
#451 - Sponsor Spotlight - C1.ai
Show notes
Alex Bovee, CEO and co-founder of C1.ai (formerly ConductorOne), returns for his third appearance on Identity at the Center. Alex walks Jim and Jeff through the rebrand to C1.ai and why the .ai matters: identity now covers humans, workloads, and agents. The conversation opens on launch week and the new App Hub, built around a question many CIOs and CISOs are facing. What happens when everyone in the company becomes a builder and vibe-coded apps start running critical workflows?
From there, Alex frames the difference between humans, software, and agents using two dimensions, trustworthiness and determinism, and explains why agents that "goal max" call for runtime enforcement instead of relying only on after-the-fact reviews. He breaks down the Hugging Face breach, where an OpenAI agent under evaluation escaped its sandbox in pursuit of better eval results, and lays out six control points for agent security: identity, the harness, network egress, data and tools, the LLM gateway, and credentials.
The group also covers why IGA fundamentals speed up AI adoption, three buckets of agents (SaaS, enterprise, and personal productivity), agents evaluating other agents, governed swim lanes over shutting things down, and the slept-on problem of credentials sprawling across endpoints. Plus girl dads, boy families, and the return of the Royal Octopus.
Made possible with support from C1. Learn more at c1.ai/idac
Connect with Alex: https://www.linkedin.com/in/alexbovee/
Learn more about C1: https://www.c1.ai/idac
Connect with us on LinkedIn:
Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/
Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/
Visit the show on the web at idacpodcast.com
00:00 Intro
00:33 Welcome back, Alex Bovee
01:28 From ConductorOne to C1 and the .ai rebrand
04:14 Launch week and the App Hub
07:07 Farm-to-table software and the limits of off-the-shelf SaaS
09:56 The real risks of vibe-coded apps
12:52 Humans, software, and agents: trust and determinism
17:10 UARs matter more for agents
17:59 What happened in the Hugging Face breach
21:23 Six control points for securing agents
25:38 Where should teams focus first?
31:33 Meeting customers where they are
33:02 Why IGA basics come before AI adoption
34:27 AI accelerates bad IAM
35:45 Governance versus business speed
37:51 SaaS, enterprise, and personal productivity agents
41:19 Runtime enforcement and agents evaluating agents
44:22 Can you train an agent not to goal max?
47:33 Governed swim lanes, not shutdowns
50:33 Publishing a vibe-coded app through App Hub
53:03 The slept-on credential problem
56:04 Girl dads, boy families, and the Royal Octopus
1:00:54 Wrap-up
IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Alex Bovee, C1, C1.ai, ConductorOne, Sponsor Spotlight, identity and access management, IAM, identity governance, IGA, AI agents, agentic AI, agentic enterprise, non-human identity, NHI, workload identity, machine identity, vibe coding, App Hub, Hugging Face breach, OpenAI, agent evals, goal maxing, runtime enforcement, runtime security, MCP, MCP gateway, LLM gateway, network egress, agent harness, just-in-time credentials, secrets management, shadow AI, user access reviews, UAR, joiner mover leaver, delegated authorization