Tackling Over-Permissioning with Oso CEO Graham Neray
Graham Neray, Co-founder and CEO of Oso, shares his journey from MongoDB to establishing Oso, which focuses on a unified permissions layer for software applications. He highlights the challenges of managing permissions and the issue of over-permissioning. With the rise of AI agents, a refined approach to identity and access management is essential. Oso targets growth-stage B2B SaaS companies and has strong backing from notable investors.
Transcript
Hey, everyone. Welcome back here to Tex Trunk tv. You know, I, I'm recording this on the day of my birthday, and it's a funny thing as you get older.
This is a, this is a first for me song. I want to call it out. My next guest is a, is a gentleman named Graham Neray, N-E-R-A-Y.
I have a good friend named Phil Neary that I've known from the tech world for, I don't know, 25 years, maybe more. And I've seen Phil go through several different companies as I have. And, you know, but you stay in touch, security guy, all that good stuff.
So it turns out Graham is Phil's son. So this is the first time I've had the pleasure of actually interviewing one of my friends' sons or daughters here on, on, uh, on our show. So, Hey, Graham, you got a, you got big footsteps to fall in there, my friend, but welcome to Tech Drunk tv.
Thanks for having me pumped to be here. Um, so before we jump into Oso and everything you do there, or Oso, I, let's hear a little bit, you know, so the last time your dad took, I'm only kidding, your dad did tell me about you, but, um, tell us a little bit about your, your adventure to how you got here today. Sure.
So I'm, I'm co-founder and CEO of Oso. Um, we're a unified permissions layer for humans and agents. Um, but I haven't been working on permissions or agents for my whole career.
Um, so before starting Oso, I worked at a company called MongoDB for about seven years. Um, when I joined there, we were still pretty early on, so doing about a million or so in revenue. By the time I left, we had gotten to about 250 million in revenue.
Um, and I kind of split my time there the first half of the time, building out the go-to market side of the business. So first the marketing org, then a function to scale the sales org. And then I spent the second half of my time there working for the CEOs as chief of staff.
Um, I kind of knew like what I wanted to do at that point was go and start a company. And so I treated that kind of like a, an apprentice trade wherein I gave him my life for two to three years. And in exchange for that, he gave me the opportunity to learn all the things about building and running a company.
Um, and so that's, that's more or less what we did. Um, in that period of time, we launched Mongo, Debi Atlas, which is now doing over a billion in revenue, helped take the company public in 2017, built the first product growth team. Um, and then when I left, um, when I left there, uh, my old boss, Dave, became the first investor in Oso.
Really? Very cool. That's kind of how I got started.
Oso. Excellent. What a great story.
So let's talk about Oso. Look, I've interviewed literally hundreds of, of entrepreneurs. I've, I'm a multiple time, you know, founder myself.
No one does it. No one wakes up at the end in one morning and says, Hey, I think I'll start a company today. Right?
There's gotta be this, this passion involved, this commitment. There's gotta be a belief that in some small way what you're doing will somehow make the world better somehow. What, what's that passion for you with Oso?
What is, what drives you on it? I feel like somewhere along the way I kind of developed this point of view that like the things that give me fulfillment in life are those that are extremely hard, where I get to work with people who only want to execute at the highest level and where there's a chance to win. And so there's all these different kinds of, like, founders out there.
Like you'll meet the, you know, the archetype I have, you know, I have one friend he left, uh, he left, you know, x, y, z fang company and wants to build the kind of system that they had, but, you know, for, for the market. Um, and you know, I know there are people, they're like, I have this problem that like, you know, if I don't sleep, you know, I won't, I won't sleep until I solve this problem whether or not anyone pays me to do it. And that's like a different kind.
And I think I'm just really an intense entrepreneur that likes infrastructure. And maybe I like technology because I grew up with it around my dad. I'm not really sure why.
Um, but, uh, but that's kind of it. And, and I was listening to this, um, interview with, um, Toby, the founder of Shopify, like a week ago, and he said something like, you know, you should be so lucky as to fall in love with as to find a problem that you can fall in love with. Um, and that really resonated with me.
Um, so I don't know. I think that's sort of how I get here. Absolutely.
So what is the problem you fell in love with? Yeah, so, um, as most men in their thirties do, I fell in love with permissions. Uh, no.
Mm-hmm. So, uh, we, we were starting to build a different product. It's not even worth describing because I can tell you that no one wanted it.
But in that period of time, people started asking us about permissions specifically. They started to say things like, you know, we have a full team that's been working on this for a year and a half. It's, we're still not solved.
