95. AI Tooling is Causing Identity Security Issues Presented by 1Password – Tech Field Day Podcast Spotlight
The rise of AI tooling and agents in the enterprise has created a gap with identity security platforms. Addressing that gap remains challenging when so much is still unclear about how users and agents interact. In this episode of the Tech Field Day podcast, brought to you by 1Password, Tom Hollingsworth is joined by Kate Scarcella, Jack Poller, and Sanjay Ramnath of 1Password.
The panel discusses the shift from client-server models to the new agentic landscape. They talk about the challenges of tracking activity and how static credential management is unable to keep up. They also talk about the need for business to lead the change in IT and enable security to keep up with the current velocity of features. They also discuss how there needs to be a shift in the way that companies develop and apply security policy to users, both physical and digital.
Transcript
The world of AI is changing the way that we see work being done, but is it also going to change the way that we do security for all of that new AI specifically around identity? In this episode of the Tech Field Day podcast, AI Tooling is causing identity security issues. Welcome to the Tech Field Day podcast, where we bring together a group of IT technical experts to discuss a single idea about key concepts in the industry.
This podcast features a variety of perspectives from the members of the Tech Field Day delegate community, and is often associated with one of our events. Tech Field Day is a part of the Future Futureum Group, and this podcast is published on our sister company site at Textron tv. On this episode, which is brought to you by one password, we're going to be discussing AI and identity security.
But before we get to that, I'd like to take a moment for our guests to introduce themselves so you know who you'll be listening to, starting with Kate. Hi, my name is Kate Ce. I've been in cybersecurity for over 20 years.
I presently am a chairperson for the CD Foundation, um, cybersecurity Special Interest Group. I'm Jack Poller, I'm principal analyst with Paradigm Technica, covering the intersection of AI identity and data security. My name is Sanjay Ramnath.
I am the Vice President of Product and Solutions Marketing here at One Password. I've spent a little over a couple two decades in cybersecurity having run product teams, and prior to that, um, I cut my teeth as an, uh, engineer writing code, uh, for chip design. Um, super excited to be here.
Alright, thank you all for joining us. Let's jump into the premise for today's episode. No doubt that you have already started to experiment with ai.
Maybe you are asking some simple questions of an LLM or you've graduated to more complicated topics like building your own agent to do things for you. But no matter what you do, you should keep security at the front of your mind because as we've seen in 2026, there have been a lot of challenges when it comes to security and not just from securing things, but the way that different security paradigms integrate with each other and quite honestly, make it difficult to know what's what. In this episode of the Tech Field Day podcast, AI tooling complicates identity security.
So I wanna kind of throw this out here because one of the things that we've seen as people have started adopting AI in their daily workflows, whether it's through testing or through adopting it to do their actual job, is that they sometimes forget that a lot of their AI build outs involve the person who's doing it. If you are an individual knowledge worker with a certain security posture, that limits the blast radius in case you do something you're not supposed to. Whereas if you are a senior system administrator and you have root access over servers and the agent has your same, uh, access capabilities, it might be able to cause more problems than you might otherwise think.
Why is it so complicated for us to understand how identity security translates over to this new world of ai? Well, Tom, I'll, I'll take a stab at that. That one of the big differences up until today, up until now, everything we've done in it has been premised on a user interacting as essentially a client server model.
A user server talks to a com compute set of computers and requests some action to be done. And that's a well understood, you know, we had 60 years of understanding that, started out with passwords, got figured out, passwords weren't secure, went to something more secure like MFA, et cetera. But it's all premised on that, that one behavior.
With the introduction of ai, particularly with agentic AI agents operating on your behalf, the line gets blurred both about who, how an activity is initiated and who is initiating that activity. And that activity is initiated by an entity on behalf of an actual user, or maybe not on behalf of an actual user, maybe on behalf of another entity. So now we have things that are, that are happening in the background without our explicit, uh, activity, initiating an action, and it becomes very hard to chase is the agent doing something on its own, or is it doing something on behalf of somebody else?
