Why AI Agents Need Execution Governance, Not Just Login
Execution governance for AI agents is the next frontier of identity security. Roland Palmer, CISO and VP of IT at JumpCloud, joins Alan Shimel on Techstrong TV. Furthermore, he explains why checking a login is no longer enough once agents are inside.
About Roland Palmer
Roland spent 20 years in the Marine Corps across network operations, cybersecurity operations and crypto work. In addition, he moved into government contracting and security program management. Consequently, he led security at a SIEM provider before joining JumpCloud in March.
The three eras of identity
Alan frames identity in three eras, starting with people and then machines in the cloud native stack. Meanwhile, the third era is agents, which promise to outnumber the first two combined. Therefore, knowing who an agent is and what it can access is the defining challenge.
Roland agrees that login focused governance worked well for humans at the front door. Furthermore, most agents are placed inside environments and never log in at all. As a result, execution governance for AI agents must audit every action tied to a credential.
How JumpCloud approaches agent swarms
Agents are good at acting, chaining and delegating, which makes swarms hard to follow. In addition, JumpCloud works across three tenets of visibility, identity and access, and governance. Consequently, the platform covers human to agent and agent to agent communication.
Visibility starts at onboarding, before anything reaches production. Meanwhile, endpoint agents and AI gateways can surface rogue agents and shadow MCP servers. Therefore, a continuous inventory is the first step toward execution governance for AI agents.
Getting started
Roland recommends a JumpCloud free trial, which includes the agentic identity and access features. Furthermore, the company blog shares its view on agent identity, access and governance.
Explore more cybersecurity coverage and the latest Techstrong TV interviews.
For more information please visit jumpcloud.com
Transcript
Hey everyone, welcome back here to Techstrong TV. I am happy to have this gentleman on. It's his first time here on Techstrong TV with us, so let's welcome Roland Palmer, who is the CISO MVP over at my friends at JumpCloud.
Roland, welcome to Techstrong TV. It's great to have you here. Alan, thanks so much for having me.
Really appreciate it. It's my pleasure. I got to mention from the outset, I usually do this when we do JumpCloud.
JumpCloud was pivotal in helping me start what became Techstrong. As a matter of fact, they're still a shareholder here and doing the right thing demands that I say that up front. Not that there's any kind of quid pro quo or anything like that, but full disclosure, and in case anybody brings it up, I'm saying it up front so you know.
Roland, as we were talking off camera, I followed JumpCloud since before it was called JumpCloud, and many of the founders there are longtime friends of mine, so I'm really familiar. But you're a new person, a new personality at JumpCloud. You're there since March, I understand.
Let's hear a little bit of the Roland Palmer story. Yeah, happy to. And like you mentioned, Alan, currently the CISO at JumpCloud, also the VP of IT at JumpCloud, and that's a recent change and happy to have that.
Happy to be part of the technology of JumpCloud and using it internally, and using all the great things that the product offers. But from the security side of things, if I move backwards, prior to JumpCloud, I was a vice president of security at a SIEM provider, and prior to that, I had some sort of protective affiliation with the military from the three years before my 20-year career in the Marine Corps, where I did everything from network operations to cybersecurity operations to crypto tech, which is not security related. It's more- Yeah ...
hands-on related. But my career naturally of protecting things culminated in the Marine Corps, where I ended up network operations, cybersecurity operations, to government contracting, doing the same thing with security program management, and then moving to the SIEM provider and naturally finding my way to JumpCloud, where I'm having a great time. I love it.
Raja and I, one of our companies that we founded did a lot of work with what they call the NMCI. I don't know if you were there when NMCI was around. Man, can we tell stories about that.
Geez. Anyway, though, sounds like a great background, right? So many of my friends in the security world have come out of the military backgrounds, right?
And it's true worldwide, right? The best place to get cut your teeth and learn your chops about cyber and security. Roland, as I said, we've been covering JumpCloud forever, but you bring a fresh perspective to it.
How would you describe JumpCloud? What do they do? If I said best in class, would that be enough, or should I elaborate a little?
Okay. Well, best in what class, right? I would say- Because we've got people out here, they don't watch every day, right?
They may or may not know. How would you describe JumpCloud for those not familiar? I would describe it in three sentences, or in a few sentences as, a one-stop infrastructure platform for identity across human and non-human access, across human and non-human, and governance across human and non-human.
