From Roles to Intent: Rethinking Identity in the Age of AI
34m 50s
In this podcast episode, Derek Holt interviews Shandra Shiroshad, Director of Engineering at Okta, about the evolution of identity and access management in the age of AI. Shandra explains that Okta’s core mission—to free everyone to safely use any technology—has been supercharged as "everyone" now includes AI agents and machines, not just humans. Her team builds Okta’s "front door," including the sign-in widget, APIs, Okta Verify, and device assurance, ensuring secure access for both human and non-human identities. The key shift is from static, role-based authentication to dynamic trust based on intent and continuous verification. In an agentic world, permissions must be just-in-time and limited, preventing AI agents (described as "over eager interns") from escalating privileges or accessing unauthorized data. This reverses the traditional trust-access-control model: now, organizations must start with limited access and tight controls, then continuously verify trust. Shandra also highlights three changes in engineering: AI accelerates code generation (like a fast junior programmer), but requires careful guardrails to prevent misuse. She emphasizes that identity is now about intent, not just roles, and that scale (thousands of authorizations per second) demands automation and policy-as-code. Ultimately, Okta is adapting to ensure that as AI agents proliferate, they can only act within their authorized scope, protecting enterprise data while enabling productivity gains.
Welcome back to release, the podcast that takes you behind the software where some of the biggest and most influential companies in the world. I'm Derek Holt, CEO of digital.ai, and I could not be more excited to welcome today's guests, Shandra Shiroshad. Shandra is the director of engineering at Aqda, is an absolute thought leader in the identity, space, brings a tremendous amount of experience to the table. Super excited for this conversation. Shandra, welcome to the podcast. Thank you, anybody? Thank you, Professor. Fantastic. Well, look, I know that with this audience, Shandra, like the reality is they know all about Aqda, but maybe I'll give a little bit of a precursor here, just in case somebody hasn't been paying attention. But Aqda is ultimately the leading identity and access management platform that sits really at the center, from my view of how people securely access technology. And from the earliest days, that was sort of web, cloud, SaaS, remote work, et cetera. More recently, we're going to spend a lot of time on this. We start to think about what is that identity layer for AI and for the models that we're interacting in the agentic solutions that we're interacting with. But really, this control plane that Aqda has provide for enterprises to make sure that the right people and systems get access to the right data at the right time, et cetera, et cetera. And so Aqda, they're everywhere. I think it's one of the things you quickly find when you're spending time with the team. They're managing billions of identity authentications every month, scale, complexity, globally distributed, all, you know, center of the AI revolution, all of the things that we love to talk about here on the podcast. So Shandra, really, really appreciate you taking the time. Absolutely. So just maybe to get the audience a little bit booted up in terms of a bit of your background and also sort of your time, both in the identity and security space, but also your time at Aqda. Maybe just give us a little bit of a brief history and provide a little context there and then maybe talk a little bit about the work that you're doing today at Aqda. Absolutely. So my tech journey has been pretty classic. Derek, I am a builder and an engineer at Aqda. I go way back in the day when floppy disks were the thing. I remember, I remember. So those times when cybersecurity was just a guy standing outside the computer lab, making sure you did not steal a floppy disk. That was the extent of the security. Make sure the door was locked as well. The door was locked. That was good too. Some parents like the, some labs used to even like, you know, make sure that you take off your shoes because walk around in the lab with the socks because they didn't want to like dust going in there. Yeah. Since then my career has evolved. I have been like seen the software industry from multiple different angles. Like I have been a system administrator protecting the machines themselves and the operating system and being a database administrator or a code database SQL server database, a DBA for some time. And I've been a web application developer for a long time, mobile application developer. But the real aha movement was when I became an identity and access management administrator. That's when it was the intersection of everything. That's when I didn't realize that, you know, identity is the central thread. The core problem was like, you know, who is this? Are you the right person? Are you allowed to be here? And are you allowed? Are you doing? What are you allowed to do? So that sparked my passion. I was always passionate about cyber security, but this is where I found my niche and the identity security. And that landed me at talk to that. Yeah. I love your role because what's super interesting I find and we have this privilege as well, which is, you know, we are engineers building tools for engineers for all intents and purposes. You are a security professional, you know, building security tools for security