And that the agent spots multiple agents, multiple agents, and it becomes very hard to chain all of that activity going forward. So that that part of it complicates things a lot. Yeah, and just to add to that, Tom, I I, I think that the, the fundamental shift that AI and agent AI brings to identity models is that it's not just a question of securing credentials or securing access or authenticating users anymore.
It's a question of securing trust, right? Uh, the future of work is not gonna be centralized. It's not gonna be static.
Um, you don't provision a user an identity and then authorize them to perform a set of actions over the lifetime of a session or, or a workflow. And, and those privileges remain, remain static, and, uh, and they carry that with them. Uh, agents operate very differently.
They're, uh, non-deterministic. Uh, they don't authenticate the same way as humans do. Um, and all of this is happening at machine scale.
So really in this new world, the question is about how do you secure trust? How do you trust what the agents do? How do you really know what agents are even running in your environment in the first place?
How do you authorize them to do just what they're allowed to do? And then make sure you control those authorization permissions, uh, on a continuous basis so you don't over provision over these agents. Uh, and then ultimately, how do you audit and observe the behavior?
How do you explain the behavior? How do you create the right auditable, um, uh, events and and so on? And, and this is really what causes this fundamental shift in the identity security stack or identity security models, because, um, identity is not gonna stop just at login with, with AI and with agents.
It has to be evaluated every time access is used, and authority has, is exercised when the credentials are used, when secrets are used, not when the sessions are created, and you have to establish distrust when this access happens. So it's a fundamental change in how we think about the identity operating model. I, I would agree with you, Sanjay, because one of the problems that we run into is people believe that if something is authorized or should be capable of performing a task, then it will always be able to perform that task and it will never change, and there'll never be anything that could potentially change the status quo, which anyone listening to this podcast is violently checking their head right now, because we've seen that being repeated over and over again.
And something as simple as the NPM mod model where we have, you know, these pluggable modules and packages out there, that one of them might be purchased by a third party that has ill intentions, but because we previously authorized that NPM to run on our system, oh, well, we should just trust it from here on out. We, the in, in effect, the asset's identity has changed, even if the name is still the same. And that's one of the things that we have to remind everyone is if the same NPM is requesting the same resources over and over again, there's a reason to trust it, but as soon as it starts requesting things that it hasn't normally requested before, that should be an identity change.
And, you know, when, think about any sci-fi movie you've ever watched, it's like suddenly if you start behaving weird, something's wrong. And we, we need to figure out why have you been replaced by Agent Smith or something like that? And you're talking about moving to behavior model as a, as right at the end of the day.
And that really becomes important because machines are gonna behave differently than humans, and especially when they start accessing, you know, tokens and, and you know, is it persistent? And so it's nice to hear that you guys are looking at the behavior. Yeah, that, that's correct.
I, I think, I think looking at the behavior is one way of, of, of putting it, for sure. Um, and it, it's not, it's not just the behavior, it's all the way from, um, make a step back. The way I would, I would characterize the, the operating model in the agentic world is, um, you know, first you need to discover, you need to understand what ex exactly is happening on your network and your environment, um, especially at the edge of the business because, um, you know, the, the agent adoption will start at the end point.
It'll start with your developers adopting, uh, co-pilots to, to write code. Um, and, um, the first step is even knowing, okay, these are the agents that are actually running in the environment. Um, and then making sure that that visibility can be translated to the right guardrails and the right governance, knowing what credentials those agents are using, knowing what permissions they're being, um, provisioned with, uh, to operate and the workflows they're integrated into.
So that's the second step is how do you secure the agents once you've discovered them and give them the right guardrails and the right permissions and broker the right set of credentials, um, in a scoped manner, right? So they don't, are, again, not, not going rogue, uh, and doing things they're not supposed to do, or carrying forward permissions and privileges that are not supposed to have after the task is completed. Um, and then the third step is really being able to audit and being able to track behavior and being able to observe, uh, in, on a continuous basis, knowing what the agents are doing and being able to correct the governance posture policies based on the, the visibility and that, and observability.