And I say human and non-human because it's very important to hear that it's not just the Rolands and the Alans of the world that JumpCloud cares about. It's everything that's non-human running in every production and sandbox environment that it actually cares about, and it's developing technology and features to make sure that it's those assets, including the people, are doing the right thing or whatever the right thing the business decides is inside of their business. Yep.
Roland, so we were talking off camera, and I mentioned, I considered identity and access management the killer security app for cloud security, right? When we started really moving into the cloud in mass, in volume, the old moat and castle model wasn't going to work anymore when everything's up in the cloud. And really, identity and access control became the trade, right?
That was how you were able to try to secure things. And of course, JumpCloud was founded into that and kind of worked around that. But a funny thing happened, funny things have happened since then.
I call it the three eras of identity, right? First, we worried about the Alans and Rolands of the world, right? Making sure we were who we say we are, and based upon that, what we can do and what we can access.
But then, especially with the advent of the cloud-native stack, now you've got containers, right? And Kubernetes, the whole cloud-native thing. And so we started this machine identity and also the rise of the Internet of Things and everything else.
You had machine identities, right? And there were more machines than there were people. And so managing identity and access control for pure machines is really the second era, to me, of identity control.
And now in the last, I don't know, let's say two years maybe, a year, we see the rise of agentics, of agents. And they promise to be much, much bigger than the other two combined in terms of just sheer volume, right? How many agents are we going to have in this world, right?
But it's the same thing. We need to understand their identity, and based upon their identity, what their access management is, right? Especially with agentics, how they're governed, right?
What governance, what guardrails do we have? What reporting do we have? What visibility do we have?
And this is, to me, not just the latest, but truly the greatest challenge in the identity space. There, I said it. What do you think?
Prove me wrong. No, I don't want to prove you wrong. I want to hop on that train.
I believe you, too. I'm with you, and the opinion and the pursuit of JumpCloud aligns exactly with that. In that, the way you described, if we talk about human users and 20 years ago into the cloud transformation, and then log on, login being the priority.
Do they have authorization to be in an environment? That was a great pursuit 20 years ago. That was a great pursuit for humans.
Can they log in? Can they walk in the front door? Absolutely.
And we became really good at that. Now we're in a world where if we let something in the front door, you necessarily can't stop it. If we let an agent in, we can't stop perhaps what it's doing.
So that transition from login-focused governance to more of a execution-style governance is so important so that once an agent is in, which these days an agent is, most times from what I'm seeing, is put inside the environment and they're not logging in. They're past the login anyway. So that execution governance that's needed, where we're looking at every action tied to an agent or tied to a credential, whatever logged in, and then being able to audit what they did and govern what they're doing, has become so important, and that's kind of the pursuit and the thought process that I think you were kind of enumerating with that next evolution of authentication and governance inside of any type of identity.
Mm-hmm. So I get that agentics, we need to manage the agentic identity and control beyond just purely logging in. Yeah.
I think what scares many of our people out here is we all hear it's sort of the swarms, right? Where one agent begets another agent, to go all biblical on you, begets another agent. And before you know it, you've got a swarm of these agents, and they're leaving notes for each other, and they're looking at everything seven ways from Sunday.
How does JumpCloud help us deal with that? Or can they not at this point? Because this is going to be a question.
It's an evolving problem. Yep. And in the news cycle today, we hear two things.
We hear model advancement and then the damage that model advancement's doing and folks breaking or agents breaking in and out of environments. So it's very important. And like you just mentioned, agents are really good at three things, acting, chaining, and delegating, whether it's within themselves or communicating with another agent.
And the opinion of JumpCloud is that, what I've seen inside of JumpCloud, is that we're thinking of things in three different kind of frameworks. Visibility and ownership, making sure that we understand what's out there and that we can see it. And then inside of that, the identity and access control.
We see it, do we know what it is? And do they have the appropriate access, just like we would a human. And then finally, governance and privilege control.
So to answer your question, communication between any two identities, whether it be human to human, human agent, agent to agent, or any variation thereof, the platform that is JumpCloud, the way we should be thinking about identity governance, access governance, execution governance. We are thinking that way. Everything from MCP, AI gateways, to discover perhaps shadow MCP servers and connections.
