SourceForge Podcast
The SourceForge Podcast is the world's largest B2B software podcast published to over 1.5 million subscribers across all major social media and podcast platforms, and to over 667,000 subscribers on YouTube. Interviews with tech and software CEOs, leaders, and changemakers. The SourceForge Podcast by Slashdot Media gives you insight into the cutting edge of software, B2B SaaS, and trailblazing technology.
SourceForge Podcast
Securing AI Agent & Human Identities: Auth0
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Auth0 makes it fast and easy to add secure, scalable authentication and authorization to any application, API, or AI agent. With 30+ SDKs, enterprise-grade security, fine-grained access controls, and support for billions of monthly logins, it helps teams launch faster without building identity from scratch.
In this episode, we speak with Gareth Davies, Chief Product Officer at Auth0, and Monica Bajaj, SVP of Engineering at Okta. This conversation centered on how identity is becoming a strategic growth driver in SaaS, especially as AI agents and machine identities multiply and enterprise workflows get more complex. The main takeaway was that modern identity systems need to be organization-aware, multi-tenant safe, and built for self-service so they can scale without creating security, compliance, or engineering bottlenecks. It also highlighted the shift from static role-based permissions to more dynamic, context-aware authorization, and closed with the idea that probabilistic thinking helps teams make better decisions in uncertain, fast-changing environments.
Follow SourceForge:
SourceForge.net - https://sourceforge.net
SourceForge LinkedIn
SourceForge X (Twitter)
SourceForge Facebook
Interested in appearing on the SourceForge Podcast? Contact us here.
The SourceForge Podcast is the world's largest B2B software podcast.
Hello everyone and welcome to the SourceForge podcast. I am your host, Bo Hamilton. Now, we're going to talk about why identity has become such an important issue for B2B software companies and how AI is making it even more complex. Now, for a long time, identity was treated as a fairly straightforward part of building software. You give users a secure way to log in, manage their accounts, and move on to the features that make the product useful, right? But for B2B software companies, identity now goes far beyond the login screen. As they start serving larger customers, they have to support entire organizations, each with its own users, admins, login systems. You have to incorporate permissions and integrations and security rules. Increasingly, the organization and not just the individual user becomes the main thing the product has to manage. And that brings up some pretty tough questions. How do you keep each customer's data and access separate without creating a custom setup for every company? How do you give the same person different permissions across different organizations? And how do you securely manage service accounts, automated workflows, and AI agents working alongside human users? These questions are just becoming even more important as companies move AI agents from early experiments into real-world use. And AuthZero has recently expanded its AI agent tools to help developers verify agents, limit what they can do, connect them securely to tools and APIs, and just keep a clear record of their actions. And joining me to explore all this are Gareth Davis, Chief Product Officer at AuthZero, and Monica Bajaj, Senior Vice President of Engineering at Okta. And in our conversation today, we're going to discuss why identity has become such an important part of growing a B2B software company, where teams often run into trouble when adapting consumer identity systems for enterprise customers, and then why the next generation of SaaS will need a shared trust model for people, organizations, machines, and of course AI agents. So we've got a lot to get into. With that said, let's go ahead and bring in the guests of the show, Gareth and Monica. Welcome to the podcast. Glad you could join us. Thanks so much, Bob. Wonderful to be here. Yeah, and welcome back to the podcast, Gareth Listeners. We had a full conversation about identity automation and AI last year that I highly recommend you listen to. This episode will sort of build upon that conversation we had, but focus more on the B2B SaaS angle. Now, before we get into the weeds on B2B SaaS identity, I do want to zoom out for a moment. Identity used to feel like a back office technical issue, but now it's something CEOs and business leaders are paying really close attention to. In the age of AI, especially agentic AI, you can't really separate the technology from the identity and access questions that come with it. One report that came from Palo Alto, and it found that machine identities, including AI agents, now outnumber human identities 109 to 1. It also found that nine out of 10 organizations experienced a successful identity-related breach in the past year. So this clearly isn't just a login box problem anymore. It's something uh companies really need to think seriously about because AI agents are here and they're only growing in uh number. So uh my question is, Gareth, if you want to tackle this, what has changed and and why has identity become such a strategic issue for B2B software companies?