You know, our permissions, uh, are specifically complex, more complex than anything you've ever seen. But I heard that from like five people in the same week. Um, and so, uh, at the time I kind of thought permissions was a solved problem.
Like, it, it's not a, strictly speaking, it's not a new problem. It's, it's been around since, like, it, it's as old as Unix, so there's nothing strictly speaking new about it. And for a while I actually just brushed it off as like, I don't know, that sounds like, I don't know, someone else's company or something.
I think that's a dumb idea. Um, and it turns out that actually it's not such a dumb idea that like every single company on the face of the earth has to build this invisible mechanism that sits behind their, uh, their application to govern who's allowed to do what and see what, and everyone builds it custom and everyone spends millions of dollars a year in engineering effort doing this sort of thing. And that, you know, that makes no sense to me.
Um, combine that with the fact that all these systems really are not built or prepared for what agents are bringing in the next few years. And yeah, I could fall in love with this problem for a bit. Absolutely.
So, so look, the, the identity access management roles and all that, there have been attempts to to productize that, right? Yeah. Um, I mean, to a certain degree, you know, uh, Microsoft's ad active directory, you know, like it or hate it, try to tackle this.
Yeah, yeah. Federated auths. And then, but the, the, what most people kind of recognize is that there's really two issues here.
There's identity and then there's access, right? Just 'cause I know who you are doesn't mean I could fine tune or fine grain what access you have. That's Right.
Right. And and access is not an all or nothing. Correct.
Or it shouldn't be anyway. Unfortunately, in too many cases it is. That's Right.
And, And, and we, we got trouble. And then, you know, Graham, you add in an agen AI future and all that, this promise is to bring to it, to me it's akin to what we tried to do with identity when we started doing non-human identity, right? Yeah.
All of a sudden we were pulling our hair out of our head because we had 6 million people, but now we've got 6 billion iot or connected devices. Yeah. And we've gotta worry about those as well.
Yeah. Um, well, it's the same thing. You think that was bad?
Wait, now we're gonna have 6 trillion agents running around. Yeah. Right?
Agents, agents don't behave like humans. No. No, they don't.
So I was, um, so I, I had this, uh, I have this hypothesis that like we tolerate a gross amount of over permissioning and all the software that we use because there's this like, uh, sort of implicit limit in the amount of time that you or I have to do, like bad or stupid things, which of course does not apply to agents, you know, with the wrong permissions, they could go and do a bunch of terrible and stupid things. And, uh, I was actually, we're doing some analysis on our customer base internally, and I was just looking, we're gonna publish some research on this, but like the customer that I was just looking at this morning, 98% of the per permissions assigned in that application never get used, which says to me that most people are grossly over permissioned. And, uh, that's, that's gonna mean big trouble for agents.
Yeah, absolutely. 98%, that's a crazy amount of number. Um, so I mean, the, quite frankly, the problem is so right, we have zero trust in security.
Well, zero trust in in the lot, right? So we could take the all or nothing approach. I'm just gonna give you no permission, and then we'll turn you on as you need it one by one.
So to play whack-a-mole. Yeah. And then that quickly becomes, quite frankly, a pain in the butt.
'cause every time you wanna do something, oh, I gotta turn it on for you. Yeah. The other side of the house is, you know what?
Yeah, Graham seems like a nice guy, right? I'm just going to give him some like blanket level of, of access, and then if, if he proves me wrong, I'll cut him off here and there and everywhere. But that, that's just the other side of that coin, right?
Where sooner or later becomes a pain in the butt. Yes. Yeah.
So how can we, yeah. Right. So rules are a convenience mechanism for exactly what you just described.
Like, it's crazy for me to go through and enumerate all the permissions I need to assign, and they're man through their manual and they're static. That is to say like, it's not, it's not easy to start configuring new roles on the fly. That's not something that software typically does today.
So our view on this is that the whole model is broken, and ultimately you need to move towards a model of automated leased privilege. And this is effectively the only thing that's going to survive past the next few years of agentic shenanigans. Um, and that's, this is like the main problem that we're working on now at Oso.
Absolutely. And it's a worthy problem for sure. Now, I suspect you could probably use AI to help do this better.
Yes, absolutely. So there's pieces where we're already using AI and oso, like we shipped an MCP server, which can do all kinds of things for helping you, you know, construct authorization, logic, and debug and understand why things are failing, all this stuff. That's great.
