Podcasts

Prefer to listen to your Identity news?  Click on the individual podcasts below or scroll further to browse all the newest podcasts to find what interests you.  Note – you won’t see the Identity Unlocked podcast in the newsfeed because our friend Vittorio has left us – but his voice and his insight are unrivaled even now, please listen and enjoy.

Identity at the Center
Hybrid Identity Protection
Identity Unlocked
  • #440 - Identiverse 2026 - Mike Kiser

    Recorded live at Identiverse 2026, Jeff and Jim sit down with returning guest Mike Kiser, Director of Strategy and Standards at SailPoint, for a wide-ranging conversation that spans two of the standards world's most active frontiers. The first half breaks down C2PA, the Coalition for Content Provenance and Authenticity, explaining how it differs from digital watermarking, how metadata and cryptographic signatures build a chain of custody for media, and why this work connects directly back to identity. The conversation then shifts to AI agents and the challenge of defining and governing intent, with Mike drawing an extended analogy to the early, under-regulated days of space exploration. The episode closes with reflections on the value of hallway conversations and community at Identiverse.Connect with Mike: https://www.linkedin.com/in/mike-kiser/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com00:00 Introduction from Identiverse 202601:00 Mike previews his two Identiverse talks01:35 What C2PA is and how chain of custody works06:51 Watermarks versus C2PA explained10:06 Why content provenance matters for identity14:22 Is C2PA a standard or a working group16:23 The SpaceX and space debris analogy for agent intent20:13 Governing agent publishing without stifling innovation22:00 Action Identification Theory and the how versus the why27:47 Can an AI actually have intent32:34 Why people humanize and fall in love with chatbots38:37 The case for locking down intent early39:39 Does intent change, or is it a new intent46:19 Favorite hallway conversations at Identiverse51:03 Wrap up and where to find MikeIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Mike Kiser, SailPoint, C2PA, Content Provenance and Authenticity, Identiverse 2026, Shared Signals Framework, AI Agents, Agentic Identity, Digital Watermarking, Decentralized Identity Foundation, Intent-Based Access Control

  • #439 - Sponsor Spotlight - Tuebora

    This Sponsor Spotlight episode, made possible with support from Tuebora, features Jim McDonald in conversation with Sanjay Nadimpalli, CEO and founder of Tuebora. Sanjay shares his path into identity beginning as one of the first engineers at Aveksa, then discusses how intelligence is reshaping identity governance and administration by replacing static configuration with continuous, context-aware decision making. The conversation covers the concept of governance debt, how AI can interpret organizational intent expressed in natural language, and where human oversight remains essential. The discussion also explores governance of agentic identities, including how they differ from traditional service accounts, the challenges posed by their ephemeral and dynamic nature, and the policy-driven frameworks needed to manage them. Sanjay closes with a reflection on what identity practitioners should be thinking about for the next few years.Connect with Sanjay: https://www.linkedin.com/in/sanjaynadimpalli/Learn more about Tuebora: https://www.tuebora.com/idacConnect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.com00:00:00 - Introduction and welcome00:00:56 - How Sanjay got into identity00:02:40 - Full circle moment with Deepak Taneja and Zilla00:03:05 - What Tuebora does00:04:14 - The story behind the name Tuebora00:05:20 - Can intelligence replace configuration00:10:05 - Why static configuration falls short today00:14:52 - Customer frustrations with legacy environments00:21:09 - Comparing this to everyday AI tool use00:23:31 - How intelligence drives outcomes00:28:42 - Maintaining security control alongside AI00:32:38 - The orchestra analogy for AI and human roles00:35:28 - Introducing agentic identity governance00:36:10 - Why agentic identities differ from service accounts00:42:20 - The scale problem of agentic identities00:44:00 - Building a framework for agent governance00:47:35 - Closing advice for identity practitioners00:52:06 - Where to find Tuebora nextIDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Sanjay Nadimpalli, Tuebora, Sponsor Spotlight, identity governance, IGA, agentic identity, AI agents, governance debt, explainability, IAM, access governance, non-human identity, Aveksa, continuous governance, identity governance and administration

  • Inside a Veteran CISO's Playbook for Crisis and Communication with Philip Keibler, VP and CISO at Meijer

