Introduction
Mark Callahan is joined by Eve Maler — newly appointed Agentic Identity Program Ambassador and one of the most respected voices in digital identity.
Eve brings decades of experience defining and evolving standards like SAML and UMA to this conversation on the growing complexity of delegation in a world of AI agents. Together, she and Mark unpack what’s broken in today’s identity patterns — from shared credentials and fuzzy intent to the absence of real oversight — and explore how identity orchestration restores trust without slowing innovation.
If you’re navigating delegated access, agent impersonation risks, or compliance in AI-driven workflows, this session offers expert insight into the future of identity governance.
What you’ll learn
- Why traditional delegation patterns break down in agentic workflows
- The difference between human-in-the-loop and human-at-the-start
- How to protect against shared credentials and first-party fraud
- Where identity orchestration helps apply consent and oversight
- How to design for transparency, traceability, and flexibility at scale
Key Takeaways
- Trustworthy AI systems require intentional governance — not just identity infrastructure.
- Consent, control, and auditability are non-negotiable in autonomous workflows.
- Orchestration is the foundation for governing agentic systems at enterprise scale.
Learn to secure AI agents in a hands on lab!
Get hands-on with identity controls for AI agents — bind, delegate, and observe authentication and authorization policies in real time.
Transcript
Read transcript
Mark Callahan:
Hey everyone. My name is Mark Callahan and I work on the product marketing team here at Strata Identity. I’m joined by Eve Maler who has joined us as a new program ambassador for agentic identity. Hey Eve.
Eve Maler:
Hi Mark, I’m very excited about working with y’all.
Mark Callahan:
This is going to be fun. I love the fact that you use y’all living in Dallas outside of engraved by, yes, I, everyone always asks if I, if I’m from the South, but I’ve never lived there, but I use y’all all the time. So I feel at home. Okay. Okay. Good. Well, so our audience that’s joining us are individuals who have signed up for the private preview invitation that we extended as Strata is really digging into.
Eve Maler:
you
Eve Maler:
I’ve started to use it non-ironically now, so I I be a little bit more.
Mark Callahan:
what it means to add those guardrails and observability for agentic workflows and agent users that we haven’t had to deal with before. And it’s like every week things are changing. The speed of change right now, I think is kind of unprecedented and how quickly everything is developing on a day-to-day basis. so Eve, you’ve done this for quite a while and you’ve really had a lot of expertise in the space. What’s exciting for you about agentic workflows or agent users?
Eve Maler:
The biggest thing is I’ve been working on the questions of delegation for a really long time, well before the current kind of gen AI agentic moment. And I’m really excited about the possibility of digging into getting rid of impersonation, benevolent impersonation, where you share your credentials and some, used to be somebody else, another human would use them kind of with your okay, which.
Mark Callahan:
Kind of customer service maybe or something where somebody’s doing something on your behalf. Totally,
Eve Maler:
I mean, just between family members.
Eve Maler:
between two humans, Alice and Bob. What we finding was you had to share your password to get things done in practical terms. And that’s just, it’s an anti-pattern. It’s not a good idea. We need to solve delegation for real, delegation of access. And then the toughest part is delegation of authority to act on my behalf. So now that we’ve come into this moment, there’s my dog. Now that we’ve come into this moment, maybe I’ll be delegating something to her in future. We are asking the questions of delegating
Mark Callahan:
Yeah
Eve Maler:
not just access rights, but delegating authority obligations to another entity. And in this case, it’s a software-based entity. And there’s major questions about how to do that right. But the one thing we know that’s wrong is just giving it our password and letting it act as us in a whole bunch of systems. Like now you don’t have fine-grained control over access. Now you have problems with auditability. So I’m quite excited that we’re finally having this conversation now.
Mark Callahan:
Absolutely.
Eve Maler:
everybody.
