Identity at the Center
Identity at the Center
Identity at the Center·Sep 30, 2026·1h 2m·Episode #451

#451 - Sponsor Spotlight - C1.ai

Show notes

Alex Bovee, CEO and co-founder of C1.ai (formerly ConductorOne), returns for his third appearance on Identity at the Center. Alex walks Jim and Jeff through the rebrand to C1.ai and why the .ai matters: identity now covers humans, workloads, and agents. The conversation opens on launch week and the new App Hub, built around a question many CIOs and CISOs are facing. What happens when everyone in the company becomes a builder and vibe-coded apps start running critical workflows?


From there, Alex frames the difference between humans, software, and agents using two dimensions, trustworthiness and determinism, and explains why agents that "goal max" call for runtime enforcement instead of relying only on after-the-fact reviews. He breaks down the Hugging Face breach, where an OpenAI agent under evaluation escaped its sandbox in pursuit of better eval results, and lays out six control points for agent security: identity, the harness, network egress, data and tools, the LLM gateway, and credentials.


The group also covers why IGA fundamentals speed up AI adoption, three buckets of agents (SaaS, enterprise, and personal productivity), agents evaluating other agents, governed swim lanes over shutting things down, and the slept-on problem of credentials sprawling across endpoints. Plus girl dads, boy families, and the return of the Royal Octopus.


Made possible with support from C1. Learn more at c1.ai/idac



Connect with Alex: https://www.linkedin.com/in/alexbovee/


Learn more about C1: https://www.c1.ai/idac


Connect with us on LinkedIn:


Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/


Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/


Visit the show on the web at idacpodcast.com



00:00 Intro

00:33 Welcome back, Alex Bovee

01:28 From ConductorOne to C1 and the .ai rebrand

04:14 Launch week and the App Hub

07:07 Farm-to-table software and the limits of off-the-shelf SaaS

09:56 The real risks of vibe-coded apps

12:52 Humans, software, and agents: trust and determinism

17:10 UARs matter more for agents

17:59 What happened in the Hugging Face breach

21:23 Six control points for securing agents

25:38 Where should teams focus first?

31:33 Meeting customers where they are

33:02 Why IGA basics come before AI adoption

34:27 AI accelerates bad IAM

35:45 Governance versus business speed

37:51 SaaS, enterprise, and personal productivity agents

41:19 Runtime enforcement and agents evaluating agents

44:22 Can you train an agent not to goal max?

47:33 Governed swim lanes, not shutdowns

50:33 Publishing a vibe-coded app through App Hub

53:03 The slept-on credential problem

56:04 Girl dads, boy families, and the Royal Octopus

1:00:54 Wrap-up



IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Alex Bovee, C1, C1.ai, ConductorOne, Sponsor Spotlight, identity and access management, IAM, identity governance, IGA, AI agents, agentic AI, agentic enterprise, non-human identity, NHI, workload identity, machine identity, vibe coding, App Hub, Hugging Face breach, OpenAI, agent evals, goal maxing, runtime enforcement, runtime security, MCP, MCP gateway, LLM gateway, network egress, agent harness, just-in-time credentials, secrets management, shadow AI, user access reviews, UAR, joiner mover leaver, delegated authorization