# Mastering agent permissions and Identiverse interviews - Amir Ofek, Howard Ting, Ajay Gupta, Sandy Bird - ESW #466 Page: https://stenobird.com/podcast/security-weekly-podcast-network-video-841420/mastering-agent-permissions-and-identiverse-interviews-amir-ofek-howard-ting-ajay-gupta-sandy-bird-esw-466 Text version: https://stenobird.com/podcast/security-weekly-podcast-network-video-841420/mastering-agent-permissions-and-identiverse-interviews-amir-ofek-howard-ting-ajay-gupta-sandy-bird-esw-466.md Podcast: [Security Weekly Podcast Network (Video)](https://stenobird.com/podcast/security-weekly-podcast-network-video-841420) Published: 2026-07-06T09:00:00+00:00 Episode link: https://securityweeklytv.libsyn.com/mastering-agent-permissions-and-identiverse-interviews-amir-ofek-howard-ting-ajay-gupta-sandy-bird-esw-466 Audio file: https://dts.podtrac.com/redirect.mp3/traffic.libsyn.com/secure/securityweeklytv/ESW_466_1--0d2305c1-0677-4782-83eb-aa9e2327b7d7--sd-converted--da613b34-0fa6-40e2-bac5-917276dadb79.mp4?dest-id=292819 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/security-weekly-podcast-network-video-841420/episodes/mastering-agent-permissions-and-identiverse-interviews-amir-ofek-howard-ting-ajay-gupta-sandy-bird-esw-466 Duration seconds: 4659 ## Resource Interview with Sandy Bird, co-founder of Sonrai Security In this week's interview, we kick off the conversation with how Sonrai's expertise in securing cloud identity permissions had the company well placed to address the explosion of AI agents and the clear risks they represented. On the surface, this looks like a cloud/hyperscaler permissions challenge, but it isn't that simple. As agents like Claude Code, Codex, and Hermes are connected to enterprise cloud agents, the risk spreads outside VPCs and onto endpoints. Check out the episode to learn more about some of the most common risks Sandy finds and how Sonrai goes about addressing them. This segment is sponsored by Sonrai Security. Visit https://securityweekly.com/sonrai to learn more about them! Segment Resources AWS Bedrock agent permissions: what you need to lock down before you go live Making Enterprise AI Agents Accountable with Amir Ofek, CEO and Co-Founder of aizome Organizations looking to unlock the power of Enterprise AI Agents, and in a controlled and safe way at the speed of AI. Identity is at the heart of it. However, NHI Governance Is Not Enough for Enterprise AI Agents. The identity industry has responded to the rise of AI agents the same way it responds to every new identity challenge: extend existing frameworks. Map agents to human owners. Enforce least privilege. Govern them like non-human identities. It is a reasonable instinct. It is also insufficient in ways that matter enormously. Non-human identity security was built for a deterministic world - service accounts, API keys, bots. These identities do what they are configured to do. Their behavior is predictable enough that static governance models work. Enterprise AI agents are categorically different. Not in degree - in kind. They don't execute… ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/security-weekly-podcast-network-video-841420/episodes/mastering-agent-permissions-and-identiverse-interviews-amir-ofek-howard-ting-ajay-gupta-sandy-bird-esw-466/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/security-weekly-podcast-network-video-841420/mastering-agent-permissions-and-identiverse-interviews-amir-ofek-howard-ting-ajay-gupta-sandy-bird-esw-466.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.