We're looking at a bunch of things, Alan, to be candid. I can enumerate probably 10 things that we're doing inside. Very feature-rich and very focused on those three tenets of visibility, identity and access, and then governance.
So Roland, it's interesting, right? Because to me, again, an old security principle is you got to know what you have before you can secure it, right? Yeah.
And that to me is the visibility piece of this, right? We've got to be able to see it before we can assign identity and access and governance. In the world of agents, how do you...
I'm at a loss personally. Do I set up sentry points along my network, along my infrastructure to identify agents? Or how does that visibility piece play?
Yeah. Well, it's as tough as the human visibility portion that we've dealt with for years on years. And if I put it in human terms, the first place to look is at onboarding.
And whether you're vibe coding or whether you have a engineering creating product, having that onboarding process before anything hits a production environment is very important. And obviously tying that into a platform like JumpCloud that can register and hold what you actually have inside of your business is very important. The rest of it is for something like, again, like a JumpCloud, where we have agents on endpoints or agents deployed where we can see activity and perhaps- Right ...
see rogue agents. That enables you to register those. Or again, I'll point back to a local MCP server perhaps running on an endpoint.
We would be able to see that, register that, and that goes right back to the visibility you talked about. Having that inventory of systems inside the platform is very important, and that's where you should start, a continuous inventory and registry, and then catching it at onboarding. So you said something earlier on.
You said, "Well, the age of identity, the age of human identity, is humans walk through the front door," right? Agents, I don't know if they beam in "Star Trek" style or come through the chimney or what it is, right? But it just seems like a different mission.
Yeah. And I'm pretty sure they beam in. If I go back to my "Star Trek" days, they beam in without a doubt.
Yeah. And the other fantastic thing that's happening is that we have a community of folks that is perhaps worldwide, that's super interested in AI, and they're building really fast. So it does feel like, and it is happening, where AI in environments are outnumbering humans, so the need to understand, going back to the visibility conversation, the need to understand what's out there and what it can do so you can manage the risk inside your business and the exposure to your platform or exposure to your people is so very important as well.
But I don't see the age of agent building slowing down anytime soon, as long as there's people with work problems that they're trying to solve or efficiency issues that they're trying to solve or tools that aren't solving problems for them that they can quickly create an agent to solve. Absolutely. I love it.
If you don't mind, we got not a lot of time left, but I wonder what, nuts and bolts for people out there who are saying, "Hey, this is a problem for us. " How do they engage with JumpCloud for this? What's the path, the on-ramp, if you will?
I'd recommend, and are we talking about how to get access to the product? Are we talking about how to engage- Yeah, but specifically for agentics, right? I think a lot of people, they get the whole human identity thing and all of that, but people are worried about agentics.
They're worried about governance for agentics. We're all reading every day, you're not a real model unless your model is broken into something, it seems like, right? JumpCloud's something that could help here, and especially as companies are saying, "Hey, we can't wait.
" Right? What's the best way to engage JumpCloud with that? I think the easiest way as far as engaging JumpCloud would be, I'd recommend anyone, if you're interested in agentic or if you're just interested in technology and how great the platform is, how good the platform is, is hop on a free trial.
It's feature-rich. And I'm not saying that as a solution to agentic. I'm saying that is that's your gateway to agent solving problems, where everything that we've talked about, the identity and access governance for agentic, the new agentic world exists in a free trial.
You can handle it there. You can test it there. And it's, again, it's just like a, for a short period of time, it's just like you had the paid version.
So engaging there. And then to be candid, the other portion of it is hit the JumpCloud website and read. And the reason I'm signing for the JumpCloud website is because the stories that we're telling there give our opinion on the pursuit about how we handle agentic and the future of agent identity, access, and governance.
Hop on there and see if it aligns with your opinion. " Excellent, man. Hey, we're overtime here, Roland, but welcome to Techstrong TV.
I hope this isn't the last time. I hope we will have you on here soon again, and we can continue this conversation because this is an ongoing conversation and evolution about what we're seeing here. Best of luck to you at JumpCloud and to all my friends at JumpCloud.
Thanks for coming on. Thanks, Alan. Thanks so much, and I'll keep following along and being a fan.
I appreciate you. All right. Hey, we're going to take a break here on Techstrong TV.
We got more coming, so stay tuned.