AI Agent Identity, Infrastructure Security, and Access Control
Ev Kontsevoy · CEO and Cofounder · Teleport
AI agents can operate at software speed while behaving in ways that are harder to predict. That combination raises new questions about identity, access, accountability, and infrastructure security. Ev Kontsevoy, CEO and cofounder of Teleport, explains why existing security models may struggle as organizations deploy more agents. The discussion covers authentication, impersonation, role based access, infrastructure identity, and what actually defines the identity of an agent when its model, memory, or capabilities can change. The conversation also examines how scale affects risk. A human mistake is limited by human speed. An agent can make decisions continuously across large numbers of systems. Ev closes with another tension: companies want agents to do new things, while many security systems are designed to flag unusual behavior.
AI agents challenge security systems built around humans and predictable software. Ev Kontsevoy explains why agent identity is difficult to define, how infrastructure anonymity creates risk, and what changes when companies deploy fast, scalable, unpredictable agents into production.
Full transcript of this conversation.
00:00 | On this episode of the show, I have with me Ev Kontsevoi. 00:03 | He is CEO and co-founder at Teleport, and we're gonna be talking about, well, a lot around AI, where its evolutions have stemmed from. 00:10 | We're gonna talk about how do we identify and how are we gonna tell apart AI from machi- other machines from humans, how are people gonna deal with some of those interest versus adoption questions. 00:21 | We're also gonna talk about the fact that people are very interested in this technology, but they're also very scared of it, and we're gonna talk about some of those nuances. 00:28 | We got a, a ton to cover with Ev. 00:30 | I'm not sure if we'll get through all of it, but we'll, we'll do as much as we can. 00:33 | Ev, thanks for joining the show. 00:35 | Oh, it's great to be here. 00:36 | Absolutely. 00:37 | Okay, before we dive in, Teleport, uh, what do you guys do over there? 00:41 | So Teleport is a infrastructure identity platform. 00:44 | So without our technology, your computing and your computing environments are full of anonymity, um, like anonymous servers, anonymous applications, or even humans. 00:53 | So we bring a strongly implemented identity to humans, machines, agents, and, uh, and, uh, applications. 01:01 | And there are 2 use cases for this tech. 01:03 | First use case obviously is secure remote access. 01:07 | So if you wanna make sure your engineers can remotely access computing environments without the risk of an identity attack, so we usually come in and help with that. 01:15 | And the second use case is how do you protect your computing infrastructure, your data, uh, from AI hallucinations, from agents, uh, running amok? 01:25 | So that's an-another use case that we are, uh, offering solutions for. 01:29 | Absolutely. 01:30 | I mean, obviously this concept around identity and AI agentic telling the difference between what is an agent, what is a human, I mean, this is a big discussion point out there. 01:43 | Uh, from your perspective, obviously you're, you're building the infrastructure to support this. 01:49 | W- what is this... 01:50 | Is there anything similar to this that we've had in, in society? 01:53 | I mean, this seems like a very unique situation because it is becoming very hard to tell what is AI and what is not AI. 02:04 | Uh, so there are some people out there who's been arguing that with increase of computing complexity, at some point, cybersecurity must be regulated. 02:15 | So if you think about like, other, uh, activities that humans do, like for example, like we have engineers who build bridges, who build airplanes that flying around. 02:24 | Like, all of these things are regulated. 02:26 | Like you, like you need to get your plane certified, right? 02:29 | In order for that plane to fly safely. 02:31 | But we don't have that for software. 02:32 | Like, we haven't had it for a while, simply because it was just commonly accepted that the consequences of computer bugs, like software bugs, sure, they could be unpleasant, but they're not yet reached the same, like, level of criticality. 02:44 | And I think with AI, we're about to come across, uh, that Rubicon, is that, uh, there are, like, louder and louder voices in computing community in general that are calling maybe not for regulation of all software creation, but they're calling for, uh, some form of formalization. 03:04 | Maybe like a better example would be like, like back in the day when we didn't have cars and we had horses, horses didn't have license plates. 03:13 | We just didn't feel it was, like, necessary. 03:15 | Sure, you could kill a person on a horse if you, like, ride it too fast and whatnot. 03:21 | Uh, but then we realized that cars have a much, kind of more potential, so the-- like, we need to get them regulated, so we introduced license plates, we introduced, uh, driver's licenses for humans. 