Um, I think what's, what's really what starts to get kind of interesting and exciting is when you ask yourself like, how comfortable would you ever feel with an agent assigning permissions an agent itself, assigning permissions? Because obviously that feels like it's subject to all the same risks that we just talked about. 999% of the time correctly, or having a system that's 98% over permissioned and fully exposed to agents.
And this is the conversation that I've been having with a lot of CTOs and CISOs today, where everyone's kind of afraid of the idea of exposing agents to their stuff, but not really acknowledging that the current state is actually not very good at all, and probably worse than what they realize. I agree with you. I agree with you.
You know, Greg, I realize we, we didn't do any housekeeping here. Oso, what's the website? com.
com? Yes. Excellent.
Um, like who's the target here? Who's your target Today? I mean, Oso has customers from startups to the Fortune 500.
Um, of course, that's like what every startup founder will tell you. And it is true in the case of Oso, but I would say that the customers that see the most value from oso are like growth stage B2B SaaS companies. These are companies who are going up market.
They have, they're in highly competitive markets. They need to do things really, really fast. They have limited engineering resources.
And, um, and they care to spend those engineering resources on the kinds of things that make their beer taste better, as it were. Um, and so these are, um, Brex, Vanta, ZoomInfo, product board, web flow companies like this that, um, uh, that really see the value in Oso. And, um, of course, you know, plenty of companies all over the market as well In order for you to manage their access.
I see. Yeah. Are you, what, what level of access to internal systems do you need to give them?
Our customers integrate Oso directly into their applications, the applications that they sell to their customers. So if you log into Brex, if you log into Vanta, if you log into ZoomInfo, all those requests are being authorized against oso in real time. Um, and they've integrated Oso through our SDKs into their application layer.
So we got it. Either they're storing core permissions data in Oso, or they're pointing us directly to it. So Graham thi this is all, I mean, I, I think this is a problem for today.
How do you work though with the legacy identity providers, folks like Okta or JumpCloud, or, I'm trying to think of some of the others, or Microsoft ad itself and all of that stuff. Yeah. Competitor, cooperation, cooperation.
How's that all fit in? It's a good question. And when we got often, uh, we're sort of in adjacent markets, like someone like Okta is gonna help you secure the SaaS apps that you buy for your internal employees.
Oso is for people building software, not buying software. So for the engineers that are building Brex, building, Vanta, building product board, you know, any of these companies, they need a way to solve permissions and authorization, and they're either going to build it themselves or buy Oso. There's not, there's not a whole lot out there, and there's really not a, like a large set of incumbents.
Very cool. Very cool. Yeah.
Now, how, how, how long has also been around now? We've been around a little over five years. Great.
And from a fundraising point of view, I know, uh, former, uh, CEO Yes. Of, uh, Mongo invested, but what, what else, what, what other kind of investment? I Mean, Oso is backed by the absolute best investors in the world, not just Sequoia and Felicis, but the founders of Datadog, HashiCorp segment, MongoDB LaunchDarkly, uh, honeycombs, Huba base.
Like I could go on. Um, and what I think that says, you know, in addition to it obviously being an extremely valuable resource for us as a company trying to make it in this world. I think what that also says to our customers is that if they're looking to make a bet, and by the way, this isn't a small bet, you make this bet, and it's like you're really gonna be stuck with it for a period of time.
Um, so you want it to be right. And if those customers are making a bet, they know that, well, the founders of Datadog, HashiCorp, segment, monger, TOB, LaunchDarkly and so on, have already made that bet on Oso and, uh, that that counts for something. I love it.
Graham, what a great story, man. You know what? Your dad must be super, super proud of you.
I have no idea. Oh, I'm sure he is. 'cause you know, I'll be reaching out to him after this and say, Hey, Phil, some More.
Oh my God. It's what a trip. Um, But all kidding aside, man, hey, thanks for coming on here and telling us about Oso.
Yeah. We'd love to hear more and keep us posted. You know, please.
I think as, as we get more agent, more agents out here, this is really going to like, blow up the whole, the whole thing of it. So, yeah. But it's interesting.
Good stuff. Yeah. I mean, stay tuned.
We're gonna be publishing some stuff in the next few months that I think is gonna be really cool. Sounds like an invite back to me. Totally.
Totally. Also, if you're in New York mm-hmm. Next time you're in New York, I happily take you out for a coffee.
Oh, me personally, I, I'm in New York every two to three months. Liz always threatened. Well, I'll, it's a deal.
Next time I'm coming up, I'll let you know. All right. Sounds good, Alan.
It's good to meet You. All right. com.
Go check it out. We're gonna take a break. We'll be back in text drunk TV in just a little bit.