Episode
Who Governs Your AI Agents? Identity, Offboarding & Open Standards
- Podcast
- Cloud Security Podcast
- Published
- Jul 2, 2026
- Duration seconds
- 2082
- Processing state
not_requested
Actions
POST https://stenobird.com/v1/public/podcasts/cloud-security-podcast-612345/episodes/who-governs-your-ai-agents-identity-offboarding-open-standards/transcription-requests
Idempotently request low-priority transcript generation for this episode.GET https://stenobird.com/podcast/cloud-security-podcast-612345/who-governs-your-ai-agents-identity-offboarding-open-standards.md
Read the agent-friendly Markdown representation of this episode resource.
Summary
Are overprivileged AI agents the biggest emerging threat in cybersecurity? In a recent high-profile attack, a vibe-coding company had its entire source code stolen because an attacker exploited a long-lived, overprivileged token tied to a third-party AI agent. In this episode, Ashish sits down with Ely Kahn, CPO at Okta, to unpack the challenge of managing Non-Human Identities (NHI) in the AI era. Ely explains why traditional, static human permissions completely break down when applied to autonomous agents. To solve this, Okta has spearheaded Cross-App Access (XAA), an extension of OAuth that uses an Identity Assertion Grant (ID JAG). This open protocol, backed by 25+ partners, including Anthropic, XAA securely passes the baton between apps without annoying consent pop-ups or dangerous static API keys. We also explore the four maturity levels of agent authorization, ranging from broad API keys to the ultimate "North Star" of intent-based security. Learn the difference between SPIFFE (for internal cryptographic identity) and XAA (for downstream resource authorization), how the Linux Foundation is building an Agent Domain System, and why every CISO needs an immediate "kill switch" for rogue AI agents. Guest Socials - Ely's Linkedin Podcast Twitter - @CloudSecPod …