Mark Callahan:
This is cool. Well, I mean, obviously we can’t hold back the onslaught or the wave that we’re in right now of agentic adoption. You know, as I look forward, you know, of course there’s all these sort of mundane tasks that can be automated and make things go much, much faster. Just out of curiosity, is there any one thing about agentic capabilities that you’re like, this is going to be cool. My life’s going to be that much easier because of it personally? I kind of put you on the spot there.
Eve Maler:
Being, as I call it, a privacy fundamentalist, one of the things I’m most excited about is potentially a personal agent that helps me manage my digital data footprint online.
Eve Maler:
And there’s lots of ways in which systems that monetize our data and get access to our data are all automated. So why can’t we automate in response? So it’s kind of a personal goal to get my arms around that whole matter. And I can’t really, but maybe with an agent’s help, can.
Mark Callahan:
I like that. And you and I have talked about that in the past. I had a history working at Twitter on the enterprise data team. And there’s that element of what is our digital footprint and thinking about exactly, especially in the light of social data and what things have we removed, but maybe still live on somewhere that we, as you say, sort of like this cleanup, it’s like a room beat for your digital privacy.
Eve Maler:
my gosh, my little robot that does consent intelligence for me signed me up. Who bring up my data, doing something with it, stopping its propagation. Yeah.
Mark Callahan:
I love this.
Mark Callahan:
all those things because I don’t even know where to begin with that, but yes, now we have a name for it. So Roomly shall be our product as we go that direction. Well, I started to digress a little bit here. So you’ve spoken a lot and you’ve written a lot about delegated authentication. We talked about why you would do this in certain cases in the human world. I suppose there’s like…
Eve Maler:
Mm-hmm.
Mark Callahan:
the impersonation and I suggested like a customer service agent who perhaps really antiquated, but is they taking over your account to show you through how to use your benefits program or something like that. You talked about family members, but what happens when we do a handoff from Mark to Mark 2.0? What maps and what doesn’t?
Eve Maler:
Yeah.
Eve Maler:
Mm-hmm.
Eve Maler:
Mm-hmm.
Eve Maler:
Yes, a digital agent acting on your behalf. And it’s funny that customer service agents, I mean, it uses the word agent for a reason. They’re there to work for you essentially in figuring out a challenge or using the system in a way that is how you would use it, illustrating how you do it right and fixing something on your behalf. So when it comes to Mark 2.0, Eve 2.0, they’re kind of pulsating, waiting to be given some instructions. There’s some great opportunities around giving it its mission.
Eve Maler:
you know, characterizing the task that it needs to do, but in a more high level fashion. And, know, there’s various, level based frameworks, kind of ladders of how you define levels of autonomy. see that with like self-driving vehicles and, know, what level of autonomy. Yeah. It can take over on the road and, you know, autonomous trucks. And so we’re starting to see these five level ladders of, how autonomous is some kind of agent starting at the
Mark Callahan:
that like my car can parallel park itself or I can actually do city driving.
Eve Maler:
simple chat bot that’s just, it’s empowered only to do a simple thing, all the way to, an agent that needs to go out to kind of fan out to a number of different systems and services and applications to achieve. So, so when you have to do that, like now you’re not talking about the classic default deny authorization scenario where every step that gets made has to be lesser and lesser privilege to make sure that you
Mark Callahan:
Yes.
Mark Callahan:
other agent.
Eve Maler:
your arms around all of it. That’s like, I think about the innovation of macaroons, which are the fancy cookies that are able to embed entitlements and make sure that it’s constantly getting sort of more and more constrained. Well, now you’re talking about fanning out and touching all kinds of systems, and how do we actually manage that? So that’s one of the things that we face as a challenge, an exciting new challenge, but a challenge nonetheless if you have a security mindset.
Mark Callahan:
Absolutely. the agents that we’re talking about here could be ones that are homegrown, that live within your organization’s environment. could be ones you created yourself. But we’re also looking at what about the agents that come in from the outside on these public agent platforms? We did some survey data that we actually asked participants, our audience here, to complete when they filled out their submission to join the program.
