Transcript
This is Savvy Talk, a show rooted in conversation where we are shaping the mindset of identity security because what else are we going to do? I'm your host, David Lee, and of course, I've got my co-host today, Enrique. How you doing, man? Hey, David. It's just us today? It's just us today, man. No Simon. No Simon. We booted him out. All right. Just for this one. It's an Enrique and David takeover. That's true. Yeah. No, without the distraction of clothes and wardrobe. Right. Now, we don't have to do the poll to see if he's the best threat. I feel more relaxed. I feel more relaxed, too. No, but I love Simon. We do love Simon, right? And Jim. And Jim. But, you know. Hi, guys. You can't get all the best hosts every single time. We had to break it up so that way you guys wouldn't get too comfortable. We keep you on your toes every time we release a new episode. But we are here live in Identiverse, which is like the identity Super Bowl. It really is. I love just everything about this event. This year, it's probably the biggest that it's been in a while. That's what I hear. Yeah. So, but it's been really cool so far. I didn't get a chance to get to any of the workshops. I was really hurt. You got a chance to get a workshop. We'll talk about that a little later. It was fun. A little debrief. But like just a quick primer. Like how was the workshop? Man. Because I heard a lot about it. The room was packed. Really? Nice. And the energy was there. I was worried because it was very early. First day of the show. But the room was packed. The energy was there. We had a lot of great panelists with us. So it was very cool. David. Nice. Awesome, man. I heard you did a good job. I did hear that from a couple of people that went to the workshop. There's always a dad joke. You got to throw those in there. Yeah. That's what you got to do. So, I am excited about today's conversation, though. Me too. We have a guest from IBM, Mike Amaday. We're going to cover a bunch of stuff with IBM, and IBM's been around forever, right? Man. They're so big. Right? And it's the whole thing of like, you're never going to get fired by an IBM. But the conversation I'm interested to talk about is how he sees AI and where it's coming because you want to talk about a pioneer in AI. I remember Watson being on Jeopardy back when I was a kid. Or playing chess. Right. Yeah. Yeah. So to have somebody here and just from that expertise to show what they think of it and where it's going, I think it's going to be really cool. That will be fun. Yeah. Yeah. Mike. I was looking forward to this one. Yeah. Absolutely. All right. Let's get this conversation started. Mike. Welcome to the podcast, man. Thank you very much. Very happy to be here. And I know I got to bring the energy. So I saw that intro. Yeah. So I have got to make sure I keep it going for the entire time. We are looking forward to this, Mike. It's two against one, but it's going to be fun. Excellent. Yes. Welcome. Welcome to the show. Thank you very much. Very happy to be here. Awesome. So just give us a little bit about your background, man. Like how in the world did you get into identity? How did you get into AI? How did you get into AI? How did you get into AI? How did you get into AI? Awesome. So just give us a little bit about your background, man. Like how in the world did you get into identity? So I actually got into identity some time ago. I was doing local area networks. And a part of what I was doing for local area network was running email systems. And email systems run off directories. And directories were one of the most important part of where we started this identity journey. But when was that? It was not last year. Do you really want… It was early 90s when you really want to get down to it. So I've been doing it but really dedicated to identity since 2000. All the grunge music, Nirvana was blowing up. I think it actually… No, it was right around grunge. It was right at the grunge period of time. But I've been focusing what we would call identity and what we've called identity since 2000. Yeah. Nice. Nice. And you work for IBM now. I work for IBM. I'm a former IBM employee. So that was super interesting because I want to ask you a question about how things are going now. And, of course, we all know Watson from decades ago. So AI is nothing new to IBM. But tell us. So what do you do at IBM today? So at IBM today, I am responsible for all of our identity services for the Americas. Okay. From Canada to Latin America and five different vertical markets that we have in the United States. And just to be clear, because IBM is huge, right? So this is the services, which is the consulting part of IBM. It's not the Tim Tam, the Tivoli, the software part. This is IBM's cybersecurity services team. We're part of IBM Consulting. And we work with our clients to help our clients protect their enterprise with whatever mechanism that they need to do it. And you're in charge of the Americas, the whole practice. I make sure my people are able to go and offer and sell solutions and