FusionAuth CEO and CTO on Simplifying Customer Identity Access Management
Newly appointed FusionAuth CEO Brian Bell is joined by company founder and now CTO Brian Pontarelli to dive into how customer identity access management is evolving in a way that is simpler to implement.
Transcript
Hey guys. Thanks for the thrill. We're here with Brian Bell, who's the newly appointed CEO of Fusion au and we're also joined by Brian Elli, the former CEO, who's now the CTO.
And we're gonna be talking about what's going on in customer identity and access management. Brian's welcome to the show. Great, great to be here.
Thanks for having us. And the invite. So starting with Brian Bell, since you're the new kid on the block, but what attracted you to the company and tell the folks at home where you've been before you got here.
Great. Well, um, yeah, I'm thrilled to, to be here now. Um, I was attracted to Fusion off for many reasons.
Um, one, the, the, the market of customer identity authentication is enormous. And Brian Pontarelli and the team at Fusion Auth has built an incredible product that really meets the requirements that developers have as they look to add authentication into the applications that they're building. Uh, and the business has grown incredibly efficiently, um, and very quickly over the last few years, and it's now kinda entering a new stage of growth.
And I'm really excited to take that, uh, take that forward. Prior to Fusion off, um, I have been in, you know, B2B enterprise software for a long time, uh, more than a couple decades and different categories of software, a lot of time in, um, service management, asset management, um, as well as some cloud applications like companies like Zuora. I also spent time in, uh, in identity and access management before where I was, uh, I was at Ping Identity where I was the head of marketing and the head of business development, um, there for a period of time.
And then most recently I was at a developer centric, uh, product called, uh, split Software, which was in the, uh, feature management and experimentation space. And I was the CEO there for the last five and a half years, and sold that business to a, a leading DevOps app dev platform called Harness, harness Software. Sure.
We, we know all those companies. Brian Pelli, um, you're decided to move over to be the CTO. What drove that and, and while we're at it, what is going around with customer identity these days?
I feel like we're talking about it a lot more, but I'm not sure we're understanding it. Sure, yeah. So I started the company many, many years ago, 18 years or so now.
And, um, we've, you know, gone through a number of different stages and launched Fusion off back in late 18, um, grew that over the years and, and, you know, I kind of reached this point where I realized that, uh, after bootstrapping and, and playing every role at the company, I just, it was a ti it was time to bring on somebody who had experience sort of scaling companies of this size. And that's where Brian Bell fits in perfectly. And so I, you know, I'll be sliding over to the CTO and, you know, focusing on engineering, focusing on product, but also looking ahead and seeing, you know, what's coming up next in our industry.
And the industry is moving pretty quickly. I mean, obviously we have specifications that are very old, like OAuth and saml. We have ones that are sort of in their mid phase, like pass keys, web and Fido.
And then we have new ones coming up, things like Depop and Gnet, uh, G app, um, which is sort of like the next evolution of OAuth. And so we have all these things that we're looking at and just as well as like, just trends in the space, right? So like if you just look at registration, very simple example, the industry is still sort of struggling to figure out how to get users registered for apps because every app has different data that it needs and different constraints around how do you verify users.
And so we're looking at those things and trying to sort, um, be a market leader and, and put ourselves out there as like one of the first companies that does, you know, full end-to-end registration flows as an example. Brian Bell, I'm sure you did a lot of research before you joined the company, but in your mind, what distinguishes you guys today versus everybody else who seems to be using the phrase identity access and management in the same sentence, but also you do something slightly different. They, They do, I think that's a great observation.
They all do something slightly different, and they approach, I think, the problem slightly differently. Um, but it's a large market and it's growing quickly, and I think that's why there are so many vendors that have, um, you know, trying to pursue that opportunity. You know, fusion Auth is unique in, in several ways.
Um, I think, you know, one of the things I, I think is so compelling about the product is the fact that it's really developer centric, right? It was really designed by developers for developers thinking about how and where developers want to live and, and work. Um, and, and that product means that it's been designed in a way where it can be deployed in multiple environments.
