Who Governs Your AI Agents? Identity, Offboarding & Open Standards
Jul 2, 2026 · 34m
Summary
Host Ashish joins Eli Khan, CPO at Okta, to discuss the critical security challenges of AI agent identity. They address risks like prompt injection and overprivileged tokens, highlighting the new XAA standard for secure cross-app access. The episode covers maturity models for agent authorization, the importance of offboarding, and actionable steps for CISOs to govern agentic identities effectively.
Topics discussed
Introduction: AI agent security challenges and prompt injection
Guest intro: Eli Khan's background in identity and security
Why AI agent identity is a unique and critical problem
Introducing XAA: Cross-App Access protocol for agents
How XAA handles permissions and autonomous agent modes
Comparing XAA with SPIFFE and other identity standards
Authorization challenges and the persistence of identity issues
Maturity levels: From broad access to intent-based security
Agent lifecycle: Onboarding, governance, and offboarding
Shadow AI discovery and the concept of a kill switch
Vendor neutrality of XAA and tactical advice for CISOs
Conclusion: Resources, standards, and podcast outro
Listen ad-free on Castria