then be able to deliver upon them. Nice. Awesome. Awesome. And before IBM, where were you? So at the IBM, I've collected three of the four big four. Started with, I still have one left. I don't think I'm running that last one. And also spent some time running a regional security business for a joint venture between Accenture and Microsoft. So I've been around, saw different things in this area. That's an interesting thing that you compared the big four with IBM. What do you think, being at IBM today, the big difference between those consulting firms versus the way IBM is running services and consulting and advisory? Well, where we are inside of IBM Consulting Services, there is a legacy that goes back to the big four. It came from, actually consulting came from. I remember that. They acquired, it was from PwC, right? So a lot of things that we do in IBM Consulting is very similar to what you see in the big four. We live with our clients. We understand our clients' business. And then we help them solve their business challenges. Yeah, that's good to know because I think a lot of people may think of IBM mainframes. But they had this huge consulting business, which I was part one day. And that was about, also about our partnership, right? So Savant, IBM, we go way back. Both of our companies doing things together in identity. Do you remember how that started? With the IBM part? I can't. Oh, that was before. Before me. I've worked with Savant since 2015. I've had a long history of working with Savant at different places where we had. IBM has been working with Savant for at least three, four years. And we are able to deliver Savant services across the globe. Yeah, and I've been working together with you guys a lot in all of the accounts. I think it's a very interesting and complementary capabilities and people in geographies that we're not there yet. So it's been very, very good for us and to our clients as well. Right. David, what do you think we take this to the next level on the identity but the AI pieces, which I think because of Watson, I think is inevitable, right? Mainframe is one thing, but also Watson, such a big brand around IBM. And I'm super curious about that, too. So I joined IBM last year. One of the reasons I joined IBM was their ability to deliver with AI. We have it. It's a part of us. We're talking about how we're a consulting firm. Really, we're a technology company at heart. And we have excellent technology, excellent technologists that are able to help us do that. What gives us an advantage over other consulting firms is it's native. It's a part of us. It's a part of our resources. We can leverage it. We don't have to sign a check to some other organization to use their AI tools. It's part of who we are. And we have a lot of people dedicated to it to be able to take advantage of it, to use it for our clients. How much of the AI conversation are you having when it comes to identity, like on the consultant side, right? I mean, give it a number if you can. Is it 20% of the time, 60, 80? Every single conversation. It's every single conversation today because we can't. It's flooded. It's everywhere in the market. Yeah, and it's like, especially from security, you couldn't do anything without talking about Zero Trust. And now everything has been, what is Zero Trust? You don't hear about it now. Everything is AI. Everybody has to have AI. Everybody's getting asked by their boards, by their leadership, what are you doing with AI? How are you keeping us competitive? So it's ingrained in everything that we do. How have you seen working with customers, right? What's been the range of adoption that you've been seeing from them, right? So we see people that are adopting and doing AI, but I don't necessarily see where you see people are doing Gen AI yet. They're collecting a lot of information that they have. They put it in the database, and then they train some things on top of it to spit answers back out. Right. So you go, ask HR, how do I do this? How do I fill out for a phone? And that's what we see a lot of it right now from an adoption part of it. Really, one of the challenges we see with AI is the maturity of the identity programs in the first place. If you aren't onboarding applications, if you're not documenting what you're doing with it, AI is not necessarily going to help you solve those until you're able to train the model to do what you're going to do with it. Yeah. I 1,000% agree. I've been having some conversations with it. Some colleagues of mine, some guys in ID Pro, things like that or whatever. And it feels like what we're starting to see is this little known kind of category that we called data security decades ago. Yeah. We kind of started playing with it and then said, no, we didn't want to do it. And enterprise was like, it's too expensive. I cannot see how we can continue to evolve on this path without coming back to that, right? Because truly, what AI has done now, what most people know, is really just commercializing machine learning, right? Again, going back to IBM's