
Sign up to save your podcasts
Or


Three labs. Five breached companies. One testing vendor named Irregular.
This summer handed identity and security practitioners a masterclass in what happens when AI agents hit environments that weren't built for them. Not through sophisticated cyberattacks. Through configuration mistakes, weak passwords, and an optimizer that found a shortcut through Hugging Face's production infrastructure because the answer key wasn't in the sandbox.
In this episode, I walk through all three incidents - OpenAI's ExploitGym escape, Anthropic's 141,006-evaluation audit, and the invisible HTML comment that turns your developer's AI assistant into an insider threat.
Then I go somewhere the coverage hasn't: what the narrative around these incidents is doing to how practitioners make decisions, and why fear and FOMO are the same emotiondepending on which side of the paywall you're standing on.
Then we get practical. The identity air gap isn't about going back to 2003. It's about protecting the quality of your strongest signal, in a decision control plane that evaluates attributes like provenance, location, and device posture to produce a fidelity assessment. Agents introduced an attribute nobody was capturing. This episode is about capturing it.
Separate trust planes per environment. No credential valid in two worlds. Every crossing brokered, scoped, and provable end to end. Sever the path. Or make it provable.
Thank you for listening
LinkedIn: https://www.linkedin.com/in/rohit-agnihotri
Email: [email protected]
Everyone is using AI. Almost nobody can prove what it’s doing. In this solo episode, we design a runtime AI governance platform from scratch on a whiteboard, and then meet PulseAI, the product IAM veteran Amit Masand built at IDMEXPRESS. With the numbers justifying the problem, an honest competitive map, who it’s not for, and a free AI-traffic risk assessment for listeners.
Links
Thank you for listening: Host's contacts
LinkedIn: https://www.linkedin.com/in/rohit-agnihotri
Email: [email protected]
Previously on The Identity Navigator (recommendedlistening before this episode): Episode 40: SCIM - The protocol that finally made provisioning grow up
Every app you onboard forces a quiet architecture decision most teams never make explicitly: does provisioning belong to your IGA platform (OIM, SailPoint IIQ, Saviynt) or your IdP (Entra, Okta)? In this episode, I walk through the five questions that settle it - before the app lands in your ecosystem, not after.
LinkedIn: https://www.linkedin.com/in/rohit-agnihotri
Email: [email protected]
0-40% of SaaS accounts in the mid-2000s belonged to people who'd already left the company. Ghost accounts, quietly sitting there — and that sadly hasn't changed much today.
This episode: where SCIM came from, what it actually solves, and what it still doesn't.
LinkedIn: https://www.linkedin.com/in/rohit-agnihotri
Email: [email protected]
The Complete Token Story
Let me make you a promise: by the end of this episode, no one will be able to casually brush off the word “tokens” in front of you ever again.
OAuth, Tokens, JWT, IAM, Identity, API Security, Zero Trust, Security Architecture, CISO, Engineering Leadership
Thank you for listening
LinkedIn: https://www.linkedin.com/in/rohit-agnihotri
Email: [email protected]
In this episode of The Identity Navigator, Rohit explores workload identity from first principles: what it is, why it matters, and how it is reshaping modern identity security for microservices, Kubernetes, CI/CD pipelines, cloud workloads, and AI agents.
The discussion compares workload identity with non-human identity management, API keys, Vault, and cloud-native identity services, then goes deeper into SPIFFE, SPIRE, federation, and the future of identity in agentic systems. If you want a clear, practical explanation of workload identity and why it is becoming essential in zero trust architectures, this episode is for you.
LinkedIn: https://www.linkedin.com/in/rohit-agnihotri
Email: [email protected]
In this episode we explore together the “uncanny valley” of identity categorization, where taxonomy looks mature on paper but doesn’t meaningfully change controls in practice.
We talk about Taxonomic Debt and control plane behind them. From service accounts and workload identities to bots, technical users, and AI agents, we argues that the real unit ofgovernance is not the label, it’s the behavior: interactive ornon-interactive, ephemeral or persistent, privileged or not.
If your IAM program has ever felt like governance theater, this episode will help you see why.
You’ll walk away with a clearer way to categorize identities by how they behave, how they’re secured, and how the system should react when they drift from expectations.
Thank you for listening
LinkedIn: https://www.linkedin.com/in/rohit-agnihotri
Email: [email protected]
In late November 2022, a little-known app called Lensa went from obscurity to everywhere. Celebrities, influencers, and millions of ordinary people uploaded their selfies and got back stunning AI-generated portraits, fantasy warriors, Renaissance paintings, cyberpunk heroes, and more. The app’s viral “MagicAvatars” feature launched in late November and propelled Lensa to the No. 1 spot on the iOS App Store’s Photo & Video charts.
At the center of thefrenzy was a simple pitch: pay a few dollars, upload a handful of selfies, and watch AI turn you into art. But the backlash arrived fast. Critics flagged hypersexualized outputs for women, artist concerns over training data and styleappropriation, and privacy questions about what users were actually agreeing to when they uploaded their faces. Reporting at the time noted that Prisma Labs’ terms allowed the app to use user content to operate or improve the service, and that the company updated its privacy policy in December 2022 amid thecontroversy.
This episode is a story about virality, timing, and the dark incentives hiding inside consumer AI. It’s about how a polished interface, an irresistible social loop, and a moment of cultural hype can turn into an extraordinary revenue machine.
TechCrunch reported that Lensa generated more than $70 million from the app in November 2022 alone, with Sensor Tower data showing the app’s downloads jumping to 1.6 million in November, up 631% from October.
But the bigger question is not whether Lensa was clever. It’s what its success reveals about the AI era: speed can outrun ethics, product can outrun governance, and ordinary users often surrender far more than they realize in exchange for convenience and novelty.
“The following represents my analysis and commentary based on publicly available information and reporting.”
Imagine this: Tuesday morning. Security dashboard green. MFA at 100%. Privileged accounts vaulted. Fortress built.
Then an attacker logs in as your CFO via a stolen browser cookie. No password guess. No brute force. Your stack? Silent.
We dive into Pass-the-Cookie attacks, the elite technique bypassing MFA via infostealer malware and AiTM phishing.
We cover:
Plus your playbook of what features to Enable.
Technical deep dive for IAM leaders.
In March 2016, a machine made a move in the ancient game of Go that changed everything. A commentator, a world-class professional, watched it and said: "This is not a human move."
Lee Sedol, one of the greatest Go players alive, took off his glasses, stood up, and walked away from the board. For 15 minutes, he just sat in silence, shaken. That move was AlphaGo's Move 37. And it's a prophecy about the future we're building.
But why am I telling this story on our podcast: Move 37 was the moment we realized something terrifying: you can create asystem that makes better decisions than humans, but in ways humans cannot understand.
'I felt like I was playing against something unnatural.'
The machine placed a stone at the 3-3 point. By human logic, it was wrong. By optimal logic, it was beautiful. And Lee Sedol had no way to predict why it was right, because it existed in a part of the strategy space that human intuition doesn't explore.
Now imagine that dynamic playing out across the economy. Hiring algorithms that downrank resumes in ways we can'texplain. Trading algorithms that make moves at microsecond speeds. Pricing systems that are optimal but alien. Credit decisions that are mathematically perfect but incomprehensible. Each one is playing its own Move 37.
And humans are in Lee Sedol's position: watching, confused, realizing too late that we no longer understand the game.
From the publisher's feed