SPEAKER_01Again, it's great to be back by thank you. I think this absolutely builds on the last conversation. To answer your question, really, I think what we're seeing is that identity is being elevated from this functional necessity. You need authentication. You know, in a B2B scenario, you're you're a software company, you're selling to customers, you need SSO, you need them to be able to onboard and manage the life cycle of their end users. Used to be this very functional thing, and it was uh you know a little bit clunky and just a necessity, a cost of doing business. But what we're seeing is identity is really evolving to be uh uh an enabler, a strategic enabler of revenue growth. Uh, and this is happening for a couple of reasons. Firstly, software is getting uh more sophisticated in how organizations think about managing their users and access to resources as SaaS moves upstream into larger enterprise customers. Uh, ultimately, if you don't have strong foundational capabilities, whether it's around SSO provisioning, lifecycle management, delegated admin, and the tools for your customers to manage their entire workforce, then really you're adding friction and complexity to your end customer. And that's just handbrakes on your business growth. And then when you compound that with the fact that 96% of enterprise RFPs for B2B software include pretty stringent and growing security controls around identity, given how foundational identity security is to application security, we're seeing that in order to win and scale and grow your business, this isn't just a basic login box. There's a core set of capabilities that are required in order to be deemed enterprise ready and to uh win and grow that business. And then the last thing I'd say is obviously the shift into AI. Software is no longer about just enabling the human customers, right? The workers within your customers' organizations to be productive. Um, we're seeing SaaS evolve with intelligent workflow automation, with first and third-party agents. Uh uh software companies are building intelligent agents that are going well beyond just simple copilots, to true orchestrators that are helping the human users get work done. And that requires access to internal MCP servers and APIs, to customer resources, and to third-party systems. So now you have this all this complexity of managing human users, agents, access to a myriad of different resources. There are complex uh uh governance and permission hierarchies that need to be managed. And this is just a huge potential bottleneck for any development team. So um, if you get it right, you can grow revenue, you can accelerate the business, and you can innovate at pace. Uh, but if if not, it becomes a massive bottleneck and uh and it slows down your business and impacts the rest of your product roadmap.
SPEAKER_00Absolutely. Yeah, I think that's a good thing to underline is just the the the growth multiplayer side of things, right? Identity has to get the right priority. And if businesses prioritize it as they should, um it can it can drive revenue, it can increase their competitive edge and ultimately reduce the headaches by reducing uh the risk uh by not getting it right and not prioritizing where where they should. Um so very very well said. I I um uh Monica, I want to pose this next question for you. Um a lot of companies in our audience, they they they started out uh perhaps as consumer-facing uh and are now selling to businesses directly. Um and on paper, I know that it's it's sort of the same login box, right? There's still like a username and still a password, that sort of thing. But clearly in the the the two worlds have sort of diverged. I noticed AuthZero actually uh rolled out B2B specific plans this year. Um I'm curious what actually makes identity so much harder when you you pivot from B2C to B2B?
SPEAKER_02So if you look at like, you know, the tenancy, the three three big areas which I focus on is tenancy, boundaries, and data modeling. Those are like very important to note. Uh in B2B, the organization becomes a first class object in your application, not just the metadata field on a user or record. Uh, because you are not just authenticating a user in isolation, you are modeling and securing an entire customer organization inside your product. Uh the second one is identity needs to understand the organizational context, like which company a user belongs to, their role, what they can access, and who can administer that environment. And in practice, every customer organization demands a bespoke experience at times, like SSO connections, provisioning. Uh, and the same user can also exist in multiple orgs, which compounds the whole complexity as well. So identity ultimately becomes the tool to define something larger, which is tenancy. And the boundary between customers and the rules that govern the access across the resources, administration, features, and even compute, uh, that is very critical these days.
SPEAKER_00So I imagine a lot of founders are listening and wondering like, how do I know when this you know becomes my problem? Like, what do I do about this? From what I've seen, I uh enterprise deals often don't fall apart because of the product itself or the price. They often get held up during the things like you know, the security review when when customers' IT teams, you know, they start asking whether the software supports things like uh SSO, single sign-on, um, automatic user provisioning, um, and their like existing identity system, that's kind of where the hangup lies. Um, when does a growing SaaS company usually realize that its its identity setup is just no longer good enough for what large clients organizations expect?
SPEAKER_01I mean, listen, it goes back to that problem and and both opportunity of revenue growth. I think when you find that the value prop of the core product is resonating, right? Let's say you're uh uh uh you know SDR software, for example, and you know, you're helping sales teams uh uh you know really solve critical business problems around enabling their SDR, BDR teams, and the value props resonating, and you've you've you know you've nailed the solution, but then uh you know, post the initial validation, security and uh procurement or IT teams can't fathom how they're going to integrate and manage and connect to various tools, you know, ultimately that translates to a lost RFP or a lost opportunity. So certainly, you know, uh um friction and uh uh challenges in the sales process is a is a huge canary in the coal mine. Um I think it's also it happens earlier as well, though. I mean, you know, you'll have customers asking a lot of these questions um uh both at the RFI and RFP stage. And candidly, if you if you don't have a compelling answer for how customers can bring their own IDP, you know, how how does IT provision and manage users via Skim? How do you configure and manage both access to internal and customer resources and third-party tools securely? If you can't answer a bunch of these questions up front, chances are you're just not gonna get the deal. So I think revenue friction is a massive one. It's it's often a primary reason we see we see B2B companies shift from either an open source or a homegrown identity model into an enterprise-grade platform because they recognize that the cost benefit is just immediately clear. If they want to, they want to scale the business, they need to outsource and and leverage a platform that can help them grow and do that at a much lower cost of ownership. Another signal is they're just their own engineering teams are spending too long dealing with support tickets and friction and requirements and uh and paper cuts all over the place that is impacting the core product roadmap. And ultimately, if you're a SaaS vendor and you're spending more time building the foundational identity and authorization policies and guardrails instead of enhancing your core product, then chances are that's a risk. And then the last one is probably with AI. Maybe you've got a decent enough foundation, but suddenly you just don't have a model to be able to understand and govern agents. Um, you need agents to act on behalf of users. There may be autonomous agents acting as first-class identities. They need to access resources across multiple boundaries. Suddenly the agents bring this compounding level of complexity into the mix that breaks traditional I am, CIAM, you know, foundations. And uh I think that's again an another critical blocker to product innovation and revenue growth. So I'd say they're the three main ones we see.
