#436 - Sponsor Spotlight - P0 Security

#436 - Sponsor Spotlight - P0 Security

Source: YouTube · Identity at the Center · published Jul 22, 2026 · 45:57

Identity & Access Management
No ratings yet Log in to rate
Transcript Available
Description

This episode features Greg Danny, CTO of PZ Security, explaining how runtime access control and dynamic roles are essential for securing unpredictable AI agents and non-human identities (NHIs) while moving toward zero-standing-privilege architectures.

Key Takeaways:
• Runtime access control enforces authentication and authorization at the exact moment of execution, addressing the dynamic nature of AI agents that static permissions cannot secure 7:22.
• Agentic identity requires distinct tracking and audit trails to prevent risks associated with agents inheriting or impersonating human access 12:51.
• PZ Security uses "dynamic roles" that inject variables like customer IDs into policy templates, enabling granular real-time filtering without pre-defining thousands of static roles 23:45.
• Agent intent is determined by comparing actions against independent sources of truth, such as ticketing metadata, to provide automated evidence for authorization 19:26.
• A critical overlooked risk is "context drift" or human prompting errors, where agents may misinterpret vague instructions and perform destructive actions 30:35.
• Organizations should start with low-risk, friendly use cases to establish best practices rather than waiting for perfect standards 39:48.

Implementing runtime access control and dynamic roles allows organizations to secure agentic identities effectively without relying on brittle static permissions.

Sources:

  • 07:22 Definition of runtime access control for agents
  • 12:51 The need for distinct agentic identity tracking

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Identity & Access Management. Commonly maps to: Identity and Access Management (IAM), Security Architecture and Engineering. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

[music] This is Identity at the Center. >> Welcome to the Identity at the Center podcast. I'm Jeff and I'm flying solo today. Jim's off uh enjoying I believe somewhere in Alaska cruise. So kudos to him for being able to get out of the office and do stuff like that. Uh today we've got a sponsor spotlight episode. So this is a series as many of you know IDAC is a nonprofit and episodes like this are what makes it possible to do what we do here and so generous support of organizations that do that for us uh is very cool. They believe in the IM community that we're building here. So we're going to go ahead and jump right in today. Our sponsor today is PZ Security. Uh if you want to find out more information about them and our conversation today, you can go to pzero.devac. And if that sounds fa…