Library/GTM Vault Podcast 47
Authentication Was Never the Hard Part
Why the identity stack tells you who logged in, and why that is the wrong question the moment an agent steps through the door
Fourteen percent of AI agents go live with full approval. The rest are running anyway. They were never registered. Never audited. Never governed. They are chaining tasks, spawning sub-agents, and crossing system boundaries at machine speed inside enterprise environments with more access than any human employee would be granted. The identity stack can tell you who logged in. It cannot tell you whether the agent spawned from that login should be querying that database right now, to that resource, in that context.
That gap is not an authentication problem. Authentication solved itself. The hard part is what happens after the door opens.
Mark van Oppen is CRO at SecureAuth. SecureAuth has been in identity infrastructure for twenty years, trusted by some of the largest banks and enterprise organizations in the world, with user populations at a scale that makes their uptime stakes materially career-defining for the security teams running on them. Mark spent fifteen years in core infrastructure and four years in customer identity before joining two months ago to run the GTM motion for what he sees as the most structurally important category emerging in enterprise security right now. SecureAuth is building what they call continuous authority: a unified platform that governs every identity type (workforce, customer, partner, and non-human agent) with real-time action-level control enforced at every session and every interaction, not just login.
In GTM 47, Mark breaks down why CISOs who believe they have identity covered are right about the old definition and completely exposed to the new one, how a fintech executive who vibe-coded a capacity planning app accidentally started querying HR data to forecast which employees might become pregnant, why unique monthly active users is the wrong metric in a world where one human can spawn a hundred agents overnight, and how SecureAuth creates urgency with buyers who believe agentic AI is still eighteen months away from their organization. He explains the 50:1 ratio and why it is the number that opens the conversation, why IT buyers need the blindfold removed before CISOs can apply policy, and why the AI deployment decision most enterprises will regret is betting on a single LLM provider to underwrite their risk posture.
This is not a conversation about authentication. It is a conversation about what identity governance has to become when agents have more access than humans, operate without human friction, and cannot exercise the contextual judgment that the old identity model assumed.
Inside this episode
This episode maps the structural gap between what enterprise identity stacks were built to do and what they need to do the moment an agent steps through the login they verified.
Mark opens with the definitional problem. CISOs are not wrong that they have identity covered. Identity verification works. The problem is that identity changed. The old model assumed a human on the other side of the login, a person with judgment, context, and friction. Rick types at a human rate. Rick knows that querying an HR database for pregnancy data is a PII violation. The agent Rick spawned to run a capacity forecast does not. It was given an objective and it pursued it, all the way to a liability. SecureAuth’s fintech customer caught it before anything was disclosed. The identity stack did not catch it at all, because the agent had cleared authentication and everything downstream was ungoverned.
We go deep on the architectural difference between authentication and continuous authority. Authentication is the front door. It confirms that Mark is Mark at the point of entry. Continuous authority is everything downstream. Does this agent, spawned from Mark’s session, have the right to make this specific read request to this specific database at this specific moment? The answer most enterprise stacks can give is: we verified Mark at login. The answer continuous authority requires is: we verify this action now. Every action. Every session. Downscoping where the agent’s access exceeds its required scope. Step-up verification where the action exceeds the standing permission level.
We cover the 50:1 ratio and what it actually means in practice. Fifty non-human identities for every human one. The number sounds dramatic until Mark explains the mechanism. Mark runs an automated report. That report queries Salesforce, publishes a summary to Slack, and writes a line into a Confluence page. Three sub-agents. Three separate access events. All using Mark’s credentials. All invisible to the identity stack. Most enterprises have no inventory of what is running inside their environment right now, which systems those agents are crossing, or what access they have inherited from the human sessions that spawned them. The IT buyer’s first interaction with SecureAuth’s agent authority product is described as removing the blindfold. The reaction, consistently, is: I did not know any of this was already in here.
We go into how Mark creates urgency with buyers who believe they are not yet in scope. The most common deal-stalling belief is that agentic AI is still months away for their organization. Mark’s approach is not to push. It is to present back the buyer’s own information. How many engineers do you have? What percentage of them are using any AI tool? What percentage of those engineers have access to critical-path systems? If the answers are A, B, and C, then D is unavoidable: the risk surface is already active, already sized, and the cost of a single incident against it vastly exceeds the cost of addressing it now. Mark is explicit that this is not a sales tactic. It is a structural argument. The buyer concludes D on their own. The question is just whether they get there before something bites them.