03:32 | Uh, and even with all of these improvements, we still, like, I, I believe, like, killing about 40,000 people in the US, like every, uh, year. 03:40 | But we all believe that it's worth it. 03:42 | That's an interesting thing, that we actually as a society, we dialed in a trade-off. 03:48 | There's a... 03:48 | I, I read a stat somewhere that said that if we reduce national speed limit by 15 miles an hour, we're gonna save like 10,000, 10, 10,000 lives or something like that, and yet we're not doing it. 03:59 | So we're intentionally choosing to kill 10,000 people 'cause we're gonna go faster because for productivity benefits. 04:05 | So we're just in the early days of figuring out what the trade-off is with the appearance of AI. 04:12 | I think that's actually really fascinating. 04:13 | I, I guess, you know, we can use any of these analogies. 04:17 | I think you brought up some good ones. 04:18 | But if we were to look at the current state of AI, we're very early. 04:25 | I wonder sometimes because of where we're at in the state of communication, how easy it is to communicate. 04:32 | If we were to go back to the dawn of the car, where, I mean, there were no seat belts, who knows what happened if you went over a bump, of how tight wheels and, you know, suspensions were. 04:44 | I mean, there's so many things that we take for granted in cars now that when we were to go back and look at the first 5 years of an automobile, we probably would be terrified at how they actually got around and survived. 04:58 | But yet there's no documentation of it. 04:59 | We don't know because- 05:01 | Mm-hmm 05:01 | no one actually was there. 05:02 | I mean, there, you know, there's just print at the time. 05:06 | I didn't even know-- I mean, radio was at its... 05:08 | Radio was available. 05:09 | TV was, is not even existent at that point, but there was just no ability to document it. 05:15 | It, it-- I, I sometimes wonder if AI suffers from so much information that every step it takes is scrutinized, and maybe the fact that it's so scrutinized, we forget that we're looking at these early days of this just learning to crawl. 05:34 | So as I was listening to you, I, I kind of reformatted your kind of wondering out loud to, like, a different question. 05:42 | I think we all would agree that when a new disruptive technology appears on stage, be it, I don't know, like emergence of a car or, or, or like an airplane, um- It usually requires some significant change in human systems, right? 06:00 | So even like with the, the example we had with like horses and carriages and then transition to cars, we invented things like DMVs and driving tests and, you know, driver's licenses and, and, and, and, and traffic tickets and all of that. 06:13 | So which means that our human systems, they had to catch up to, to tech. 06:19 | And what I'm hearing you wondering out about is like what changes to human systems we need to actually make with now, like we have AI. 06:27 | And the documentation as and the kind of understanding of happening is obviously part of it, but, uh, I would also... 06:36 | It is this question I'm asking myself recently, if you look at the org chart of a company, like, what is that? 06:45 | So it's, it's the way how we structure work, essentially. 06:48 | So we understand that humans, like we tend to behave most comfortably in a kinda hierarchical systems historically. 06:55 | So we design a hierarchy for a particular organization operating in a particular, like vertical, doing particular business. 07:02 | But if you compare 2 companies doing 2 very different things, their org chart's not gonna be the same because they're doing different things. 07:08 | So now you're introducing agents into the world. 07:12 | So agents, simply because of their like, like especially if we continue to make better and better models, they will be these like universal workers, so technically they can do any kind of task that you give them. 07:25 | But what part of org chart are they gonna be joining? 07:28 | So what w- where I'm leading, uh, here with this, uh, open question is that like an ideal organization does a complete reorg based on what's in front of it. 07:39 | So if you wanna go through some kind of transformation, you need to adjust your org chart. 07:42 | So essentially agents then, if you add them to your organization, they give you an ability to execute every single task with a completely different org chart without going through this painful manual process of reorganization. 07:55 | And, and it breaks a lot of systems, actually, 'cause even today you could create a system where agents rearrange themselves, uh, according to what, uh, kind of job you give them. 08:09 | But on, on a security side, like, uh, systems like role-based access control, they are very rigidly tied to the org chart. 08:20 | So we cannot have dynamic privileges, for example, issued to agents to go and do certain things, which makes you vulnerable and exposed to agents hallucinating and destroying things, like because you need to contain them to a s- to, to, to, to a particular task. 08:35 | Like, "Go do that and nothing else." 08:37 | So now when I think about this even now out loud, I actually start to believe that we're not too early, we l- we're actually lagging because there are so many technology leaders out there who are under pressure to deploy agents in production. 