of hurt before you know it. So this is the first finding is this, you know, ninety-six percent of permissions. Um, I'm, I'm happy to, you know, elaborate or answer any questions from here, Alan.
Tell me. Sure. No, I, I...
So look, first of all, let me raise my hand and say guilty, right? I'm, I'm good for this too. I, I go and, and, you know, set stuff up and then forget I did it, or I just, you know, I thought I needed it, but I really didn't need it, and, you know, it's almost...
I don't want to say it's human nature, but it's definitely, you know... It's the same thing that drives cloud engineers to not shut off an instance when they're done messing with what they were doing, right? Yeah.
It- it... We just... And, and what it really, in my mind, it's a form of debt.
It's a form of technical debt. Yes. Right?
Which is kind of that whole DevOps thing we, we talk about, right? Yes. And technical debt.
So big picture then, unused permissions, technical debt, yes, no, sometimes? Oh, no, this is, this is like security debt, and by the way, I don't... You know, I...
We're all guilty of this. There's no, there's no... Anyone in the industry who claims to me that they have implemented least privilege at their company, I'd really like to see the proof.
The problem is not a human issue. The problem is not that security teams don't care or didn't know. The problem is that the juice was never really worth the squeeze because there were other things that were bigger risks.
And- Yep ... in reality, this isn't a human issue. This is a systems issue.
So our friends at Cyera, you know, one of the things that they share with us and that is included in this report is that eighty percent of SaaS permissions are managed statically. You know, if that's the way the system works, you're creating a really high burden for someone who, you know, for security teams who are already way understaffed to go and do something about this problem. Um, and so this is not- But let me stop you here a sec, Graham.
When you say managed statically, what do you mean for our audience? What I mean is, the way this typically goes is you start your job, you get a bunch of roles, andThat's it. Someone...
If, if you... If there is supposed to be any sort of change, someone physically has to go and spend the time to manage that change by hand. Yes.
Okay. And, and that's, you know- So, so it's, so it's manual ... it's manual, and for companies that ob- you know, even small companies wind up with over 200 SaaS applications, you know, large companies, like in, you know, the, the biggest ones have over 7,000 applications.
These are the customers that we're speaking with. You can't manage that stuff by hand. That's crazy.
Um, but, but not only that, you now have... So in addition to, you know, em- employees not accessing 96% of the permissions they have, they also don't touch 91% of the sensitive data they have access to, and almost a third of them have the ability to destroy or exfiltrate sensitive data. So again- Crazy ...
acceptable for humans, but you wanna hook up Claude Code or ChatGPT or whatever to this grossly over-permissioned service area, and an agent at that point, a tricked agent, an agent hallucinating, an agent doing something silly that it thinks is the right thing to do now has what feels like carte blanche to do something very destructive. And where, you know, PWC is saying that 88% of executives want to accelerate their, their AI spending in the next 12 months, but, but I don't think any, you know, most of them are not clear on what's going to happen when the, you know, the rubber meets the road. You have these incidents like what happened with AWS and others, you know, people getting freaked out about OpenClaw.
These, again, these are just canaries in the coal mine. I, you know, I, I, I told my team when we, when we started this research that I would shave my head if the number were less than 90%, and as you can see, Alan, I still have my hair. Still have your hair.
Okay. On this interview, I'll tell you, I will shave my head if there is not a massive, massive issue like the AWS one, but, like, way bigger in scope before the end of 2026. You know what?
Okay, we're gonna hold you to this one, Graham. Like, I could shave my head, but it really wouldn't do any good. But for you, it's gonna mean something.
So we're, we're gonna come back, and, you know what, if we, if we see an incident, we're knocking on the door with our clippers. Um- We'll bring the clippers ... ex- yeah, that's a bold, that's a bold marker you're putting out there, my friend.
Oh, I'm, I mean, it's easy. This is, this is like child's play. By the way, I haven't...
I've buzzed my hair only once in my life, so this is something I actually care about, and I'm fairly certain my wife won't be happy if I have a buzz cut. No, I don't think- So I have real skin in the game here, Alan. This is, this is real skin.
So let me ask, is there anything in this study that, Cyera and Oso partnered on that kind of r- you weren't surprised at? I mean, you were sur- excuse me, that you were surprised at, like, you didn't see that coming, didn't have that on the bingo card? Um, honestly, no.
And, and I think that's kind of, like, the, the proof of the pudding is in the eating. " Like, we all know it. This is, this is not...
" However, I think this is the first time, or one of the first times, in history where you can draw a straight line between security work and a business outcome, which is to say that every board and every CEO, you know, from, from, like, you know, Fortune 1 on down, has an initiative right now to drive adoption of AI. They also need to protect their businesses. They have, you know, massive, massive businesses to protect, and if they want to do, one, drive adoption of AI without putting their business at a massive risk, they have to address this permissions issue.
And so our hope is that this drives conversation in the industry for security practitioners where they can, you know, both... " Excellent. Graham, we're almost out of time here.
Um, I wanted to... So th- this study is out now. If you're watching this, the study's already been released.
com or where- Yes ... where do you go for this? com.
We'll have a banner at the top of the site. Excellent. Hey, man, continued success with Oso.
Keep up the great work. You are in the, the permission nirvana space right now, right? Where- Who knew?
Who knew? Go figure. Yeah.
Uh, good for you. Do say hello to your dad, though, too, Graham. I will.
I will. Thanks, Alan. All right.
You just watched Graham Nouray, CEO of Oso, here on techstrong TV about this new release, a new study done with, Oso and Cyera. Check it out. We're gonna take a break on techstrong TV.
We'll be back in a minute.