professionals. So yeah, I'd love to understand sort of just like the area within, within Octa that you find yourself in and sort of how you guys think about, you know, the work that you guys are doing in terms of your teams. So my team, I lead the teams that build the front door. In a very simple one line answer is like, my team is responsible for the front door. By that, I mean, like think of us as like buffed up bouncers guarding the internet's most popular club. So everything that you see at like when you try to log in to using Octa, the first thing that you see is that well, we drop with the bouncers standing there, which is the sign in widget. And then we are responsible for the STKS as well, which is the bouncers for the back door. So you can use authentication as the case and we don't have to go through the sign in widget, but you can build an application that uses our authentication as the case. Octa verify. That's the two, which is an authenticator, but it's not just an authenticator. I like many people think, Oh, Octa verify is an authenticator. It is, but it does a lot more things than authentication. It's our primary device posture provider. It's a collection signals from your device. And this is where, uh, this is where I help us, like, you know, I don't know our application here, right? And in addition to Octa verify, we have device assurance, which is basically, yeah, sure, we know who you are. You have access. We'll let you in. But the device that you're coming from is not compliant. It's not managed or it doesn't have, um, you don't have a fast, fast code on it. So we need to make sure that you are who you are, but also you are coming from a device that can be trusted. What what I love about your solutions in this space generally is, uh, in one hand, it is some of the most complex or neat, uh, engineering, engineering efforts, right, to get it right. And on the other hand, when you get it right, it's almost seamless, right? It's almost behind the scenes. And, and so there is a magic to, to that level of complexity that, that to the end user, when done right, uh, it is a seamless, fluid, uh, uh, experience. But when you log into a new system or you're, you're trying to gain access to something obviously that you would be permission to gain access to. Exactly. And, and the, and the friend door, what used to be like, who wants knocking on the door? Now it's not just people knocking on the friend door. Now it's like not human identities, the machines, so the AI agent, some of these are like the, even though I know my team's focus is changing in the way that, you know, not just the humans are knocking at the door, but different entities, different kinds of identities. Yeah. Well, so, so, so let's talk through that, right? I, I, I, I kind of came to fame or kind of came up in the, the cloud sass, you know, online world of you just want to think about it that way by sort of unifying and simplifying and, and, and, um, enhancing identity across what I guess we will now all think of as like the beginning part of the internet. Now we have the AI, uh, the AI dimension. How has octas mission to become the foundation of the identity layer on sort of the old mission, I think, which was like more deterministic applications and software to the new mission, which is that and AI and agents like how has that evolved? How has that challenged your team? How are you guys thinking about it? I'll tell you one thing. Our core vision is not much has changed when it comes to our core vision. Our vision is free everyone to safely use any technology. And that's still very much true. If anything, it has been super charged now. The definition of everyone and any technology has been changing. The word everyone now includes the AI agent. That's the part I was talking about earlier. Now we are gone from being a bouncer at the door, uh, for just, uh, the humans to like any any kind of identity. So, uh, think of it as like a valley. Like you hand a hand off your, you know, car key to that valley. We want to, that's an authentication. That person is authenticated. He is, he of she is allowed to do something. But are they just doing what they are allowed to do or what they are authorized to do, which is to go and park your car and bring it back to you or are they going to enjoy it? So that's the part, which is what we should be taking care of right now. The you direct is allowing a have an agent you wanted to do a specific thing. Pull a report for you, but it's supposed to do, uh, it has supposed to have access to only certain amount of data and not beyond that. Cannot have a levated permission and go grab something that you don't have access to. So these are some of the things that are changing. The big conceptual shift is from static authentication, which is what used to be like rule based. Here are the rules you follow it and then we'll let a person in to a dynamic trust. Continuous verification. Making sure that, uh, what is being authorized is what is being used for. It's super interesting to me. I think, you know, a lot of times for those of us in the industry were spending a lot of time thinking, okay, hey, there's a new, you know, Opus 4.6 comes out or or Chattu BD 5.2 and then all the tools that are using it to be able to to power the tools that we have access to. I think often we're looking at the, um, capabilities as the found of the foundation models as being like the delimiting factor. Whereas I think what we're seeing, and I'm, I'd love to get your take on this in the enterprise. There's actually two non well there's two different things that are