Mark Callahan:
And we’re going to do a follow-up session where we actually share back the aggregate results of that. So that’ll be exciting. But nevertheless, those agents live in many different places too. So I mean, the challenge is compounded by architecture.
Eve Maler:
Yes, absolutely. And there’s a faint echo of the current enterprise situations that people have where you might have tens or dozens or hundreds. In a couple of cases, I’ve seen thousands of internally developed apps to run the business or that can be customer facing. And then you’ve got the wide, wide world of SaaS apps. that’s a pretty wide spread of quality assurance and controls over who gets access and all.
Eve Maler:
kinds of factors like that. So now we’re replicating those challenges in the agentic world by having so many choices and by they’re being made so easy to build.
Mark Callahan:
So, you know, as we think about the, let’s maybe touch a little bit more on the delegated authentication aspect. So when it’s two humans, if you’re using it with a family member, you haven’t forbid anti-pattern shared credentials, I’m giving it to my brother. My brother knows to only do X, Y, Z amount with it, but then he’s not going to go do something untoward or inappropriate with it. Hopefully I get along well with my brother. You don’t know my brother that well, so maybe he does. But nevertheless, in the human world, there’s that element of,
Eve Maler:
I don’t know your brother.
Mark Callahan:
you know, the intent and how long and the duration of what we would allow somebody to have that access. But Mark 2.0, like where can things go wrong? I guess, I don’t know. Are there places that you can think of like where, oops, that I shouldn’t have shared those credentials with Mark 2.0?
Eve Maler:
Well, there’s certain cases, like even in the today’s circumstance, where we’re not too good often yet at doing things like, I think of them as expiring entitlements, simply putting time limits on how long the access lasts in order to accomplish the effect that you want to have. So we’re not good at that in the non-agentic world, particularly. We need to get better at that and get more fine-grained in respect to time and space and everything else.
Eve Maler:
in the agentic world, we’re going to need that. And we’re also going to need really superior auditing of what’s happening and who’s taking access, you know, who’s using the access and what is it that they did. So something that’s new in the picture is how do we look at some access that was used and then judge whether it was on mission, that it was according to the charter that I set the agent to do. Those are some
Eve Maler:
subtle semantic things that, when you think about authorization in, in the before time, we had enough trouble with the semantics of each application. And, know, so MCP servers are kind of specialized in packaging up the semantics of each application in fashion of exposing an API, right? but now how do we control which elements of those get used? It’s, it’s, kind of gets fractal very fast because everything you
Eve Maler:
might be able to do with any one application. I mean, it’s kind of infinite at the end of the day. gives a lot of choice.
Mark Callahan:
It truly is. Well, and couldn’t Mark 2.0 do things in whether not maliciously, accidentally, it well intentioned, repeat the task multiple times and to a point of draining my bank account almost immediately, you know, it’s like, hey, go buy the concert tickets and book a flight to, you know, go see Kendrick Lamar. And it did that once, but then it found VIP tickets and it got me first class tickets and then it did it again. And then it bought it for another, I mean, yes, the
Eve Maler:
Sure.
Eve Maler:
you
Mark Callahan:
the impact gets pretty profound.
Eve Maler:
And now this ticket buying that you’re referring to, I think that’s an example that we’ll be seeing more of, right?
Mark Callahan:
This is is true and actually I think in an earlier video Eric Olden actually shared the the analogy there of how this passes through You know just as an example of that agentic workflow and that example just remind everyone who if you saw that video or not was using an agent to go out and work on your behalf to go buy tickets to you very popular concert and in doing so
Mark Callahan:
it not only has to have access to the APIs at the ticket brokers site. So it has the right seats, the right venue location, the right date, but there also might be like an age element, age API for consent, you know, for certain things. But then we also go further because just as we’re discussing now, what if it, I didn’t want it to buy the $2,000 tickets. I put a cap of $200 tickets
Mark Callahan:
the ticket broker itself wants to have someone to make sure that there’s actually a real live blood Mark Callahan behind this. Mark 2.0. That’s right, Mark 1.0 that exists, that is one, good for it, that it’s the right mark, that it’s not Mark Nefarious Mark, that it’s Mark Callahan, the actual one and only, and the consent thing, right? You know, an angle where it says it’s supposed to do this action, and I say, yep, that’s correct. So,
Eve Maler:
Mondado, so to speak.