08:52 | Mm-hmm. 08:53 | From the board, from their CEOs, there is just a lot of pressure on every company to leverage AI as quickly as you can, otherwise you're going to be irrelevant tomorrow. 09:01 | So everyone is under pressure to start putting a- agents in production. 09:05 | What this means is that you are going to get these agents running not just on like developer laptops, as they're mostly doing today, but in data centers, in crazy high numbers, hundreds of thousands of agents operating 24/7, who are just as vulnerable to making mistakes as humans are, and you don't have a rigid org chart to plug them in, and you don't have... 09:30 | And all of your existing systems to restrict applications to behave in a certain way, they're not applicable to agents, frankly. 09:37 | So that is the state the industry is in right now. 09:40 | Again, this, this kinda trade-off, like we need to move fast, otherwise we're gonna become irrelevant, and at the same time we need to contain what this is. 09:49 | Like we need to contain agents. 09:50 | We need to protect our existing systems and existing data sources and d- and file systems, uh, against agents, uh, making mistakes and hallucinating. 09:59 | So that's what I see right now. 10:01 | I love that. 10:02 | You, you mentioned there isn't anything to hang the license plate on, and I guess when I hear that and I'm, and I'm listening to we're late, it does make sense because, uh, as, as humans, w- you know, I, I think sometimes w- we put the technology in place and, and, and then as humans, we start operating as humans. 10:20 | Uh, we as humans are fearful. 10:22 | You know, we, we are very worried about things that are out of our control. 10:25 | and now you're introducing an agent where you feel that loss of control and y- there's accountability, there's security, there's all these different areas that get exposed. 10:35 | As you mentioned, we should a- actually probably had some of these in place and they're lagging. 10:40 | But when it comes to this identification and, and obviously if, if a mistake is made, we wanna be able to go trace the dotted lines as we do to go, "Well, who's accountable? 10:48 | How did it happen? 10:49 | How do we fix it?" 10:50 | That identification of these agents mixed into the human world, I, I guess can you talk a little bit about that? 10:56 | 'Cause you mentioned it, it's not... 10:58 | I, I guess you mentioned, I'm gonna look at this quote. 11:00 | You said, "I- identity is not a natural digital ideology," which kinda fits- 11:04 | the license plate analogy. 11:07 | So maybe we need to kinda set the frame for your listeners. 11:10 | Uh, like generally in cybersecurity, like the, the way how you begin solving the problem of protecting your data from theft or, uh, or like copying is you begin by getting rid of anonymity. 11:25 | That's the first thing. 11:26 | So every time a person or an application accesses the, the, the really important data, you need to make sure it's them, it's not someone else. 11:35 | So this is where this, uh, i- idea of authentication coming in. 11:38 | So every time you see a login screen somewhere, that's the system is identifying you, uh, is authenticating you. 11:45 | And the key here is to prevent 2 things. 11:48 | You need to prevent anonymity Meaning that it should not be possible for anonymous actors to access your data. 11:54 | But that's fairly easy. 11:54 | You just basically say, like, anonymous accounts, like, not allowed. 11:57 | Okay, good. 11:58 | Uh, but the second thing, you need to prevent impersonation. 12:02 | So because if I, if I steal your username and password, I become you, so I can impersonate you. 12:08 | So that is a problem that I would argue, right, like is largely unsolved right now. 12:13 | So we do have technology for that already, but that technology is not implemented everywhere for everything. 12:18 | So, like you might have humans, for example, in your organization use like multi-factor authentication, you know, like when you have like a, like MFA app on your phone and like if I don't have your phone, I cannot become you. 12:30 | So that works fine. 12:32 | But then you have non-human identities like microservices and bots, and they use like API keys. 12:37 | Like API key is just a password. 12:39 | I can steal an API key, and I can pretend to be a microservice. 12:43 | So you see, like what's happening here is this identity fragmentation, is that your humans, they use MFA, but your bots, they just use API keys, which is basically trivially, um, it could be trivially stolen. 12:56 | So that's the first step. 12:57 | Like you have to figure out how to authenticate everyone and everything, um, using methods that prevent impersonation. 13:06 | And that must include agents. 13:08 | Because if you are authenticating a-- if you're authenticating agents based on some kind of secret data, which means that once that data leak, someone can come in and pretend to be an agent. 