roots, right? For us nerds who've been in data science and all this, all the complicated, hard math that you had to do was all machine learning. And you had to have data sets. Structured or unstructured, you still had to have some kind of understanding around your data sets. And so, while this has made this a little easier, it still comes back to the point where your basic blocking and tackling has to be done. Is it really going to get anything done? So, I worked with the team that built this and asked them questions. How do you do this? But we ingest information. We bring information in. We bring in roles. We bring in access models. We bring in documentation. We bring this information into the Gen AI solution. If it's not there, I can't ingest it. And I need to have that information so I'm able to do it. You don't magically, what we built is a digital assistant using natural language. I go in, I say, I need access because I work with Enrique's team and I do this job. If I don't have that language model and that information, it's not going to know what access I need to do to do it. It has to exist in that LLM, right? And to your point too, David and Mike, do you think that's why you see perhaps this organization starting with the data? Let's accumulate. Whatever we can get, we just accumulate. Yep. And eventually, okay, something will come out of that. So, I think… If you're just accumulating garbage, what's going to come out of it? A lot of garbage. That's right. It's going to go, oh, I provisioned this very quickly and it doesn't match to what the person's going to do. I think I may have a hypothesis that a lot of companies are doing that. They're just accumulating, hopefully thinking something good is going to come out of that. And to your point, no, garbage in, garbage out, or poop in. So, to that point, if we go back to that original state of data security, of big data, then now LLMs. What do you think is missing perhaps in maturity or posture of those clients to understand, okay, it's not only about accumulating and hoarding data. Right. But how IBM is helping them, okay, let's claim this or prioritize things that matter. Right. I mean, we come in with our clients and it's not plugging. You don't plug our Gen AI, Ask IAM solution in. Oh, is that a name? Ask IAM. Ask IAM. Make sure I get the right name. IBM's Ask IAM. So, is it a product? What is it? It is something. You're not going to go get a SKU and you're going to go buy it. It's part of our consulting services that we have. Oh, they're going to call you and say, yeah, I want to buy this thing. You can buy it, but it comes with our consulting services that go along with it. Ask IAM. Okay, did I say it correctly? IBM's Ask IAM, but you don't have to worry about that part of the brand. I do. It's Ask IAM. And it's actually part of the Savient Marketplace that we have available for our clients. Yes, which is I think it's a super important phase for our evolution as a company, too. So, where IBM, other partners, they can just publish apps. It's like an app store, right? But also a way for even like it could be a very small company to monetize. And I think I love that idea. So, Ask IAM. So, you said, is it a co-pilot? Is it an assistant? So, it's right now a natural language digital assistant. Is there a difference? That's a good question. Do you think there's anything different? What is a co-pilot? An assistant? I don't know, Gent. I really don't know what a difference between a co-pilot and an agent is. I don't know. David, you know. No, yeah. Well, co-pilot is just a name that they gave it. It's a brand. Yeah, co-pilot is a brand. They call it Microsoft Co-pilot. Instead of giving it a name, they just call it co-pilot. So, at the end of the day, it's LLM or a generative AI application built on top of LLM. You call it whatever you want to. Yeah. Co-pilot, assistant. To us, it's a digital assistant. That's what we're calling it based on natural language. Because you interact it like you and I are talking to each other. We built it right now off of multiple different communication platforms, Slack teams. But it could be a web interface. It could be however you want to do it. I prefer that definition because when you explain that as an AI assistant, it's there to augment whatever humans are doing, right? It's not like, ah, it's a replacement. And you may not have deployed all use cases yet. Yeah. You may get to a point and say, I need to do X, Y, and Z to tie into a privileged module so I can do that. Well, we may not have trained the language model yet to be able to handle that. Right. That's where we still may have to redirect somebody back to it. It's just you have to get the information from there, ingest it in it, and then take it and turn it into actually actions that we could fulfill as saving as that engine. So, what does Ask IAM Assistant can do today? Today, we have it as an add, change, delete mode for an individual's access. For IAM stuff. For IAM stuff. So, it will go out. I need to say, hey, I'm brand new in this job. It