Podcasts

Prefer to listen to your Identity news?  Click on the individual podcasts below or scroll further to browse all the newest podcasts to find what interests you.  Note – you won’t see the Identity Unlocked podcast in the newsfeed because our friend Vittorio has left us – but his voice and his insight are unrivaled even now, please listen and enjoy.

Identity at the Center
Hybrid Identity Protection
Identity Unlocked
  • #443 - Ghosts in the Machine with John Huyette and Omer Arshed

    Jeff and Jim are joined by John Huyette, AI Risk Leader at RSM, and Omer Arshed, North American Digital Identity Leader at RSM, to explore how identity controls can help organizations manage the growing risks of AI agents. John introduces five laws for managing AI risk: governability, lineage and integrity, trust boundaries, authority containment, and human impact. The conversation connects those ideas to familiar IAM principles including ownership, auditability, zero trust, least privilege, just-in-time access, privileged access management, and continuous monitoring. They also discuss prompt injection, shadow AI, human accountability, and why organizations should start by building an honest inventory of the AI capabilities already operating in their environments.5 Laws of AI Risk: https://www.linkedin.com/feed/update/urn:li:activity:7487942457075257344/Connect with John: https://www.linkedin.com/in/john-huyette-1373906/Connect with Omer: https://www.linkedin.com/in/omerarshed/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.comTimestamps00:00 Introduction, 3D printing, and conference updates06:58 Introducing John Huyette and Omer Arshed07:52 John’s path from technology risk to AI risk12:11 Omer’s identity origin story13:43 The five laws for managing AI risk18:00 What “ghosts in the machine” means for identity20:17 Governability and ownership of AI identities25:17 Do you know what has access to what?29:43 Applying decades of IAM lessons to AI32:35 Lineage and integrity35:20 Building an AI bill of materials37:12 Trust boundaries and external data38:36 Prompt injection and untrusted content42:48 Applying zero trust principles to AI agents47:26 Authority containment49:56 PAM, least privilege, and just-in-time agent access56:22 Human impact and accountability58:41 Is agentic AI really a new identity problem?01:02:35 Starting with lower-risk AI use cases01:04:21 Where organizations should start01:05:07 Shadow AI and zombie accounts01:07:09 What excuses would an AI give during an access review?01:12:20 Wrap-upKeywordsIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, John Huyette, Omer Arshed, RSM, AI risk, AI agents, agentic AI, AI governance, governability, lineage and integrity, trust boundaries, authority containment, human impact, shadow AI, identity governance, IAM, zero trust, privileged access management, PAM, least privilege, just-in-time access, non-human identity, NHI, prompt injection, AI identity, access governance, continuous monitoring

  • #442 - Identiverse 2026 - Identity After Dark with Bravura Security

    Recorded live at Identiverse 2026 in Las Vegas on June 17, Jeff and Jim are joined by Bart Allan, General Manager at Bravura Security, for a live recording with a studio audience. In a late-night talk show format, the three host an open Q&A driven by IAM practitioners in the room. From securing AI identities to whether access reviews are headed the way of the password, this is an unscripted conversation driven by practitioners for practitioners. Topics include identity as a business enabler, zero standing privilege, agentic authentication, standards for AI agents, vendor relationships, the captive customer problem, community, and hiring IAM talent. Thanks to Bravura Security for supporting the Identity at the Center podcast.Connect with Bart: https://www.linkedin.com/in/bartholomewallan/Learn more about Bravura Security: http://bravurasecurity.com/idacConnect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com00:00:00 Welcome and Introduction00:03:00 AI Identities: Should IAM Teams Panic?00:07:30 Identity as a Business Enabler vs. Cost Center00:24:00 Continuous Identity and the Future of Access Reviews00:35:00 Zero Standing Privilege and JIT Access00:38:00 Standards for Agentic AI00:46:00 Vendor Relationships and the Captive Customer Problem00:55:56 Normalizing Rip and Replace01:01:00 IDPro, Identity Beers, and Building Community01:11:00 Agentic Authentication and Non-Human Identities01:18:00 Hiring IAM Talent01:26:00 Team Diversity and Multiple Perspectives01:27:00 ClosingIdentity at the Center, IDAC, Jeff Steadman, Jim McDonald, Bart Allan, Bravura Security, Identiverse 2026, Identiverse, IAM, identity and access management, identity security, AI identities, agentic identity, agentic authentication, non-human identities, NHI, access reviews, zero standing privilege, JIT access, continuous identity, IGA, vendor selection, identity community, IDPro, IdentiBeer, live podcast

  • What Cloud Identity Really Costs When It Fails with Chris Steinke, Director of Product Strategy at Semperis