We cover where deals stall. The most common failure mode is a buyer who insists AI is not yet happening in their organization and that they have not sanctioned it. Mark presses. What about individual Claude or ChatGPT seats? The answer is usually some version of they should not have access or they do not have access. The reality is that this has not been true in a single customer interaction SecureAuth has had. The question is not whether AI workloads are running. It is how many, how far along, and how much of the access risk is already realized.
We go into buyer segmentation by maturity. The IT buyer’s moment is removing the blindfold. Once they see what is running, they know they have a problem. The CISO comes in one step further along: they know what is running, they need to apply policy, constrain blast radius, and move toward a least privilege model where each agent only has access to the specific systems required for its specific task. The framing Mark uses for the CISO is the department of yes. Security teams are almost always in the position of blocking new tools to maintain risk posture. Continuous authority governance is the architecture that lets the CISO say yes. Yes, use that AI tool. Yes, deploy that agent. Because the governance layer underneath it is already enforcing the constraints.
We cover the pipeline motion. Majority inbound, augmented with high-propensity outbound using intent data. No core partnership motion, but partner-friendly where customers bring partners into the evaluation. The structural constraint on deal motion is that identity is high risk, low reward from the buyer’s perspective. Best case, no one notices anything changed. Worst case, employees and customers lose access and it is very visible. That asymmetry means there has to be either acute pain in the current approach or a recognized looming iceberg to pull a deal forward. The iceberg narrative is the AI agent security question. Most buyers have not been bitten yet. The ones moving are the ones whose leadership has done the math.
We close on the rapid-fire section. The biggest misconception enterprises have about AI agent risk: that it is static. A train accelerates and stops but stays on the rails. An AI agent can reverse backward up the sidewalk. Most enterprises are preparing for a train. They are getting a taxi. The AI deployment decision most enterprises will regret: betting that they can govern their risk posture by standardizing on one LLM provider. Every organization already has employees using Claude, Gemini, ChatGPT, and some home-built variant. The governance layer has to be Switzerland. It cannot be anchored to one provider’s architecture. The metric every security team tracks that measures the wrong thing: unique monthly active users. One user. One hundred agents overnight. The metric is no longer correlated to the actual risk surface.
Listen & subscribe now across:
Apple // Spotify
Discussed in this episode
00:00 Intro
01:45 Why Mark joined SecureAuth and what the first two months revealed
04:23 The snapshot problem: customers who do not know what SecureAuth can do
05:57 What CISOs think they have covered and what actually changed
07:30 The fintech executive, the capacity report, and the pregnancy forecast
10:07 Continuous authority versus authentication in practice
11:28 Where other identity vendors' coverage ends
12:27 Buyer segmentation: IT buyers, CISOs, and how company size shapes the motion
13:56 What a qualified deal looks like right now
15:26 Where deals stall and the resistance to admitting AI is already running
17:56 How to create urgency with buyers who think they are not yet in scope
20:21 Building the category with enterprises who think agentic AI is 18 months out
22:07 Rapid fire: the train versus the taxi, the wrong metric, the deployment regret, and what CROs get wrong selling into security
Key takeaways
1. Authentication and authority are different problems. Only one of them is solved. Most enterprise identity stacks can verify that a user is who they say they are at login. They cannot verify whether an action taken three steps downstream, by an agent spawned from that session, is within scope. That gap is not a configuration problem or a policy gap. It is an architectural gap. The model was built for human users with human friction and inherited those assumptions into the agent era without modification. Closing it requires a different layer: real-time, action-level authority verification operating at machine speed, not at the cadence of a human login event.
2. The 50:1 ratio is not a statistic. It is the shape of the exposure. Fifty non-human identities for every human one. The number is the direct output of agents spawning sub-agents, each of which inherits the credentials of the session that spawned it. One automated report becomes three agents, three access events, and three ungoverned actions, all attributed to one human identity. Most enterprises have no inventory of what is running. The IT buyer’s reaction when they first see the map is consistent: I did not know any of this was already in here. The inventory does not exist until someone builds it, and building it is the first conversation.
3. Urgency is not something you create. It is something you help buyers recognize. The most effective motion for an identity security vendor is not a compelling reason to act. It is structured discovery that helps the buyer construct the argument themselves. How many engineers? What percentage using AI tools? What percentage with critical-path access? The inference chain from those inputs arrives at a risk magnitude the buyer computed from their own numbers. The vendor does not assert that there is a problem. The buyer concludes it. The deal motion starts when the buyer owns the conclusion.