Eve Maler:
Mm-hmm. Google Mark.
Mark Callahan:
that human in the loop element really does become, I don’t know if I call it a problem, I guess a challenge. Like how do you reintroduce that in the agentic workflows to bind it back to a human’s intent?
Eve Maler:
I think that’s so critical to think about the aspects of…
Eve Maler:
Some of us who are privacy fundamentalists also worry about things like automation that gets run away. And so you always want to plan for, you know, the unhappy paths or just the regularized paths of a check on runaway automation. And human in the loop has become, you know, the way that we think about this and designing the journey of how a human gets involved is just as important as all those, you know, backend, you know, mark
Eve Maler:
2.0 is still kind of a machine. and all that backend activity could be proliferating without your realizing it, unless you have those kinds of breaks in there, those policies that allow for the triggering of somebody to come in and not, not just approval workflows. You know, we see, we see those things a lot in IGA, but seeing it as the natural consequence of getting into an area that’s got squishier boundaries and it gets into an
Eve Maler:
think of it as like an uncomfortable area for the agent and that’s a great chance to come and go well I would rather weigh in on this I have opinions about this color whatever it is okay not a color of tickets but color of a sweater that you’re going to The ski selection is a big one I have big opinions about that yes absolutely.
Mark Callahan:
I was going to say, lower the seat selection maybe. Yeah. Yes.
Mark Callahan:
Are you a floor person or are you a balcony at this point based on your music background?
Eve Maler:
You know, I’m okay with balcony for a live performance. When it comes to movies, we’re always way up close.
Mark Callahan:
Okay. Okay.
Mark Callahan:
Well, seat selection does obviously matter in this, too. And then, you know, there’s an element, too, of as we think back to the real world tie in and binding that agent behavior back to the humans. There’s also the regulatory licensure things that we need to consider, you where we start talking about stockbrokers or medical doctors or somebody who holds an actual human real world license that is asking the agent to go do the majority of a task. But at some point, it has to come back based on
Mark Callahan:
FDA license or their broker’s license to ensure that can you actually write this prescription or can you execute this trade needs to be tied back to that human element as well. And you can’t just hand that off to the agent.
Eve Maler:
No, it should not be handed off. can’t be handed off. And I actually wrote a post recently about why AI can’t be your actual therapist. And a lot of people are just using AI as a therapist.
Mark Callahan:
Where can our audience find that by the way?
Eve Maler:
workshop.venfactory.com. Thank you for asking. Yeah. When I look back at like the blogging that I’ve been doing lately, it turns out that I’ve had like a solid two months of AI blogging, but you know, there’s basically a law at this point that all you can talk about anymore is AI. So yeah. And talking about that, you know, there’s, there’s no legal liability. there’s no confidentiality guarantee when you’ve got this software based component in this role, you know, seemingly in this role. So therapist 2.0 versus.
Mark Callahan:
Absolutely, absolutely. Okay.
Eve Maler:
therapist 1.0, things definitely need to be handed off at a certain point. And that is almost like a classic approval workflow. If something can be achieved by the software to help the situation, at some point it does have to sort of deterministically go through a human for proper, you know, whether it’s legality or appropriateness or even separation of duties, violation checking.
Mark Callahan:
Yes.
Mark Callahan:
reputation, I’m thinking about like celebrities who always, you know, maybe have a little too much to drink and post something untoward on social media and then, I was, you know, that could actually happen, right? Like you’re, if you accidentally send your agent off, bad things could happen.
Eve Maler:
Thank you.
