Teleport Extends Infrastructure Identity to AI Agents
Infrastructure Identity Moves Into the Agent Era
Infrastructure identity is becoming a higher priority as enterprises prepare to let AI agents interact with production systems. In this Techstrong TV interview from Black Hat 2026, Diana Jovin, CMO at Teleport, explains why identity can no longer stop with human users and traditional machines. Modern environments now include workloads, services and autonomous agents that need secure access without static credentials.
Teleport’s approach is built around a unified identity layer for humans, machines, workloads and agents. That model is designed to reduce identity fragmentation while helping engineering teams move faster. It also supports zero trust by removing standing privileges and replacing long-lived credentials with short-lived, cryptographically backed access.
Zero Trust Needs to Evolve for Agents
The conversation explores why traditional zero trust principles still matter, but need to be extended for agentic systems. Jovin argues that “verify explicitly” becomes continuous enforcement when agents are involved. Since agents can run quickly and persistently, organizations need visibility into what they are doing at all times.
Infrastructure identity gives teams a stronger foundation for that control. It helps define what agents can access, how long they can operate and which actions should be reviewed. That becomes critical when many agents work together, because individual actions may appear harmless while the combined effect creates risk.
Teleport Beams Creates a Trusted Runtime
Teleport Beams is presented as a trusted runtime for infrastructure agents. Jovin describes it as an ephemeral microVM that embeds identity, access control and auditability into the agent’s operating environment. When the task ends, the runtime expires and cleans itself up.
That model gives organizations a way to apply least privilege, continuous monitoring and audit trails to agent behavior. It also supports a broader shift from assuming breach to assuming misalignment. If an agent drifts from its intended objective, teams need evidence, context and intervention options.
Security Becomes the AI Adoption Gate
The discussion closes with a practical view of AI adoption. Jovin notes that many organizations are still early in the transformation, even if the AI conversation feels crowded. The next phase is less about plumbing and more about putting AI-native practices into real operational environments.
For security and engineering teams, infrastructure identity can help make that transition safer. As agents begin deploying software, accessing databases and taking operational action, identity-backed controls will become essential. Teleport’s message is that trusted agent adoption starts with a foundation that treats every actor as a first-class identity.
Transcript
Hey everyone, welcome back into our Black Hat coverage. We're having a great time, but I have to tell you the truth, I prefer to do the videos up here than down on the floor. We were down on the floor.
That is the most wild, loud, kinetic floor that I-- "Kinetic" is the word, I'll tell you. It's like, that I've ever seen. And this is my 23rd Black Hat.
Okay? I've been to 23 Black Hats, almost 25 RSAs. Wow.
I've never seen a floor like this. This is nuts. But we're here.
We're here with Diana Jovin. Yes, that's right. Thank you.
Got it right. Yep. And Diana's with Teleport, though I found out, and I should've known this, she was with DigiCert in a past life, another company that I like to cover.
But Diana, there's more to Diana than it appears. Share with our audience a little bit of your story. My story or Teleport's story?
Your story first. My story. Okay.
Then we'll go to Teleport. Well, I'm the chief marketing officer at Teleport. Mm-hmm.
Prior to Teleport, I ran product marketing at DigiCert. Mm-hmm. I've been in enterprise software and various flavors of technology for 30 years, 30-plus years, so- I know.
a lot of change in that time. Yeah. There's been a lot of water under the bridge, yes.
Yep. So a few major transformations in technology over the course of those three decades. But having a blast here at Black Hat.
In many ways, what's old is new again, and lessons that you think you learn, you get relearned, and I'm in the same boat, right? We've been doing it. So it is interesting.
You came to Teleport in 2023, around there you had mentioned. Yeah, 2023, yeah. Yeah.
Almost 2024. It's funny. That just about coincides with when I first became aware of Teleport.
And I'll take full blame for it, but give our audience who may or may not be familiar with Teleport, a little of the Teleport story. Sure. Well, Teleport started as an open source project in 2015.
At that time, the company was actually focused on a different area, and Teleport was a helper project for that. But around about six years ago, it was clear that Teleport itself was solving some major important problems for our customers, and so we pivoted to that at that time. And the company then pivoted from being known as Gravitational to Teleport.
Now I see. Yeah. Now I see.
Okay. So the thing that we are about is a category that we call infrastructure identity. And so for companies with a lot of infrastructure, now every company is infrastructure of some sort, but there are a lot that have a large investment in modern infrastructure where either it is running a digital product or service, or it is a division in a company that is, like think about a neobank or something like that, right?