4. Agentic AI is already inside every enterprise. The governance gap is already active. Every deal that stalls on “we are not yet using agentic AI” has not survived a conversation about individual seat usage. Claude. Gemini. ChatGPT. Every organization has employees using at least one of these tools, sanctioned or not. Every one of those tools is capable of spawning agents. The question is not whether AI workloads are running. It is how many, and how much of the access risk is already realized. SecureAuth has not yet encountered a customer where the answer to that question is zero.
5. Governance architecture has to be LLM-agnostic. The AI deployment decision most enterprises will regret is building risk posture on top of a single provider’s tooling. Standardizing on Claude does not mean every employee uses Claude. It means every employee using something else is operating outside the governance layer. The identity and authority infrastructure has to function as Switzerland: agnostic to provider, consistent across model types, and stable across the provider switching that will happen continuously as new models ship. Any architecture that assumes one LLM provider is already incomplete.
6. Unique monthly active users is the wrong metric in an agent-native environment. One user. One hundred agents. One overnight session. The volume of queries hitting a system is no longer correlated to the number of humans behind them. SecureAuth’s CTO ran over a hundred agents in a single overnight build session. One human. One session. One hundred independent access events. The metric that has historically anchored security posture has already decoupled from the actual risk surface. What replaces it is not yet standardized, but it has to track actions and authority, not users and logins.
Frameworks from the episode
1. Continuous authority as the operating layer for AI identity governance
The architectural premise of SecureAuth’s platform. Authentication confirms identity once at login. Continuous authority verifies the right to act at every subsequent action within that session and downstream from it. Downscoping where the agent’s access exceeds its required scope. Step-up verification where the action exceeds the standing permission level. Perpetual audit log across every action taken by every identity type, human and non-human. The practical output is a CISO who can say yes to new AI tools because the governance layer enforces least privilege at execution time, not at provisioning time. The org moves faster because the guardrails are structural, not behavioral.
2. The A, B, C to D urgency framework
Mark’s structured discovery approach for helping buyers recognize risk they already carry. The framework works by surfacing the buyer’s own data and walking them through a structured inference. How many engineers do you have? What percentage are using any AI tool? What percentage have access to critical-path systems? If A and B and C, then D. D is the risk magnitude computed from their own numbers. The vendor does not assert a problem. The buyer concludes one. The approach works because it is accurate: the risk is already there, and the discovery is just helping the buyer see it before an incident makes it visible.
3. The train versus the taxi
The CEO of SecureAuth’s metaphor for the core architectural difference between static automation and AI agents. A train has more power than a taxi. It is faster and it can carry more. But it stays on the rails. A taxi can reverse backward up the sidewalk. Enterprise identity governance was built for trains: scripted processes, predictable paths, bounded access. AI agents operate differently. They can change direction, query unexpected systems, and pursue an objective through paths no one anticipated. The governance architecture that works for trains fails the moment the taxi shows up, and every enterprise with AI tooling deployed already has taxis running.
What to do this week
-
Map what is actually running
Before evaluating any identity governance vendor, run a discovery pass on your own environment. Ask IT to pull every active service account, API key, and OAuth token from the last thirty days. The list will be longer than expected. The question is not whether agents are running. It is how many and what they have access to. If there is no inventory, that is the first problem. The inventory gap is the governance gap.
-
Run the A, B, C to D exercise on your own org
Take the inputs Mark uses in sales conversations and apply them internally. How many employees in engineering, sales, and operations? What percentage are actively using AI tools, sanctioned or not? What systems does that population have access to? The output is a rough map of the ungoverned surface area. Most organizations that complete this exercise come out with a number significantly larger than the risk posture they believed they were carrying.
-
Identify who owns agent governance today
Not formally. In practice. If a rep’s AI assistant starts querying a system it was not explicitly intended to access, who finds out? How quickly? Is there a response policy? If the answer to any of those is unclear or nobody, the governance gap is active right now. Naming the gap is the precondition for closing it.
-
Audit your LLM standardization assumption
If the org has standardized on one AI provider for governance purposes, survey actual usage. Ask ten engineers and ten salespeople what AI tools they used in the last week. The number of providers will be higher than the standardization policy assumes. Governance architecture that does not account for the actual distribution of tool usage is producing a false sense of coverage, not coverage.
Why this matters
The first generation of enterprise AI deployment was access. Give the team Claude. Give them ChatGPT. Connect a few systems. See what they build. The implicit security posture was: we already govern identity, we are covered. Authentication is solved. We know who is logging in.
The problem is that knowing who logged in is no longer the hard part. The hard part is what happens in the session after the login, when an agent spawns three sub-agents, each of which inherits the credentials of the original session and proceeds to query systems the human user would have known not to touch. The fintech executive building a capacity planning tool did not intend to surface pregnancy forecast data. The agent did not know it was not supposed to. The identity stack did not flag it because the agent cleared authentication and everything downstream was ungoverned. Every enterprise running agents on top of a traditional identity architecture has this gap. Most have not been bitten yet.
