
#436 - Sponsor Spotlight - P0 Security
Show notes
In this Sponsor Spotlight episode, Jeff Steadman flies solo and welcomes Greg Danyi, co-founder and CTO of P0 Security, to the show. Greg walks through P0's approach to runtime access control, covering how it applies to humans, non-human identities, and AI agents alike. The conversation digs into the difference between authentication and authorization, why zero standing privilege is more achievable now than before agentic adoption took hold, and how dynamic, evidence-based policies can reduce reliance on manual approvals. Greg also shares real examples, including row-level access control for data lakes and a CRM mishap that shows how easily agents can misinterpret intent. The episode closes with a look at where enterprise AI agent governance may be headed over the next few years, plus a lighter conversation about explaining IAM to a 10-year-old. This episode is made possible through the generous support of P0 Security as part of IDAC's nonprofit Sponsor Spotlight series. Learn more at p0.dev/idac.
Connect with Greg (Gergely): https://www.linkedin.com/in/gergely-danyi/
Learn more about P0: https://p0.dev/idac/
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
00:00 - Introduction and sponsor acknowledgment
01:13 - Greg Danyi's path into IAM
02:18 - What P0 Security solves for
03:21 - Where P0 fits versus PAM and IGA
04:46 - Agentic identity as a driver of adoption
05:27 - MCP servers and unpredictable agent actions
07:10 - Defining runtime access control
08:50 - How authentication and authorization work together
09:07 - Standing access versus expressed intent
10:16 - Zero standing privilege in practice
12:27 - Agentic identity as a distinct identity class
19:24 - Automated evidence for approvals
20:42 - Walking through a support agent example
22:13 - Row-level access control for data lakes
23:35 - Dynamic roles explained
29:55 - CRUD risks and underestimated concerns
31:32 - Human intent and giving agents clear direction
36:32 - Where enterprise AI agent governance is headed
39:36 - Advice for CIOs and CISOs getting started
41:15 - Explaining IAM to a 10-year-old
42:29 - Board games, dice, and calculated risk
44:00 - Closing thoughts and where to learn more
Keywords: IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Greg Danyi, P0 Security, runtime access control, agentic identity, zero standing privilege, non-human identity, authentication, authorization, IAM podcast