Right. So in those companies, there are often needs in engineering that map very well to what we do. So with infrastructure identity, what we're doing is creating a unified identity layer for humans, machines, and now agents, also workloads, right?
And, the problem that we're solving is one that has plagued identity fragmentation- Yes ... and static credentials, right? If you're an engineering team trying to do things fast at scale or in compliance in those environments, it is very challenging.
Yes, it is. And so by creating this unified identity layer, we enable companies then to solve the problems, remove friction for engineers, and help them increase their engineering velocity. And at the same time, this is what's great because it's different from the DevOps world.
At the same time, we make those environments more resilient because now you remove standing privileges. You remove all the places that identity attackers have been focused on. Now, all this propagates zero trust all the way through infrastructure, and what is also great about the world that we're in today is that it is the foundation that you need, that is a requirement to now layer AI in an effective way on top of that, which is what we'll talk about in a moment.
You can do this by yourself. What do you need me for? But you're 100% right.
But you know, I'm listening to you, and I'm thinking back. As you said, you've been doing this a while. I've been doing it.
We never really solved the infrastructure identification management piece. You think back to things like IBM Tivoli. That's what Tivoli was trying to do, not 100 years ago, but 25, 30 years ago.
Identifying your assets, your digital assets, marrying them to people, and who's using these things. It was a monster, Tivoli, right? People would hear Tivoli, they'd get headaches, right?
You didn't want to deal with it. It took an open source project like a Teleport to kind of bring that into people to let them try to solve this problem. But this is a problem that every time we think we're getting close, it's like you move the goal post, right?
So all right, so now we can map all our infrastructure. Great. Now, and we can give it identity because people have identities.
And it's not just identity, though. What is important here is that the identity is cryptographically backed. Right.
So you don't have a digital thing that can be lost or shared or stolen. Right. And then everything has short-lived privileges that are bound to a task.
So this is the whole zero trust thing. Exactly, and so you now collapse the window that is your blast radius, and you don't have places where people can laterally jump from one thing to the next, right? And it gets into the whole micro-segmentations and all of these things.
The problem is the world keeps expanding on us. The universe, let alone the world. The universe of the things you got to do this to.
Yeah. And that brings us to the agentic piece of it. Yes.
Because now this is blowing it up. Just when we thought, again, we had a handle on it. If you're going to have 100 agents for every person, 1,000 agents for every person...
So two principles here. The first one is you don't want to drop your agents in an environment where you have static credentials and standing privileges, right? They'll never work.
They work fast, and they are persistent. They don't stop, right? No.
So you need that solid foundation, and you need those agents and your humans and your workloads and your machines to all be interacting with one another, so they all have to be first-class actors that can connect. Okay, but the thing that I think is really interesting about the place that we're in, people keep talking about zero trust and agents. Right.
The thing about zero trust and agents is that zero trust is necessary, but it is insufficient. But the three principles that have governed humans and machines have worked really well for the last few decades, right? So let's talk about how you now extend them to agents.
So take the first one, verify explicitly. Okay. For agents, the idea that you verify at a gate is incorrect.
What you need to do is enforce continuously. So you need to have an eye on them at all times, right? You need to manage what they can do.
You need to bound the surface area in which they have autonomy. And so to do that, we've introduced a product called Teleport Beams, which is a trusted runtime. Okay.
So this is a microVM that embeds identity and access control and allows you to integrate with the target resource using- Is that ephemeral like it lasts for a given- It's ephemeral. Okay. Got it.
And so now when it expires, it's gone. It's gone. Right?
So you don't have anything hanging around that could compromise Beams. And it cleans itself up. Exactly.
So now take the second principle, which is least privilege. Use least privilege, right? Sound security.
So for agents, you need this, but what you actually need is to bound collective autonomy, meaning, let's say you have 10, 1,000, 10,000 agents that are governing a database. They each can operate according to their individual permission set, but if collectively they individually take behavior that is collectively problematic, you can see how you might have a bad outcome. Yes.
So you need to be able to manage groups of decisions, right? So that gets into how do you do classifiers and aggregate, roll up an individual behavior into group behavior. The third principle- Actually, before we get to the third principle- Yeah ...
something on the second. This is one of the neat things, or potentially not neat things about the AI and agents, is they have a way of chaining together these little things to get what they want done, right? So, the hugging face thing.
They found a zero day, not by finding a zero day. They put together a chain of kind of relatively minor, meaningless things, but used it In total to make a zero day. Yeah.