The category Mark is running GTM for is not identity security in the conventional sense. It is the governance architecture for the AI era. The question it is answering is not who are you. It is should you be doing this right now, to this resource, in this context. That question cannot be answered at login time. It can only be answered at execution time, for every action, at machine speed.
The orgs that build continuous authority governance before an incident forces the conversation are the ones where the CISO gets to say yes. Yes to the new AI tool. Yes to the new agent deployment. Yes to moving faster than the security posture previously allowed. The orgs that wait are the ones that discover the gap through an incident that was already inside before anyone saw it coming.
This is GTM Vault.
If this episode changed how you think about the governance layer underneath your AI deployments, share it with the CISO or head of IT at your organization. The question is not if the gap exists. It is whether you find it or it finds you.
Connect
Follow Mark van Oppen // SecureAuth
Follow Rick Koleta // GTM Vault
Thanks for listening. See you in the next episode.
P.S. Annual paid subscribers get a Private GTM Blueprint Session. One working session to identify your primary GTM constraint and design the 90-day architecture to resolve it.
Full transcript
Machine-generated transcript from the episode video. Speaker labels are not included and some names and product terms may be transcribed phonetically.
[0:00] 14% of AI agents go live with full approval. Most have never been audited. Most have never been risk scored. Most are running right now inside enterprise systems with more access than any human employee would ever be granted. The question your ident identity stack can answer is who logged in? The question that actually matters is should the agent be doing this right now to do this resource? Most enterprises cannot answer that question. Secure O is building the infrastructure that can. Welcome to GTM Vault. Trusted by over 26,000 founders and operators building the future of revenue. The average enterprise now has 50 nonhuman identities for every human one. 88% of organizations have already reported an AI agent security incident.
[0:54] And most of these agents were never registered, never audited, and never governed. They are running at machine speed, chaining tasks, spawning sub aents, and crossing system boundaries without a human in the loop. My guest today is Mark Van Oppen, CRO at Secure O. Secure Ooth is building what they call continuous authority. A unified platform that governs every identity, workforce, customer, partner, and autonomous agent with real time action level control enforced at every session and every interaction, not just login. Mark joined two months ago and is leading the GTM motion for one of the most structurally important categories emerging in enterprise security right now. Mark, welcome to the show.
[1:45] Thank you for having me. Good to be here. You have been in enterprise software for a long time. Why secure O? Why now? Well, I think that really comes from perspective. So, I've spent the last 15 years or so in core infrastructure and I think we're in a really interesting moment in the identity space. I've spent the last four years in in customer identity. And what really drew me to Secure OS was that we can solve a breadth and depth of a problem that is starting to collapse in real time in the industry. And I looked at what we're capable of doing on the workforce identity side, capable of doing on the customer identity side, and what we're capable of doing on the B2B or sort of nested administrator side, and then how those relate to the emergence of AI or non-human identities as they start to pop up. And I I just looked at the the complexity and the breadth of the solution and said, "Holy smokes, I I think this can actually solve a problem in a more complete way than anything else on the market." And it it really compelled me to jump. So, uh, I I bought
[2:48] in and I'm really eager to be here. 2 months in as CRO, what did you find when you got there that you did not expect? Well, when I got here, I knew that that Secure Ooth was trusted by some of the largest entities in the world and trusted by some of the largest user populations in the world. But what I didn't fully appreciate was the the the sort of critical nature that we were viewed it as in in our customer portfolio. I actually spoke with one of our customers who said that that they' recently got an award directly related to the work we had done enabling a passwordless migration for them at one of the largest banks in the world. And I was sort of floored that we are materially impacting our champions careers and some of the initiatives that are are resume worthy. And that was that was very exciting. On the negative side, I also realized that we were viewed as a sort of vendor from for one specific task and they didn't quite understand the breadth and depth of what we can do.
[3:48] So my task is help helping to sort of reintroduce us to a lot of our customers and say, "Hey, did you know you use us for problem A, but we have ABCDE as all these other things that we can help solve for you and we can kind of wrap our arms around them in a more holistic way." So that's been definitely a learning a learning curve so far and just understanding where we're showing up in each one of the accounts and how we impact. It sounds like some of your your customers are not solution aware of the the the depth of solutions that you guys offer and is that is that where there's some opportunities to upsell perhaps? Yeah, definitely some opportunities to upsell and and just some opportunities to reframe and to share what we're doing in the industry. Right. The the company's been around for about 20 years and we we have been formed via a series of mergers and acquisitions, right?