will be an interactive conversation back and forth to not interrogate but to get information out of the person about what it is. Where do you work? Trying to understand where to then go back and forth and talk to the databases that are behind it and say, you work for so-and-so. All right. This is your manager. I check these things. And it allows an individual to request access to be provisioned for them and still have all the same audit logs and still all the approval checks in place. But it's now no longer that individual is going to a saving UI or another UI to get it. It's being done through their normal collaborative tool. It's another channel, right? So, we keep talking about multi-channel experience. So, I think that this is what's getting like a meeting. It's a channel that you and I would use to do our job, right? It's a normal channel that I would, instead of talking to David to get, you know, instead of talking to or going to a UI, I'm talking to David. We could call the digital assistant David. How many companies are still doing that, right? They have that one guy. They have a, let's call Alicia. Alicia, hey, give me access to AD, right? Right. Okay. And you're still, you know, it allows you to add, change, delete, remove, do all the different types of accessing that you would need for it. Yeah, but I think it's, I almost look at it as it's slightly different than like different channel because, again, it goes back to like Microsoft's vision for this, right? And the CEO has now come out and said this twice, that the evolution of how we're going to build applications and shifting, basically creating AI as itself as the interface, right? And so, the back-end business logic and applications and all that just kind of really disappears. And so, you create this nice thin layer between AI interaction and then straight data. So, now it's just have a conversation wherever you're at. The logic is there. That's your interface. Yeah. And so, you just have a normal conversation and whatever you're talking to, assistant, whatever, LLMs, however you're behind it. But it's going to go figure out, let me go find out the right business object, the right ways, the route. It handles all that. And your interface is always just chat conversation wherever your user is at. But I think we're there yet, right, David? And Mike, what do you think about that? Because do you think we are on a stage of maturity that we can really propagate the business logic to the AI layer and just decommission apps? I mean, no, not yet. Yeah, right. You still, I mean, no, you can't do that yet. I mean, if we even just, let's talk about what the identity part of it is. Yeah. If you don't have this stuff captured, we have to capture it so that we can train the model so that the model and the Gen AI knows what the heck to do with it. Right. Because if you don't have it, you have to get to it. And, you know, ultimately where I see it, and I get yelled at for everybody because they make it seem like I'm predicting. I shouldn't even have to go to that interface. I shouldn't learn enough about you over time through your use. And, you know, marrying the access that you have and what you do with it, bringing that into the model. Every Tuesday, David logs into this system and does this stuff. Well, guess what? First thing Tuesday morning, I'm going to give David that access. Tuesday evening, that access goes away. Like a true assistant. And it's done behind the scenes. David doesn't even need to know about it. Guess what's nice about it? David's manager doesn't now have to certify access because it's done on demand when you need it and when they want it. There are, you know, there is one thing that people hate more than requesting access. And that is what? Reviewing access. Reviewing access. And I spent two years as a global head of identity and access management for a large financial institution. I was responsible for 535, not 536, but 535 high-risk applications. And we had to certify the majority of that access every quarter. Do you think people liked me? No. They did not. We didn't have the ability, the tools to help them out yet. And it was really a drag on the productivity in that organization. And I had to meet with regulators on every quarter to say, well, how do you know that access is appropriate? How do you know they're not rubber stamping? How do you know they're not doing all these other things? And it's like we need to, using these tools and technology, get to the point of where people have access when they truly needed to do their job. And it goes away. We're not carrying that latent access around with them. And you know why people never got rid of access? Because it was a pain to get the access. And scary, right? Because they may be removing stuff and people just locked out of accounts, locked out of their apps, right? And one thing you mentioned, 535 apps. Thank you for remembering 535. Yeah, it looks like something really got stuck in your mind. Because one of the very stressing items, a lot of CISOs and a lot of clients