    This episode features Chris Steinke, Director of Product Strategy at Semperis.Chris has spent more than 20 years across cybersecurity, digital identity, infrastructure, and operations, including leadership roles at American Express and Early Warning Services (Zelle) and early work at MightyID, where he helped bring one of the industry's first dedicated identity resilience platforms to market.In this episode, Chris explains why moving identity to the cloud creates a single point of failure, why backup and recovery alone aren't enough, and why the next frontier is making trust portable, so applications aren't locked to a single identity provider.This episode reframes identity resilience as a continuity problem: not just recovering after an outage but keeping the business running through one.Guest Bio Chris Steinke is Director of Product Strategy at Semperis and a technology executive with more than 20 years of experience in cybersecurity, digital identity, infrastructure, and operations. Throughout his career, including leadership roles at American Express and Early Warning Services (Zelle), he has helped organizations build resilient digital ecosystems and defend against large-scale identity threats. As an early pioneer at MightyID, Chris helped bring one of the industry's first dedicated identity resilience platforms to market.Today, his work focuses on the future of digital trust, including identity resilience, multi-IdP architectures, and trust portability - the next evolution in ensuring business continuity in an identity-centric world.Guest Quote “We spent years making identities portable, and that's what we did really at the start. We were worried about the identities. So, the next challenge is how do we make trust portable?”Time stamps 02:11 Meet Chris Steinke: 20+ year Technology Executive 03:10 Why Identity Resilience Matters 08:43 Hidden Risks in Cloud Identity 15:52 Multi-IdP Failover Playbooks 23:06 Applications Are the Hard Part 31:46 The IRON Framework 37:35 Conclusion and Final ThoughtsSponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world’s leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.LinksConnect with Chris on LinkedInConnect with Sean on LinkedInDon't miss future episodesLearn more about SemperisHIP Conference 26 is coming to Nashville, September 8–10, 2026.Join us to explore this year's theme, Redefining Resilience, at the world's premier practitioner-led conference focused on securing hybrid identity environments.If you love the conversations on the HIP Podcast, this is where the community comes together in person. Learn more and register at https://www.hipconf.com/.

  • #441 - Identiverse 2026 - Sachini Siriwardene and Ian Glazer

    Live from Identiverse 2026 in Las Vegas, Jeff and Jim sit down with Sachini Siriwardene, winner of this year's Kim Cameron Award, along with Ian Glazer of the Digital Identity Advancement Foundation (DIAF). Sachini shares how she moved from open banking API security into consumer identity work at a bank, and what led her to apply for the award named after identity pioneer Kim Cameron. Ian explains DIAF's mission to remove financial barriers to industry participation and previews the upcoming Vittorio Bertocci award for standards contributors. The conversation covers agentic AI and non-human identity governance, the AuthZen specification, continuous access management, and how practitioners can separate real AI capability from marketing hype. The group also swaps favorite hallway conversations from the show floor, including a discussion on extending the shared signals framework beyond RISC and CAPE, before wrapping with some very Vegas talk about the Sphere.Connect with Sachini: https://www.linkedin.com/in/sachini-siriwardene/Connect with Ian: https://www.linkedin.com/in/iglazer/Learn more about the Digital Identity Advancement Foundation: https://diaf.org/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com00:00 - Cold open and conference banter01:35 - Jim's origin story with identity and Kim Cameron03:22 - Welcoming Sachini Siriwardene and Ian Glazer04:02 - Ian explains the Digital Identity Advancement Foundation05:54 - How Sachini got into identity through open banking08:46 - The moment identity clicked as mission critical09:47 - Agentic AI and non-human identity governance11:25 - Optimist or pessimist on AI and the job market14:45 - Applying for and winning the Kim Cameron Award15:41 - How DIAF selects award recipients17:21 - Standout sessions and the AuthZen specification18:36 - First impressions of Identiverse20:01 - Advice for future award applicants22:03 - Managing agentic identity in practice23:16 - Separating AI hype from real capability24:32 - Where the identity industry can improve27:08 - Acting fast without chasing hype28:05 - Favorite hallway conversations29:23 - Extending the shared signals framework30:39 - A D&D themed conference talk31:08 - Vegas talk and the Sphere experience34:19 - Wrap up and how to support DIAFIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Sachini Siriwardene, Ian Glazer, Identiverse 2026, Kim Cameron Award, Vittorio Bertocci Award, Digital Identity Advancement Foundation, DIAF, agentic AI, non-human identity, AuthZen, continuous access management, open banking, OAuth2, FAPI, shared signals framework

  • #440 - Identiverse 2026 - Mike Kiser

    Recorded live at Identiverse 2026, Jeff and Jim sit down with returning guest Mike Kiser, Director of Strategy and Standards at SailPoint, for a wide-ranging conversation that spans two of the standards world's most active frontiers. The first half breaks down C2PA, the Coalition for Content Provenance and Authenticity, explaining how it differs from digital watermarking, how metadata and cryptographic signatures build a chain of custody for media, and why this work connects directly back to identity. The conversation then shifts to AI agents and the challenge of defining and governing intent, with Mike drawing an extended analogy to the early, under-regulated days of space exploration. The episode closes with reflections on the value of hallway conversations and community at Identiverse.Connect with Mike: https://www.linkedin.com/in/mike-kiser/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com00:00 Introduction from Identiverse 202601:00 Mike previews his two Identiverse talks01:35 What C2PA is and how chain of custody works06:51 Watermarks versus C2PA explained10:06 Why content provenance matters for identity14:22 Is C2PA a standard or a working group16:23 The SpaceX and space debris analogy for agent intent20:13 Governing agent publishing without stifling innovation22:00 Action Identification Theory and the how versus the why27:47 Can an AI actually have intent32:34 Why people humanize and fall in love with chatbots38:37 The case for locking down intent early39:39 Does intent change, or is it a new intent46:19 Favorite hallway conversations at Identiverse51:03 Wrap up and where to find MikeIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Mike Kiser, SailPoint, C2PA, Content Provenance and Authenticity, Identiverse 2026, Shared Signals Framework, AI Agents, Agentic Identity, Digital Watermarking, Decentralized Identity Foundation, Intent-Based Access Control

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.