This episode features Sarah Cecchetti, Director of Product Management at Semperis.
A veteran identity executive, Sarah co-founded IDPro and co-authored NIST SP 800-63-3C Digital Identity Guidelines. She previously led Amazon Cognito as Head of Product at AWS, where she also open-sourced Cedar, the policy language at the center of this conversation.
In this episode, Sarah presents her Bsides Seattle talk "Identity Crisis: IAM's Wild Ride in the AI Jungle" on why the assumptions that shaped modern identity have been overturned by the pace of agentic AI. She covers where authentication and authorization standards currently fall short for non-human identities and walks through the emerging frameworks the industry is building to fill that gap.
This episode makes the case that natural language safety instructions are not a substitute for provable, external guardrails.
Guest Bio
Sarah Cecchetti is a seasoned technology executive driving product management at Semperis. At AWS, she led Amazon Cognito to triple-digit growth as Head of Product and led the open-sourcing of Cedar, a new access management language. She co-founded IDPro and co-authored NIST SP 800-63-3C Digital Identity Guidelines. Sarah has designed secure identity systems for corporate clients as well as US and Canadian governments and is recognized as a top identity professional by Okta Ventures and OWI. She’s a keynote speaker at global identity conferences like Identiverse and Authenticate.
Guest Quote
“[The] average enterprise has 250,000 non-human identities, and 97% of those have excessive privilege. And 68% of organizations lack AI identity controls...The concept of excessive privilege has almost been accepted by the industry at this point. That's just the way it's done.”
Time stamps
01:45 Meet Sarah Cecchetti: Seasoned Identity Executive
02:36 Sarah’s Bsides Seattle Talk: Identity Crisis: IAM's Wild Ride in the AI Jungle
04:19 How Deepfakes Broke Biometrics
06:37 The Scale of Non-Human Identities
09:34 How NHIs Differ from Human Identities
10:38 Why FIDO Doesn't Work for AI Agents
12:19 Introducing SPIFFE and Workload Identity
15:45 How SPIFFE Works in Practice
17:34 Where AI Protocols Are Falling Short
21:12 The Problem with OAuth Client Credentials
23:18 Dynamic Registration and Database Sprawl
24:38 Client ID Metadata Documents Explained
28:43 Authentication Standards: Who Wins the Client ID Field?
30:21 Cedar: Deterministic Authorization for AI Agents
33:58 Clawdrey Hepburn: Sarah's AI Agent in Practice
40:09 Conclusion and Final Thoughts
Sponsor
The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world’s leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.
Links
OAuth Client ID Metadata Document
Connect with Sarah on LinkedIn
Connect with Sean on LinkedIn
Don't miss future episodes
Learn more about Semperis