that we speak to, right, David, is the application onboarding. So perhaps just bringing those apps in. And to your point, back then, there was no other way to do it. Just elbow grease, right? And just interviewing people. I had a team of 12 people onboarding applications. Yeah. And so do you see AI? Because that's another thing. I speak a lot with our clients and our strategic advisory board. And one of the recurring points that we keep going back to is application onboarding. So, hey, now maybe we have better tooling to help us with that, too. Do you see that from your point of view as well? So that's a perfect lead-in. So one of the other use cases that we're working with with Ask IAM is having the same digital assistant, the same user interface, to interview the application owners. Or interviewing the right people across the organization to find out about this so that we can actually onboard the applications for them. And, you know, if this application, say, is already onboarded to an existing system and we're moving them from one system to Sabian or something else, we can now ingest that information in, because it's already an onboarded application, and then go through a digital assistant type of activity with the app owner to verify the information that's in there. So that's the second real use case that we're going into where we're at. Because you're 100% right. If the app's not onboarded, I can't control it. I can't bring it into the system. It's those two dimensions that I see, right? So in a project like this, correct me if I'm wrong, but one dimension is what's the user populations you have inside of that thing, but also what are the targets and what are the systems connected to it? So speaking of those two dimensions, right? And the first one, I think there's the inevitable one, which is NHI. You see everybody talking about that, too. So have you seen IBM in your travels with your clients today? How is that in the list of priorities of an identity leader or a CISO? Do you see it's going up? Is the needle even moving? Yeah, I think part of it is it's going up in importance because a lot of attention is being drawn to it. But I also think it's so much easier to create those non-human identities now than it was before because the cloud has made it so much easier, right? You're not physically going and having to provision things. If you look at it, you should have been managing those non-human identities. Yeah, the agentic AI, too, right? So you're giving this power to people to just create more agents. Those are non-human or machine identities, too, right? Right, and that's the other part of it is we're spinning those up. If you're looking at the machine identities, that's one part of it. And the non-human is the other one. It's just they grow faster. It's so much easier. I think a lot of it is the idea of discovery and finding these sticks because you used to have to work to be able to technology. You used to have to procure things. You have to get up. Now, I just got a credit card. I go and I spin it up, and I spin up a data center in minutes with it versus what it was before. As we used to have shadow IT, right, with SaaS in the beginning of the day, now we have shadow identity, which is an interesting problem. But do you think is it now making the discussion to the board meetings, to the board level type of discussions, is machine identity? I don't know if machine is up to that area yet. Now, maybe the agents and the non-human stuff is getting to the point of, as we're creating it, we have to do it. I haven't heard it being talked about at that board area. Me too. What I see, and David, do you see that too, is like people know it exists. There's this latent problem. But I think most organizations, yeah, I still have so much to do with humans. I'll get to that event. I think boards have – I'm sorry, David. I think boards have been educated so much more now about cybersecurity, period, across the board. And I think because they've been bitten by breaches, and they also look at it and say, damn it, I can't let that happen to me and my organization, so they worry about it. I think that's a topic or two that still hasn't gotten to their level. The problem I keep hearing from customers with NHI is that it's – they'll look at it, and they'll get whatever vendor puts something in front of me. It's absolutely, oh, I see it, visibility, great, cool. But to your point, Enrique, it's like, okay, great, but how do I roll this into what I'm doing today? What you can't give me is visibility and then no way to actually take action because if you're telling me you're just going to give me another report, I don't have a team to do that report. If you're telling me there's no way to work it into my current operations, I don't have room to go buy your product and spin up more operations. So there's a lot of interest. There's a lot of we want to understand this, but it's like we need this to kind of either get matured or some of our platforms already have to take care of this because I can't have yet another