#390 - Identity Management for Agentic AI with Tobin South

#390 - Identity Management for Agentic AI with Tobin South

In this episode of the Identity at the Center Podcast, hosts Jeff and Jim sit down with Tobin South, co-chair of the OpenID Foundation's AI Identity Management Community Group, to delve into the intricacies of identity management in the age of agentic AI. They discuss the challenges and solutions related to AI agents, the role of the Model Context Protocol (MCP), and the concept of recursive delegation and scope attenuation. Additionally, the conversation covers practical advice for developers and enterprises on preparing for AI-driven identity management and explores the cultural touchstone of coffee from various global perspectives.


Connect with Tobin: https://www.linkedin.com/in/tobinsouth/

OpenID Foundation: https://openid.net/

Identity Management for Agentic AI (OpenID Whitepaper): https://openid.net/wp-content/uploads/2025/10/Identity-Management-for-Agentic-AI.pdf


Connect with us on LinkedIn:

Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/

Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/

Visit the show on the web at http://idacpodcast.com


Chapter Timestamps:

00:00 – Jeff and Jim banter about unopened iPads and conference season

05:55 – Introduction to Tobin South and his AI identity background

07:00 – How AI has evolved from machine learning to generative models

09:00 – The OpenID AI Identity Management Community Group

10:30 – ChatGPT’s impact on the AI perception shift

12:00 – Users vs. Agents: What’s the difference?

14:00 – Letting the right bots in: AI agents vs. bad bots

17:00 – AI impersonation, delegation, and the risk of shared credentials

20:00 – Impersonation vs. Delegation – what practitioners need to know

23:00 – Governance, oversight, and delegated authority for agents

26:00 – Liability and “who is responsible” in agentic systems

30:00 – How developers can prepare for agent identity and access management

32:00 – Explaining the Model Context Protocol (MCP)

36:00 – Enterprise use cases for MCP and internal automation

38:00 – Is MCP the next SAML?

42:00 – Recursive delegation and scope attenuation explained

46:00 – The one key takeaway for IAM professionals

48:00 – Lighter note: Coffee talk – from Sydney to San Francisco

54:00 – Wrap-up and where to find more IDAC content


Keywords:

IDAC, Identity at the Center, Jim McDonald, Jeff Steadman, Tobin South, OpenID Foundation, AI Identity Management, Agentic AI, Delegated Authority, Impersonation vs Delegation, Model Context Protocol (MCP), Recursive Delegation, Scope Attenuation, Identity Access Management, IAM, AI Governance, AI Standards, Enterprise AI, AI Agents, Identity Security

Episoder(391)

Identity At The Center #7: How the IAM Value Proposition Has Changed

Identity At The Center #7: How the IAM Value Proposition Has Changed

On this episode, Jim and Jeff talk with Luis Almeida, VP of Business Development at Identropy, about how the value proposition for IAM has changed over the years. You can read his take here. Want to join the conversation? Leave us a message here: anchor.fm/identity-at-the-center/message

16 Aug 201945min

Identity At The Center #6: Black Hat 2019

Identity At The Center #6: Black Hat 2019

Warshipping, US military CAC's on the way out, and how to identify Deepfakes... all topics of discussion brought to the table by Jeff who has his boots on the ground at the annual Black Hat conference in Las Vegas. Want to join the conversation? Leave us a message here: anchor.fm/identity-at-the-center/message

9 Aug 201933min

Identity At The Center #5: What Just Left Your Wallet?

Identity At The Center #5: What Just Left Your Wallet?

On this episode, Jim and Jeff talk about the recent news regarding the Capital One data breach and what might have been the motivations behind the incident. They also reference this video when talking about man in the middle attacks against two-factor authentication. Want to join the conversation? Leave us a message here: anchor.fm/identity-at-the-center/message

2 Aug 201928min

Identity At The Center #4: The Circle of (IGA) Life

Identity At The Center #4: The Circle of (IGA) Life

On this episode, Jim talks with Jeff about his idea in an upcoming article he is writing about the IGA lifecycle: Approve - Provision - Collect - Verify Want to join the conversation? Leave us a message here: anchor.fm/identity-at-the-center/message

26 Jul 201930min

Identity At The Center #3: Healthcare IAM, MFA, and PAM Oh My!

Identity At The Center #3: Healthcare IAM, MFA, and PAM Oh My!

On this episode, Jim and Jeff talk about Kacy Zurkus' article "Healthcare Organizations Too Confident in Cybersecurity" for InfoSecurity Magazine and why multi-factor authentication (MFA) isn't more widely adopted. Jeff also poses a question to Jim: Do you choose MFA or Privileged Access Management (PAM) first if you can only do one? Want to join the conversation? Leave us a message here: anchor.fm/identity-at-the-center/message

19 Jul 201932min

Identity At The Center #2: Getting into the sexy world of IAM

Identity At The Center #2: Getting into the sexy world of IAM

With Jim on vacation this week, Jeff has called up Fletcher Edington as a pinch hitter. Fletcher talks about his path from college intern to IAM implementation engineer to IAM sales. They also talk about how to get young talent into the IAM space to solve the UI and design challenges of the future. Want to join the conversation? Leave us a message here: anchor.fm/identity-at-the-center/message

12 Jul 201931min

Identity At The Center #1: Introduction to an IAM Strategy Framework

Identity At The Center #1: Introduction to an IAM Strategy Framework

It's our first one! Hosts Jim McDonald and Jeff Steadman have a combined 30 years of experience in the identity and access management field. In this episode, they talk about how to create identity and access management strategies to better secure your organization. ***Correction - In this episode, we mention our friend Mario. He works at Callsign and not Transmit Security. Sorry, Mario!***

2 Jul 201937min

Populært innen Teknologi

lydartikler-fra-aftenposten
romkapsel
tomprat-med-gunnar-tjomlid
rss-avskiltet
teknisk-sett
rss-impressions-2
shifter
nasjonal-sikkerhetsmyndighet-nsm
smart-forklart
fornybaren
elektropodden
energi-og-klima
teknologi-og-mennesker
pedagogisk-intelligens
rss-polypod
rss-bouvet-bobler
rss-alt-som-gar-pa-strom
blaskjerm-brodrene
rss-snakk-om-sikkerhet
rss-rimelig-mistenkelig