    This episode features Philip Keibler, Vice President and CISO at Meijer, one of the nation's largest privately held retailers.With nearly three decades of security leadership, including CISO roles at Bass Pro Shops and Finish Line, Phil brings a rare long-view perspective on what the job actually requires day to day. He also talks about his feature in Semperis' upcoming documentary Midnight in the War Room, premiering at Black Hat on August 5.In this episode, Phil explains why CISOs who struggle to get budget usually have a storytelling problem, how he defines success in a role where stopping every attack is impossible, and what it takes to lead a team through an active incident. He also dives into why fundamentals are what actually address most of an organization's risk.This episode makes the case that the hardest parts of the CISO job are rarely technical, and that mastering the basics matters more than chasing the newest tool.Guest Bio Philip Keibler has spent nearly three decades at the intersection of technology, risk, and business building information security programs that work in the real world.As Vice President and Chief Information Security Officer at Meijer, Phil leads security for one of the nation's largest privately held retailers, overseeing the protection of supply chains, customer data, and critical operations across hundreds of locations in the Midwest.Phil's career spans industries where the stakes are high and the margin for error is low. Before joining Meijer in 2015, he served as CISO at Bass Pro Shops and previously held the CISO role at Finish Line. Earlier in his career he led security at Herff Jones, bringing security discipline to the manufacturing sector. He began his career at EDS and spent years consulting in the Aerospace sector where he got his start in security.What sets Phil apart is not just longevity, it is perspective. He has watched information security evolve from a reactive, audit-driven function into a proactive capability that enables business velocity. His approach centers on integrating security into how organizations operate, not as a checkbox, but as a competitive advantage that lets teams move fast while managing risk in practical ways.Beyond the day-to-day, Phil is a passionate contributor to the broader security community. He has served as a guest lecturer on cybersecurity and data privacy at the University of Chicago Law School, sits on the Institute for Cybersecurity Education and Research Advisory Board at Grand Valley State University, serves on the IT Advisory Committee at Kent County Technical Center, and is a board member the Meijer Credit Union. He is also featured in Midnight in the War Room, a Semperis documentary examining the human reality behind enterprise cyber defense.Phil has held his CISSP certification since 2009, attained his MBA from Davenport University, and a career's worth of operational experience across retail, aerospace, insurance, and manufacturing.Guest Quote “A successful CISO understands that it's not about prevention, it's about resilience, it's about recovery, and it's about identifying those things in your program that you can do incrementally better every single day. We're in the pursuit of perfection, but we understand we'll never get there.”Time stamps 02:46 Meet Philip Keibler: From Sysadmin to Security 04:35 Becoming a CISO 06:20 What CISOs Really Do 08:50 Defining Success and Resilience 10:41 Storytelling to the Board 13:29 Semperis' Midnight in the War Room 17:47 Team Care and Crisis Leadership 21:47 Advice for CISOs 24:24 The Case for Mastering the Fundamentals 31:02 Conclusion and Final ThoughtsSponsor The HIP Podcast is brought to you by Semperis, the leader in identity-driven cyber resilience for the hybrid enterprise. Trusted by the world’s leading businesses, Semperis protects critical Active Directory and Entra ID environments from cyberattacks, ensuring rapid recovery and business continuity when every second counts. Visit semperis.com to learn more.Links Connect with Phil on LinkedInConnect with Sean on LinkedInDon't miss future episodesLearn more about SemperisHIP Conference 26 is coming to Nashville, September 8–10, 2026.Join us to explore this year's theme, Redefining Resilience, at the world's premier practitioner-led conference focused on securing hybrid identity environments.If you love the conversations on the HIP Podcast, this is where the community comes together in person. Learn more and register at https://www.hipconf.com/.

  • #438 - Identiverse 2026 - Sean O'Dell

    Recorded live at Identiverse 2026 in Las Vegas, Jeff sits down with Decoded co-host Sean O'Dell for a wide-ranging state of the union on continuous identity, shared signals, and the identity questions AI keeps raising. Sean shares what he is hearing on the ground about the upcoming transaction tokens spec, why continuous identity has moved from concept to mainstream adoption, and how shared signals are expanding into commerce. The conversation shifts to AI: the real cost of securing it, why model provenance matters, and the murky question of who is on the hook when an AI agent makes an expensive or harmful decision on your behalf. They debate companion agents, consent versus power of attorney, and whether the identity industry even owns this problem. Sean closes with a simple piece of advice for anyone feeling overwhelmed by AI right now.Connect with Sean: https://www.linkedin.com/in/seanodentity/Connect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.comTimestamps:00:00 Intro and a Decoded update00:44 Transaction tokens spec preview01:51 State of the union on continuous identity03:39 The questions organizations are asking04:34 Is it still all about the data05:07 Shared signals framework moving into commerce06:40 Is AI a fad at Identiverse this year07:11 The real cost of securing AI08:00 Model provenance and indemnity09:39 IAM for AI versus AI for IAM10:18 Trusting agents to act without oversight14:51 Assigning authority to the who and the what16:13 The cruise booking example and who is on the hook20:16 Companion agents, consent, and power of attorney23:00 Does the identity industry own this problem25:00 Relationship and intent as the real issue28:03 Could an insurance market emerge for agentic AI29:18 An access review scenario gone wrong30:41 Small specialized language models for identity tasks32:11 Favorite hallway conversations at Identiverse36:05 Wrap up and words of wisdom on AI FOMOKeywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Sean O'Dell, Decoded, Identiverse 2026, continuous identity, transaction tokens, shared signals framework, agentic AI, AI security, model provenance, IAM, digital identity, identity and access management

  • #437 - Identiverse 2026 - Pam Dingle

    Live from the IDAC booth at Identiverse 2026, Jeff and Jim sit down with Pam Dingle, Director of Identity Standards at Microsoft, to unpack agentic identity. Pam breaks down assistive versus autonomous agents, walks through where standards like SPIFFE and OAuth hold up, and explains the difference between delegation, impersonation, and partition. The conversation also covers credential discovery risk, shared signals and revocation, what enterprises should prioritize now, and the value of hallway conversations at Identiverse.Connect with Pam: https://www.linkedin.com/in/pameladingle/OAuth Actor Profile for Delegation: https://www.ietf.org/archive/id/draft-mcguinness-oauth-actor-profile-00.htmlConnect with us on LinkedIn:Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/Visit the show on the web at http://idacpodcast.comTimestamps:00:00 Intro and Identiverse 2026 vibes04:01 Defining agentic identity07:06 Has the earth really shifted11:38 An old problem thats been bejeweled15:13 From Nulli Secundus to Microsoft16:00 How standards are holding up19:27 Client ID metadata and just in time trust21:41 Shared signals and the revocation problem24:43 Deploying agentic identity at scale28:11 Registries at scale29:04 Delegation authorization and attenuation32:33 Delegation vs impersonation vs partition36:03 The one thing you can fix right now37:56 Favorite hallway conversation42:29 The solar system of hallway conversations45:51 Remembering Kim Cameron48:00 New voices to watch52:08 Wrap up and thank youKeywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Pam Dingle, Pamela Dingle, Microsoft, Identiverse 2026, agentic identity, agentic AI, non-human identity, delegation, impersonation, SPIFFE, OAuth, identity standards, IAM, digital identity, workload identity

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.