Eve Maler:
my gosh. Yeah. Totally. Yes, sometimes humans need human approval loops too, for sure. Stop me before I tweet again or something.
Mark Callahan:
I agree with that. agree with that. Maybe we need to like introduce that back into this as well. this, this exactly, this exactly. The challenges are immense. They really are. But I think that a lot of what we’re hearing from our customers and from the private preview audience as well is right now we’re really in the experimentation phase, right? I think that everyone’s just, these problems aren’t fully defined yet. We don’t quite know what angle to take.
Mark Callahan:
you and I talked a little bit about like orchestration. just, we talked about our core angle being one of, independence and, neutrality. I guess like vendor neutrality, but perhaps you would look at this from the element of how do I extend my existing vendor infrastructure to adopt agent workflows? How do I, MCP seems to be the one that everyone’s adopting, but there’s all these other protocols that are coming. I don’t want to like hard code in having a universal remote or Zeta stone in the middle.
Eve Maler:
Mm-hmm. Mm-hmm.
Mark Callahan:
Sounds like it’s a lot more important now than before.
Eve Maler:
Yeah, honestly, there’s so many.
Eve Maler:
options coming out and so quickly new versions of models and many models that are tuned in various ways. Experimentation is appropriate at this point, I think with some guardrails and being able to kind of hook them together at this juncture is so important and accounting for humans in the loop, accounting for all the other infrastructure that they’re going to need access to. like how do you make sure that an agent has the data it needs? That entire process
Eve Maler:
of feeding it what it needs to know in order to do what it needs to do. Like all of that wants to be loosely coupled, I think. And once it is loosely coupled, I don’t think that there’s going to be a lot of…
Mark Callahan:
Yes.
Eve Maler:
consolidation into a single amorphous blob. So it’s important to have a great way to orchestrate the pieces so that it’s flexible for all the needs in the future and all the things that are going to be increasingly frequently made in the future.
Mark Callahan:
You know, I shared, you and I were talking prior to the call. I literally looked at a article that Gartner had put out, a note just recently about handling delegated authentication from humans to agent, agents. And as I was looking through that, a couple of notes that they made as assumptions, you know, didn’t talk to the Gartner team here, so I’m not trying to give a direct quote, but nevertheless, they said that by 2028, so just five years, I’m sorry, three years out.
Eve Maler:
yes.
Eve Maler:
Thank
Mark Callahan:
They’re assuming that 90 % of agent workflows may potentially have to be undone because of the wrong way they’ve handled delegated authentication. That there’s, it’s just the easiest path and it’s logical to share credentials right now, but oops.
Eve Maler:
Yeah, you know, there’s supposed to be a rule. This rule is only honored in the breach and it’s, you’re supposed to throw the prototype away. so there’s a lot of stuff that’s going to end up going into production that, you know, you can see the chewing gum and the bailing wire. And so you want to be sure that the hooking together is flexible and has best practices kind of built in. So yeah.
Mark Callahan:
Yes.
Mark Callahan:
I like that. The flexible, it’s, I really, that’s a good analogy. The bailing wire, gardeners or anyone else that you can reuse and it doesn’t break after you use it. Or the one-time zip ties are not the answer here. This is something that’s flexible. I did, I did at a farm in South Dakota and that’s, top of mind. It’s totally top of mind. But I think the other thing that was interesting in the note was they mentioned,
Eve Maler:
Yeah.
Eve Maler:
Yeah, and I hear you just had an encounter with barbed wire and that’s very Sorry to call it out.
Mark Callahan:
much there’s going to increase the first-party fraud and the account takeover risk that is also subsequently coming because people still think that perhaps sharing credentials with mark 2.0 is the course of action here. And Strato, we’re saying firmly that’s not the path. You are screaming that’s not the path.
Eve Maler:
Thank you.
Eve Maler:
Yes.