So it's almost like a continuum of sorts, and you're right, behavior is at the core of, um, of the continuum. So something, something you said, uh, that you and Tom said sort of lead me, uh, around the concept of trust, and you brought up trust early on, Sanjay, and I think one of the things we're sort of dancing around is this concept of we used to understand the behavior of an application. Tom's example was NPMs, right?
A module that you've installed or you've installed, just a simple application that's gonna make database queries. We understand it, it's well scoped, well understood. So when you install that application, you can go ahead and look at it and say, I understand it, I can put guardrails around it, and if it steps out these guard steps outside the guardrails, I can then say something's wrong, right?
The science fiction character has gone crazy, hasn't been replaced, but AgTech AI behaves differently in that it doesn't have a well understood behavior profile because it's not limited in scope or actions, and it's non-deterministic. So it's very hard early on to be, to put those types of guardrails on. So we wanna change that concept of putting guardrails around it.
And, and also, you know, you talked a little bit about understanding visibility of what, what things are happening out there. The, the world is now moving so fast and agents spawning other agents and creating their own task profiles that we can't keep up with it. We can't have pre, pre for, for knowledge and whitelist blacklist type environments to look at what agents are doing.
So I think what we're saying is instead of trying to identify the agents, try to identify the users and the agents having an identity and being another form of a user and authorizing them for specific actions with limited scope at limited points in time, which is really sort of bringing that whole concept of zero trust in to apply that everywhere, starting with identities and whether it's ais and agents or other applications, we really have to get back to this concept of we have an entity that's trying to access data and take action based on that data, and should it be allowed to do that or not? Regardless of what type of application it is, it's really, is it authorized at this particular moment in time to do this activity? Yeah, that, that's correct.
I, I think the one, uh, maybe nuance I would add to that is the non-determinism or the non probabilistic nature of agents is also a superpower in a way, right? Because that's what you want agents to do. You want them to be adaptable, you want them to perform tasks based on, um, environments and, and conditions that they can learn from.
Um, and from a security standpoint, um, you know, from a, at least a one password ethos is really to help our, our customers, uh, safely embrace the future. Um, without looking at this more as a, hey, it's a, it's a threat, or it's, it's not a dom and gloom scenario, I think a AI can be powerful if harness properly. Um, so really the question is how does security models evolve?
Um, how does the technology stack evolve so we can adapt the models, adapt the technology, adapt the way we configure policies and roles and provision identities and track behavior and things like that to this new world where you have agents operating, um, on behalf of humans, um, at machine scale, uh, and operating in that more adaptive, uh, environment. So it's really about empowering the business to harness the power in a safe and secure manner as opposed to, um, managing the fear that, hey, you have, you know, rogue agents and swamps of agents that are just gonna, you know, go wild and, and do things they're not supposed to, uh, supposed to do. I think it's an important distinction, it's a nuanced distinction, but, uh, the conversation should be one of enablement rather than one of fear.
And I think it's important that you bring up this whole enablement versus fear discussion, because one of the problems that tends to grow out of this particular dichotomy is what happens when users meet friction in the real world. Because time and time again, we have seen users will tend to avoid the friction instead of trying to fix the problem, saying, oh, well, the reason why my efforts to do this aren't as good as anybody else's is because, you know, there's all these extra security controls in place, or you've mandated that we're gonna use this particular AI platform instead of that one, but I really prefer the one that's installed on my laptop. You, you don't typically hear, let's, let's try to resolve this security policy, so that won't be a problem.
Instead, what you usually see is, oh, well, I, I just did what I wanted to do anyway, and, and I went around it. And, and we've seen that happen quite a bit recently, where people are like, oh, well, I'm just gonna download this program and it's not corporate approved, but that's okay, I'm just gonna test it out. And then a couple of days later, what you find out is that, you know, oh, well now it's, it's going out and it's requesting information on my behalf and doing all of these things.
And the people that work in the corporate risk department are like, we shouldn't be doing this. This wasn't on the approved list. How can organizations work together with their users to allow them to work at the speed they want to, while also continuing to protect the things that they know really shouldn't be uploaded to the public internet or introduced into these models that could potentially cause exposure later?