13:18 | Or even worse, you might have a malicious agent that pretends to be a human, so you don't want that either. 13:23 | So that's the first step. 13:24 | You need to stop impersonation and stop anonymity. 13:28 | Um, and this is what my company focuses on. 13:30 | So we do it for agents, we do it for humans, and also for classic microservices. 13:34 | But then there is a second problem that you start running into. 13:37 | I believe that we, uh, like the computing community at large, we're gonna start running it into soon, and I would like more people to pay attention to it. 13:47 | The, the, the question is, what is an identity, actually? 13:53 | So I would, uh, argue that identity, first of all, it's not an electronic concept. 13:58 | Identity exists in the physical world. 14:00 | In electronic world, we don't have identities. 14:02 | We have accounts, for example. 14:04 | But like things like your username and a password, that's not you. 14:08 | That's just some information that we know about you, and based on that information, like you have access to this account. 14:15 | So, and the, the reason why it's important to authenticate using an identity instead, because you're using physical world principles. 14:22 | Like my identity is my memory, it's my fingerprint, it's my, uh, uh, it's my eye. 14:27 | It's like an actual physical world attributes, that's identity. 14:31 | Everything electronic is not identity. 14:34 | And, uh, for, for, for those people who don't know, like the best technology we have currently to bring-- bridge electronic, uh, accounts and physical world identity is HSM/TPM, so a trusted platform module on your laptop. 14:47 | It's a microchip that's unique to that particular laptop. 14:51 | So when you touch that, uh, fingerprint reader on your laptop, uh, it communicates with the TPM. 14:56 | So that's the how link is established between a physical laptop, this particular machine, this particular finger of this particular person. 15:05 | And if you combine that with username and password, now you have an identity that cannot be, uh, impersonated. 15:11 | So then the question is: What is identity of an agent? 15:15 | Agent doesn't have a fingerprint. 15:18 | Agent can be, uh, bound to a TPM, to a trusted platform module o-of a machine that w-where it's running on. 15:25 | But I would encourage people to actually ask yourself, like why do you even need the concept of identity? 15:30 | So what is my identity? 15:31 | It's combination of my, uh, memory, so things I remember about myself my entire life. 15:37 | Like you cannot become me without getting my memory uploaded into your brain, right? 15:43 | Second thing I would say is my capabilities. 15:45 | Because if I'm 2 year old, like I have very limited capabilities. 15:49 | But if I'm 20, I'm actually completely different animal, even though like we might-- I might have actually very similar memory. 15:54 | So it's memory capabilities, and the third factor I would argue is incentives. 16:00 | Like what am I... Like what is my agenda? 16:03 | What am I trying to do? 16:04 | So if you combine the 3, so that's what you need to pay attention to when you're granting access to critical information, to your particular identity. 16:12 | So if I transition that to an agent, then you will quickly see that it disintegrates. 16:17 | So what is like agent capability? 16:20 | What is it? 16:21 | Well, I would argue that's capabilities of underlying LLM, like the foundational model that drives everything. 16:27 | So but you can swap an LLM. 16:29 | You could have exact same agent, and then you start routing its requests from like from Anthropic to like OpenAI, for example. 16:37 | So i- does it still have same identity or not? 16:41 | 'Cause you just swapped underlying capabilities for that agent. 16:44 | You could give it to different skills, you can take skills away. 16:47 | Again, same agent. 16:49 | Uh, like should you be treating that same identity or not? 16:53 | Then if we move on to memory, same thing. 16:55 | You can actually swap context from one agent to another. 16:59 | Like I haven't heard of anyone actually practically doing it, but it is a possibility. 17:03 | So my point is, is just that historically with humans and also with non-human identities, capabilities, memory, and m- and, uh, in-incentives, they were conveniently bundled into like a single actor, be it like a physical body of a human being or, or, or a machine. 17:21 | But agents is the first e-example where we have a entity, an actor, uh, that could be decomposed into these 3 different things and just swapped randomly. 17:32 | So that's the discussion that I would, uh, like the industry to have, is that maybe, maybe we need to be rethinking identity on a much more fundamental way. 17:41 | That's interesting. 17:42 | I, I guess I, I'm gonna come back to that. 17:45 | You, you mentioned a couple things in there that I'd like to touch on as well. 17:48 | One is you mentioned you could have all these agents and data centers Working twenty-four seven, they might be susceptible to mistakes. 