or potentially holding organizations back. One is classic, which is just generally organizational change, right? Having new ways of working, trying new things, getting out of doing things the way that they used to be done. And there's a whole bunch of techniques around driving that. But the other one that I think is maybe not so obvious to somebody from a distance is if you don't get identity right, it's almost impossible to roll these things out in large-scale enterprises and maybe even more so in any regulated industry because you cannot have to your point, it's one thing that gives the agent access to get in. You can't have the agent doing a joy ride on your data. And so talk a little bit about how your products are evolving to meet not only the obvious needs of the beginning stages of an agentic world, but also how do you stay up on everything when next week things are going to change again? Yeah. So the identity is shifting from roles to intent, right? So earlier, it's like you would hire somebody as a sales engineer, sales rep or a accountant. And they would have specific titles. And then you buy that by the department they are in a role-based-- - Sort of information. - Yeah, you have permissions. You have access to skills for it. You have access to work day, whatever. But that is changing. Now it's identity based on intent, right? It's not just who, but also what you're trying to do. Like if there is an agent which is running on behalf of an accountant, it's allowed to do a certain things only. It cannot have access beyond what that particular accountant is supposed to have. What is the intent? And the second thing is about permissions, right? And these agents can run any time of the day, right? It's not like they're going to-- - They'll sleep the last I checked, right? And they cannot have standing permissions. These permissions have to be just in time. So they-- if an agent needs to run a query on a database to pull a report for an accountant, it should have not only just the limited amount of permission, but also just in time. You need access for 15 seconds or 10 seconds or even fraction of a second to run that. And after that, after the task is done, the access is due. No standing permissions. And also the scale, right? It's machine scale now. You cannot have like me or like an admin, you start sitting in granting access. It has to be automated. It has to be policy as a core, right? The access is granted at thousands of permissions or thousands of authorizations are given and reworked per second, maybe even, right? So that is kind of scale we're dealing with here. - Yeah, it is really interesting. I mean, it is not just-- so on one hand, to your point, there's a scale ramp, right? And so if I have, I don't know, if I have 10,000 employees and I've got 100,000 agents, like there is clearly an order of magnitude scale difference. But to your point, it is a fundamental shift in how we even think about, quote unquote, identity, right? Because like in the past, it's been an email address, a name, to your point, a job title, and probably a series of permissions that are either checked or not checked. We are now moving to a dynamic environment where it's about intent. And in some ways, you could argue that intent is sort of spans agents and humans, right? Because intent is the ultimate thing that's going to matter. Really interesting. Now, do you guys see, as you start to think about it, maybe we're getting a little bit into the future here a bit, but you alluded to it a bit. But much like we have thought about identity or now intent as a bit of a, you know, what job is to be done. Let's say I'm on the legal team or I'm on the finance team. Because your hypothesis or what you're seeing that agents are going to be classified very similarly in the sense of they are going to be organized into certain functional areas. And then within that, they are going to have a set of things that they're allowed to do and not allowed to do. And frankly, as you highlighted, maybe times when they're allowed to do it and times when they're not allowed. I mean, this is where the relationship between trust, access control. I mean, these are the things. The relationship among these trust, access and control is reversed now. Think of like analogy would be like giving your teenager a credit card. So the access itself is a plastic card or an agent, the case of an agent AI and spending limits like you want to make sure that how much they spend and what are they spent. So these are the controls you need to have. And then you need to have a price, obviously. So model used to be now trust access control. Oh, I trust you. So I give you access and I have I put some controls on it. Now here we have to do it the other way around. We have to start with with limited access. I am granting you access to do specific things. But I'm going to put some very tight controls. And then I'm continuously continuously verifying the trust. And let me show that you are doing exactly what you're doing. And I am monitoring these things. And then if ever like basically putting guard rails on AI. Yeah. Yeah. But it's a different paradigm. Yes. Interesting. And so how do you think about when you think about the in many organizations, the large scale organizations, even when we were just managing human identity that are that are maybe administrators and using the octetools and getting things set up. How is their job going to change or how is it already changing in this new AI? So