
#444 - August 2026 Mailbag
Show notes
Jeff and Jim open with the unavoidable topic of AI agents and the tension between enabling innovation and governing agent permissions, then run through a packed fall conference schedule. The August mailbag pulls questions from Singapore, Toronto, Prague, Johannesburg, Helsinki, and Seoul. They discuss when externalized authorization makes sense, why passkey recovery can become the weak link in phishing-resistant authentication, what EU digital identity wallets may mean for enterprises, how continuous access evaluation changes the meaning of terminating access, and how to build resilience around a centralized identity provider without creating a second full-scale IdP. The episode closes with a lighter question: if every IAM product needed a giant warning label, what should it say?
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at http://idacpodcast.com
00:10 - Welcome and have we talked about AI too much?
01:32 - Governing AI agents without becoming the progress prevention department
03:50 - Fall conference season and IDPro
04:40 - Cybersecurity Summits in Chicago and Atlanta
06:40 - SailPoint Navigate, InfoSec World, FIDO Authenticate, and Identiverse DC
10:40 - 3D printing, challenge coins, and superfan status
11:56 - August mailbag begins
12:19 - Singapore: Is externalized authorization ready for mainstream IAM?
20:30 - Toronto: Passkeys, account recovery, and help desk social engineering
25:55 - Prague: What should enterprises do about EU digital identity wallets?
31:44 - Johannesburg: Continuous session revocation and what “terminate access” really means
38:04 - Helsinki: Designing identity resilience around a centralized IdP
45:23 - Seoul: What warning label should every IAM product have?
48:26 - Wrap-up and how to send future mailbag questions
IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, IAM, identity and access management, August 2026 mailbag, externalized authorization, authorization, policy-based access control, passkeys, account recovery, phishing-resistant authentication, identity verification, EU digital identity wallet, continuous access evaluation, shared signals, session revocation, token revocation, identity resilience, identity provider, disaster recovery, business continuity, AI agents, agentic identity, IDPro, FIDO Authenticate, Identiverse DC, InfoSec World, SailPoint Navigate