
#448 - Sponsor Spotlight - Opal Security
Show notes
Howard Ting, CEO of Opal Security, joins Jeff Steadman for a Sponsor Spotlight covering identity governance for both human and non-human identities. Howard traces his path through RSA Security, Microsoft, Palo Alto Networks, Nutanix, and Cyberhaven before returning to identity to lead Opal. The conversation covers why disabling a departing employee's account rarely ends their access, the orphaned tokens, service accounts, and agents left behind, and why visibility has to come before ownership and risk analysis. Howard and Jeff dig into agent intent and authority: whether an agent can declare its own intent, why permissions should stay a subset of what its human creator holds, and how narrowly scoped, single-task agents make governance easier. They also cover how Opal matches AI decision capacity to a growing volume of access requests, including how the company's Paladin AI supports approvers and campaign creators today. The episode closes with Opal's announcement of a unified platform for governing human, non-human, and agent identities together, extending Paladin's decisioning to agents and introducing Policy Insights to help security teams balance friction against risk. Howard shares his view that identity has to shift from an episodic, event-driven practice to a continuous one, along with a lighthearted detour into 90s video games.
Connect with Howard: https://www.linkedin.com/in/howardting/
Learn more about Opal Security: https://www.opal.dev/
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at idacpodcast.com
00:10 Intro and welcome
01:01 Howard's identity origin story: RSA, Microsoft, Kim Cameron
02:48 What Opal does: unified control plane for human and non-human identities
04:16 The opal.dev domain and how Opal got its name
06:42 Termination and lifecycle: why access doesn't fully go away
09:33 Session management and orphaned accounts
13:57 Visibility as the first step in identity governance
17:31 Can an agent declare its own intent?
20:29 Authority: should an agent ever exceed its creator's permissions?
22:12 Inside Opal: Risk Center and Policy Insights
25:41 How Opal connects to systems and collects usage data
27:30 Cross-application segregation of duties
29:06 Zero standing privilege and AI managing AI
32:12 Building trust in AI-driven access decisions
39:00 Announcing Opal's unified platform for agents and non-human identities
44:18 Explainability and traceability in Paladin's decisions
48:54 Tuning risk tolerance and autonomy in Paladin
51:20 Proving value: demos, POCs, and industry skepticism
57:47 The shift from episodic to continuous identity
59:50 Lightning round: favorite 90s video games
IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Howard Ting, Opal Security, Sponsor Spotlight, identity governance administration, IGA, non-human identity, NHI, agent identity, agentic AI, access governance, least privilege, just-in-time access, JIT, zero standing privilege, Paladin, Risk Center, Policy Insights, segregation of duties, SOD, RSA Security, Microsoft, Kim Cameron, Palo Alto Networks, Nutanix, Cyberhaven, continuous identity, identity lifecycle management, orphaned accounts, service accounts, API keys, intent-based access control