Why AI Agents Are the Ultimate Identity Challenge
The era of the “digital human” is officially here, and it’s rewriting the rules of enterprise security. John Aisien, Senior Vice President of Central Product Management at ServiceNow, explains how their recent acquisition of Veza catapults the ITSM giant into the access intelligence game, allowing them to govern the chaotic new frontier of “agentic” workloads that demand their own dynamic identities and ephemeral permissions. As auditors begin demanding tamper-proof evidence of AI access controls, organizations must evolve beyond lazy provisioning and embrace a strategy of collective defense before these autonomous agents become the attack vector of choice for the dark web.
Transcript
Hey guys, thanks for through. We're here with John Isian, who's the senior vice president for central product management at ServiceNow. And well, now that the deal between them and VESA has been closed, well, we're gonna have a little chat about identity management and all this stuff, and where it fits in in the age of AI.
John, welcome to the show. Thank you so much, Mike. It's a pleasure to be here.
I think early on when this deal was first announced, a lot of people were skeptical. They were... " Because essentially, AI and AI agents are a new type of identity we need to manage.
They're a persona essentially, right? That's exactly right, Mike. I mean, we, for the entirety of our over 20 years as a- an enterprise software vendor, we've, established ourselves, as one of the de facto, asset intelligence providers for organizations.
So if you want control over your software assets, your hardware assets, any other form of asset, you generally partner with ServiceNow, especially at the sort of high end of the market. It's a very natural expe- e- extension even to then want visibility initially, and then over time, control over who has access to those assets. And in the world of agentic and system-to-system interaction, also what has access to those assets.
So for us, it's a very natural extension to evolve from a world of providing asset intelligence to a world of, providing asset and access intelligence, and it's that second dimension, access intelligence, that Veza, uniquely powers. How did you wind up picking these folks? I mean, it seems like already there's a lot of players in the category.
And, and is it a category, or is it gonna be just melded into the core platform? Um, I think it's both to start with. I'll answer the second question first.
It, it is a category. There is a category, called identity security. There's a number of large cap and small cap, participants that play in that market.
Customers have also rolled their own, tremendously, inclusive, Mike, on ServiceNow. So as part of the diligence that we performed, we were actually astounded to find the number of organizations, including actually a Fortune 10 organization, that had built an access, intelligence as well as an access governance application on ServiceNow using our, sort of custom, workload, builder, which is an essential part of ServiceNow. And that again was another source of signal that told us that we had brand permission and essentially technical permission to participate, in this market.
But then to directly answer your question, we will also be incorporating, core subsets of Veza that make sense, specifically that access graph, into our overall platform, capabilities, such that other workloads built on ServiceNow can take advantage, of that access graph even if those workloads are not native ServiceNow workloads. Um, so that's essentially a part of our future direction of travel. How should we think about AI agents?
" But I also feel like there's starting to emerge these somewhat semi-autonomous AI agents that are performing a task on behalf of an organization that well, I'm not clear who's responsible for those. Yeah. We...
So to us, the answer is both. Um, and it would depend on the workload. It would depend on the, prevalent security and other forms of policy that apply, for the organization.
So in summary, our capabilities all up enable AI workloads of all sorts to inherit human identities and then gain, from the pre-validated, pre-curated sets of permissions that have been associated with those human identities. That's one, modality that we could see. But if you look at our AI specialist construct, actually a set of announcements that we made in February of this year, an AI specialist is essentially, a digital human that gets trained the way a physical sentient human gets trained, gets associated with policies and permissions, and gets, associated with knowledge, that's part of the training, and in itself requires its own identity, and that identity then, benefits from incremental permissions in specific systems.
And by the way, Mike, some of those permissions are ephemeral. The permissions may last 10 seconds, 15 seconds, or perhaps even microseconds. So in that context, it's super important to have the ability to, to manage these agentic workloads as their own distinct identities, or where it makes sense, to associate their identities with existing human identities.
And the flexibility of our architecture, allows us to support both, models. Will this also become like the attack vector of choice now? Because the bad guys will be sitting out there going, "Well, these things have awesome amounts of permissions and-"Uh, we're really adept at stealing credentials, so we'll just steal the credentials of the AI agent and away we go Yes.
Yes. Well, bear in mind, we are, well, the capabilities that we've acquired from Vaser and that we're integrating into ServiceNow is an admin time construct. So, Mike, this is a who has access to what, what has access to what, who should have access to what, what should have access to what.
Those are representations of the kind of value that Vaser provides. When one wants to make a runtime access request, so Mike literally wants to access a system right now, an AI agent, wants to update, a clearing and settlement system right now, the subsets of the identity stack that power that are provided by, partner organizations. Uh, we are not in that business right now.
Now, hey, we'll see where the future takes us as we continue to perform research and then develop against that research in this sort of early innings of the platform shift that we're going through. But as things stand right now, that capability, think about it as an IDP, is capability that partner, solutions provide as opposed to, ServiceNow Right. 'Cause there's one thing to provision the AI agent, managing it during its, post-provisioning cycle is a whole other day two motion, right?
That's exactly right. So the, the sort of constant change, and that's why those two, examples that I gave earlier of the AI agent inheriting human identities and permissions and the AI agents having their own distinct identities and permissions are so important. The, the ability to support those, I, I think, both, excuse me, speak to the, specific point that you just made I think it's fair to say that maybe we're seeing a little irrational exuberance when it comes to deploying AI.
We're, in a lot of organizations, we're ahead of our skis, as it were. Um, do you think at some point auditors are gonna come around and start asking some interesting questions about, well, what are these things accessing and how and why and who said so? They're already doing that.