area that I need to go manage. And part of, I think, like anything, you were talking about data security earlier, is the discovery aspect of it and being able to find where things are. Yeah. Because they don't know where they are. They don't know where they are. And they could be doing a perfect job understanding, they just don't know where it is because it's not a data center anymore. It's not confined to somewhere. It's, you know, David's at home spinning up David's data center that he just procured off a HUD provider and it's there. Hey, AWS is a free tier, man. Yeah, I keep thinking more about that shadow IT type of thing, shadow identity. What do you think, Mike, is the biggest risks that we have to face? And then when I say we, it's we vendors, practitioners, but also our clients. What's the biggest risk they have to deal with AI today? With AI today? Yeah. I personally think the biggest risk is it, is a model that's not accurate. Okay. That you got a model in it. I did an enablement session a few weeks ago in Atlanta after RSA. We, after RSA, our head of our cybersecurity services said, we got to let the world know what we're doing with AI. So we had an enablement session. And I'm going through and I'm talking to it. I'm talking to an individual. An individual got it spot on. He was basically saying, if you have that bad data, you can make bad decisions very quickly that was in your model. So to me is that if you built a model that's not accurate and somebody didn't catch it and moving it in, you're now making mistakes and you're making mistakes at the speed of light that you used to require a human to go fulfill those mistakes. I agree. That's the beginning of everything, right? Without quality data, you don't get quality results. However, how about the risk of, and we see this in the news already happening, right? The job replacement by AI. Do you think, is it something it is warranted? Is it something, oh, no, maybe it's a overblown, over proportion. I forget who wrote the book and other people that were talking about it. I think there's a re-skilling of it. And I think you even said it. It was the re-skilling of how people use AI to do their job as the re-skilling of it. That's how I think. The more healthy way. Are there going to be people that are impacted at the future in the present? Yeah, there's going to be people be impacted. I grew up in a coal mining town. Automatic coal miners came. Where did you grow up? Western Pennsylvania. Okay. Great place to be from. But anyhow, it's going to be a model for people to have to learn to change the job, right? Yeah. We don't have enough people now working in IT departments. They've gotten so thin. There are plenty of jobs that aren't being done today that people are going to be able to do that. I agree. Skill shortage is a real issue, right? Yeah. And the up-skilling of people, the things will balance it out, right? I have a cousin in Brazil. He said, well, Enrique, money will find its way too. So if this part of the industry is struggling, this whole generation perhaps will shift and do other things. I think that's something top of mind for a lot of people, especially if you work in IT and work in other jobs. One thing that I – this is just my hypothesis, eh? Because if you are perhaps an average, mediocre developer, I think you're done with AI. I think your job is done. Or if you are a mediocre database administrator, I think your job is going to be done. What do you think? But it's always going to – there's always going to – there's change, right? Yeah. And if you're going to have to keep track of the change, then you're going to have to move. And you may be done. Maybe you shouldn't have been a developer in the first place. Maybe you should have had another calling. Maybe you should have run podcasts. There you go. I mean you should – when you – not to switch it, but you went back and said, well, what was the biggest risk? I guess the risk – the second biggest risk, first one being we're saying bad language models. Yeah, yeah, yeah. The next biggest risk is not taking advantage of it and not using it. And falling behind because – That's a big one. Because you're not using it inside of your organization. You're not going to be able to compete against the organizations that are. And you're not going to be able to compete against small, nimble people that are going to be able to take advantage of this. That is true. So it is risky, but I agree 100%. You can't afford not to top and be left behind. Right. Everybody is not always. Yeah, and individuals. The whole organization is done, right? Yeah. And it's, you know, it's not – it's not being – it's not just in IT. AI. Right. It's everywhere. It's everywhere. Do you think identity? So in us, in our industry, we have a role, a job, in making the adoption of AI safer? Oh, I mean, we definitely have a role in it because we need to make sure what we're using it for is right. And we're out promoting that we are using it and that people understand what we're capable of. My goal is to make