SPEAKER_00Now, like I'm curious, like let's say you start, uh you started landing uh bigger, bigger customers, um, and now each one wants its own sort of set login setup, its own single sign-on, its own security rules, its own just way of managing users. Um, I feel like that's that's where the excitement of winning an enterprise customer can can turn into like the headache of maintaining dozens of custom configurations. Um, how how do you give each organization its own sort of tailored experience without overwhelming your engineering team with the one-off setups? Because you alluded to the engineering engineers earlier and how they're, you know, they could be spending all their time rebuilding login stuff instead of building the actual product. Um, how do you balance the two?
unknownYeah.
SPEAKER_02So piggybacking on what Gareth mentioned earlier, you know, the internal signals are equally important because product and engineering teams start noticing that they are spending time, more time recreating these foundational B2B identity infrastructure rather than building new product features. And ultimately the question shifts from like a technical problem to a business imperative, which is like, how much enterprise revenue are we leaving on the table by not modernizing the identity model? And the mistake, what happens is treating every enterprise customer like a custom implementation. It is manageable at first, but soon it becomes more of an engineering and support burden and it is unmaintainable at some point. The better approach is to build a shared platform model where the organization itself is dynamically configurable. Instead of writing new code paths, the product provides a self-service dashboard, allowing customer IT teams to manage their own identity settings and also following the best practices across the board, because we need to understand that in this journey, we are both the customer and you know, Okta Od Zero as a uh vendor, they are both sharing the best practices. So in this model, we have to be very explicitly clear about the data contract between their IDP and your applications, how users' roles, metadata, map across the board. So that handshake uh at the login moment, like you know, the login handshake is very important. I would say the best products do not just support enterprise identity setup, they make it obvious they should be testable and recoverable for the admin who is configuring it.
SPEAKER_00Okay, gotcha. Yeah. So it's it's you you in other words, like you have to really stop treating every big customer like a like a custom job. Like you make it something their IT team can set up themselves and and sort of uh get out of the way, so to speak. And and um, I also think that point about uh making it easy to just test and easy to fix. Um I I I just I think that resonates. I think I bet the person sitting, it's like setting up the the login SSO on the customer side is just, you know, they're they're constantly terrified of of locking out their whole company and and um the issues that that comes with that, right? Um I want to uh next talk about multi-tenancy. And this is the idea that one software platform can serve many different customers while keeping each customer's data and access completely separate. Um on a uh whiteboard, let's say it can it can look pretty simple. You attach a tenant ID to everything and you sort of call it done. But I know that in reality it gets pretty complicated. And I know that the stakes are pretty high too, because if one customer can see another customer's data, trust disappears almost immediately. Um, so that could be a very very bad thing to happen. Um, where where do teams usually go wrong when it comes to keeping tenants separate and just managing permissions?
SPEAKER_01Yeah, I mean, I think you kind of nailed it in the setup there, Bo. It it isn't as simple as just having a tenant ID on a database and a lookup to apply custom logic. You need to have really strict and and well-defined um boundaries around an organization that are in no means porous, right? It and it's much more than, to be clear, than just data partitioning. Uh, I think of tenancy, maybe a helpful analogy is to the concept of a shipping container, right? In in the past, if you wanted to move goods and services around the world, right, you whether you're shipping a piano or a bunch of bananas, right, if if you didn't have a shipping container, which is a uh a modular, standardized, internationally understood container for goods, right, ships would have had a whole bunch of complexity loading goods on and loading them off and ultimately um a lot of pain and a lot of associated cost. And then you know the global freight industry basically solved that problem by creating these standardized boxes that are uh absolutely uniform uh wherever you are in the world, regardless of the ship, regardless of the provider, everyone can load their goods on and they can move them from A to B. And so if you think about tenancy as constructing the shipping container, organize your customer A versus customer B may have wildly different requirements. Or customer A may be a multi-uh national conglomerate with multiple complex business units. And each business unit may have local or regional subsidiaries. And so you'll have this kind of grandparent, parent-child relationship where you'll need to persist certain authorization and access policies as you move down an organization. But in each environment, you might need different local logic, data partitioning, access and governance rules. And so rather than again thinking about simplistic authentication and access, tenancy becomes this architectural concept, this very simple way for a B2B company, a SaaS vendor, to set up their customers in a way that gives their end users, their ad IT admins at their customer, the control to uh manage the boundary of their own internal users and access and resources and agents. And so tenancy becomes much more than authentication. It impacts and recall that now everything needs to be uh organizational aware. So in this tenancy model, you have this concept of organizations. So now that means that you know, all your access tokens and all your auth logic and your permissions, they all need to understand the context of that container. So tenancy provides this very scalable framework to ensure rigid control, no leaking of data or um risk at the boundary or perimeter of the organization, but enough flexibility for the customer to set up their uh their users and manage their organization in a way that is self-service, frictionable, frictionless, and ultimately scales. And so that means you spend less time dealing with complex custom configs for your customers. Your customers have a much more scalable framework for onboarding, managing humans, agents, resources, and then you can get back to the core business of innovating and growing your growing your product and your business.