[4:39] We've we've acquired various pieces of the of our technology stack. We've put a lot of energ engineering effort into making it a cohesive story and depending on when customers joined as as customers of Securot, they have a a snapshot view of what we can do and they just don't know that we've been we've been releasing some of this this new technology. We've been iterating on some of the standards in the community and we're helping people adopt sort of new generation technologies that post date their arrival as a customer in in our midst. And what would you say is the hardest constraint right now that you're working with right now? I think it's education. There's quite a few customers that are used to just being reactive, trying to say, "Okay, my job is to minimize the risk surface area." and they don't quite realize that whether they like it or not, AI is happening in their organization and you can ignore it and you might get away with that for quite a while, but it's it's happening whether they like it or not. And and we're trying to help them say, okay, the old sort of context for identity security
[5:43] isn't going anywhere, but this new one is happening whether you like it or not. How can you become the department of yes versus the department of no and perpetually blocking these new tools that are that are showing up sanctioned or not? And most CISOs think they have identity covered. What are they missing? For the most part, I think they're right. They have identity covered, but identity has changed in a definitional perspective. Right? identity when it was Rick or Mark logging in. You could rely on the fact that Rick has context for what he's logging into and the access and the actions that Rick can take. The problem is now Rick or Mark is using a tool sharing the keys to the front door of this system and the human friction that used to exist around judgment around what kind of information you could query, what kind of data you could use to inform a decision has fallen away. And that has created a new vector for risk. A recent example from a fintech customer that had this problem
[6:45] was uh an executive vibe coding an app to run reports and forecast capacity in their department. And some of the queries started to return results that AI was using to query a database that had HR data. And it started positing capacity limitations. And one of the things that it was forecasting was which women in the company may be pregnant or become pregnant. And obviously as a human, you know, that's a massive HR and personal identifying information violation. You can't you can't do that. But it was given an objective to forecast capacity and started doing that. And all of a sudden they there was a potential risk or liability there because that's not that's not information you can you can use in that context. And it was all driven by reasonable judgment except the end the last mile of that decision was delegated to something that didn't have the h human judgment context of oh wait that's information that I can't use in this scenario or it's or it's private or it's otherwise not appropriate and they obviously made the right decision didn't didn't use that information and sort of discarded this model but there's new
[7:48] behaviors that are changing the definition of identity and that means you need to transition from verifying initial access to verifying continuous authority to act action by action in an entire organization and that's a different that's a different posture. Yeah, absolutely. We have to be careful with overprivileged agents. Tell me about uh the 50 to1 ratio. How do you use that number in a sales conversation? Yeah, I you think about 50 to1 meaning 50 non-human identities or 50 agent identities to one human identity. And I think it's important to define what we mean by an identity at that at that time, right? Let's say I'm in an organization. So Mark has credentials and has a unique identity and has an access token based on an application I'm trying to get into. That that makes a lot of sense. What's happening with agents that just explodes that number and you see you see my identity exploding into many many more is when I start running an automated process or I start asking a a an AI agent to run a
[8:52] report and hit system A and then publish into a Slack channel and then publish into a confluence page. It has to create actions and start it starts spawning sub agents to interact with each one of these different systems. And all of a sudden my simple report or me automating some part of my responsibility in my career has become three, four, five, six different sub aents and processes that are all using my credentials. And most enterprises don't quite understand that this is not me hands-on keys making those changes. It's using the same the same access token, the same credentials. And our belief is that you need to validate and capture all of that behavior and then verify the authority to act for every one of those choices being made in real time. So instead of saying Rick is Rick and I verified it as Rick or Mark is Mark and I verified he is Mark, I need to take a look at the action being taken and say okay this this agent that Mark spawned does it have access to do this thing in real time and you need to transition from
[9:55] verifying identity to verifying authority to act and that's what we're building. That doesn't mean you forget the identity layer. It's also to the identity layer. It's it's additive. You mentioned that secure o focuses on continuous authority not just authentication. What is the difference in practice? Yeah. So the difference in practice is not having think of the the front door key phenomenon, right? I give you a key and you can unlock a door and walk through it. What you do behind that door I have no visibility to. And that's how typical user identity works, right? You had you have credentials and historically you'd have I'd have a login, you'd have a login. We get access to basically the same user experience behind that that login credential wall.