everybody is going to become more efficient. Like we are seeing this in our development as well. So everybody is going to be more effective and get the productivity. The everybody is going to get again huge amount of productivity again. However, we need to be extremely careful on usage of AI. So I would think of AI as a over eager intern. So it wants to help you. It's a very, very eager and it's fast and wants to help you. But the thing is it might, it doesn't know the difference between what's like it's supposed to do and what it's not supposed to do. It can overstep its authority and go beyond because it's like it's naive, right? It doesn't know what it's supposed to do. So an accountant may ask AI to do something and it can accidentally go and get access to something. This is where the, it can escalate its privilege. It's escalation might happen. Sure. That's where the identity comes into the picture, right? We have to make sure that the amount of access and authorization that is given to that AI agent is limited and it's delegated authentication. You have access to work on behalf of the account and you can only do what that accountant can do. So that's the kind of things that we need to be able to put guardrails on when it comes to professionals. It's super interesting. I think you think about the traditional identity and access management administrator or you know, I am manager, what not. Their role has always been, hey, we got to really partner with the business. Now more important than ever as you're starting to think about the adoption of additional agents and the evolution of managing, you know, intent and identity in this, in this new world. Super dynamic, super interesting and of course, Octa is very much at the forefront both of what we know today, but also with the things that I think we're all learning as we, as we go. So, Sean, maybe pivot a little bit here. You run engineering teams, right? You happen to be in this particular industry, but you run engineering teams. You got a deep background as you mentioned across a whole bunch of different roles. We talk a lot about at digital.ai that we are, we have entered what we call the fourth wave of software development and delivery in the context areas. Wave number one was procedural, maybe even before the floppy disk, right? We had co-located teams. There was no obvious networks outside of maybe the physical location that you're in. And teams were co-located and they delivered in a waterfall fashion, not because they want to do, but that was the only way to deliver software when you had to go print the floppy disk, right? Obviously, the internet then late '90s became obvious and that unlocked incremental or iterative delivery, which to me, the internet was as responsible for starting the wave of agile development methodologies as anything, right? Like it was core, I think object oriented help, but like really modern tools and the ability to deliver software every time you wanted to deliver software over the internet was like a real big unlock. Obviously, we're sort of on the backside of what I consider more of a scale moment, which was around cloud and mobile and going from roughly 100 million people on the internet around 2000, 2001 to everybody being on, you know, crosses. I'm sitting here. I got at least five devices connected to the internet for just me. We've now entered this new wave, right? And we went through the procedural, the agile development. I'd say cloud and mobile were kind of marked by scale, DevOps, like automation, et cetera. When you think about this fourth wave, how is it change or how is it evolved to think around how you guys build the solutions that we all use, how you do engineering, how are you guys thinking about adoption? Yeah, there are three things that come to my mind, right? There are three shorts I would call it. One is how we build. These are like a few years ago, engineers used to start from scratch, like trying to blend sleep paper, right?
like just a blank whiteboard. Yeah, exactly. And then I would, I used to have like good ideas, not that ideas were not there. The idea is, but I would still be writing the code from scratch pretty much. It would take me a long time to do that. Now we have AI, as I said, like SuperEager intern helping me, but that junior programmer is very fast. He can get me the first draft very, very quickly. And he does his fairly good job. And I can only imagine how he, you know, what he, what that junior intern can be, will be able to do in the, in the next year or next three to four years. But already the first draft of the code comes out really, really quickly. And that's what we're doing. We have rolled out co-pilot. We are using code, Gemini code assist and Cloud code. So all of these are being, we are using this for productivity. And things that are very interesting are like, you know, we get the unit tests, the documentation, the boilerplate code, the refactoring, all of this is happening really, really fast. So we're using AI for our productivity. We want to be able to deliver our time to market will it's going to be faster, you know. The value to the customers will bring it much faster. And the second thing is what we build, right? It's how we build, obviously, helps with productivity. The what we build is also an important thing. And that's what we have been discussing all along, right? We have to change what we are building. Now we have to leverage AI in every aspect of our product. For example, we have after AI, which is helping in our identity risk, sorry, identity, I