Yeah, the, the, the term that comes to mind, um, Tom, uh, and we, we use it a lot and it's, it's part of our DNA is that security should be about making the easy thing, the secure thing, right? So if you, if you make the easy way of doing things, also the secure way of doing things, then naturally you have a, uh, alignment across, um, the security requirements and the business requirements. And that's, it's not easy.
It's, it's, it's, uh, I recognize as a security, um, uh, vendor that we always run into this friction where, um, security teams want to, to buy in, in, in, in, it's the right thing to do. You have to be paranoid if you're, because there is, uh, a lot of bad stuff out there. Um, but what that ends up translating to is, um, a set of, of, uh, rules and policies and a model really that starts constraining business velocity.
Uh, and when security starts constraining business velocity, the business almost always wins. Um, developers need to write and ship code faster, and you need to operate the business faster, especially in this world where, um, SAS is the norm, um, browsers at the front door of work, um, people are allowed to use their own devices, um, on, on enterprise networks. Um, so you need speed and you need to kind of maintain that, that competitive edge.
So the challenge that security practitioners have is how do we make sure that we do this, um, in a secure way? How do we empower the business to move with velocity? How do we empower developers to move velocity?
How do we empower users to, um, find and adopt the tools they need to, to operate and do their best creative, innovative work, uh, but make sure there's the right set of guardrails around it. So, um, you know, moving security closer to the business, closer to the edge where work really happens, and this is massively amplified by ai, as you can, you can imagine, um, AI is all about empowering, um, users to, uh, create this parallel workforce of sorts that, that massively accelerates their ability to do productive work. So now really the question for security is, um, you know, how do you, uh, how do you build the right framework to empower and enable the business to move with the velocity we call this business led?
It. Um, and that's gonna really come from, uh, moving the controls, um, and the discovery and the auditability, um, to the point where work really happens. The old model where everything was centralized, where your identity registries were centralized, your policies were centralized, your authentication systems happened in one place, and the users were only allowed to do what the centralized system allowed them to do, uh, is gone.
That's, that's not gonna survive. It's, it's already broken. With SaaS and with ai, it's gonna be obliterated to the point where you have to move the identity model, the security model, to a place where, um, the, the, the users are empowered, um, to, to do their best work.
And your CIO and Cs CISO is empowered to say yes rather than say no. That's the model of the future. So you're talking about velocity and speed and everything else, um, in order to not basically be the no, right, we don't want cybersecurity to always be the no.
So how are you gonna for, for ci, cd and automation pipelines, which is, you know, something that ideal with, how do you prevent AI assisted pipelines from becoming these secret brokers? Yeah, yeah. So, so one of the, the, um, use cases that we've been helping customers with is, uh, managing, uh, developer secrets and, um, environment files and, and, uh, artifacts of that nature, um, and enabling them to utilize those credentials and secrets, um, in a secure manner.
Um, so an example is, um, today we have developers that use our enterprise vault, uh, to store, um, SSH Keys store, API keys store secrets and tokens and environment files, uh, in a way that makes it super easy to integrate into their ci cd pipelines, into their ID environments. We've also integrated into, uh, AI development environments now, like cursor and, and so on. So, uh, so that's an example where, um, using our vaulting capability and then having the, the guardrails that are built around, uh, our ability to, to provision those credentials and also govern how those credentials are used in development pipelines, we're able to enable developers to continue building with velocity, continue adopting the tools they need at the endpoints to build with velocity at the same time, provision secrets and keys and tokens and environment files, uh, and also share, uh, those types of artifacts in, in a very secure manner.
Does, does that, does that answer the question, Kate? Well, I think my, my, my one question though is, um, doesn't that then, aren't we then talking about static and then doesn't static then how do you cut off the access, like, you know, the whole thing with AI and, and security for the, for agents, isn't it important to only have like a time of use moving forward? Yes, Exactly.
So that, that's really where the policy framework around all of this will evolve. And that's, that's some of the ideas we're working on right now is around how do you provide scoped access to those credentials? And this scope could have multiple dimensions.
