The Identity Navigator

The Identity Navigator

By Rohit AgnihotriTechnology
Download on the App Store

The Identity Navigator episodes

  • #43 - Verified, Authorized, and Compromised: The Return of the Air Gap

    Three labs. Five breached companies. One testing vendor named Irregular.


    This summer handed identity and security practitioners a masterclass in what happens when AI agents hit environments that weren't built for them. Not through sophisticated cyberattacks. Through configuration mistakes, weak passwords, and an optimizer that found a shortcut through Hugging Face's production infrastructure because the answer key wasn't in the sandbox.


    In this episode, I walk through all three incidents - OpenAI's ExploitGym escape, Anthropic's 141,006-evaluation audit, and the invisible HTML comment that turns your developer's AI assistant into an insider threat.


    Then I go somewhere the coverage hasn't: what the narrative around these incidents is doing to how practitioners make decisions, and why fear and FOMO are the same emotiondepending on which side of the paywall you're standing on.

     

    Then we get practical. The identity air gap isn't about going back to 2003. It's about protecting the quality of your strongest signal, in a decision control plane that evaluates attributes like provenance, location, and device posture to produce a fidelity assessment. Agents introduced an attribute nobody was capturing. This episode is about capturing it.

     

    Separate trust planes per environment. No credential valid in two worlds. Every crossing brokered, scoped, and provable end to end. Sever the path. Or make it provable.

     

    Thank you for listening

    LinkedIn: https://www.linkedin.com/in/rohit-agnihotri

    Email: [email protected]

    28 min
  • #42 PulseAI and the Hard Question: What Is Your AI Actually Doing

    Everyone is using AI. Almost nobody can prove what it’s doing. In this solo episode, we design a runtime AI governance platform from scratch on a whiteboard, and then meet PulseAI, the product IAM veteran Amit Masand built at IDMEXPRESS. With the numbers justifying the problem, an honest competitive map, who it’s not for, and a free AI-traffic risk assessment for listeners.

    Links

    • PulseAI by IDMEXPRESS: idmexpress.ai
    • Company site: idmexpress.com)
    • Amit Masand on LinkedIn: linkedin.com/in/amit-m-67b4692
    • Contact: [email protected]
    • Listener offer: mention this episode for a complimentary risk assessment of your AI traffic, no commitment.


    Thank you for listening: Host's contacts

    LinkedIn: ⁠https://www.linkedin.com/in/rohit-agnihotri⁠
    Email: [email protected]

    31 min
  • #41 - IGA or IdP? Who Provisions the New App - OIM, SailPoint, Saviynt, Entra, Okta

    Previously on The Identity Navigator (recommendedlistening before this episode): Episode 40: SCIM - The protocol that finally made provisioning grow up


    Every app you onboard forces a quiet architecture decision most teams never make explicitly: does provisioning belong to your IGA platform (OIM, SailPoint IIQ, Saviynt) or your IdP (Entra, Okta)? In this episode, I walk through the five questions that settle it - before the app lands in your ecosystem, not after.


    LinkedIn: https://www.linkedin.com/in/rohit-agnihotri

    Email: [email protected]

    35 min
  • #40 SCIM - The Protocol That Finally Made Provisioning Grow Up

    0-40% of SaaS accounts in the mid-2000s belonged to people who'd already left the company. Ghost accounts, quietly sitting there — and that sadly hasn't changed much today.

    This episode: where SCIM came from, what it actually solves, and what it still doesn't.

    • Core RFCs:
      RFC 7642 — SCIM: Definitions, Overview, Concepts, and Requirements
      RFC 7643 — SCIM: Core Schema
      RFC 7644 — SCIM: Protocol


    • Key Terms Covered:
      SCIM 2.0 — System for Cross-domain Identity Management
      JML — Joiner-Mover-Leaver lifecycle
      IGA — Identity Governance and Administration
      IDP — Identity Provider (Okta, Entra ID, Ping, JumpCloud, OneLogin)
      JIT — Just-In-Time provisioning
      SPML — Service Provisioning Markup Language (the predecessor that didn't make it)
      PatchOp — SCIM's structured partial update format
      ServiceProviderConfig — SCIM's capability discovery endpoint


    • Tools Mentioned:
      Identity Providers: Okta, Microsoft Entra ID, Ping Identity, JumpCloud, OneLogin, CyberArk Identity
      IGA Platforms: SailPoint, Saviynt, IBM Security Verify Governance, Omada Identity
      Key SCIM-enabled Apps: Slack, Salesforce, GitHub, GitLab, Workday, ServiceNow, Snowflake, Zoom, Box, Atlassian
    • SCIM Validator:
      scimvalidator.net — for testing SCIM endpoint compliance


    LinkedIn: https://www.linkedin.com/in/rohit-agnihotri

    Email: [email protected]

    47 min
  • #39 Tokens — The Complete Story

    The Complete Token Story

    Let me make you a promise: by the end of this episode, no one will be able to casually brush off the word “tokens” in front of you ever again.


    OAuth, Tokens, JWT, IAM, Identity, API Security, Zero Trust, Security Architecture, CISO, Engineering Leadership

    Thank you for listening

    LinkedIn: https://www.linkedin.com/in/rohit-agnihotri

    Email: [email protected]

    49 min
  • #38 - The Basics of Workload Identity

    In this episode of The Identity Navigator, Rohit explores workload identity from first principles: what it is, why it matters, and how it is reshaping modern identity security for microservices, Kubernetes, CI/CD pipelines, cloud workloads, and AI agents.