think it is identity that detection and response, our risk assessment. So authentication or the identity management has moved from just the front door to beyond, like, it's not like, oh, I have the front door and it's locked and it's secure. That's not enough. The threat can be afterwards as well. Like, that's where AI is coming and helping us here. Has anything changed? Did you device posture direct was on his mobile phone? Loved him to very sensitive application. But then he moved, he was in a car and he was connected to the home Wi-Fi and they went to a coffee shop. The threat immediately changed. The risk has changed. It's gone out. We need to do something. So things like that, we are changing what we're building with AI, right? And then obviously the last thing is we're exploring, like what else we can do, like, you know, identifying bottlenecks, identifying vulnerabilities and how can we design a more secure and more stable application and so on. So we're going to use AI in almost every aspect of our software. I love it. One of the things that's super exciting about the industry that we both find ourselves in, which is like, when everybody asks, you know, I don't know, if you go to a non-technical domain and ask the team, how are you using AI? They'll tell you, oh, well, we use a copilot, like a Microsoft or a chat GPT or whatnot. Helps us write emails, helps us respond to certain things. Helps us summarize things. But for us, it's very nuanced, because like, there's a set of things that are changing. Number one, we are using AI to get more productive at the task that we do, which is like building software. Number two, the software that we are building are helping people build AI-based software. And so like, we're going from deterministic applications and I would say, "Octa historically has had to manage "and help secure identity for deterministic applications. "Now you gotta do it in a non-deterministic world," which opens up a whole new run. And then we're also saying, with the advent of AI, what are the new opportunities to drive value that like we never even considered before, right? And so it's so multifaceted, like, I sort of have to laugh a little bit when somebody says, "Oh, how are you guys using AI?" I'm like, "How long do you got?" It's pretty complicated, right? - So we are using AI, the way they are using, which is for productivity. It's malicious, my email, it's malicious, my email. We're using everything that they're using it for. But in addition to that, we are also thinking how we can protect them from hurting themselves. - Yes. - Using AI, which is a differentiator between them and us, because we have to, not only be, we have to use the way they are using to improve our productivity, but we also have to think then, what can, what harm can AI do? - How do you say that? - How do you say, our customers from AI related issues? Do you remember that, I don't know if you know about this, I'm like, there was a socially engineering attack where there was a room full of people, like your own like CEO and your finance, CFO, and everyone, they were all fake. - Yeah. - Somebody extorted like $2 million by a make-up and account and sign a check with the entire fake people. - Yeah. - And this is a long way from the random WhatsApp's that claim that I need somebody to buy me a Best Buy or Amazon gift card ASAP. Those were pretty rudimentary and easy to detect. To your point, everything's changing. And as we've talked about a lot, like obviously most of it, hopefully most of it is being used for good and for innovation, as always. And certainly this was the case with mobile and web and others. We got to also keep an eye on the fact that threat actors are using these things more aggressively. And the levels of sophistication and change. - Or threats are going to have changed, really. - The way we do threat models have completely changed now. - Right, they changed, yeah. - Yeah, yeah. - Well, in the scale that they can operate it. Well, like talk a little bit about then, just like as we start to think forward, and particularly like what we just described, I mean, we're lucky enough that like all day, every day be thinking this, you're probably similar to me. Like even when I'm not working, I'm reading these things. I'm just like a student of the space. It's much my passion as is my career. But it is a lot. It is moving fast. I was just on earlier this week with the, pretty senior first and at one of the foundation models. And I was like, one of the observations I have for myself is like, historically, I've tried things. I've learned what it's good at, what it's not good at. And then that's how I kind of code my usage. With the speed of innovation around the foundational elements, it's almost like you can assume if something didn't work last week, that it might not work this week, right? And all of those improvements are happening sort of behind the scenes. You almost have to have this like very experimental mindset in everything you do. And you've got to assume that maybe it got better. And let me try it. You try that same prompt again and see if it's improved. As a leader in a forward leaning company, what are some of the techniques that you use to stay up to speed yourself? I use the app. Yeah, it is ironic you can. Yes, yes. It's, it's, it's so awesome. Right, you use AI to learn AI, right? We have several tools within AAPTA. I mean, one of the important things like, you know, for engineering leaders like us, right? Used to make sure that AI is used correctly, right? At