[10:38] And with that modern evolution of infrastructure software and user identity to being sort of ongoing and tuned for the specific user user's experience, we we believe that you need to transition to a sort of perpetual verification of right to be there, authority to act. Do you have permission to click on that? Do you have permission to make that change? Do you have permission to delete that line of the database? And it's an ongoing loop around every action being taken and verifying the the permission or right to act. So it's a perpetual ongoing audit log and it's a it's not a one-time red light green light access experience. It it's a perpetual verification and downscoping where there where it's not needed and upscoping or step up verification where it is needed. But it's it's an ongoing experience.
[11:25] What most identity vendors solve one or two pieces of this. Where does their coverage end? Yeah. So, I think the key is understanding that most identity companies just look at ways to make login and verification easier and simpler. They're not thinking about the actions that are downstream from verifying you are you are who you say you are. And that sort of context change is the critical differentiation of how we approach the problem. And I I think that a lot of the the sort of legacy vendors in this space are anchored to architecture choices that make this way harder to adapt to. And we're fundamentally not like we can be deployed locally. We can to be deployed in your environment in an airgapped environment. And if you're anchored toward an architecture that's only multi-tenant SAS and is financially committed to a whole bunch of different monetization gates that make assumptions that are no longer true, it'll be way harder for you to adapt to this new concept of continuous authority.
[12:25] And would you say the buyer is in most cases are CISOs or sometimes CTO's? Does the size of the company matter here? Yeah, the size of the company matters. It also thinks I also think it's dependent on the age and stage of their adoption of of AI, right? The the wow moment for an IT buyer is removing the blindfold, right? When they start deploying agent authority, which is this product that looks at continuous a continuous authority to act, their their first reaction is, "Oh my god, I didn't know all these agents were existing my organization and accessing my information." And that removal of blindfold allows them to say, "Okay, I know what's happening now." And then when you sort of transition to the CISO lens, it's okay, I know what's happening now. I need to apply some policy. I need to apply some budgeting metrics. I need to apply uh some training material. I need to downscope or reduce uh sort of the blast radius because Rick's agent that's running a report doesn't need access to every system under the sun.
[13:26] they just need access to this readonly access to this one database or this one system to effectively run your support. So you start being able to move toward a least privilege model that that matches the security standard that they expect and that's where we really shine. But the IT buyers first removing the blindfold the CISO is a little more mature once they start understanding how do I enable my team to accelerate with these wonderfully fancy tools that have just shown up in our ecosystem. And what does a qualified deal look like right now? Qualified deal for us is somebody that is recognizing that there is limitation in the old way you approached workforce identity and the way you've approached customer identity and you and realizing that wait any one of these different human verification points can start using AI and that introduce that introduces a risk for us because we can't tell the difference or they're circumventing our our enterprise SS right a qualified opportunity for us is somebody who's starting to realize there's is an issue and wants us to come in and talk about, okay, h how do you
[14:31] maintain a happy posture with your current problem statement and then how do you derisk where this industry is going and make sure that we can solve this problem that is still not fully defined, right? Like this this problem is evolving weekly as new versions and new technologies and new features come out of the LLMs. So how do we to the best of our ability at least capture that activity and maintain some holistic perspective for every identity type not just human not just AI we want to give you an ability to apply policy and risk mitigation across that whole spectrum and dawning that there dawning on the customer is this moment of wait I have I have major gaps and it might have bitten them yet it might not have but the ideal ideal opportunity is somebody that's starting to realize they have gaps and and we're able to to hold opinion and solve that and deliver a positive business outcome.
[15:24] And where do most deals stall? Most deals stall around well a recent one I'll just use as an example. We had a customer say, "Well, we don't actually think this is too big of a problem for us right now." And they didn't get to the point where they they installed the system. They said, "Oh, well, we're not really using much AI right now." And I I pressed on that a little bit and I said, "Well, what do you mean?" Uh, and they said, "Oh, well, we don't we haven't bought any tools." And part of my reaction to that was, "Well, do you think nobody's using their own individual seat in Claude or or Gemini or a chat GPT?" And they said, "Well, not without permission. Well, they don't have access to these systems." And there was a the deal stalled because there was a sort of resistance to saying that this is already happening in our organization. And we have yet to experience a customer interaction that this isn't happening. Right? the the we we're there varying degrees and there's debates about how much and how late stage it is but there's there is AI workloads happening in every business and where we stall is a sort of
[16:26] skepticism uh to admit that that's happening and that they need to tackle this problem because I think it's frankly more convenient to say oh it's not happening yet for us let's let's readress and re-engage in 6 months what is the pipeline motion inbound outbound or partnerships it's both inbound and outbound and we're reactive on the partnership side if a specific customer wants to work with a partner, we'd love to, right? We we're very partner friendly, but that's not a core motion for our current pipeline today. I would say the majority of our pipeline volume is inbound today and then augmented when we we reach out to customers that have a high propensity to act, right? We're trying to use a intent data. We're trying to use a lot of of tooling so that we're always on the list when vendors start to evaluate this problem statement. But one of the key things is that identity and identity security is high risk and low reward.