It could be time-based, it could be role-based, it could be based on the resources they're trying to access. It could be based on the environment it's working on. Um, so it's really a multidimensional problem when it comes to scoping credentials, access.
Absolutely. Right. Uh, that's gonna be a critical, uh, aspect of, uh, how we provision, uh, AI agents or agent development, uh, and not just development even, you know, agents that are operating outside of developer environments.
How do you provide them the right information and the credentials they need and the secrets they need in that scope malor? And I think if, if I remember correctly, um, one password, you have a a pretty nice user interface when it comes to governance, right? And, and will that basically translate to AI agents?
I mean, is that, I'm not saying it's easy for you guys, but is that gonna be something that you look at within the interface that you can easily identify the AI agents and the whole scope of work so that things are done within a single pool glass? That's correct. Yeah, that's, that's correct.
I, I, I think, um, you know, if, if you, if you step back in time and look at one password's history, um, we built, um, tools, um, for, for users, um, and there were secure tools, but ultimately it was all about making things easy for users, uh, to secure their digital identities and their digital lives. Uh, and that, uh, that thread will, you know, carry through everything that we build as we build tools for enterprise. As we get into agent ai, um, that's a northstar that we hold ourselves to is let's make sure that this is super easy, not just for the administrators, not just from a control and a policy standpoint, but it should be super easy for, um, ultimately for the users to embrace it.
Uh, now an example there is, um, you know, one of the, the capabilities we have in our, in our identity stack is the ability to add device context, um, as a dimension, um, uh, of trust, right? So when, when there's an access request, making sure that we govern that request, not just based on identity, um, or the resource being requested, but also make sure the device from where the request is made is compliant. Um, and, uh, when you find non-compliance, uh, you wanna make it easy for the user to remedy that.
So we provide guidance, we provide, um, you know, a quick way for the user to self-correct that and get back on track without having to file an IT ticket and without having to wait for a few days for somebody to respond to it. Uh, they just fix the problem and they move on. So those are the kind of of things that we would wanna carry on, um, through the agent AI workflows, through developer workflows, is to make it super easy, not just to identify where the security gaps exist, but also make sure that we provide enough information and context to the users themselves so they can, they can remediate and, and, and correct, at the same time, providing the administrators with the visibility they need to apply those guardrails and, and tune, tune the policy.
So that balancing act is gonna be really important. So Sanjay, one of, one of the things that you brought up a little bit earlier in the conversation was the, the world of centralized identity store is basically over. And it's funny because, you know, 2, 3, 4 years ago when I was talking about this, we would always talk about how we had many silos of identity, and that that's, that was a challenge, and the centralized tools were the solution to that challenge, right?
Bring everything under one roof and then you can control it better. And I think what you're saying, which I agree with, is that the modern way of working, particularly with AI and agent AI, is you and with developers, what Kate's talking about with CSCD stack and needing to have access to so many different things simultaneously, programmatic access is you need to be able to have and work with silos of identity. And so you need to enable that type of framework instead of saying it doesn't work, bring everything under a central roof when you have, um, you know, anywhere from 40 times to a thousand times more non-human identities as human identities.
And we probably get even more than that now. It becomes untenable to try to have a central repository of all those identities as well as the associated secrets and API secrets and stuff like that. It's just not manageable in that fashion.
So I think I'm very enamored with the one password approach was just saying, how do we enable silos of identity and how do we control access while still having silos of identity and enable that to become an enabler of the business rather than a blocker of the business? Yeah, a a, absolutely, I, I, I think there is, there is a place, um, for, uh, for the centralized control plane, if you, if you'll, right, uh, there are things that, that make sense to, to centralize. For example, I think, uh, visibility is something that, that belongs in, in that centralized control plane.
Um, auditability is something that belongs in that centralized control plane. But then when you think about, um, authorization and authentication and enforcement of policies and governance, those are some of the aspects that need to start moving out of that kind of centralized, siloed approach and start moving closer and closer to where the work actually happens, where the access requests are actually made. So you can do this on a more continuous basis as opposed to having a, a static set of policies that are enforced statically, uh, in a centralized manner, because that just breaks the entire model.