AAPTA, we have had what's called as AI days, like company wide AI days, right? And then we had a whole month of prompt engineering, I wouldn't call it prompt engineering. Basically, there was a training like every day, we were given a challenge to write prompts. We have various training models like we, we were, we had mandatory training basically on AI within the company. Everybody needs to become proficient with AI basically. How do we use it? It's what are the nuances? Like the AI can hallucinate. It's very verbose, for example, it just spits out way too many things. You need to know exactly how to ask AI and put the guard rails on it and make sure that you're getting the best out of it. And that's the kind of thing overall for everyone, it is important, but for engineers, it's even more nuanced. Like we need to, especially if you're using it to write code, we need to make sure that every line of code that AI writes is wetted by an engineer, a senior engineer. Everything that AI writes is owned, but it's not, yeah, I can write it. It can help me write the code, but it should, finally, it's my code. The best way I've heard it stated, and I'll probably butcher this a little bit, but the best way I've heard it stated is, there's this conversation, and you can insert the name of any job. Is AI gonna take my engineering job? Let's use that as an example. And the response I've heard that I think is most well thought is you don't have to worry about the AI taking your job. What you have to worry about is the engineer who learns how to use I better than you do taking your job. And I think that's the way we all need to think about it. Yes, yes. Yeah, I know them take your job, but somebody who knows the AI better, will take your job. That's right. And this isn't the first time that's happened, right? Like I was, I was highlighted this on a more recent podcast where there was an image in an magazine somewhere that I was reading online, obviously, but that was from an office in the '80s. And I'm looking at it, like there's very few computers, right? Like there are executives just sitting at desks with a phone, like a lot of sacks of paper, and they had to change the way that they worked, right? And you think about now, you wouldn't go into any office without, without probably multiple big screens and whatnot. And this is very similar. It's another tool for the mind. It's another way for us to drive innovation. Yeah, the key is continuous as you can. It's a problem.
It applies to you, it applies to me, it applies to the junior engineering, it applies to everyone in the organizations. If you don't keep up with the tools and the technologies that are evolving, which are happening much faster than before, by the way, which means we need to be able to pick up things really, really quick. But it's not, at the same time, things are not that hard, though. I mean, picking up, as I said, like, you know, I use AI to learning AI. If I don't understand something, I can ask Chachipiti. Gemini, hey, I don't understand this concept. Please can you simplify it and tell me in the end of the term. It will give you very, very concisely. I think that's the most important thing. I think probably the biggest thing holding anyone back, and this is probably the same for everything, is that the old, it's always been done that way, mentality. And as long as you have a, let's try new things, mentality in this day and age, to your point, it is democratizing the ability to learn how to do just about anything. And really, it's the onus is on the individual to kind of lean in and constantly almost disrupt themselves. Right. You got to constantly be making yourself better. And I think it's a great taste. Well, look, one of the things I want to close on, and this has been awesome conversation. One of the things I wanted to close on is let's go back to octo. Let's go back to identity. Let's go back to this dynamic time that we're in. When you start to look out, and I don't know what the appropriate time horizons ever are, six months, twelve months, 18 months, 24 months, when it comes to identity, when it comes to the importance of identity to usher in safely, securely, this agentic AI future, what are some of the things that you guys are thinking about that maybe aren't, you know, kind of top of people's list right now, but you think they might be in a year or two? Yeah. So for your listeners or for any engineering leader out there, I would say the single most critical thing is to win the unification battle. By that, I mean, or the period of time or the decades, your organization has a sprouting mess of finding identity silos. You have customer identity, you have employees, you have a bunch of engineers who have written code with API keys in there. So it's right now all over the place, and it's a security nightmare already. And with AI coming in and people writing a whole bunch of agents, it becomes uncontrollable. It'll become an nightmare for sure. And one thing that you could do is like, unify everything, you should have a central identity operating system. I'd call it the identity nervous system. And one single glass of pain where you can control all the policies. As opposed to like, you know, having all the different people controlling different kinds of identities, different kinds of systems are managed by everything. Otherwise, you'll be playing a hopeless game of whackable. This is a really good, really, really good take. And we've seen this in some other areas. You know, one was just having a conversation with a