SPEAKER_00I love the the shipping container analogy. I think that's a great way to to phrase it and illustrate it. Um, I mean, the the it what you're saying kind of is like the the walls, the walls between customers have to exist everywhere, sort of like in the shipping container, I guess, in the permissions, in the access rules, all of it. Um otherwise that the that ID tag isn't really protecting anything. And sticking with permissions for a second, um, most teams, I feel like they they start with a few basic roles. You have admin, you have maybe the editor and the and viewer. Um, what's the difference between that simple approach and the more detailed, like organization-specific access controls that that modern B2B software needs?
SPEAKER_02Yeah, so if you look at the traditional RBAC model, right? Role-based access control, it answers the question uh what the user can do. But in B2B SaaS, the real question comes up is like, what can this user do within this specific org under this specific scope? That leads to more of granular-based access. And the same person can have different roles and permissions across different uh customer organizations. So access has to be organization aware and not assigned globally. That's important. Uh enterprise customers also have complex hierarchies where different admins manage different users, teams, or regions uh depending upon the varying level of uh levels of authority. Umganizations aware access controls let you express those rules more clearly, making it possible to enforce the uh real-world use cases as well. So that is the difference between when we have roles and where we have a real B2B authorization model. So that is the key in this case.
SPEAKER_00Yeah. Could you uh I'm curious if you have like a real-world example, like I'm thinking of like a consultant who might be an admin in one customer's workspace, but only a viewer in another. I think that's sort of where the difference becomes much easier to maybe understand. I don't know if even uh example to illustrate.
SPEAKER_02So basically, um the way to look at it is like, you know, when if a customer has a tenant and a user is associated with it, depending upon like, you know, what level, what organization it belongs to, to what resource it is able to access with what permissions. I think that is very important to understand in this case, right? That's where the whole uh relationship based access control comes into play as well, because the finer and finer the access can uh authorization goes into picture.
SPEAKER_01A simple example may be, you know, you're a sales manager. Again, I'll go back to like the sales software. And you have, as a manager, you have the ability to uh view all uh leads and opportunities in your team and the aggregate dashboard, but you may only have write options on the accounts that you individually own, right? And so um just ensuring that you've got very specific boundaries around permissions and you know that could be propagated everywhere. But again, in a in an in another environment, the you know, that same user may have a whole different set of of uh of permissions and abilities to be able to delegate and share and you know, delete, et cetera. So um knowing that in different contexts, users will show up with different responsibilities uh, you know, requires a more flexible authorization model so that it isn't just extremely static and and role-based. And you know, this is where we also see things like fine-grained authorization come in. Sometimes it isn't just a crud kind of read, write, delete type model. It may be that you know, user A, so you know, account executive A can access uh, you know, this customer record, but perhaps within the file, they can only see a subsection of the data, right? So you want to strip out access to the more sensitive account data. You want to only look at a certain opportunity data. And this is where things like FGA can allow you to enforce not just uh role-based access at the uh document level, but a relationship-based access. And you can get much finer down to the object under specific scenarios. Perhaps you can only access a given record for a certain duration of time. For example, maybe you have a live uh RFP. So through the duration of team members submitting to the response, people can you know can read or write after the data, you know, the the the document gets locked down. So we're seeing more and more advanced kind of collaboration and authorization policy roll out. That means that it's kind of somewhat separate just from your role. It also depends on the context of the action that's being taken.
SPEAKER_00Um for companies building integrations into customer environments, just how important is it to limit that machine-to-machine access to a specific organization and a specific set of actions?
SPEAKER_02You know, you well said, like, you know, we are living in the agentic world. We cannot escape that. In my opinion, machine identities should follow the same organizational boundaries and least privileged principles as human users. In fact, much more than that. So scoping machines, access to um uh the specific org and ideally to a specific set of actions within that organization reduces this cross-tenant risk and improves security, uh, auditability, and customer trust. That is very key. The architecture also becomes really very important when it comes to integrations, automation, because AI agents are taking more operational responsibilities within the enterprise environments. And sometimes they can go haywire. So that is very important. The future of, if you look at the future of B2B identity, is it's not just about authenticating machines. It's ensuring that they operate within the right organization, within the right permissions, and under continuous governance. Governance has become really top of mind for enterprises because they want to know how the how do these agents are working across the board and what they are doing, how much control they have, and at what point in time they can be abandoned. So that is very, very important.
unknownOkay.
SPEAKER_00So yeah, it sounds like yeah, machines, machines don't get a free pass. There's they got to follow the same rules as humans. Um, if not, you know, have have more. Um yeah, no, I because I can just imagine like uh, you know, a bot has access to everything. Just that just that's the scariest thing um in the whole system.