Uh, you cannot do that in this, in this new world where you have, um, the actual actions are moving away from, from the center of the business and moving closer and closer to the users and the endpoints and, and that's where work actually happens. And then don't we actually go back to the original, you know, these behavior indicators. I mean, isn't there definitely a difference between behavior, um, from a machine and how you can see it and how it can act and as opposed to human?
Yeah, No, absolutely. And, and that's one of the, um, uh, things that I, I believe one password is in a, in a really good position to, um, uh, to act on because, um, we have, um, uh, a tremendous scale and presence on endpoints today. We started our journey as, uh, credentials vault as a, as a password manager.
Uh, and that by definition is, uh, securing credentials for users or users securing their own credentials at the end point. Um, and now if you translate that to what you just said, Kate, which is behavior, um, one of the important aspects of, of discovering and understanding behavior is knowing what's happening at the end point. You need signals.
You need to know what your users are doing, what they're accessing, what credentials are being used, how they're being used, where they're being used, what they're being used for. Um, and being able to get those signals, uh, is a very important part of, of, uh, building that kinda identity security continuum we talked about as we push it more and more to the edge of the business. Um, so spot on, right?
Um, being able to get those different signals, identity, application usage and credential and device signals even, and then using those signals to build the identity model and applying that to the security model is gonna be really important going forward. And I think we're, we're pretty well positioned to do that. And, and I, I totally agree with that.
Um, and I think you guys are, and don't you then start to look at, um, time-based versus intent-based? Like, doesn't that come as a part of your conversation? Yes, yes.
It'll, I mean, I think that's, uh, you know, going back to the, the question that you asked earlier about scoping and, and just in time provisioning, I think those are all components that, uh, we're gonna have to like, uh, start looking at, um, as we build, build this model and build this framework. Um, and it starts with getting signals. It starts with the presence at the endpoint.
And then once we have that, and, and I believe you're kind of already there, um, we can build a, a, a number of different dimensions of scope and dimensions of, of control if you'll around those signals. And those could be intent based, this could be time-based, that could be environment based, it could be based on identity, it could be based on the resource that's being accessed. All those will factor in, you're absolutely right, intent and time would be important components of that.
So as You can tell, the new world of AI tools have shifted the way that we think about doing work, but it shouldn't just do that. It should shift the way that we think about security and the way that we look at our new digital coworkers and how they are going to be performing their roles. Because one of the things we don't want to do is let the business leave security behind in order to be more enabled, because that's how we end up having more issues to solve than we initially started with.
And we need to have a good understanding of how all of those pieces come together so we can create the right policy, the right procedures, and the right protections in order to keep everyone safe and secure and doing things that they need to be doing. This episode is brought to you by one password, and I know that one password has been working very hard on solving a lot of these challenges. Sanjay, if people wanna learn more about some of the solutions that you've come up with, where can they go to see that?
com. There is a wealth of information on our website. Um, if you're a developer, we also have a dedicated section on our website.
It's one password com slash developers. Uh, and there's a bunch of tools for developers. You can, um, uh, download the tools.
You can, I can, you can try the, the vaulting capabilities. There's guides on integrating our tools within developer pipelines and so on. So those are the two resources I would, I would start with.
We've also published, um, some, some interesting thought provoking blog articles, uh, around AI and agent AI problem. Uh, those would be good, uh, good readings as well. So, uh, so yeah, that's where I would, I would stop.
Alright, well thank you very much to everyone for listening to this episode of the Tech Field Day podcast. If you enjoyed this discussion, please do us a favor, subscribe on YouTube or in your favorite podcast application of choice, so you don't miss this episode or any of our other ones. We'd also love it if you'd leave us a rating, a review, and possibly a comment on what you thought about this episode, because those all help our show grow.
This podcast was brought to you by Tech Field Day, the home of IT experts from across the enterprise, which is a part of the Futurum Group. com/podcast or check us out on Techstrong tv. Thank you very much for listening and we'll hope to see you next week.