How It Works: AI Agent Security & NHI Federation
and welcome to today's webinar. My name is Suresh Satyamurthy. I'm the chief marketing officer for Akeyless Security. I have with me our cofounder and CEO, Oded Haravan. And today's topic is about two solutions that we launched in the last month. One was Secretless AI. It's a trademark solution for AI agent security, and other is nonhuman identity federation. And the way we define solution is how we bring the capabilities, the features, and integrations in the product to address a need in the market. With the rise in AI agents, we developed the solutions for AI agent security. And today's session is going to be slightly different from the formats that we have had in the past. You would have seen us in executive conversations, fireside chat formats. You'd have seen us in live demos. Today's session is what we call and how it works session. So it's going to be more technical than the briefings, and we are going to walk through an architecture of how the solution works, which we believe will be interesting and exciting to the audience who have registered, for today's webinar. Let me first, get started by, having Oded introduce himself. Some of you in this call already know him, but I know that there is always new attendees in this call. Oded, would be great if you can talk a little bit, about your background, what led you to start Akeyless, before we get started. Sure. Well, nice to have everyone here. Very much excited to have our webinar, on the on the topics of NHI Federation and AI agents. I believe that, this is, one of the one of the first ones that we are about to continue and provide even more information about AI agents and the a lot of excitement around that into, around identity management within, this role. As for myself, I started, with the cybersecurity industry around twenty five years ago, within the Israeli Defense Forces. I'm a reserve captain. I've done, lots of a lot around identity management for the Israeli Defense Forces, some SIEM SOC, endpoint security, infrastructure, key management systems, privileged access management, PKI systems, and so on and so forth. What today with time has been converged and part of our, you know, of our of our business today. Lately after that, I was, the PMO and project manager for, the professional services for CA Technologies. I started there as an as an architect for IAM, specifically IAM and cybersecurity solutions. I've done this, back in Israel. Today in Jersey, very happy, to be, to be here. After that time, I took some time off enterprise security. Went to become, the product guy for, digital product a company named Moveit that was acquired by Intel. And then six years back, together with my two cofounders, we established Akeyless, within the realm of machine identities, and today is, within the identity security realm. That's great. Thank you for the quick intro. Oded, I know that over the last eight to twelve months, you have met hundreds of CSOs. As early as, last month, you were in Florida Keys at the CSO village with over a hundred CSOs. What are you hearing, as the biggest blind spot, or what do you see as the biggest blind spot in the industry, based on your conversations with them? Yeah. So more than anything, you know, know, as you can as you can imagine in terms of, you know, blind spots, when you think of where actually the industry is and where the tools are. Right? So the I'm industry specifically was very much focused on solutions for human beings. We started to talk about this gap years ago, when talking about how machines behave, our workloads, containers, virtual machines, and, you know, functions as a service, how they behave versus humans. Today with AI agents, that gap became even much greater where the traditional solutions are very much focused on on humans and how human behave, and they're not very much, adopt well, not very much, built for how machines and AI agents are actually behaving. Now just to share maybe a few of that, you know, of how how the industry looks look at it and the in present mode. Let's just, put it like that. Yeah. Okay. So this is how the industry looked at the, the ratio between the number of human to the number of machines and now to the number of AI agents and especially with the number of identities. And when I say identities, they are being represented as objects, but the object that authenticate them, credentials, certificates, and keys, as a result of those, right, they are sprawling away the different sprawling, in different environments. They're sprawled within different tools. We have those machine identities and the AIA identities very much soon within the DevOps environments, within the CICD processes, within the development processes, and eventually within the production. Either it's a shelfware or if you're developing solutions within your organization, you would find those identities more and more. What used to be a service account challenge, right, like back twenty years back, where you you were actually being able to count the service that you've had within the data center. Today, it's impasse almost impossible to really list and to count the number of components that within, the network, and this is the expectancy, of growth up to twenty twenty eight. We've taken some different sources to include Gartner as well, in order to build this particular graph. So the number the volume is is very much different. What we see is the result right now. This is the result of using or trying to use the industry. We're trying to use the, existing tools for humans. Very much understand that it's not very much viable. Right? So adaptation for the different types of tools is a must. And as you see is the current result of lots of those breaches that are basically being, facilitated as a result of exploiting a password, an API key, account credentials, all of those are related to machine identities and how we call it and soon, to be, to be, connected, with AI agents. So ninety one percent of organizations report an identity related breach and eighty five percent reporting, that it is related to, to machines as you can see in front of you. So this is in terms of, you know, the way that we look at this, the way that we look at the those differences. And it's not just about the volume. Right? And it's not just about the trend. The behavior of those machines, they log differently. Right? They, they communicate about what the things that they're doing differently. And administering. And that that's one of the major shifts with machines and AI agents comparing to the past. I am professionals, in which I I, I