449 episoder
- George Fletcher joins Jeff Steadman and Sean O'Dell for a Decoded deep dive into transaction tokens (Txn-Tokens), the OAuth Working Group specification designed to secure requests as they move across microservices. George explains the problem transaction tokens solve: hop to hop security gaps, replayed access tokens, and the difficulty of tracking a single transaction across a graph of internal services. The conversation covers the anatomy of a transaction token, including the subject, audience, scope, and TXN claims, how a token's time to live should be scoped to the transaction itself, and why immutable parameters prevent tampering mid chain. George and Sean also explore how transaction tokens apply to AI agents and delegated authorization, referencing draft work on agent specific claims and cross domain trust. The episode closes with practical starting points for organizations of any size, including open source options and where to track the specification through the IETF OAuth Working Group.
Resources mentioned in this episode:
Transaction Tokens (base draft): https://www.ietf.org/archive/id/draft-ietf-oauth-transaction-tokens-11.html
Transaction Token Chaining Profile (Cross Domain Trust): https://www.ietf.org/archive/id/draft-fletcher-transaction-token-chaining-profile-02.html
Transaction Tokens for Agents: https://www.ietf.org/archive/id/draft-araut-oauth-transaction-tokens-for-agents-00.html
Tokenetes: https://tokenetes.io/
OAuth Working Group: https://github.com/oauth-wg
Decoded by Identity at the Center:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Sean O'Dell: https://www.linkedin.com/in/seanodentity/
Visit the show on the web at http://idacpodcast.com
00:15 Introduction and catching up with Sean O'Dell
01:25 Introducing today's topic, transaction tokens and zero trust
02:26 George Fletcher joins the show
02:41 George's path into identity, from AOL to the Liberty Alliance
04:22 The problem that led to transaction tokens at Verizon Media
09:01 What a transaction token is, in plain terms
10:25 The specific problem transaction tokens solve
11:43 Transaction tokens versus a short lived access token
13:48 Delegated authorization, traceability, and the TXN claim
22:04 How long a transaction token should live
27:13 Local AI, vibe coding, and shrinking token lifetimes
28:45 What is inside a transaction token, the core claims
35:39 Call chains and the transaction context claim
39:05 Applying transaction tokens to AI agents
41:08 The transaction tokens for agents draft and the ACT claim
43:37 Getting started with limited resources, open source options
46:32 Scaling transaction tokens at a larger organization
50:38 What transaction token nirvana looks like
53:31 Whether this replaces a standard OAuth server
55:59 Where to learn more, the IETF OAuth Working Group
58:09 Cross domain trust and calling outside the enterprise
1:01:38 Alternatives to transaction tokens and adoption incentives
1:05:16 George's summary of the conversation
1:07:26 Sean's closing thoughts and takeaways
1:09:19 Wrap up and close
IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Sean O'Dell, George Fletcher, Practical Identity, transaction tokens, Txn-Token, OAuth, OAuth Working Group, zero trust, microservices, access tokens, JWT, authorization, delegated authorization, agentic identity, AI agents, call chain, token exchange, TXN claim, scope claim, Verizon Media, IETF, Keycloak, Tokenetties, cross domain trust, Decoded - Howard Ting, CEO of Opal Security, joins Jeff Steadman for a Sponsor Spotlight covering identity governance for both human and non-human identities. Howard traces his path through RSA Security, Microsoft, Palo Alto Networks, Nutanix, and Cyberhaven before returning to identity to lead Opal. The conversation covers why disabling a departing employee's account rarely ends their access, the orphaned tokens, service accounts, and agents left behind, and why visibility has to come before ownership and risk analysis. Howard and Jeff dig into agent intent and authority: whether an agent can declare its own intent, why permissions should stay a subset of what its human creator holds, and how narrowly scoped, single-task agents make governance easier. They also cover how Opal matches AI decision capacity to a growing volume of access requests, including how the company's Paladin AI supports approvers and campaign creators today. The episode closes with Opal's announcement of a unified platform for governing human, non-human, and agent identities together, extending Paladin's decisioning to agents and introducing Policy Insights to help security teams balance friction against risk. Howard shares his view that identity has to shift from an episodic, event-driven practice to a continuous one, along with a lighthearted detour into 90s video games.
Connect with Howard: https://www.linkedin.com/in/howardting/
Learn more about Opal Security: https://www.opal.dev/
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at idacpodcast.com
00:10 Intro and welcome
01:01 Howard's identity origin story: RSA, Microsoft, Kim Cameron
02:48 What Opal does: unified control plane for human and non-human identities
04:16 The opal.dev domain and how Opal got its name
06:42 Termination and lifecycle: why access doesn't fully go away
09:33 Session management and orphaned accounts
13:57 Visibility as the first step in identity governance
17:31 Can an agent declare its own intent?
20:29 Authority: should an agent ever exceed its creator's permissions?
