Identity for the Agentic AI Era
Identity used to stop at login. In the agentic AI era, it can’t. Peter Barker, Chief Product Officer at Ping Identity, joins Alan Shimel on Techstrong TV to break down what changes when every employee is suddenly running dozens or hundreds of agents — some long-lived, some ephemeral, many over-permissioned. Drawing on more than 20 years in identity, security, and mobile, and 8+ years leading product at Ping, Peter explains how the company is securing more than 8 billion accounts globally and why the trust control plane must now converge humans and agents under one governance model. He and Alan dig into Identity for AI, Ping’s end-to-end solution covering discovery, lifecycle, entitlements, certification, and runtime authentication and authorization of agents — plus Ping’s new AI-first headless platform that delivers Markdown-native docs, IDE plugins, CLIs, MCP servers, and pre-built skill files that cut agent token usage by 91% and operations by 70%.
Transcript
Hi, everyone. Welcome back here to Techstrong TV. I was talking to my next guest backstage before we came on, and Ping Identity is a company that I actually was in Colorado, I think, when Ping was first started.
It's got to be 2007, '08, in that range, maybe 2006. Those years start running together for me. But, unfortunately, I haven't really had an update with them recently, so I was really happy to see this gentleman on our calendar.
Let me introduce you to Peter Barker. Peter is the CPO, chief product officer, over at Ping Identity. Peter, how many Pings can Peter pick?
Peter, welcome to Techstrong TV. It's great to have you on here. Yeah.
Thanks, Alan. Really appreciate it. Glad to be here.
All righty. So Peter, I'm going to assume you weren't there back in 2006 or '07 or '08, whenever it was, when Ping first got started. But why don't you give people a sense of where you were and what your journey's been like.
Yeah. A couple of things. First of all, as you said exactly, Ping founded over 20 years ago by the founder and still CEO, Andre Durand, started out solving federation, identity federation challenges, but has grown and evolved massively since that time to be a full digital trust company.
And we are providing identity solutions to the world's largest enterprises and brands on the planet. We're securing over eight billion accounts globally now as a company. And our mission ultimately is to help bring digital trust to every moment of the journey in this world where so much is changing so rapidly, especially with AI.
And for me, I've been at the company now eight and a half years. I've led the product organization during that time. Very exciting times, and I would say even way more exciting now with the advent of AI agents.
And I've been doing product development now for over 20 years of my career. About half of that is in the space of identity and security, and the other half in mobile security. And then prior to that, I actually was in the IT function at multiple large companies, building systems that would do things like integrate identity and implementing those systems.
So just a long track record of being around this space. I love it. For me, I always thought of identity as the killer security app of the cloud era.
Right? Because we moved away from moats and castles into a cloud, and really the only kind of control that we had was the IAM, identity and access control. Access management.
And so to me, identity's been front and center for a long time. I completely agree. It used to be you controlled everything.
You controlled the workstation that people logged in on, you controlled the network they came in on, you controlled the environment they were connecting from because they were in physical offices. You controlled the data center where the apps rode. You controlled everything.
But all of that went out of the control of IT, and the one thing that IT still can control is the identity. And so it has become, it's a little bit cliché to say it, but identity being the new perimeter is really the way that that evolved. Yeah.
And then we were talking kind of off camera again about the identity. In some ways, the whole identity problem is like a balloon. First, we blew it up with the amount of people we had.
Then we blew it up exponentially when we started bringing IoT, OT devices onto it. Right? Where all of a sudden, we had billions more identities to manage, or we needed to be able to manage.
Then with the advent of cloud native architectures and so forth, where every single container and every little piece of your network needed its own identity, its own unique identifier, and corresponding access controls and so forth, access management. Again, that balloon got blown up even bigger, and just when we thought this balloon is as big as it could possibly get, along comes agentic AI. Right?
100%. And we're talking about, depending who you listen to, maybe there'll be 100 agents for every single person. Yeah.
Maybe more. Who knows? Yeah.
It's hard to say. And it's interesting too, because there's going to be different flavors of agents. There will be agents that are long-lived.
