#390 - Identity Management for Agentic AI with Tobin South

#390 - Identity Management for Agentic AI with Tobin South

In this episode of the Identity at the Center Podcast, hosts Jeff and Jim sit down with Tobin South, co-chair of the OpenID Foundation's AI Identity Management Community Group, to delve into the intricacies of identity management in the age of agentic AI. They discuss the challenges and solutions related to AI agents, the role of the Model Context Protocol (MCP), and the concept of recursive delegation and scope attenuation. Additionally, the conversation covers practical advice for developers and enterprises on preparing for AI-driven identity management and explores the cultural touchstone of coffee from various global perspectives.


Connect with Tobin: https://www.linkedin.com/in/tobinsouth/

OpenID Foundation: https://openid.net/

Identity Management for Agentic AI (OpenID Whitepaper): https://openid.net/wp-content/uploads/2025/10/Identity-Management-for-Agentic-AI.pdf


Connect with us on LinkedIn:

Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/

Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/

Visit the show on the web at http://idacpodcast.com


Chapter Timestamps:

00:00 – Jeff and Jim banter about unopened iPads and conference season

05:55 – Introduction to Tobin South and his AI identity background

07:00 – How AI has evolved from machine learning to generative models

09:00 – The OpenID AI Identity Management Community Group

10:30 – ChatGPT’s impact on the AI perception shift

12:00 – Users vs. Agents: What’s the difference?

14:00 – Letting the right bots in: AI agents vs. bad bots

17:00 – AI impersonation, delegation, and the risk of shared credentials

20:00 – Impersonation vs. Delegation – what practitioners need to know

23:00 – Governance, oversight, and delegated authority for agents

26:00 – Liability and “who is responsible” in agentic systems

30:00 – How developers can prepare for agent identity and access management

32:00 – Explaining the Model Context Protocol (MCP)

36:00 – Enterprise use cases for MCP and internal automation

38:00 – Is MCP the next SAML?

42:00 – Recursive delegation and scope attenuation explained

46:00 – The one key takeaway for IAM professionals

48:00 – Lighter note: Coffee talk – from Sydney to San Francisco

54:00 – Wrap-up and where to find more IDAC content


Keywords:

IDAC, Identity at the Center, Jim McDonald, Jeff Steadman, Tobin South, OpenID Foundation, AI Identity Management, Agentic AI, Delegated Authority, Impersonation vs Delegation, Model Context Protocol (MCP), Recursive Delegation, Scope Attenuation, Identity Access Management, IAM, AI Governance, AI Standards, Enterprise AI, AI Agents, Identity Security

Avsnitt(392)

Identity at the Center #48 - Eve Maler, IAM UMAnitarian

Identity at the Center #48 - Eve Maler, IAM UMAnitarian

Jim and Jeff talk with Eve Maler, CTO at ForgeRock about her work in the IAM space which includes helping found standards like XML and UMA, why we think blockchain identity is over-hyped, and some of the highlights of the recently released ForgeRock 2020 Consumer Identity Breach Report. 2020 ForgeRock Consumer Identity Breach Report: https://www.forgerock.com/resources/2020-consumer-identity-breach-report ForgeRock ROI Calculator: https://www.forgerock.com/roi-calculator/ Find Eve here: Twitter: https://twitter.com/xmlgrrl LinkedIn: https://www.linkedin.com/in/evemaler/ Connect with Jim and Jeff on LinkedIn here: Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Email the show at questions@identityatthecenter.com or send us a message on LinkedIn.

15 Juni 202050min

Identity At The Center #47 - IAM Program Drivers & Requirements

Identity At The Center #47 - IAM Program Drivers & Requirements

Jim and Jeff talk about IAM Program Drivers & Requirements and which comes first. LastPass Report: https://www.lastpass.com/identity-and-access-management-by-industry Connect with Jim and Jeff on LinkedIn here: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Email the show at questions@identityatthecenter.com or send us a message on LinkedIn.

8 Juni 202052min

Identity At The Center #46 – The 2020 KuppingerCole Leadership Compass for Privileged Access Management

Identity At The Center #46 – The 2020 KuppingerCole Leadership Compass for Privileged Access Management

Jim and Jeff talk about some of the findings in the recently released 2020 KuppingerCole Leadership Compass for Privileged Access Management. Grab the report from any of these leading vendors (in alphabetical order): BeyondTrust: https://www.beyondtrust.com/resources/whitepapers/kuppingercole-leadership-compass-privilege-management CyberArk: https://lp.cyberark.com/kuppingercole-leadership-compass-pam-2020.html Thycotic: https://thycotic.com/why-thycotic/analysts-opinions/kuppingercole-leadership-compass-report/ Identiverse 2020 Conference Link: https://identiverse.com/ Connect with Jim and Jeff on LinkedIn here: Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Email the show at questions@identityatthecenter.com or send us a message on LinkedIn.

1 Juni 202056min

Identity At The Center #45 - The 2020 Verizon Data Breach Investigations Report

Identity At The Center #45 - The 2020 Verizon Data Breach Investigations Report

Jim and Jeff talk about some of the findings in the recently released 2020 Verizon Data Breach Investigations Report (link below). Report link: https://enterprise.verizon.com/resources/reports/dbir/ Identiverse 2020 Conference Link: https://identiverse.com/ Connect with us on LinkedIn: Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Email your questions, suggestions, and topic requests to the show at questions@identityatthecenter.com

25 Maj 202050min

Identity At The Center #44 - IDSA Report-Identity A Work In Progress

Identity At The Center #44 - IDSA Report-Identity A Work In Progress

Jim and Jeff talk about some of the findings in the recently released Identity Defined Security Alliance (IDSA) report "Identity Security: A Work In Progress" Want to join the conversation? Leave us a message here: anchor.fm/identity-at-the-center/message or email us at questions@identityatthecenter.com.

18 Maj 202035min

Identity At The Center #43 - Passwords and Phishing in the COVID Era

Identity At The Center #43 - Passwords and Phishing in the COVID Era

Jim and Jeff talk about passwords for World Password Day (May 6th) and a Barracuda Networks commissioned study about the security concerns businesses are seeing during the COVID-19 pandemic. Want to join the conversation? Leave us a message here: anchor.fm/identity-at-the-center/message or email us at questions@identityatthecenter.com.

11 Maj 202042min

Identity At The Center #42 - Ron's IAM Program Framework

Identity At The Center #42 - Ron's IAM Program Framework

Jim and Jeff talk with Ron about the IAM program framework he is developing and some of the challenges some organizations face when it comes to IAM context and operations. Want to join the conversation? Leave us a message here: anchor.fm/identity-at-the-center/message or email us at questions@identityatthecenter.com.

4 Maj 202037min

Identity At The Center #41 - Server Access Management 101 with Paul

Identity At The Center #41 - Server Access Management 101 with Paul

Jim and Jeff talk with Paul Volosen from Centrify about the IAM concepts used to secure server access. Want to join the conversation? Leave us a message here: anchor.fm/identity-at-the-center/message or email us at questions@identityatthecenter.com.

27 Apr 202051min

Populärt inom Teknik

uppgang-och-fall
natets-morka-sida
elbilsveckan
market-makers
bilar-med-sladd
rss-uppgang-och-fall
rss-technokratin
rss-elektrikerpodden
skogsforum-podcast
hej-bruksbil
rss-racevecka
rss-veckans-ai
rss-digitala-influencer-podden
rss-laddstationen-med-elbilen-i-sverige
rss-badfluence
bli-saker-podden
developers-mer-an-bara-kod
rss-snacka-om-ai
solcellskollens-podcast
rss-en-ai-till-kaffet