22:12 Inside Opal: Risk Center and Policy Insights
25:41 How Opal connects to systems and collects usage data
27:30 Cross-application segregation of duties
29:06 Zero standing privilege and AI managing AI
32:12 Building trust in AI-driven access decisions
39:00 Announcing Opal's unified platform for agents and non-human identities
44:18 Explainability and traceability in Paladin's decisions
48:54 Tuning risk tolerance and autonomy in Paladin
51:20 Proving value: demos, POCs, and industry skepticism
57:47 The shift from episodic to continuous identity
59:50 Lightning round: favorite 90s video games
IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Howard Ting, Opal Security, Sponsor Spotlight, identity governance administration, IGA, non-human identity, NHI, agent identity, agentic AI, access governance, least privilege, just-in-time access, JIT, zero standing privilege, Paladin, Risk Center, Policy Insights, segregation of duties, SOD, RSA Security, Microsoft, Kim Cameron, Palo Alto Networks, Nutanix, Cyberhaven, continuous identity, identity lifecycle management, orphaned accounts, service accounts, API keys, intent-based access control - Jeff Steadman sits down with Andi Hindle, conference chair for Authenticate 2026, for a preview of this year's event. Making his seventh appearance on the show, Andi walks through how Authenticate has evolved since its founding alongside Identiverse and outlines six major topic areas shaping the 2026 agenda, including passkeys in practice, regulatory pressures, security and standards architecture, digital identity wallets, and non-human authentication. The conversation moves into hardware-based identity for retail and industrial settings, age verification challenges, and a detour into 3D printing and supply chain assurance. Jeff and Andi dig into continuous identity and zero standing privilege, the shift toward non-human traffic dominating infrastructure requests, and how agentic AI is forcing organizations to rethink authorization and human-in-the-loop decisions. They close with privacy and consent questions for non-human identities, thoughts on where authentication and authorization standards are headed, and a lighter look at Authenticate team traditions and sci-fi recommendations.
Connect with Andi: https://www.linkedin.com/in/ahindle/
Impact of GDPR on Identity and Access Management by Andi Hindle: https://bok.idpro.org/article/id/24/
Learn more about FIDO Authenticate 2026: https://authenticatecon.com/event/authenticate-u-s-2026/
Non-FIDO members can use the code IDAC15 to save 15% on their in-person conference pass.
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
00:10 - Introduction and discount code rundown for upcoming conferences
01:10 - Andi Hindle returns for his seventh appearance
01:29 - Favorite episode banter and the running Andrew Shikiar joke
03:08 - Origins of Authenticate and its relationship with Identiverse
09:01 - Passkeys are solved, so what comes next
09:53 - Lessons learned building the Authenticate agenda
12:59 - The scale of effort behind running Authenticate
15:29 - Adjacent topics expanding beyond the core passkeys mission
16:09 - Six major topic areas planned for Authenticate 2026
22:13 - Identity as the foundation for everything digital
23:14 - Hardware identity and non-human authentication
24:53 - Retail tokens, badges, and age verification use cases
28:36 - Replacing things only when the replacement is actually better
29:41 - A detour into 3D printing and personal satisfaction
31:39 - 3D printing, supply chain assurance, and identity problems
36:38 - Introducing continuous identity
37:28 - Zero standing privilege and why it matters now
40:46 - The human user as the infrastructure edge case
45:16 - Speed, scale, and the limits of human in the loop
46:11 - Setting red lines for agentic risk
50:56 - Privacy and consent questions for non-human identities
56:51 - Anonymization, data logging, and GDPR parallels
59:51 - A GDPR and IAM resource from the IDPro Body of Knowledge
1:00:26 - What Authenticate topics might look like three years out
1:04:59 - Why accounts may not make sense for agents
1:06:49 - Authorization as the next hard problem to solve
1:08:20 - Inside jokes from the Authenticate organizing team
1:09:30 - The story behind Andi's favorite Britishism
1:10:38 - Book and media recommendations
1:14:39 - Closing thoughts and sign-off
IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Andi Hindle, Authenticate 2026, FIDO Alliance, passkeys, identity verification, identity wallets, continuous identity, zero standing privilege, agentic identity, non-human identity, authorization, shared signals, GDPR, IDPro, Identiverse, age verification, hardware authentication - Rick Scot, Global CIO and CISO at Elevate Textiles, joins Jim and Jeff to talk about how he went from leading a data team to holding both the CIO and CISO seats at a global manufacturing company. Rick shares the moment that pulled him into security, how his tight-knit Charlotte cyber community shapes his thinking, and how he balances speed and control when the two roles pull in different directions. The conversation moves into identity for the age of AI agents: whether an agent is a human or non-human identity (Rick argues it's neither), who should own accountability when something goes wrong, and how session termination has to extend beyond turning off an account. Rick also digs into shadow AI, the real cost of tokens versus flat-rate licenses, and how he evaluates new identity technology against his organization's size and risk appetite. The episode closes with what excites and concerns him most about AI over the next three to five years, his advice for identity practitioners, and a lighter look at hobbies people wouldn't expect.
