In this Sponsor Spotlight episode, Jeff Steadman flies solo and welcomes Greg Danyi, co-founder and CTO of P0 Security, to the show. Greg walks through P0's approach to runtime access control, covering how it applies to humans, non-human identities, and AI agents alike. The conversation digs into the difference between authentication and authorization, why zero standing privilege is more achievable now than before agentic adoption took hold, and how dynamic, evidence-based policies can reduce reliance on manual approvals. Greg also shares real examples, including row-level access control for data lakes and a CRM mishap that shows how easily agents can misinterpret intent. The episode closes with a look at where enterprise AI agent governance may be headed over the next few years, plus a lighter conversation about explaining IAM to a 10-year-old. This episode is made possible through the generous support of P0 Security as part of IDAC's nonprofit Sponsor Spotlight series. Learn more at p0.dev/idac.



Connect with Greg (Gergely): https://www.linkedin.com/in/gergely-danyi/

Learn more about P0: https://p0.dev/idac/



Connect with us on LinkedIn:


Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/


Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/


Visit the show on the web at http://idacpodcast.com



00:00 - Introduction and sponsor acknowledgment

01:13 - Greg Danyi's path into IAM

02:18 - What P0 Security solves for

03:21 - Where P0 fits versus PAM and IGA

04:46 - Agentic identity as a driver of adoption

05:27 - MCP servers and unpredictable agent actions

07:10 - Defining runtime access control

08:50 - How authentication and authorization work together

09:07 - Standing access versus expressed intent

10:16 - Zero standing privilege in practice

12:27 - Agentic identity as a distinct identity class

19:24 - Automated evidence for approvals

20:42 - Walking through a support agent example

22:13 - Row-level access control for data lakes

23:35 - Dynamic roles explained

29:55 - CRUD risks and underestimated concerns

31:32 - Human intent and giving agents clear direction

36:32 - Where enterprise AI agent governance is headed

39:36 - Advice for CIOs and CISOs getting started

41:15 - Explaining IAM to a 10-year-old

42:29 - Board games, dice, and calculated risk

44:00 - Closing thoughts and where to learn more



Keywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Greg Danyi, P0 Security, runtime access control, agentic identity, zero standing privilege, non-human identity, authentication, authorization, IAM podcast


Podden och tillhörande omslagsbild på den här sidan tillhör Identity at the Center. Innehållet i podden är skapat av Identity at the Center och inte av, eller tillsammans med, Poddtoppen.