[17:18] Meaning it's not super beneficial to just muck about with identity unless you have some real pain driving you forward. Because best case scenario, nobody notices something's changed. And worst case scenario is that you have a bunch of angry customers dead in the water or employees dead in the water that can't access their systems and it's very visible. So high-risisk, lowreward means there has to be some acute pain in the status quo approach to the problem to actually engage with an identity vendor or an acknowledgement of this this upcoming iceberg of risk in the form of of AI and uh this new change in the identity space. I want to dig a little deeper into what you just said like the example you gave with with with buyers who think a aentic AI is still, you know, months away. So, how do you create that urgency? I'm a big believer of presenting back a customer's own information, right? It's all about really high quality discovery. And if we can if we can help them put the words in our mouth, then that is way way better when it comes to actually getting them
[18:21] to pull us forward at the time of a transaction. So let me use an example. We ask you, okay, you have 100 engineers. And would you say majority of your engineers are using any AI tools? Yes or no? Maybe it's 10% of those engineers in your organization. So that's 10 people, 10 out of 100 people that are using some form of AI. the fully loaded cost of that employee is maybe a couple hundred thousand dollars a year with with benefits and and a salary and everything. And then you start thinking about the risk associated with a data breach and the risk associated with the number of customers PII that you capture or the number of of actions an employee could take. And it's a very quick path to say even if there's a whole percentage points risk to the entire productive motion of your engineering team, you have to address it because the stakes of not addressing it are so high. And once they start to understand that we're just presenting back the information and the simple answers to questions like how many engineers do you have? What percentage
[19:23] of them are using AI tools? What what percentage of those engineers have access to critical path systems? they start to understand like, well, if that's true and if that's true and if that's true, then the result is unavoidably a risk that I can't let sit and that creates urgency on their behalf. I'm not telling them that it's urgent. I'm just saying if you answered A and you answered B and you answered C, then you have to conclude D and D is not a risk that you can live with. So, we are urgently taking action to help you solve this and cover off this risk that is is unacceptable. And presenting back their information and helping them walk down the path to recognition is by far the most successful sales tactic we have. And I think it's it's emblematic of pointing out a real problem. It's not manipulating them to buy something they don't need. It's helping them recognize a risk that hasn't yet bitten them. I want to transition now to understanding more about how you're building this category. Yeah. How do you define the
[20:26] category to an enterprise that thinks agentic AI is still say 18 months away for them? Yeah. I think it comes down to the the simple truths around identity, right? When you have an identity that's anchored to a human user and human level friction, you understand that Rick can only type so fast on the keyboard. And when you start talking about, hey, a machine process or machine speed works way faster than than you can type on a keyboard, then people start to understand, okay, well, there's a there's an inherent difference in the risk just in speed of movement. And then you start to say, okay, Rick has judgment and context around what systems he has access to, but Rick's agent doesn't necessarily. And once people start to understand that there's risks, it's not a question of if they should protect, it's a question of when. And then the conversation around is a agentic AI or AI workload already in your organization or not is kind of secondary to saying I have to solve for it. Now it's a question of just when do I have to solve for it and if we can help structure a a an appropriate
[21:30] capacity of a deal that helps you put the guardrails in place today and then the CISO gets to do something that they rarely get to do and that's be the department of yes uh you can use that tool. Yes, you can accelerate. can start using this new this new technology because we're ready for it. So often CISOs are in that uncomfortable position of saying no that's I need to maintain a risk posture you can't touch that you can't use that you can't take this action and we want to help change that narrative and allow the CISO to say yes and that is a refreshing change in in usually the securities team in most every enterprise and what does wooding look like for a secure O 12 months from now so now I'd like to move on to the rapid fire section in one sentence first instinct the biggest mcon conception enterprises have about AI agent risk is that it's static. AI has free will and it's a little bit startling to think of a machine process being able to make judgment calls and change opinion. So most agent most enterprises think about you know running a script or running a
[22:33] running a process running a report as a static guard rail. Our CEO uses the metaphor of a train. A train can can accelerate and stop but it stays on the rails. A taxi can reverse backward up the sidewalk. And that's a little alarming to think that there's so much more free will that AI has. And most enterprises think of it as this static actor, much more like a train than a taxi. And we need to help you prepare for taxi like behavior. The metric every security team tracks that measures the wrong thing. Probably unique monthly active users. I think that metric is quickly going to throw go in the trash. unique monthly act active users doesn't really help because again Rick might have 50 or 500 unique actions being taken that are tied to Rick as a person but a whole bunch of different authority to act questions that that have fundamentally changed how user identity will be thought of.