Um, it's a downloadable authentication product. If you wanna run it locally, you can run it, uh, as a single tenant in a hosted environment, um, and then not have to put that burden on your own infrastructure. And it, it, it gives you incredible, um, options in terms of how you want to run the software and manage the software.
Brian Pelli, to that point, who is actually responsible for identity security these days? 'cause the developers theoretically are putting this in their code somewhere, but it, it's just one thing of many. And the security people are the ones who are obsessing about identity these days, but don't have the mechanisms to implement it.
So where does this fall? When we talk about customer identity and access management, because it's part of the app, this tends to fall on the engineering team, and not every engineering team has a security expert or a security architect or, or somebody on staff that manages this. And those engineering teams often don't want to get, you know, pull a CISO or the IT team into the mix.
And so it sometimes it falls on DevOps or SREs, sometimes it falls on, you know, sort of the engineering, the core engineering team. But I think that's one of the reasons that the market is growing so quickly is the engineering teams are realizing that the expertise in order to do this properly just doesn't reside on their team. And so per, you know, outsourcing it and giving it to a vendor like Fusion off makes a lot more sense now than it used to, just given the complexity of security.
And so that's why we see so many of these engineering teams looking for third party solutions. Now, Brian Bell, are we at some sort of inflection point? And I'm asking the question because in the age of ai, people are saying, we're gonna develop more software in the next three years than we have in the last decade, and theoretically we're gonna have to authenticate people for all of this stuff, and it's just maybe gonna overwhelm us, Right?
Yeah, and I think that's absolutely true. I mean, you know, the ability to write software is changing, um, massively, uh, the ability to generate new code and to create apps. Um, and, and that will absolutely continue.
There will be more code written, there will be more apps built, and there will be, uh, a new generation of AI first applications being built within enterprises around the world. And as you do that, you need, you absolutely need authentication. And that's definitely gonna be tailwinds for this category overall.
And, you know, products like Fusion off were really built for this moment, right? Because it's incredibly flexible, it's developer first, it's easy to implement, um, and easy to get up and and running. And you're gonna see, uh, the ability for developers to, as they build apps, very easily integrate that authentication service into those new AI applications.
I think the other trend too that we're gonna see is the need to authenticate into agents that are being created right now, uh, around the world. And those agents, just like humans, will need to be authenticated and you'll need to know, you know, what the identity is and what access and what permissions do they have to do the work that we're asking them to do. Ryan Pelli for the uninitiated, how does Fusion off actually work?
And that's a great question. So this, the kind of the simplest getting started guide would be, you know, a developer downloads it, puts it on their laptop, nobody has a desktop anymore, um, puts it on their laptop, gets it up and running, and then they create what we call an application and that that's the thing that they're building, right? And so that's their app.
And, and then the simplest integration is that they leverage a standard, very likely, um, OAuth Open Id connect. And the way that that works is that their application redirects the browser over to Fusion off. Fusion off is where the user then logs in or registers.
Once they've done that, within Fusion off, we send the, um, the browser back to the application. And then there's this sort of, we, we call it the token exchange, but basically a little stitching in the back that allows the application to talk to Fusion off and make sure everything's hooked up. We generate a bunch of tokens, and then those tokens are what then represent the user in that application.
So whenever the app is calling APIs or doing work, um, you know, that the user is, is actively participating in clicking buttons, filling out forms, we use those tokens to then identify that user. And so that's sort of like the simplest form of getting someone logged into an app and then allowing them the application to identify who they are. Brian Bell, that sounds all very important, but it also sounds like maybe it's undifferentiated heavy lifting that is better left to you versus a lot of times I still talk to developers who are trying to manage this themselves.
Yeah, I absolutely, I mean, that is, that is where a lot of the opportunity is for Fusion au there is what we call greenfield opportunity, meaning you have development teams that, uh, often initially just think, Hey, let's build this ourselves, right? How hard could it be to build authentication? We can just build it ourselves.