You're also- Yeah. Ephemeral versus, right- Ephemeral, right ... persistent.
Yeah. Yeah. Exactly.
But they're all going to need identity. If we're going to seek to manage them in this world that we live in. I was talking to a guy yesterday who's basically building like a Slack for agents.
Not a social network. We did that already with OpenClub. Yeah.
But, for these agents to talk to each other, to hand off one job, let me bring in the security agent from my developer agent to check the code I just developed. And so you're going to need, I got to know that this is really the security agent that I'm thinking it is, that I'm dealing with. It's just look, it's a question of scale, and so this balloon now gets blown up even bigger.
And for companies like Ping that sit at kind of the backbone, the intersection of all this, it's redefining the control plane. Yeah, you're hitting on a really, really key point. The control plane is the key word, and identity is a control plane.
It's a trust control plane at the end of the day. And agents introduce a series of risks. Some of those risks are the same kinds of risks we saw in other waves of identity, like you mentioned, IoT and OT, and just even human identity.
And some of the risks are new. If you look at just what's happening in the world of agentic AI is, it's board level, it's CEO level mandates for companies to transform and adopt and to go faster. And so you have a bunch of folks inside organizations who are out there just running ahead with agentic, and meanwhile you are creating a sprawl, potentially you're creating a risk surface that may not yet be under control.
And so that's going to be really important because over-permissioned agents, for example, may start acting well beyond their intended scope. Like a good meaning developer might give credentials to an agent to do one specific thing, but a very resourceful agent with those credentials may go do something completely different than was intended, is just- Absolutely ... and just one insight that we really help with our customers, talking to our customers about is, identity maybe historically, I know it's a simplification, but it sort of stopped at login, assessing all the risk signals and should I allow you access or not.
But when it comes to agents, we have to move the security boundary from login to the moment of decision or action that the agent is taking. And so that it's bringing in a much more even post-authentication continuous posture to ensure that these somewhat unpredictable actors are doing things that they should and hope, guarding against things that they shouldn't. I love it.
I think you hit the nail right on the head here. So let's get into it a little bit. I think we've defined the problem.
What are you guys proposing is the solution? Yeah, so at Ping Identity, we look at the opportunity in AI to help our customers ultimately embrace and adopt AI, but in a safe and a controlled and a governed manner. And so we have a very robust, rich solution that we call Identity for AI from Ping Identity, and that is a full lifecycle, everything from governance, which includes things like discovering, onboarding, managing, controlling, assigning entitlements and permissions, and ultimately certifying the agents in your environment on one hand, and on the other hand, providing runtime control in the way that we just talked about a minute ago.
So things like authentication and authorization of these agents accessing resources in the enterprise. And so this is a complete end-to-end solution that we offer to the market. And our customers are asking us to solve this for them.
And then one other thing, you mentioned the control plane, the trust control plane. We see that the trust control plane needs to be a converged control plane of not only agents, but also humans. Because what's important also around how agents work and interact is they need to be delegated to by a human owner, and they need to act under some sort of proper authority.
And so the control plane not only needs to understand the agents and everything they're supposed to be doing, but also the humans who control them, and then importantly, broker trust between those two worlds. And so that's our overall just simplistic way of describing a complete end-to-end identity and access management solution for agents, but also importantly, keeping those humans in the loop and part of that trust control plane picture. I love it.
This is available now, Peter, or something coming? No, it's all available now. We did our initial launch at RSA back in March.
Mm-hmm. We just did a big follow-on launch just a few weeks ago. And there was also something else we introduced outside of the solution itself, which is we are also transforming our platform itself to be agentic operable.
So think of it as a headless identity control plane, so that our customers now not only can leverage our platform to manage and secure agents in their environment, but also use agents to do that. To manage the platform. Exactly.
So you guys are kind of eating your own or drinking your own champagne, eating your own dog food, whatever you want to, however you want to characterize it, right? 100%, yes. Exactly.