SPEAKER_01You just can't do that, Bo. And if you think about it as well, is we move beyond, you know, agents are are not service accounts, right? What we're seeing are non-deterministic behaviors from agents. So a user will have a prompt. So let's say I'm in uh some sort of business intelligence software, right? In in the past, I would have constructed SQL queries, let's say, to interact with data, or I'd use a drag and drop GUI to try and you know overlay data and understand, you know, sales trend reports, for example. Now, obviously, as we as we all know, we've got this natural language prompt. And in the prompt is some intent. The user's trying to get some sort of insight, but the the way each user will express that in natural language will be wildly different. And so now an agent needs to insert, basically, you know, introspect that prompt, defer and understand intent, right? It needs to access resources because if you think about it, the the the limit on intelligent agent outcomes isn't just simply the underlying LLM or the amount of compute that you throw. Of course, as models become smarter and smarter, model enhancement yields higher outcomes. But I'd argue the biggest enabler of enterprise value when it comes to agents is access to resources and context, right? An agent that doesn't have access to information simply cannot solve the task or deliver meaningful value to the end user. And so suddenly what you find is that identity isn't just making sure that the agent now operates on behalf of a user or has a sovereign identity that you contract for governance and compliance and control, or have a kill switch for the agent. So if it goes rogue and hallucinates, or or you find that there's been a threat vector and the agent has been compromised with prompt uh injection or tool poisoning or whatever, you can stop it. The authorization boundary is now the enabler of agent value because if you if you think about it, accessing the right information at the right time is what makes the agent smart. And to do that, this is all an identity problem, right? Should that agent have access to that specific file or folder that's you know exposed through that NCP server or API? You have to you have to govern all of this, but because the agents are non-deterministic, you don't know exactly how they're gonna behave. So not only do you need to build identity and access in for these agents, we now have to look at the intent. We have to look at the behavior of the agent at runtime, we have to think about the risk that's being introduced relative to the reward based on how the agent's gonna respond. So we have we have a totally different uh security uh uh dynamic at play here, but also a real dynamic where if you can securely give agents access to the right resources, whether that's the end customers' own internal resources or third-party resources, that's the difference between effective agents and effective B2B software and pretty simple co-pilots. And that requires an authorization and an identity model that's much more flexible and intelligent and can govern and manage risk at runtime. And that that's a transformation for the whole identity architecture of most businesses and and and problems that the average B2B company just, you know, that's a hard thing to solve for.
SPEAKER_00It is a hard thing to solve for, but you know, it sounds like you um you're thinking about all the right things and putting the right sort of barriers and checks and balances in place. So you two, are you two are talking to uh enterprise buyers all day long, right? And I know this this shift is happening fast on the product side too. Um uh Okta announced a whole new wave of auth zero for AI agent uh capabilities back in in May, I believe. Um things like auth for MCP, model context protocol, and uh token vault with organizations support. So, so feel free to plug what your team has shipped here, Gareth. Um, what are what are customers asking for today that they just weren't asking for a year ago?
SPEAKER_01Yeah, so uh thanks, Bo. So, you know, we we've been in the business of both B2B and B2C identity for for quite a long time now. And we power some of the most innovative uh B2B and AI startups from labs all the way to, you know, folks transforming the SaaS landscape to some of the biggest software companies in the world. And I think um the investments you've seen us make, we went GA with our Aut Zero for AI agent product suite back in November. We've shipped Auth for MCP, um, we've shipped agents as principles. We've seen that agents need these first-class identities that you can manage through the entire life cycle so that you can explicitly govern and control and enforce authorization policy for the full life cycle of an agent, whether it's a short-lived ephemeral agent or a long-living agent or a fleet of agents orchestrating and swarming their own agents, you need the ability to assign and manage identity through that life cycle. So we've been pretty quick in our in our iterative releases to launch things like Auth for MCP, to expand into agents' principles, um, to expand our, as you mentioned, token vault support for organizations so that agents don't have access to overprivileged or static credentials, you know, hard-coded into apps and creating, you know, immense security vulnerabilities. And instead, agents get very defined, short-lived, tightly scoped access tokens explicitly for the resource and the task in question. And uh, in addition to all our work on fine-grained authorization, we now have a very robust framework where a developer can basically assign identity to an agent. They can govern exactly what resources that agent can access. They can define what actions it can take, including bringing humans in the loop for authentic, you know, for a step-up authentication process for more sensitive actions. And we can now fully govern and manage access to resources, not just APIs, but NCP servers and so forth. So we've we're excited that we've got, I think, a pretty robust foundation and toolkit. And then uh as we look ahead, I think we're excited about some of these more advanced runtime security, intent-based permission constructs where we have to not just predefine authorization policy prior to the agent taking action, but we have the ability to at runtime understand how the intent of the user based on the prompt, the behavior of the agent at runtime and how it's calling various tools and APIs and enforce the right policy so that we can ultimately increase the value or the intelligence or the impact of the agent. We can make agents smarter by connecting them to the right resources and do that without increasing the risk profile. Because in the past, if you wanted to make the agent smarter, you had to fundamentally trade off some of that risk by giving it more access or more scope. And we think that's a problem we can solve and enable developers to have their cake and eat it by making agents smarter, but also safer. So um there's a tremendous amount we've been doing. There's lots more to come. I'll perhaps stop there. But all of that is so that our customers can build uh really intelligent, agentic uh capabilities into their products and also help their end customers uh connect resources and scale their own use cases.