identity completely invisible. And nobody can even know that we have an identity organization because nothing against identity. It's been very good to me. It's helped me do a lot of things. It's been good to all of us as a company. Right. But unless you're selling identity, nobody goes to work every day saying, I want to certify access. No. Nobody does that now. I want to fill out an access request. No, that's not what people do. It's like, let's make it invisible. Let us work behind the scenes, making it as visible as possible and people get the access they need to do their job. And do it. Its job was always supposed to be an enabler, right? Yeah. It was always its job. And we just, right, when you go back to Tarbanes-Oxley and Anderson Consulting and all that, when the industry really kind of took this jump, it came front in mind because of that legislation. And so we, as an industry, just kind of looked at it and said, oh, we're going to help you go do this. So we made it be this big thing because it had to be up in front. But it was always meant to be a behind-the-scenes enabler, right? Yes. We did it. When I first started doing this, besides the email systems I built, we were putting single sign-on over portals, right? We were enabling people to do business, to sign in, to sign in one place and access all your web apps or do all that kind of stuff. And you're right, Sarbanes hit. And then we spent this 10 years because we didn't understand access well enough. We didn't know how to train the auditors. We didn't know how to, and we're like, you're going to certify every entitlement in your enterprise. And I'm like, why? We spent an entire decade trying to make a better Excel spreadsheet. Yep. That's what we did, right? I mean, that's literally like when I tell people who are coming in, I did it. I was like, well, what is it? I was like, literally, we spent a decade, maybe even two, trying to make a better Excel spreadsheet. And like every single vendor that came out there was like, what does every single access review screen look like at just a different version of an Excel spreadsheet, right? And somebody would say, oh, let's do a demo. We're going to do a demo of an access recertification screen? It's like, I'll do a demo of Ask IAM. I'm not going to do a demo of how you certify access. Now, some of the different things that you're doing is using intelligence behind the scenes. You know, I had people that would come up to me and say, I certified Fred's access four quarters in a row. He's had the same job for 15 years. He didn't change jobs. He never changed anything. He never changed his car. He didn't change anything. Why am I certifying Fred's access every quarter? Come on, Fred. Yeah. So, Mike, this has been awesome. So, as we wrap, I want to ask this one question. So, you've been across identity. You've seen it. You've spent some time in it. What is the one thing that you see that, like, at any turn, it could be anywhere, right, that says, okay, this is the one thing we need to fix in the next three years? The number one thing that I always lean onto is the, we got to fix the applications and the resources before they get brought into the enterprise. How are we going to manage the access first instead of being come into the game after the fact where something's already there, then we're trying to have to fold it into the rest of our enterprise? Identity needs to be front and foremost with the people as they're developing, as they're building, because it's like, okay, we're going to build this great thing. How are we going to use it? How are we going to manage it? How are we going to keep people of it? Because we solve the identity problem up front because we've been, like you're saying, we've been playing catch up for 20 years. We've been trying to unwind these systems that were built that no one ever thought they were going to, now we have to go and unwind that. And it's like, I think we fix it up front and we do it the right way. Maybe it gets to the point where, I forget which one of you are talking about, where AI is the interface, right? And everything else goes away. It's like we ask AI and AI makes the decisions and where we go from it that way. So that's my thought. And it goes back to it. I want to make it invisible. All right. You get no worries from me, man. I've always wanted it to be invisible, right? Then maybe we could hide in the background and go play golf and not have to worry about it. Because AI's got it. AI's got it. You're good, guys. Mike. I had lots of fun talking to you. And of course, thank you for the partnership. I think it's so important to us, saving it, but also our clients as well. I think better together. Yeah. We know how that story goes. And golfer, right? So just to close this, something that people don't know about Mike. What kind of music do you like listening to? Favorite band? Pixies. Yes. Okay. All right. You know Pixies? Of course I do. There you go. Now I like you even more. Thank you, Mike. Excellent. Thanks, everybody. All right, guys. All