development leader on the podcast where we're recently where. But one of the things we were talking about was the engineering organizations that had built more automation into their software delivery process, are the ones that are most ready to take advantage of the power of AI, right? Because they sort of got their house in order. They've gotten things organized. And therefore, the benefits that they're seeing around building more quickly, they actually are delivering more quickly. The ones that didn't, where there was a lot of manual stuff down streaming, they're writing a lot more code. But they're shocked that they're not delivering anymore, right? But that's because they've not made those investments. And this idea of unifying identity, I've typed this down. I think it's probably fair to say, even if your company, you know, maybe a customer or a potential customer, even if they are not diving all the way into the deep end of AI, they need to be getting identity unified, organized, ready to go. Because otherwise, they're going to be in a really tough position as things continue evolve. Fair to say. Yeah, absolutely. That's exactly the same. You already took a little bit much better than I did. No, no, no, this is great. Well, this is Shandra. Amazing to talk to you as always. We really always appreciate the partnership. You guys are on the forefront here. And I mean this sincerely without octa, this revolution doesn't happen, right? It'll help one off people, but helping large enterprises, large organizations do this safely securely. And hopefully as a collective for a long, long time, it's going to take you guys figuring out, you know, continue to do what you do, but also figuring out some of the new challenges and new opportunities are being unlocked. So thank you guys for doing what you do. Thank you for the partnership. Thank you for the time. And for those listening, we'll be back with another episode soon. But but we'll mark this one as a really great one and Shandra really, really appreciate it. Thank you, Nick.
Podcast Summary
Key Points:
Okta is a leading identity and access management platform, now expanding its focus from human identities to AI agents and machine identities in an agentic world.
Shandra Shiroshad, Director of Engineering at Okta, leads teams responsible for the "front door" (sign-in widget, APIs, Okta Verify, device assurance) and emphasizes a shift from static, rule-based authentication to dynamic trust and continuous verification.
The core vision remains "free everyone to safely use any technology," but "everyone" now includes AI agents, requiring identity to shift from roles to intent and from standing permissions to just-in-time, limited access.
Key challenges include managing machine-scale authorizations (thousands per second), preventing privilege escalation by AI agents (described as "over eager interns"), and implementing guardrails through delegated authentication and tight controls.
Shandra identifies three "shorts" in engineering
The relationship between trust, access, and control is reversed
Summary:
In this podcast episode, Derek Holt interviews Shandra Shiroshad, Director of Engineering at Okta, about the evolution of identity and access management in the age of AI. Shandra explains that Okta’s core mission—to free everyone to safely use any technology—has been supercharged as "everyone" now includes AI agents and machines, not just humans. Her team builds Okta’s "front door," including the sign-in widget, APIs, Okta Verify, and device assurance, ensuring secure access for both human and non-human identities.
The key shift is from static, role-based authentication to dynamic trust based on intent and continuous verification. In an agentic world, permissions must be just-in-time and limited, preventing AI agents (described as "over eager interns") from escalating privileges or accessing unauthorized data. This reverses the traditional trust-access-control model: now, organizations must start with limited access and tight controls, then continuously verify trust.
Shandra also highlights three changes in engineering: AI accelerates code generation (like a fast junior programmer), but requires careful guardrails to prevent misuse. She emphasizes that identity is now about intent, not just roles, and that scale (thousands of authorizations per second) demands automation and policy-as-code. Ultimately, Okta is adapting to ensure that as AI agents proliferate, they can only act within their authorized scope, protecting enterprise data while enabling productivity gains.
FAQs
Okta's core mission is to free everyone to safely use any technology, which now includes AI agents alongside humans.
Identity is shifting from static, role-based permissions to dynamic, intent-based access, where agents have just-in-time permissions and continuous verification.
Her team builds the 'front door' of Okta, including the sign-in widget, authentication SDKs, Okta Verify, and device assurance to ensure secure access.
Okta uses delegated authentication, limiting agents to only what the human they represent can do, with no standing permissions and access granted just in time.
Dynamic trust means starting with limited access and tight controls, then continuously verifying trust by monitoring actions to ensure agents only do what they're authorized to do.
AI tools like Copilot, Gemini Code Assist, and Cloud Code help engineers quickly generate first drafts of code, acting as a fast, eager intern that boosts productivity.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.