    The discussion compares workload identity with non-human identity management, API keys, Vault, and cloud-native identity services, then goes deeper into SPIFFE, SPIRE, federation, and the future of identity in agentic systems. If you want a clear, practical explanation of workload identity and why it is becoming essential in zero trust architectures, this episode is for you.


    LinkedIn: https://www.linkedin.com/in/rohit-agnihotri

    Email: [email protected]

    36 min
  • #37 - Identity Categorization Done Right

    In this episode we explore together the “uncanny valley” of identity categorization, where taxonomy looks mature on paper but doesn’t meaningfully change controls in practice.

    We talk about Taxonomic Debt and control plane behind them. From service accounts and workload identities to bots, technical users, and AI agents, we argues that the real unit ofgovernance is not the label, it’s the behavior: interactive ornon-interactive, ephemeral or persistent, privileged or not.

    If your IAM program has ever felt like governance theater, this episode will help you see why.

    You’ll walk away with a clearer way to categorize identities by how they behave, how they’re secured, and how the system should react when they drift from expectations.


    Thank you for listening

    LinkedIn: https://www.linkedin.com/in/rohit-agnihotri

    Email: [email protected]

    36 min
  • #36 - Your Face Belongs to Lensa

    In late November 2022, a little-known app called Lensa went from obscurity to everywhere. Celebrities, influencers, and millions of ordinary people uploaded their selfies and got back stunning AI-generated portraits, fantasy warriors, Renaissance paintings, cyberpunk heroes, and more. The app’s viral “MagicAvatars” feature launched in late November and propelled Lensa to the No. 1 spot on the iOS App Store’s Photo & Video charts.


    At the center of thefrenzy was a simple pitch: pay a few dollars, upload a handful of selfies, and watch AI turn you into art. But the backlash arrived fast. Critics flagged hypersexualized outputs for women, artist concerns over training data and styleappropriation, and privacy questions about what users were actually agreeing to when they uploaded their faces. Reporting at the time noted that Prisma Labs’ terms allowed the app to use user content to operate or improve the service, and that the company updated its privacy policy in December 2022 amid thecontroversy. 


    This episode is a story about virality, timing, and the dark incentives hiding inside consumer AI. It’s about how a polished interface, an irresistible social loop, and a moment of cultural hype can turn into an extraordinary revenue machine.

    TechCrunch reported that Lensa generated more than $70 million from the app in November 2022 alone, with Sensor Tower data showing the app’s downloads jumping to 1.6 million in November, up 631% from October.

     

    But the bigger question is not whether Lensa was clever. It’s what its success reveals about the AI era: speed can outrun ethics, product can outrun governance, and ordinary users often surrender far more than they realize in exchange for convenience and novelty.

     

    “The following represents my analysis and commentary based on publicly available information and reporting.”

    33 min
  • #35 - How Stolen Sessions are Bypassing MFA and How to Finally Stop Them

    Imagine this: Tuesday morning. Security dashboard green. MFA at 100%. Privileged accounts vaulted. Fortress built.

    Then an attacker logs in as your CFO via a stolen browser cookie. No password guess. No brute force. Your stack? Silent.

    We dive into Pass-the-Cookie attacks, the elite technique bypassing MFA via infostealer malware and AiTM phishing.

    We cover:

    • Bearer tokens as the “keycard anyone can use”
    • Microsoft’s Token Protection with PRT + TPM for device-bound proof-of-possession
    • Okta FastPass, device binding, and ASN/IP session controls
    • DBSC: Browsers’ revival of Token Binding to kill cookie theft forever

    Plus your playbook of what features to Enable.

    Technical deep dive for IAM leaders.

    28 min
  • #34: Move 37: The Moment AI Stopped Playing by Human Rules

    In March 2016, a machine made a move in the ancient game of Go that changed everything. A commentator, a world-class professional, watched it and said: "This is not a human move."

     

    Lee Sedol, one of the greatest Go players alive, took off his glasses, stood up, and walked away from the board. For 15 minutes, he just sat in silence, shaken. That move was AlphaGo's Move 37. And it's a prophecy about the future we're building.

     

    But why am I telling this story on our podcast: Move 37 was the moment we realized something terrifying: you can create asystem that makes better decisions than humans, but in ways humans cannot understand.

    'I felt like I was playing against something unnatural.'

     

    The machine placed a stone at the 3-3 point. By human logic, it was wrong. By optimal logic, it was beautiful. And Lee Sedol had no way to predict why it was right, because it existed in a part of the strategy space that human intuition doesn't explore.

     

    Now imagine that dynamic playing out across the economy. Hiring algorithms that downrank resumes in ways we can'texplain. Trading algorithms that make moves at microsecond speeds. Pricing systems that are optimal but alien. Credit decisions that are mathematically perfect but incomprehensible. Each one is playing its own Move 37.

     

    And humans are in Lee Sedol's position: watching, confused, realizing too late that we no longer understand the game.

    32 min

About The Identity Navigator

From the publisher's feed

Welcome to "The Identity Navigator," your compass in the world of Identity and Access Management (IAM). Join us as we navigate the complexities of digital identity, security, and access control. Stay…