EPISODE · Jul 15, 2026 · 27 MIN
Beyond the vault: Why AI agents force us to rethink Privileged Access Management (PAM)
from Identity Decoded | The Identity Security Podcast · host Silverfort
Rohit Agnihotri has spent nearly two decades helping organizations rethink identity, building and leading IAM programs and advising executives on strategy. He's also the founder and host of the widely listened to Identity Navigator podcast. In this episode of Identity Decoded, he joins Roy Akerman and Rob Ainscough to make the case that traditional, vaulting-first privileged access management is dead, and to unpack what's replacing it. Rohit walks through why the old "vault everything" model breaks down under the sheer volume of machine identities, why standing privileges are one of the biggest attack vectors in the enterprise, and why organizations are shifting from vaulting to just-in-time access and, ultimately, zero standing privileges. The conversation turns to agentic AI, where Rohit introduces his own "Identity Uncertainty Principle": as an agent's autonomy increases, certainty about whether it's still the same agent you started with decreases. Together, they explore what that means for privilege, behavioral analytics, and why every autonomous agent needs a kill switch. Key Topics 1. Why the old, vaulting-first model of PAM is dead 2. Moving from vaulting to just-in-time access to zero standing privileges 3. The Identity Uncertainty Principle: why more autonomous agents are less certain 4. Why every agentic AI identity needs a kill switch, not just a session timeout 🎧 Episode Highlights [01:37]: Rohit's identity journey, from backend developer to IAM leader [03:27]: Why the traditional, vaulting-first PAM model is dead [07:57]: The rise of the authorization plane, and why brokered access is the future [14:21]: Introducing the Identity Uncertainty Principle for agentic AI [21:37]: Why agentic AI security can't be session-based, and the case for a kill switch [26:33]: Rapid-fire round: identity myths, hard truths, and the most over hyped term in the industry 🔑 Key Takeaways: ● Vaulting credentials doesn't scale to machine identities. With machine identities projected to outnumber human ones by as much as 82ish to1 or more, vaulting every credential becomes too expensive to license, too static for identities that spin up and disappear, and too painful to review. Organizations are moving from vaulting to just-in-time access, and ultimately toward zero standing privileges. ● "What identities are privileged?" is becoming the wrong question to ask. Every organization defines privilege differently, and that inconsistency breaks down further with AI agents. Rather than asking how privileged an identity is, security teams are better served asking how much freedom it has to act, and what outcomes and risks that freedom creates. ● The more autonomous agents are, by definition, the less predictable they are, too. Rohit's Identity Uncertainty Principle holds that as an agent's autonomy increases, certainty about whether it's still behaving as originally intended decreases. Because agents can chain tools and pathways in ways no one anticipated, and carry none of the guilt, shame, or job-related restraint that shapes human behavior, security teams need dynamic risk scoring, behavioral analytics built for agents rather than humans, and a kill switch that can act in real time, not just at the end of a session. 👤 Guest Spotlight: Rohit Agnihotri Rohit Agnihotri has spent nearly two decades turning identity and access management from a technical function into a strategic business lever. His path into identity began early in his career writing back-end code, before a move to a startup introduced him to single sign-on and identity federation — and he's been leaning into the discipline ever since. He has led IAM from every angle, as a developer, architect, consultant, and executive, building and leading global teams at organizations including Northwestern Mutual, KPMG, and Cyberinc across IGA, PAM, cloud identity, and Zero Trust transformation. Today, CISOs and business leaders trust him to drive enterprise-wide IAM strategy, align identity with cloud modernization and M&A, and build high-performance teams and future-proof operating models. He's also known across the industry for challenging conventional thinking on privileged access management and identity for agentic AI, including his own "Identity Uncertainty Principle," and is the founder and host of the widely listened to Identity Navigator podcast. Stay Connected: ● https://www.silverfort.com ● https://linkedin.com/in/rob-ainscough ● https://www.linkedin.com/in/roy-akerman ● https://www.linkedin.com/in/rohit-agnihotri
Embed this episode
NOW PLAYING
Beyond the vault: Why AI agents force us to rethink Privileged Access Management (PAM)
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.