Connect with Rick: https://www.linkedin.com/in/rickscot/
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
00:00 - Intro and community shoutouts
07:06 - Introducing Rick Scot, Global CIO and CISO at Elevate Textiles
07:46 - How Rick got into cybersecurity
09:22 - Charlotte's tight-knit cyber community
11:18 - The moment that made security the focus
13:06 - Balancing the CIO and CISO roles
16:17 - What "Identity at the Center" means to Rick
19:26 - Where to start when building an IAM program
23:29 - Balancing risk and innovation with AI
27:46 - Who should own accountability for an AI agent
29:38 - A hierarchy for agent identities
33:31 - Terminating access and sessions, not just accounts
36:25 - Dealing with shadow AI
41:37 - Standing up a governance process for new AI projects
43:19 - Evaluating new identity technology and token costs
48:51 - Training and governance around AI usage
52:22 - Established vendors versus disruptive startups
56:56 - Looking three to five years ahead
1:00:20 - Advice for identity practitioners
1:01:41 - Lightning round: hobbies and surprises
1:08:40 - Closing and where to find Rick
IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Rick Scot, Elevate Textiles, CIO, CISO, identity and access management, IAM program, identity governance, AI agents, non-human identity, agentic identity, shadow AI, session management, offboarding, token costs, Charlotte cybersecurity community, identity leadership - Jim McDonald hosts this Sponsor Spotlight episode of Identity at the Center, made possible with support from Twine Security. Jim is joined by Benny Porat, co-founder and CEO of Twine Security and previously co-founder and CTO of Claroty. Benny shares how his cybersecurity background led him into identity and explains the concept of the "execution gap," the space where identity teams are accountable for outcomes but lack the full business context to act on their own. The conversation explores Twine Security's AI digital employee, Alex, and how it differs from traditional automation and RPA, where AI-driven execution fits best within identity operations today, and the balance between the parts of a task AI can handle easily versus the harder remaining work. Benny and Jim also dig into governance and trust, including why least privilege matters even more for AI agents and non-human identities, how organizations typically start with read-only access before expanding permissions, and how access reviews and recertification could evolve as AI takes on more of the process. They close with reflections on measuring success, how the identity practitioner's role changes as more execution shifts to AI, and a lighter round on what a personal AI digital employee might look like.
Connect with Benny: https://www.linkedin.com/in/bennyporat/
Learn more about Twine Security: https://www.twinesecurity.com/
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at idacpodcast.com
00:00 - Introduction and welcoming Benny Porat, co-founder and CEO of Twine Security
00:52 - How Benny found his way into identity and access management
02:21 - The origin of the name Twine
03:28 - Defining the IAM execution gap
05:53 - AI digital employees versus RPA and automation
08:07 - Where AI digital employees are best suited today
09:45 - Why AI is strong at eighty percent and what makes the rest difficult
14:45 - Where a digital employee like Alex fits within identity operations
18:43 - Trust, governance, and giving AI agents the right permissions
21:42 - Applying least privilege to AI agents and non-human identities
25:19 - How organizations start using Alex, from read-only to full execution
30:27 - Rethinking the role of access reviews with AI involved
33:14 - Measuring efficiency gains and revocation rate improvements
36:00 - Addressing concerns about AI replacing IAM practitioners
39:12 - How customers define and measure success
44:15 - How the practitioner's day-to-day role changes with AI agents
47:12 - Closing thoughts and where to learn more
47:37 - Lighter note: imagining a personal AI digital employee
Keywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Benny Porat, Twine Security, Sponsor Spotlight, AI digital employee, Alex, identity and access management, IAM, execution gap, least privilege, access reviews, recertification, agentic AI, non-human identity, NHI, Claroty, IGA, PAM, governance, human in the loop
Flere Teknologi podcasts
Trendige Teknologi podcasts
Om Identity at the Center
Identity at the Center is a weekly podcast all about identity security in the context of identity and access management (IAM). With decades of real-world IAM experience, hosts Jim McDonald and Jeff Steadman bring you conversations with news, topics, and guests from the identity management industry. Do you know who has access to what?
Visit us on the web at idacpodcast.com
Podcast-webstedLyt til Identity at the Center, Search Engine og mange andre podcasts fra hele verden med radio.dk-appen

Hent den gratis radio.dk-app
- Bogmærke stationer og podcasts
- Stream via Wi-Fi eller Bluetooth
- Understøtter Carplay & Android Auto
- Mange andre app-funktioner
Hent den gratis radio.dk-app
- Bogmærke stationer og podcasts
- Stream via Wi-Fi eller Bluetooth
- Understøtter Carplay & Android Auto
- Mange andre app-funktioner


Identity at the Center
Scan koden,
download appen,
begynd at lytte.
download appen,
begynd at lytte.
Identity at the Center: Podcasts i samme familie