Um, you know, and of course I'll have to respect customer confidentiality. But this morning, Mike, I was on a call at 6:00 AM with an It- Italian financial services firm. I, I won't say any more, but the primary premise that drove the deputy CISO, chief information security officer, Mike, to reach out to us, and ostensibly perhaps other providers, was exactly that.
Um, there was essentially an audit finding, and he did not articulate if this was an internal or an external audit finding. But there was an audit finding nonetheless that required them to demonstrate tamper-proof, non-repudiatable evidence that they had control over both, coarse-grain permissions, so what do the agents and the service accounts have rights to access, but also fine-grain permissions. What are the specific CRUD operations that these, these agents can perform in different forms of target systems?
And so that was the basis of a conversation that we started this morning with a specific organization, and we'll see where that goes. And incidentally, Mike, we were already participating in conversations of this sort even pre-Vaser, 'cause in that instance we'll be describing how our asset intelligence will power a subset of the data that they need. But now that we're in both the asset intelligence and the access intelligence business, we believe that at least on paper we are very well positioned to meet the entirety of the needs that this audit finding has, placed on this organization How dynamic are these AI agents likely to be?
Because I think we had trouble just keeping up with the humans in, in comparison, they're relatively static. But it seems like with AI agents, you know, we may be not only provisioning new ones constantly, but also ripping and replacing the old ones Yeah, but also the, the, the workloads themselves, the agentic workloads themselves can self-request incremental access, at least on paper. They can, step up, permissions in a system they already have access to.
They can execute on both the system and the human tasks necessary to change access privileges. Again, on paper. I believe for enterprise AI to evolve to true full-blown ubiquity for this, platform shift to become truly mainstream, and I do believe that that, that it will happen.
In other words, these forms of workload will become mainstream. It's a matter of sort of when, not if. But I believe one of the anchor pillars necessary for this platform shift to evolve from, you know, kinda scale experimentation, which is where I would argue we are today, to true mainstream adoption, one of the pillars that need to be put in place is a pillar that addresses exactly what you just described, which is when, reasoning determines that an agentic workload needs incremental permissions, how do you ensure that the permissions that are granted are still consistent with internal policy and external regulation, even as those policies and regulations themselves, continue to remain dynamic?
That is an unsolved problem for the industry as a whole, and we expect to play a role in solving that problem through a combination of existing IP, future IP that we may develop, and very importantly, the incremental talent that we're adding to ServiceNow b- b- through, you know, organic hiring and some of these, inorganic transactions that we've announced So what are you seeing, even though it's still early days, people doing today that maybe we'll come to regret tomorrow? Man, people have always done things that... You know, look, I'll give a philosophical answer.
I-i- yeah, clearly there are some absolutely hard guardrails, constraints that we as organizations need to, align behind. You know, there's a, a, a difference between a rule, an explicit thou must not, and I expect folks, you know, even in this era of agentic to stay on the right side of such, you know, sort of Boolean rules. But, on that right side of those Boolean rules is sort of multiple shades of gray, and i-in that world, I, I expect, the combination of customers, enabling, providers like ours, third-party enabling providers, and many of whom we compete with but we also cooperate with, to, execute on the right forms of experimentation that enables, I, I'll call it rapid iterative learning.
It, it's almost like agentic AI terrain grabbing, and you're grabbing that terrain to solve business problems, but also to rapidly learn. It's no different, Mike, than the previous platform shifts that, you know, we've all been through in the past. You know, client-server to web, web to cloud, the emergence of mobile as a dominant ergonomic form factor.
We went through a comparable iterative learning cycle, through those previous shifts, and I don't see why this should be any different, as long as, again, we stay on the right side of those, Boolean rules and regulations that e-exist for a reason. I might argue that historically we've been kinda lazy in this space in this regard. Uh, when we hired somebody, we set them up and we would say, "They need access to X, Y, and Z," and then we'd be like, "Oh yeah, and they might someday need access to these 10 other things," and so we gave them access to that early on.
And I wonder if we're in danger of doing the same thing with AI agents that are gonna be much more voracious in their, desire and enthusiasm for accessing data, and maybe, you know, all kinds of havoc might ensue. Yeah, including malfeasance. Yeah, so that, that danger's real, Mike, period, and I think, it's our job to collectively defend against that danger.
Like, I really do mean that. Um, I take my responsibilities as one of the custodians of ServiceNow's go-forward security strategy very seriously. I don't expect to be able to solve problems of the ilk you described exclusively on my own.
I think our customers, and frankly governments and society as a whole, has an implicit expectation that we will collaborate with other asset providers, even if those asset providers are primarily competitive, to sort of come together to collectively defend against, the threats, that you're describing. The, the defenders are doing that, by the way. They're collaborating on the deep dark web.
They're sharing tools, techniques, procedures. They're sharing code. They're sharing data.
So we are at an inherent disadvantage if we don't fully imbibe, authentically the importance of collectively defending. Nobody, no single vendor can be best in class at everything. We believe we're best in class across the asset intelligence dimension.
Vaiza's given us an astounding leg up around access intelligence, but we're not necessarily best in class at endpoint usage intelligence or net flow or digital exhaust that arises from CSPM. Sorry to use an acronym, but cloud security posture management. Y- we're not.
We partci- participate in those markets, but I wouldn't argue that we're best in class in any of those. It's our job, literally a hard responsibility, to partner with those vendors that are best in class in those representative categories to ensure that we can, define a collective defense architecture that makes sense for our customers for this emerging, age of agentic. All right.
Well, folks, you heard it here. Even before the arrival of AI agents, we were saying that identity is the new perimeter. What's changing here is that perimeter is not looking like anything we ever saw before.
John, welcome. Thanks for being on the show. I appreciate the opportunity to, to bond with you and your listeners.
Cheers.