SPEAKER_02I would like to add here, uh, make it a little bit more simpler in case of like, you know, today, uh if you look at like a year ago, identity was all about letting your customers employee login. That's it's simple, right? But today it's all about securing this whole mesh of humans, agents, autonomous AI agents, like automated workflows, who are the players inside this whole entire ecosystem. So it is very important that we look from that lens. And the way I look at it is like, you know, the three-way, three things. Like one is the self-service is the new default because customers expect their IT teams to independently configure old SSO, manage permissioning, uh, troubleshoot the routing issues. The second one is, of course, the ecosystem interoperability is also coming into play, where you know, you want customers want identity to adapt to their operating model. Um, and then the third is what Gareth mentioned about intent and behavior, uh, but also the rise of AI agent governance is very important as well. Because we want to design these architectures in such a way that non-human identity, when they do the delegation, we can monitor that as well. So that is really, really important uh across the board in terms of authorization, delegation, intent, and behavior.
SPEAKER_00Well, it's it's really exciting and fascinating to hear about everything you guys have shipped thus far, what you're working on, and and just like thinking about how fast uh the bar has moved just in you know the last like couple of years. Now, when teams finally sit down to modernize their identity stack, you know, they they they like what um they're hearing in this podcast, they want to start incorporating some of these of these tools and capabilities. Um, where do you see them sort of underestimate that the complexity the most? Is it the the human users, the machine identities, or that sort of messy overlap where the two collide? Like I'm just thinking of like scenarios like an AI agent acting on behalf of a specific employee inside a specific customer organization with that employee's uh permissions. It just gets pretty messy and complex. Um and that that's just three layers of identity uh stacked on top of each other. I'm just curious, like where where do you where does the complexity lie?
SPEAKER_02So today, uh, if I look at this, I would say the overlap between the two, right? The most teams understand by now that human identity in B2B is complicated. What is still underappreciated is that non-human actors increasingly need to participate in that same model. And companies are picking this up. But once you start combining the human authority, uh organizational boundaries and machine execution, identity becomes much more nuanced. And the hardest problem in building this coherent across the system where users, organizations, admins, service accounts, uh, and agents are all uh operating in the same plane field. We need better trust, we need better authorization framework, that is the key. And the teams who are thinking from that lens are going to be better positioned across the board than the ones who are going to treat this as separate problems. Because that's where we need to consolidate and understand what else can go wrong in the workflows.
SPEAKER_00Well, we've covered a lot of ground thus far. Um and I I've got um a few more questions or so to ask both of you. Um, but I want to I want to ask um what's a common misconception about B2B SaaS identity that you wish more people understood?
SPEAKER_01I think the misconception is it's about authentication and simple access and onboarding of users. And the reality is that the organization is this much more um critical container of the local business logic of your customer. And whether you're managing access, um, you know, enabling IT teams to be able to onboard, manage, control their entire organization, whether it's about enforcing security and policy to keep uh customers secure, or whether it's about really uh enabling more intelligent software, helping the agents that are now running in your product become smarter by accessing your customers' resources in a way that doesn't create risk and liability. Um, identity becomes much less about just the individual user and much more about the organization, as again, this container for critical business logic. And when you when you get that set up right, not only does it decrease the end burden on your end customer, it helps you win more deals, right? You you are more secure by default, and it allows your products to get smarter through the access to resources and enabling users to get their jobs done more effectively. So the misconception is that it's this kind of functional, must-have basic building block. And I think the reality is that it's increasingly a strategic enabler of revenue growth. It's how you win deals, it's how you move up market, it's how you ensure strict data residency or control and separation, and it's how you enable your end customers to be successful, which translates into happy customers, more growth, more adoption. And as AI comes in, it's just getting harder. So if you have a partner can that can help simplify that for you, um, it frees you up to focus on the things that really matter, scaling your business and your product more broadly.
SPEAKER_02Yeah, I want to add uh one more thing to you know what Gareth mentioned. Like, you know, identity is definitely a critical business enabler, no more a defensive security feature. Uh and a weaker identity model can show up in many ways, like, you know, not just the revenue part, the delayed deals, but a lot of support burden, a lot of slower onboarding, engineering time which is being spent on admin work, and there is less room to innovate uh across actual product. So that is very important to keep in mind.
SPEAKER_00Yeah, yeah, very good point. I um I'm I'm thinking I I want to, I think that's a good takeaway for listeners. Um, and I also want to give you guys another chance to sort of um hammer home something for listeners, something they can sort of screenshot. Um, if if a if a fast-growing software company sort of came to you tomorrow and you could give them just like one piece of advice, I'm curious, um, what would you tell them to focus on and just get right earlier than they they think they might need to?