And they start to do that, and maybe they get, uh, you know, an a a service up and running, and then they realize, wait a minute, why are we using our, our our, you know, uh, critical and talented engineering resources to build the service when there's a third party like Fusion Knot that can provide that service in a more secure and flexible way than than we could even build. And so often we're going in and either just going into an account where development team is looking for that service, or we're going in after they've tried to build it themselves and, and we replace, you know, that kind of homegrown offering that they started to build. Uh, that's a very, very common pattern that we see.
The other one is there might be multiple tools being used. They might start with some open source product or some, you know, DIY homegrown offering, um, maybe even a third party and they say, let's pick a standard that we wanna use across all of our applications to create a more seamless authentication experience for our customers. Brian Elli, you've been doing this a while and we've been talking about DevSecOps for just as long in the grand scheme of things are, are we making progress here?
It's, it, it, it feels like it's, you know, one step forward, two steps back sometimes. I, I think that's pretty accurate. Although, you know, with pass keys and within like the last 12 months, we've seen a pretty big adoption rate.
Like we went from I think like less than 1% to, you know, mid double digits. I think we're getting, you know, like 2030s getting closer to that 50% rate. Um, it's pretty rare now that you go to a newer application where they're not using PAs keys, right?
So I think that speaks volumes to where the vendors, you know, and tools like Fusion off are, are really pushing PAs keys and basically saying like, Hey, please use these, these improve your security by orders of magnitude by just clicking a single button and enabling this feature. Um, and, and developers are starting to do that, right? Banks are lagging, they always lag, they're always 20 years behind, but even some, you know, smaller, more modern banks are, are using passkey.
So I, I do think that the industry as a whole is, is, you know, is catching on and, and actually starting to do things the right way. Ryan Bell, how hard is it to get people to kinda wrap their heads around all this? 'cause I think part of the issue is just, I don't wanna say education as much as it is just inertia against this is the way we always did something and now I have to think about doing it differently and I got a thousand other things I'm thinking about doing differently.
Yeah, I think that's true. I mean, you know, this is a pattern I guess we've seen, you know, for decades as people think of the old way of doing thing, and, um, and sometimes they're not even aware. Part of it starts with awareness.
I mean, um, I, I think one thing that has one level of awareness that has increased is just the importance of having an offering and using, uh, creating an authentication service that is secure, right? Because there's still, uh, you know, quite a, uh, a lot of, um, you know, security issues that occur. You hear, read about them all the time, you know, passwords being stolen or, uh, stolen credentials of some sort.
Um, and, uh, authentication is, is core to solving that problem. And that awareness I think, is growing not only at, um, at the developer level, but certainly at the executive and board level as well. So I think that awareness is driving the need to look at, um, new offerings and new approaches to ensure that security is greater and that the developer experience and that the user experience is better as well as Brian just described with the PA keys, that's what's really, you know, driving the growth and I think leading to the change that we're seeing in this category.
Brian Elli last question to you. Are we gonna get rid of the password someday or not? Because, you know, we've been using passwords since the first caveman grunted who goes there?
Um, maybe, uh, I don't have a crystal ball, so I don't know. But the kicker is, is is like sort of the lost device problem. Like, you lose your phone, you get a new phone, all your pass keys still need to be sort of reattached to this new device.
And the way that you do that is with the password, right? And you have to log into something to then pull your pass keys out. Um, I know Apple and Google and Microsoft and like, there's a ton of people working to try and figure out how to remove passwords from the dev core device itself, but it's not a solved problem.
And so I, I think until the industry figures out a way to remove those at the operating system level, that fundamental level, uh, you're, you're gonna have a password, you gotta log into your laptop, you know, you gotta log into your Windows machine. You, you, you, you have to do that at some level. Eventually that might go away, but we're not there yet.
Right? Folks, you heard it here. Somebody once said doing the same thing over and over again and expecting a different result is less than sane.
That might be what we're seeing here with identity as well. Gentlemen, thank you for being on the show. Great.
Thank you. Thanks Michael. All right.
And back to you guys in the studio.