right. That's another wrap for another Rooted Conversation here at Savvy Talk. See you guys later. See you guys later. I had fun. Yeah. It was a great conversation, man. I like Mike's aspect, especially at IBM, man. Listening to him talk about how they've set up their services and their advisory, and it's got this Big Four take to it, right? I honestly never knew that much about IBM Consultant, right? Oh, yeah. But I think watching... It's going to be interesting watching to see what IBM does from the AI side to this point. It's baked into kind of what they do and the way that they can kind of execute on that and the different solutions they're going to be delivering to customers. I think it's going to be very interesting. But yeah, it was a great conversation. I'm jealous, man. He's getting ready to go on this golfing thing, man. You're going to call him out? Yeah. No, I was wondering if... Yeah, I wish we had more time to talk about, okay, how does that compare, for example, with the other AIs out there, right? Yeah. So the Gemini's of the world, right? And where Watson fits in that whole picture of AI. But I like his take, which is very pragmatic. Yeah. Hey, this is... Man, if you are a practitioner, if you're dealing with adoption of AI, yeah, you've got to look at the data. Yeah. That was a big takeaway for me. Yeah, absolutely. Well, I mean, it makes sense, right? When you deal with, in that realm, consultant services, and he's seeing different clients day in, day out, right? All this stuff, it always comes down to basic blocking and tackling, right? You've got to... Of all the innovation and things you want to do, it's always about slowing down to move fast with all of this stuff, right? And I think being able to have that view of it, especially from a lens of like an IBM, I think is super cool for them to be able to see kind of the trends before they happen. So I want to... Before we head on this one, though, again, quick trailer in the NHI workshop, man. Let's just talk a little bit about what that was like. Because I was excited they added that to the agenda this year. I didn't get a chance to make any of them, though. That sucked. But what was that like? You were talking about a little bit the energy of the room earlier. Yeah, man. It was like 24 people on stage. 24 people on stage? On stage. Wow. And the audience was like hundreds. Okay, nice. 24 people, like panelists, and so very diverse mix of people like us in the vendor side. Right. Plus people that are clients or people adopting or looking to solving the NHI risk issues. So it was very well done. I even wrote a LinkedIn post about, hey, congrats organization. Number one, to make this room packed. Yeah. But also the way they split the panels. It was super cool. I learned a lot. That's awesome. There was a point of view on managing risk of NHIs. Mine specifically was about the intersection between agentic AI and NHIs. Nice. And just the amount of practical advice, the insights, I think it was very valuable. You had to be there to understand what I'm talking about. I know. FOMO, right? Yeah. Dude, big time. Big time. I'm so jealous. But I'm glad it went off well. I really love what Identiverse is doing with this conference. Me too. They're leaning more back into a lot of things like with workshops to get practitioners. You can come. You can get the information you want. You can take away. Just kind of like real advice that you can go and take, especially something like NHI and AI because it's, as we talked about, it's here. You got to have to figure out what your game plan is going to be. So to come to a place like this and be able to get to the workshops, I think it's pretty cool, man. Yeah. I agree. And the way the adoption of agentic is growing, man. So I think this is going to be perhaps the biggest attack surface, if you think about non-human identities and all machines. I agree. I think a big chunk of that will be AI agents. I agree. And a lot of people like coding stuff without knowing. There was a friend of mine yesterday, Marco Venuta. You know Marco. I hope so. Yeah, I introduced you to him, man. Oh, when we went to… The Italian guy. Yeah, yeah, yeah. And he said, Enrique, I'm not a super faster coder. And we were talking about this with Mike, right? So do you think all these average guys like me, I'm not a super faster coder either. So he actually built a full app using, I think it was Gemini or one of those. He created an app for his phone. He was showing me. It was a super funny thing. But I think it becomes more within reach for people to build those stuff, which is good and bad because now it's democratization that gives people access to this type of power without even thinking about identity and the other controls. So I think to Mike's point, we've got to design things with a controlling mind. And I think that was actually one of the outcomes and takeaways from the workshop this morning. It all comes together, man. Yeah. All right. We'll wrap this one up. Folks, we'll see you in the next episode. I miss Simon. I don't.