SPEAKER_01Yeah, I I would just think about getting that organizational model right from out of the gate. As you scale the deployment of software within, you know, the end customers they scale within their own environment, getting the architectural approach, getting the foundations and access right on day one is what sets them up for ease of adoption. When you buy software, you're buying software to solve a business problem. And generally speaking, the more users that have access and get time to value, the faster you reap ROI on that software investment. And so if you think about the organization as a framework for enabling your end users to see value quickly, and it can be configured in a way that scales based on your organization and it can be secure, then you're setting yourself and your teams up for success. And uh, you know, you don't have this painful migration onboarding process, tons of friction and support that just plagues SaaS adoption. So get the organizational model right from day one and have a framework that scales so you can get back to doing what matters most, which is growing your business.
SPEAKER_00Well said, yeah. Get it done on day one because you know, uh bolting it on later just just means more of a headache, more of tearing things out, redoing huge parts of your product, um, and you know, foregoing uh causing more issues with with bigger deals and integrations and whatnot. So very well said. Um, Gareth, Monica, this has been fantastic. I want to just end this episode with a a few thought leadership questions that pick your brains about, you know, your your experience in the industry. I'm curious, uh, what qualities do you think are essential for someone aspiring to be a leader in today's business world?
SPEAKER_02The way I think it is like, you know, the two important things. One is having a cognitive flexibility is very important. And why I say this is like we are way past, like, we can't have like a three-year plan. Like because the macroeconomic shift, it can change everything. Uh the ability to hold these perspectives, swapping the mental models on the fly as the technology shifts are happening, the businesses are changing, and making those highly critical decisions with imperfect data is very important these days. So that is one. The second part is communication. I mean, communication has been the first principles across the board, more so because it is very important to translate those business metrics for the executive team and the business goals into technical context for your own teams is very important so that they know what they are building, and then you can come, then you can cover the whole, you know, the gap between the boardroom and the code base. So that is extremely important, in my opinion.
SPEAKER_01In the world we're in right now, this current time of AI, it's really hard. The pace of change is so radical that it's hard to truly predict uh what's happening next. And so I think there's this delicate balance of having courage of conviction. You have to form a thesis. As a product leader, you need to have a strong long-term vision around what problems you're solving for whom and why, and you know, how your product and roadmap can deliver long-term value for your customers. And so you have to establish conviction in a space where there's a lot of moving parts. And I think that takes courage. And so, you know, being being able to, you know, form strong hypotheses, and it goes back to the basics. How do you get a kind of a vision and conviction? Often it's a mixture of spending a ton of time in the market with customers, but also taking a step back and thinking deeply about what. The market's going. You can't just ask your customers where to go. You get back into the faster horse trap. So you have to have a deep understanding of where you're going and why. And I think that's often driven by vision and mission and kind of an awareness of your own strengths. But then you have to be flexible because no one knows the answers and um the pace of change is so rapid. So being courageous, I suppose, being flexible, being agile, you know, however you frame it, whilst you've got to have conviction, you also have to have flexibility to adjust as you learn and get new insights. So that that balance is really important. Otherwise, if you're too brittle, just uh things things won't uh play out the way you expect them.
SPEAKER_00Yeah, absolutely. Courage and conviction, uh that have that uh cognitive flexibility, like Monica was saying, and just it makes me think of just the importance of um retaining the ability to think critically in this AI era, um, which you know so much of our mental capacity is being offloaded um to some of these uh automated uh tools and LLMs and whatnot. So being able to think critically, um, communicate effectively, those are all very, very good qualities to have. So very well said. I totally resonate with with both of all those things you mentioned. Okay. And then I want to also ask if you could go back to the start of each of your careers, what's one piece of advice you'd give yourself?
SPEAKER_02Yes, and it I learned this the hard way. Uh, you know, as an engineer by trade, I always used to think that, okay, you know, you have the best technology, best architecture. That's the key to success. The reality is I was wrong because it is very important. Like that is an important piece. Don't get me wrong, that is an important piece. But before that, it's important to understand, you know, have a solid handle on product market fit, business justification, who are who is your persona, who is your under, you know, understanding your customer base is very important when it comes to building great products. So it's a combination, both go hand in hand. But as an engineer, I always always used to think I have the best technology, I can build the best architecture, and I can meet the customer needs. I have to go the reverse way. So I would say that that's the way I think now.
SPEAKER_01It's got to be something to do with curiosity. I think that the gift of the product management craft is how multidisciplinary it is as you shift from strategy to technology to business, and you know, you build and you support and that you play all these different roles. And at the core of it is a need of, I think, deep empathy and obsession with the customer problem. And I think where I've seen myself or teams get unstuck is when you fall in love with the solution instead of the problem. Right. And so really cultivating curiosity, delving really deeply to understand customer needs and um getting passionate, finding your actual energy, like your internal drive and purpose and energy from understanding and tackling big, meaningful problems is, I think, what gives you the fire to be able to, you know, to, to, to build and scale over multiple years and to whether the storms of technology and business shifts. If you're too wedded to the solution, again, you become become pretty brittle and unstuck, and bias comes into the decision process. When you stay curious and you really fixate on a core set of customer problems, I think that's where the best innovation comes, the best ideas, you get surprised by what you learn. Uh, and ultimately that translates into better products. And uh, of course, all of that isn't in a vacuum. Collaboration is critical. Um, you know, PMs don't actually build anything. It's engineering, it's design, you know, it's your partnership with the field. It you have to be highly collaborative and translate your insights around customer needs into language that the rest of your teams can understand and build around. And so um I think that mixture of yeah, curiosity and collaboration, if you can figure that and and just stay wedded to the problem space, generally good things will happen.