That's what we're talking about here with the second piece of it, right? Mm-hmm. And again, this, and I feel like I'm compelled, I got to say this, it's not that these agents are evil or they don't have bad ill or intentions, they just do their job, what they're told to do.
Yeah. It's up to us humans to define, and that's what we're talking about here. Exactly.
How do you create a harness, right? Yeah. How to harness behavior at speed that is now governed, right?
Exactly. That's what it is. All right.
Yeah. Let's go to number three. Number three.
Number three is assume breach, right? So this is still true, but with agents, you have to now extend that to assume misalignment. That at some point, the intended objective, you'll have departure from it.
And so there you need to have a way to first have attestation of what the objective was- Sure ... and then second, be monitoring and scoring what it's doing so that if it diverges, you both have an appropriate alert where you're not flooded with alerts- Mm-hmm ... and you can decide how you want to intervene.
So for some people running infrastructure, that does mean some sort of intervention. For others, it is they just want to know about it because maybe it is a problem to shut down the infrastructure. Right.
Maybe that problem may be bigger than the problem you're solving. Exactly. But now you can see how you have the Zero Trust foundation for your humans and machines, so you can now extend these principles to how agents actually behave, and they can interoperate as first-base class actors.
So that's the surface area that we're trying to solve. We have more than 650 customers. Using Teleport Beam, using- Using Teleport.
Yeah ... or just Teleport itself. Just Teleport, yeah.
And then, the open source project has... We still offer a community edition that is open source. Yeah.
So- Do you have any idea on users on that? No. I'm going to bet it's more than 650.
Yeah. Those are our commercial users, right? That's what I'm saying.
Those are commercial. There's a broad engineering community using Teleport, and one of the things I think that is different about the world that we live in is that the security professional is living inside the engineering organization. So it's an infrastructure security organization that is tied together with what the engineering objectives are.
And in this world where now the digital realm is so tightly coupled with the physical realm, right, this is becoming more and more important. Absolutely. If you don't mind, one more area I want to touch on.
I mentioned how frenetic, kinetic, the Black Hat show floor is. Yes. Mm-hmm.
What do you, and agentic is the topic on everyone's mouth and mind. What's your take on it? What are you seeing here?
Look, we've seen waves come through security and technology. You've seen, well you've lived through them. Yeah.
I've lived through them. The ups, the downs, the bubbles, the popping, and everything else. What's your take on what we're seeing here?
Well, if you lived through the internet transformation- I did ... right? Yeah.
There are things that are familiar, right? There are ways that AI is offering transformational opportunities. There are ways that it can drive efficiency.
I think that the thing that is useful to companies now is to begin investment in AI-native practices- Yeah ... because by doing, you learn. In our world that we're focused on, a lot of the AI discussion is around AI tooling, right?
AI IT- Yeah ... or how do you deploy models internally? We're focused on what happens is when you put agents in infrastructure, because not too far from now, they will be deploying software.
They might be purchasing software. Maybe we'll have a Black Hat where the humans show up- Right ... and there's an agentic Black Hat happening.
I was just going to say, maybe there's a separate Black Hat for them. We'll have a leaderboard, right? Black Hat agentic.
Yeah, with a leader... Don't laugh. It could happen.
It's likely to happen in our lifetime. Right. But, there are people out here, like I meet a good swath of people.
And some people are like us. We could talk about this all day. " And then there are other people who say, "Oh my God, I'm so late to this party.
I'm done. I'm toast. " Yeah.
What do you say to organizations who maybe are feeling a little late to the party? There's parts of it that are just starting, right? I think the last few years have been about the plumbing.
Right. Right? Now it is about the transformation.
What works, what doesn't work. Yeah. Where are we headed?
How do you, I think ensuring security in a world, the world that is being shaped by AI, is one of the most important things you can do. Absolutely. And if history is any guide, when security shows up, that means it got real, right?
Because we're never the first to the party, right? And that's just the pulse of that. Well, except historically, engineering and security have been separate.
Right. Right? Now you're the first spot.
Now they're beginning to get there, right? That is the first time. Peanut butter and chocolate.
Absolutely. Yeah. Good for you.
Now, last question. I promised, I said last question three times to you, but this is really the last question. People who want to stay up on this, find out what, keep in touch with what Teleport's doing, check it out, what's their best kind of on-ramp?
com. There you go. So, that's the- Go Teleport ...
best place to start. Yeah. And go right to there.
Yeah. Anne, thank you so much. Thank you.
I appreciate it. Nice speaking with you. Enjoy the rest of your Black Hat.
Thank you. You too. Hey, we've got more Black Hat coverage.
Hope you're enjoying it. "