And- I love it ... it's a really important evolution in terms of going headless. It's interesting, if you really think about it, I think a lot of platforms have been headless for a while in the sense that we've offered APIs, and- Yes ...
a lot of our customers have, a lot of the personas inside of our customers have been developers who programmatically interact with our platform via APIs. But what's different now is you've got these new actors being agents, and while agents are ... capable at interacting with APIs, it's not the most efficient way to enable them to interact with the platform.
It requires a lot more, and so that's part of what we launched is not just headless, because we've had APIs this entire time, but it's an AI-first headless approach that I could dig into more with you. Look, we've experimented here. So for instance, our web content management, we've moved from traditional WordPress to headless.
Mm-hmm. Though it's still the same back end for my editorial team to do editing and publishing. Oh, wow.
But the way the sites are designed and run, they weren't run in a headless environment because they're much more script-driven than they are HTML or CSS-driven. We see it with a lot of our other SaaS kind of stuff that we're working. The biggest problem we run into there, though, Peter, is not all APIs are so great.
Some APIs are good, and some, quite frankly, are crap. And such a limited range of what you can do via API that you have no choice but to still go through the interface. I think with agents, we have a way of redesigning that, right?
Because maybe it's not agent to API, maybe it's agent to agent, or use MCP. There's other protocols other than that, than the APIs that we can call in. You're hitting on a super key point, and there's even yet another factor as well, which is this whole concept of token maxing out there, where the cost of tokens is becoming a first-class concern.
Kind of like when cloud compute came on- First came out. Yep ... in Shadow IT.
Shadow IT, exactly. And so when earlier I said that what we've introduced is an AI-first headless approach, we were being very intentional with those words because we're addressing some of the points you've just raised. Number one, not all APIs are created equal.
And an agent is certainly capable of reading documentation and trying to determine a plan of action to interact with APIs. But wouldn't it be far more efficient if we made agent-first interfaces that they are far more efficient at interfacing with? And it starts with the documentation.
So the first thing we've done is we've taken all of our product documentation, and we treat our documentation as a product that has its own pipeline, just like software, and we're now publishing it in markdown format, which is super agent-friendly. And that sounds simple, but it costs 91% less tokens for an agent to read our document- And that's huge ... in markdown than reading our website, and that's massive and far more efficient.
And then you have to introduce things like plug-ins to the IDEs that developers use. You need to have CLIs, which is where agents are pretty comfortable using and tend to be more efficient than things like APIs. And then finally, MCP servers and all of the tools that they expose.
But then there's one other thing. So those are those, I'll call it agent-first interfaces that are necessary- Mm-hmm ... to really make it easier for these agents and cheaper for these agents to get the job done.
But the final thing you have to layer on top of that is: what about the skills that the agents need so that they don't have to go relearn every time they come to your product how to do everything? And so that's the other thing we're doing as well, is introducing all of those agent-first interfaces, and then also publishing the skill files that you can insert into your- That you can ingest ... plug-in.
Yeah. And that makes it far more efficient as well. So we've also measured the token efficiency of that approach, and by doing that, we have reduced operations by over 70% as well by- I love it ...
by doing that. And so this is what we meant by AI-first headless. Because, again, people interacting with platforms programmatically, it's not necessarily new.
But this is a way to do it that gets to a much better outcome for everybody. I love it. Like I said, we've been through a bit of our own experiments and experiences.
Sounds like you really understand the issues, and you got it going on, and it's not pie in the sky. It's out there now. Peter, for people who want to get more information, because our time's almost up, what's their best-- Obviously, go to Ping Identity, but what's their best kind of path, route here?
Yeah. com. You can tell your agent to go research Ping as well.
Get it for you. All right. It'll do it for you.
We invest a lot in making sure that agents themselves can get that information and summarize it for you. Of course, we have things like our documentation and what have you. But yeah, there's some great resources out there for folks.
I love it. Peter, I want to thank you for coming up here on Techstrong TV with us. Please don't be a stranger.
Keep us posted. Best of luck with what you're doing. We'll check back in soon, okay?
Appreciate it, Alan. Really a pleasure to be here. My pleasure.
Peter Barker, CPO, Ping Identity, here on Techstrong TV. Hey, we're going to take a break here. We're going to be back.
We've got a lot more on today. Stay tuned.