SPEAKER_00I love it. I love those answers. Yeah. Stay curious, uh, collaborate, understand context, customer needs, and and I think also that that note about um yeah, the internal drive and just the the purpose, getting purpose from understanding and and sort of tackling the meaningful problems. I love that. Well said. Um, okay, last question. Um, again, putting you on the spot here, but what's a a resource, a book, maybe a podcast, um, it could be a movie or TV show documentary that has a really big impact um on your your leadership style, has really resonated with you over the years. Um curious to hear if anything, you know, know if anything comes to mind.
SPEAKER_01I love to read all types of stuff. Um, I'm probably gonna go for a book, I'd say. Couple uh jump out. For me, um, Inspired by Marty Kagan is for me is like the Bible. There's so many good product management books or or kind of product adjacent books. Inspired is is really a manifesto for customer-obsessed product thinking, and it really encapsulates a lot of the values that I think about around um, you know, deep curiosity and empathy for customer needs and just frameworks for how you how you build and scale great products and do that in a very collaborative way. So all the kind of stuff I've touched on. And then um one relatively quick read um that I read a couple of years ago that has stuck with me is uh thinking in bets. I think it's Annie Duke. She was a psychologist slash professional poker player. The the basic premise of the book is to basically think of um your decisions like uh like you're building a machine learning uh uh algorithm, you're you're effectively predicting and pricing the probability of an outcome with every decision. So the framework allows you to break down your thought process, um, dissect it into chunks, and apply probability weightings to each of your assumptions. And so I think if you think like this, you don't think in a binary deterministic way. Your thinking is grounded in a core set of assumptions that can be validated. And you also have a framework to test and learn after the fact. Was I right around this bet on product functionality or usability or go to market? Um, you know, if I was off, why was I off? How can I make my decision-making process better in the future? So, really, rather than books that tell you, you know, what to think, books that teach you how to think are the ones that excite me. So they're two that jump out.
SPEAKER_02I would add to it, you know, I I have read that book as well. Uh, but the biggest thing which I look at, you know, I listen to a bunch of things like technology, business, leadership podcasts. Uh, that's the easiest way for me to grab. Um, but my the way I look at like, you know, what has influenced my leadership style has always been adapting to change. And the best learning I feel is around us, which we never realize is the nature. The nature changes so fast. Uh, I tend to connect my day-to-day uh leadership style with how the nature is changing. And because nature reminds you about resilience, nature reminds you about the structural flexibility, and also being able to stand and hold that grit uh without breaking. So that is very important. I know it sounds very deep, but I feel like I go back to their first principles of like, you know, there is so much to offer around us, and we don't realize like how much we can embrace that and make it as a part of our lives.
SPEAKER_00I love that. I love that so much. That's very well said. Adapt to change, um, uh, and and kind of just think think big picture and focus on um, you know, the nature and the environment and um and then uh underscoring those those two books, um, inspired by Marty Kagan and Thinking and Bets by Annie Jukes. I'm gonna have to add those to uh my reading list. So I appreciate the the recommendations and hope listeners enjoyed those as well. Incredible insights. I appreciate both of you sharing everything you shared with us. Um and I would love to have you guys back again in the future and just talk updates. Again, this space is just growing so fast, and you guys are really at the at the crux of um you know this AI energetic era and some of the problems that they're um posing for the industry um around identity and whatnot. So thank you guys so much. And um, do you guys have a resource or a link that you would recommend users or listeners uh uh check out before they sign off here? Where's the best place to go to learn more?
SPEAKER_01Well, it's uh.com and uh and go from there. We've got a ton of content for developers across various social forums, including X and YouTube. But uh, you know, if if you're intrigued in any of this, go through the website. There's uh there's a ton there for both developers and business leaders uh or reach out to us directly.
SPEAKER_02Yeah, there are a lot of blogs around like, you know, even the AI stuff, AI and agent tick, how we are making changes in that. So I would highly recommend that. And you know, before we sign off, Paul, like one thing I would definitely say to the audience is the next wave of B2B SaaS identity is all about governing both humans and AI agents under the same trust model. That is very important. Uh, this is piggybacking on what Gareth said about organization. Let's not forget that.
SPEAKER_00All right. Um, auth0.com, go get in uh contact with Gareth and Monica over on LinkedIn. Um, thank you again for everything you guys shared with us and hope to hope to chat with you again in the future.
SPEAKER_02Thank you for having us.
SPEAKER_00Thanks so much. Thank you. Thank you all for listening to the SourceForge podcast. I'm your host, Bo Hamilton. Make sure to subscribe to stay up to date with all of our upcoming B2B software related podcasts. I will talk to you in the next one.