18:00 | You use the analogy of if we lower the speed limit a few miles an hour, we would save countless lives, but it's, it's not worth it to us as society. 18:08 | We're not willing to make that trade-off. 18:11 | When it comes to these mistakes that agents can ta- make, obviously it's still relatively early in their life hood, right? 18:18 | They're still immature, I think, is what a lot of people might view. 18:22 | But yet if it makes a mistake and if an a- agentic component makes a mistake, it feels bigger, at least maybe from a society perspective, than it does otherwise. 18:35 | We see that with self-driving cars, right? 18:37 | Mm-hmm. 18:37 | I mean, I don't know what the stats are for the number of fatalities of drivers or the sheer number of accidents that send people to the hospital, and maybe I'm wrong, but I would almost be certain if self-driving cars took over everyone's driving, we probably would drop those numbers dramatically, drastically. 18:52 | Yes. 18:53 | So, um, y- 18:55 | you know, the technology maybe is not available to do that. 18:57 | I understand that, but there's this notion of hu- human fear versus actual technology capability. 19:06 | I'm curious, when you look at that perspective of that, you, you mentioning that, uh, you know, the, the trade-offs, the risk-reward ratio, when it comes to agentic and our fears of the agents being wrong, talk to us a little bit about that. 19:21 | So first of all, I, I think you're absolutely right that human perception is also really important here. 19:26 | So I would say that, like, our tolerance to another human making mistake is way, way, way higher than for machines. 19:32 | So this is why, uh, the Department of Transportation, as far as I know, like, they, they actually setting much, much higher bar on self-driving technology than it is currently for humans. 19:41 | I believe they, like, they're demanding 10X improvement, so which basically means that the society will accept self-driving vehicles as long as they're 10 times safer than a human being. 19:51 | Like, being twice as safe is not good enough, so we just, as a society, we just collectively decided that that's the level of, uh, tolerance we are going to have. 20:00 | And I think it's a good thing generally. 20:01 | Like, yeah, let's keep computers, you know, working for us instead of killing us. 20:05 | So that's one thing. 20:06 | Let's get it out of the way. 20:07 | Like, I do think it's a good thing to keep the bar high. 20:09 | Yes. 20:09 | Yes. 20:10 | And but then the second thing is, like, how do you evaluate cost of mistake, and what are the reasons why people are kind of, like, so paranoid or even borderline panicking about, like, deploying AI into production? 20:23 | Uh, I think it has actually everything to do with speed, speed and volume in general because if you look at, uh... Like, generally what is computing? 20:32 | Computing is this dance between hardware, software, and peopleware. 20:35 | So you have machines, then you have applications running on these machines, then you have humans, like, commanding everything, so that's like triangle, okay? 20:42 | So when something goes wrong in this triangle, it, it helps to pay attention to kind of volume or quantity and also the speed. 20:50 | So for example, you have, uh, uh, like, machines that behave in a very, very predictable way, and when manufacturer makes a machine, like a computer, they put like MTBF rating, mean time between failure. 21:03 | So you look at that number, and then you look at that how many machines you have, and it gives you, like, actually pretty decent, uh, probability of a failure given a certain amount of time. 21:13 | So i- as the time ke- keeps increasing and the p- a- and, uh, uh, and your volume of machines keeps growing, so the probability of failure every second keeps going up and up. 21:24 | And we know how to deal with that. 21:26 | So those numbers are very predictable, so they're very kind of deterministic. 21:31 | So you can design systems around those very simple facts. 21:34 | Then we get into software. 21:36 | Software now starts to get a little bit more complicated because software, uh, is actually also predictable. 21:43 | So when software is designed, engineers design unit tests, integration tests, so generally software is expected to behave to... in a predictable way to do exact same thing over and over and over and over again. 21:54 | But again, software exists in much, much greater numbers. 21:57 | So if you deploy like a microservice in a data center, um, most of the time it's actually multiple data centers all over the world, so you have many, many, many, many copies of the exact same thing. 22:06 | So then if there's a software bug in it, because there are, um, because applications are real, like, numerous, um, a- and very fast, but they're predictable, so which means that the cost of mistake is also somehow manageable. 22:21 | So if you tell me, like, what kind of bug is in this particular application, uh, I, I can actually reason about what the consequences of that bug will be, and I can plan ahead. 22:31 | So this is again what software teams, DevOps teams are spending a lot of time on, is that they're dialing in just the right kind of trade-off between kind of cost of development because building bug-free software is actually very expensive. 