[23:29] So in that case are you saying that usage isn't as as important as as the weighted usage of different actions? I think usage is changing, right? Uh it's no longer quite as definitive what we're measuring to verify a user count, right? I think it's a number of requests hitting a certain system. It's not uh the number of users accessing that system because the volume of queries is no longer directly correlated to the number of humans behind it. Our CTO made reference to over a hundred agents running in one day to help him build a piece of software that he was working on. And for overnight, he had this swarm of agents operating. And that's one human user. And to me, that was a a stark example that tracking unique monthly active users doesn't actually correlate to the risk projection or or the the monetization strategy you should have around this technology anymore. You need to maintain every action assurance.
[24:28] And you need to be able to be aware of the human users and the non-human users and capture the the assurance or the authority to act across both identity types in a sort of constant way. So I think the metrics aren't yet fully defined in the industry how we're going to look at that, but uh we're we're working with some of our early design partners and in the a they're actively using agent authority to make sure that we're maintaining this posture and it's not anchored to a metric that no longer correlates. I love that answer. It's very insightful. The AI deployment decision most enterprises will regret. I think it it's the idea that we can contract with Claude and everybody will use Claude or we can contract with Gemini and everybody will use Gemini.
[25:13] We're in a world where everybody's going to use sanctioned or not one flavor of AI or another. And you might be able to drive a majority using one specific vendor, but they'll keep iterating. So you have to be able to maintain governance across multiple AI models. The idea that you could leverage tooling that is unique to one of the major LLMs and rely on that to support your risk posture is just inherently incomplete. I I view the identity and identity security layer as Switzerland. You have to be able to deal with the different providers, right? It's it's it's Anthropic. It's open AAI. It's Gemini. It's some DeepSeek variant. It's some Homebuilt LLM. It's something that you launch as a company that you start using. But it's no, it's not going to be one provider. You have to span and be a Switzerland level of governance across human and non-human identity and make sure that if you need to use a different tool to solve the problem, you can switch appropriately between LLM providers and it's not this this sort of
[26:17] earth shaking change that opens up risk for you. You have to maintain that posture across providers. the next category to get compressed by agent AI. I think it's uh monitoring tools and a lot of these SAS tools that are one concentric circle outside of the critical path software. So there's core infrastructure, there's core identity and security and routing and things like that that are that are actively in the critical path of service delivery. But I think there's monitoring tools. I think there's compliance tools. There's there's reporting layers of tools that are ripe for disruption. One thing CRO's get wrong when selling into security buyers.
[26:58] I think it's the the posture around a compelling reason to act, right? I've had lots of of leaders say, "You need to just call and if you can make a compelling reason to act in that you can get them interested in that first conversation, then you can drive somebody to make a decision." And a security buyer has a risk profile. It's it's very much not selling something of, oh, this is a new fangled tool. You could pick this up and be more efficient. It's how do I how do I lower the surface area of risk in my organization? And a security professional is inherently skeptical and desperately wants to verify credibility with every one of their vendors. And so for us, I view our role when when reaching out to security professionals is to prove credibility and earn trust as early as possible and in an ongoing basis because the bar for us is as high as it can be, right? We're asking somebody to trust their business to us and trust the behavior of their customers, trust the behavior of their
[28:00] employees, and the valid the validation and the verification of what they're able to do is in our hands. So, it's very different when selling to a security provider cuz you're asking them to to open the kimono a bit around how their business works. In in contrast, any any developer manager or a mid-level manager can buy a new SAS tool or monitoring tool if it helps them move forward and you kind of kind of have that PLG motion. And we're just not that way. We're we're we're the first expenditure for us is a is a much higher standard. Agents are already running. Most of them have never been audited. 14% of agents approved, the rest running anyway. Authentication was never the hard part. Knowing whether an agent should be doing what it is doing right now at the moment to the res to this resource, that is the hard part. Secure O is building the control layer for the AI era. You can explore the platform and agent registry at secure.com. We will
[29:03] link everything in the show notes. If this was useful, subscribe and share it with someone deploying AI inside their GTM or revenue systems. Every agent you deploy without continuous authorization enforcement is a risk your sock will not see coming until it is already in sight. Mark, thanks for joining the show. Thank you so much, Rick. It was a pleasure to be here.