Cloud Security Podcast Cloud Security Podcast

Who Governs Your AI Agents? Identity, Offboarding & Open Standards

Jul 2, 2026 · 34m

Summary

Host Ashish joins Eli Khan, CPO at Okta, to discuss the critical security challenges of AI agent identity. They address risks like prompt injection and overprivileged tokens, highlighting the new XAA standard for secure cross-app access. The episode covers maturity models for agent authorization, the importance of offboarding, and actionable steps for CISOs to govern agentic identities effectively.

Topics discussed

Introduction: AI agent security challenges and prompt injection Guest intro: Eli Khan's background in identity and security Why AI agent identity is a unique and critical problem Introducing XAA: Cross-App Access protocol for agents How XAA handles permissions and autonomous agent modes Comparing XAA with SPIFFE and other identity standards Authorization challenges and the persistence of identity issues Maturity levels: From broad access to intent-based security Agent lifecycle: Onboarding, governance, and offboarding Shadow AI discovery and the concept of a kill switch Vendor neutrality of XAA and tactical advice for CISOs Conclusion: Resources, standards, and podcast outro
Listen ad-free on Castria