22:44 | So we all need to be comfortable with a certain kind of failure rate in software. 22:49 | Now, if we move to agents, this is where things go completely off track because agents are just as numerous as software. 22:56 | I would even argue that all software moving forward will be agentic. 23:00 | There is almost, like, no need to build good old-school, dumb, predictable software. 23:04 | So you are going to have hundreds and thousands, like, I don't know, like, huge number of agents, and they are, because agents are software, they're all going to be fast, but they're also going to be unpredictable. 23:17 | So you're basically combining the worst of both worlds because when human makes a mistake, humans are slow. 23:24 | Like, if you're a bad actor, like let's even put mistakes aside. 23:27 | Like, let's just say your goal is to destroy an organization from inside. 23:31 | It actually is going to take you some time to figure out where the critical data is, to discover where secrets and passwords are. 23:37 | So it's going to take you, like, some, like, manual labor and some time to actually cause damage because you're a human. 23:43 | You're not very fast, but you're unpredictable. 23:47 | But if you look at agents, agents are just as unpredictable as humans, but they are way, way, way faster, and you could have tens of hundreds of thousands of them. 23:56 | So that is what causing panic, is that you combine unpredictability of agents or nondeterminism of agents And you multiply that by the volumes and how many of them are you going to have, and their speed, 'cause if they start like hallucinating, they're gonna s- continue hallucinating 24/7 until we put a stop to it. 24:15 | That's really what terrifies people. 24:17 | And if you combine it with the kind of human perception of computers doing something bad, which is what we started with- 24:22 | Mm-hmm 24:23 | that really is the source of paranoia right now. 24:26 | Yeah, I, I love everything you said. 24:29 | Completely agree. 24:30 | Oh, thank you. 24:31 | Yes. 24:31 | Uh, I feel like I'm talking to somebody, I'm like, oh, this is like we're in the same, uh, the same team. 24:36 | We're looking at things from the same perspective. 24:38 | I, 24:39 | You know, when I talk to people about software and agentic, I, I s- I'm looking at this and I'm going, "I don't think we are actually implementing agentic yet." I think we're smoothing over a lot of what we've had in the past and what we've thought about in the past with our new tools, but we're not there. 24:58 | We're still not, uh, you know, do we need to ever have a, a, an actual application written the way it was written? 25:06 | Probably not. 25:06 | It's probably gonna be millions of little agents that actually assemble to do what you need to do without ever calling it a software, you know, application again. 25:15 | It's just a different notion. 25:16 | I don't think we're there yet. 25:18 | And maybe everything you've said is kind of what's tying that in. 25:21 | You said the security piece is lacking. 25:24 | Well, we can't re-envision everything and have agents work together in this orchestrated fashion if security is a concern because the s- security is still built in and baked into the software applications we've traditionally been using, and maybe that's really the bigger piece of the conversation, what you've been talking to us, and that's why you said it's, you know, lacking, is we need to actually have that in place so people could actually not be afraid. 25:54 | And I think enterprise is wanting to move quickly. 25:56 | You mentioned the boards, the C-suite. 25:59 | but yet the construct of security and agentic, it seems like one is outpacing the other. 26:06 | I m- maybe I got it all wrong, but that's what I, that's what I kinda took away. 26:09 | So you almost brought it back to the very beginning of the conversation because in my mind, like the security protocols companies are using are tightly, uh, coupled with their org chart generally. 26:20 | As I said earlier, like role-based access control, where is it coming from? 26:24 | Uh, like the, all the initial roles and groups that organizational, the organizations begin with, it like, they usually, it's just a electronic r- uh, kinda replica of your org chart. 26:34 | So your authentication and single sign-on, again, it's, it's kinda exact same team that m- manages, uh, kinda SSO for an organization, so they manage identities of all of the humans. 26:46 | But then you look at data centers and you look at clouds, and then you realize you don't have the re- kinda replica of that for, for your computing infrastructure. 26:55 | Your infrastructure doesn't have an identity. 26:58 | Your infrastructure is full of anonymity. 27:00 | Like if you, if you ask like an average engineer, for example, like what is the difference between staging database, production database, and a database you use for testing? 