Eve Maler:
And you don’t have to is the thing. mean, now that delegation options are becoming available, it’s got to be considered a best practice not to be broken. Right? Like, you know, I’ve been predicting this day for a long time. You know, we’ve been sharing passwords and then then we got pass keys, which are going to really make it complicated to like, you know, how do you have benevolent sharing of access? And, you know, with user managed access, which, you know, I’ve worked on for a long, long, long, time.
Eve Maler:
The paradigm is…
Eve Maler:
Alice to Bob sharing of access. so we didn’t know about Alice to bot sharing coming along in the current era and, know, or Alice to Alice two.o sharing. Right. So like it’s important to be able to do that sharing in a constrainable, selective, auditable fashion. And so frankly, that’s why we need more identities in the picture identities for all the different entities that are involved from, you know, something that’s acting as a client app.
Eve Maler:
which agents are going to be doing a lot of the time, as seen from our kind of classic OAuth perspective, all the way to you’re sharing with a company that needs access and they’ve got agents that are working on their behalf to do something with what you shared. So there’s going to be bigger and bigger ecosystems of these entities that need to play together. And it’s going to have to be extraordinarily transparent for us to be able to check whether they’re doing the right thing.
Mark Callahan:
And I think that’s probably a hope of the private preview program. know that organizations who have signed up to work with us, ideally we would love to have people join on as design partners. As we can hear really more about the needs, we would love to help shape that back. And we’re not just asking to give, give, give. We want to give back. Of course, I will do a follow-up recording just on the aggregate data that everyone shared in filling out the form.
Eve Maler:
That’s really exciting, by the way, because you really reached statistical significance, I think, with that survey. So I can’t wait to see some of that data again.
Mark Callahan:
We do. do. mean, we’re the audience, just so you know, you’re in a sphere of about 350 and growing organizations that have raised the hand or individuals, should say, to be clear, who have raised their hand and said, yeah, I’m actually interested in learning more. So you’re right. The statistical relevance of our audience size, our end is large enough to give some good insight. So I think, you know, that’ll be exciting to share some of that data back with this group. But back to the experimentation, I feel like we’re at a place where
Mark Callahan:
hopefully that transparency, know, we’re not just talking about transparency of the workflows, but like we’re all learning from each other because the problems aren’t defined yet. Like it’s, we can’t just hold all this stuff secret to our chest and think that we have all the answers. This is going to be a group thing decision. Like we’re going to, we’re going to do this together.
Eve Maler:
Yes, as in so many things, this is going to be a team sport for sure.
Mark Callahan:
I like that. like the agentic identity is a team sport. You’re here first. That’s that’s that’s definitely it. Well, you know, so you’ve written a lot about this. You mentioned that you’ve got your own blog. Again, where would they find that information?
Eve Maler:
workshop.venfactory.com and I hope to see folks there. Thanks.
Mark Callahan:
Awesome. Well, please sign up for that. will, we’ll be contributing some, we have a Slack group where we’d like folks to join and actually have some questions. And so you and I will be participating actively in that as well so that they wanted to reach out. And then videos like this, the next in the series, we’ll go through some of the results that we heard from the audience in this. You know, a couple of little spoilers. I think that on-prem agent deployments seem to be just.
Mark Callahan:
makes sense. If far and away as people are saying, this is where I need help. That’s where we’re experimenting. That’s where we’re safe. I think really, you know, within that perimeter, like our known space. And so.
Eve Maler:
Yes, I think people are looking for whatever control knob they can sort of crank all the way up to the right. And that seems to be one for starters. So yeah, it’s going to be really interesting to see how this goes for everybody.
Mark Callahan:
That’s it. Well, we’re thrilled to have you working alongside us. It’ll be fun to do this going together going forward. Our audience has a chance to connect with you directly as well. And with that, know, thanks for joining. Glad to introduce you to our team, the team sport here. And look forward to catching up again as we get into some more of the data and what we’ve heard about what people are challenged by when it to agentic identities. So stay tuned.
Eve Maler:
I’m very excited as well.
Mark Callahan:
Thanks