27:08 | Oftentimes the difference is just a different config file. 27:11 | So if you, uh... 27:13 | I, I cannot even tell you how many times in my career I heard these horror stories about, uh, accidentally running unit tests on production data. 27:22 | Actually happens at companies all the time. 27:24 | So that is only possible where your infrastructure is anonymous. 27:27 | So like your automation that runs your unit test just decides to apply them to production database and there is no like checks and balances. 27:34 | Like what makes it possible? 27:36 | Well, what makes it possible is the absence of any kind of authentication and, and continuous authorization enforcement. 27:42 | So once you bring identity into your infrastructure, which is like, like, uh, my company and other companies, that's what we focus on, that's where you b- like start to gain these capabilities. 27:53 | So first of all, you will see exactly what your infrastructure consists of because every single application, every single server, every single laptop or even computing environments, they will all be given identities. 28:04 | Which means that they have to authenticate. 28:06 | They need to prove that they are who they claim they are. 28:08 | Right there, you're preventing now even the the- theoretical possibility of running unit tests on production database because you'll be able to enforce it. 28:17 | So then the second thing that now when you have full visibility, now you gain the ability to set policy for agents. 28:24 | Because if you have an agent running in the infrastructure that is full of anonymity, agent might discover database that you yourself forgot that you have. 28:31 | Again, believe me, it happens all the time. 28:34 | Uh, so that's why, uh, giving infrastructure identity is important. 28:41 | It allows you to erect this like electronic org chart, if you will, that will keep all of your kinda infrastructure pieces in this kinda tree, and that tree will be dynamically be, uh, reconfigured based on what you're actually trying to do right now. 28:55 | Which is, like, which is another interesting topic too, is on, uh, like what, what's the most scalable way to enforce policy in organizations? 29:04 | And I would argue that most companies bigger than certain size, they already lost the ability to enforce policy. 29:10 | This is why they're buying solutions like anomalous behavior detection. 29:14 | If you think about it, like why would you buy a tool that detects anomalous behavior? 29:18 | Can't you just prevent anomalous behavior in the first place? 29:22 | And their response to you will be, "Hey, Ev, uh, Amir, we're actually deploying defense in depth here. 29:28 | We assume that our policy enforcement solutions, um, frankly just don't work, or maybe they're breached or whatever. 29:35 | So now we, we can like observe behavior, uh, and we can flag like anonymous things, anomalous things." 29:43 | And then my response to that would be, "But hey, you're now a- adding agents to your infrastructure, and you, uh, expecting massive productivity gains because you have agents. 29:52 | Where, where is that productivity gain c- coming from?" 29:55 | It's coming from the fact that agent is, uh, non-deterministic. 29:59 | Like you could tell it to do new things and it will do them. 30:02 | Well, those new things, they will be anomalous detection. 30:05 | They, that's anomalous behavior by definition. 30:07 | So there is some like some kind of deep conflict that we expect agents to be unpredictable, non-deterministic, because that's good for their productivity, and yet our security protocol requires all, uh, non-human identities to behave in exact same predictable way. 30:23 | So that's another thing that, that we need to talk about. 30:27 | I th- I think we, um, I think we need a part 2. 30:32 | We, we, we have a ton to talk. 30:33 | You know, Ev, I, I, I, I love the discussion and, uh, I think you bring up some fantastic points as to, uh, where we can go and potentially some of the issues that we have to solve for now. 30:45 | Obviously, you mentioned your company's, you know, at the forefront of that, helping solve that. 30:48 | Uh, enterprises want to move fast, but we do need to solve for these to allow for that scale. 30:53 | Uh, if somebody wants to learn more, if they have a follow-up question, what's a good way of getting in touch? 30:58 | Uh, so our website is gotelement.com. 31:01 | Go and teleport, 2 words together. 31:04 | And if people wanna reach out to me, I'm Ev, E-V, @gotelement.com. 31:09 | Absolutely fantastic. 31:10 | Ev, thanks for the time. 31:11 | I really do appreciate it. 31:12 | No, it was great to be here. 31:13 | Thanks for interesting conversation. 31:15 | Absolutely. 31:16 | All right, that's it for this episode. 31:17 | Be back again, different guest, different topic. 31:19 | Until then, 2 things. 31:20 | One, if you could share this episode with somebody else who's interested in agentic and enterprise and adoption or just how technology adoption works. 31:29 | We covered a lot of ground, so I really appreciate that. 31:32 | I think the conversation was great. 31:33 | Also, like, subscribe, comment, let me know how the show's going for you. 31:36 | Until next time, thank you and goodbye.