count myself as one of those. Right? We tend to look at the world out of the eyes of what we will be able to manage, right, with the traditional identity management systems. What happens with machine and AI agents is that this whole centralized approach of managing the entitlements and the identities can no longer live within machine identities and AI agents, and the control need to be somehow, decentralized. Having that platform teams is now within the picture. Right? We have cloud architects that are very much relevant to the era to the area of machine identities and AI agents. And you have many other stakeholders that need to cooperate. So it's not just about the IAM. Now we need to cooperate with information security, with IT, with platform, and DevOps teams in order to influence and eventually to implement a good practice for security for machine and AI agents. Thank you. Hey. Let's jump into the solutions. I understand that it would help the audience if you can, give us a quick briefing about Akeyless and the Akeyless platform, as I understand the platform's capabilities lend itself well to the solutions we are gonna talk about. So if you could take a moment to just introduce the audience to Akeyless and the platform itself, that'd be great. Sure. No problem. Let's, let's share once again very quickly, and and we'll do that briefly, obviously, just to for the sake of the audience that is not aware of us. Akeyless is, you know, machines, AI agents, and human identities and access, basically an identity security, provider. We started, six six years ago, started specifically with secrets management realm. And ever since, we evolved and it became a much larger platform, which I'll talk about in a minute. We serve Fortune ten, S and P five hundred, as you see in front of you, the top retailers, global financials, as well as health care and pharmaceuticals, software and online leaders, as you can see, being covered by different analysts. And I think, you know, when you think of what is Akeyless, if you wanna describe it, it's a SaaS based solution, pure SaaS based, but a hybrid solution that provides also for on prem. We have a very, very unique approach in terms of architecture, with a gateway approach, with caching and so on to make sure that everything is is live and ready, twenty four seven. When you look at it, we're, based we have based our entire solution. We've built on top of our DFC technology. It's a very innovative technology to manage encryption keys with different fragments. One of the fragment on the on the customer side, it provides zero knowledge, so we cannot we cannot decrypt, we cannot access the customer's secrets. So when you think of it, the identity security platform to manage the credentials, certificates, and keys for any type of identity, obviously specializing with you with machines and AI agents. Within that platform, we have secrets management and universal secrets connector to govern many different secret stores as well as the full blown secrets management solution, certificate life cycle management, the next gen PAM within our platform. It's a secure access solution and encryption and key management, within within that. So unified platform built from ground, ground up, with the understanding that all of those different areas are basically overlapping. We did not grow through m and a. This is not platform by marketing rather than a true platform that is unified and created with just in time and zero standing privileges, principles. Got it. Could you just, double click on one item, which is, DFC? And I have, one prospect on this call who had asked us, earlier that, hey. I prefer self deployed vaults and secrets management solutions. Why should I consider Akeyless? Because I have complete control of my secrets if it's self deployed. What is Sure. So yeah. So I'll I'll do it briefly, obviously, because our our aim here is to talk about AI agents and and machines. But to go, to go and touch upon the DFC, distributed fragments cryptography, that's DFC stands for. Basically, we are, we have an innovative way to perform cryptographic operations using fragments of encryption keys without ever combining them. So imagine, like, different cloud providers or different regions that we operate, and they have different fragments. The, the fragments are created as such, so we do not create a key and then split it rather than creating those fragments. One of the fragment on the customer side, so we don't have access to that. And, the encryption and decryption happens on the customer side where, again, we don't have access using a customer fragment, and, again, the fragments are never combined. This structure that is FIPS one hundred and forty dash two certified and validated, this whole mechanism makes sure that your secrets are very much protected in the cloud. Again, with our gateway approach, you enjoy, caching in full performance acceleration. Our SaaS provides twenty four by seven with four nines and five nines of availability depending on the SLA and depending on the type of, different components that you implement. We have great experience with providing, over the sun, support and on and and truly live system. So for everyone who has some tendency for on prem, we serve for on prem, and we created the mechanisms that allow us to provide business continuity and service continuity around around the the clock. That's fantastic. So you get all the benefits of SaaS and the complete control of your of the secrets. Now jumping into solutions, we are just past ten minutes in. With the name of the first solution was Secretless AI. So before we go into what Secretless AI is, could you explain the concept of secretless, which may be, new to many folks on the call? Yes. Very much so. So I'd like to go before we'll go exactly as you're saying deeper into secretless AI and deeper into the concept of federation in NHI. Everything those two concepts are built on the following concepts that we basically take and help our customers to move on from the, major risk of having static secrets. Okay? Everything starts there. The whole world was very much based and, unfortunately, still is. This is exactly our mission. Aculus, that's our name, right, to make sure that no static secrets, no key, are being, are being required whatsoever as much as possible. This is a great, you know, ideology and a great dream to go to. But as you can imagine, in some cases, static secrets are still there, especially in OT devices and so on. But, basically, that's the that's the that's the basic, common that is happening with everyone. We help our customers and large enterprises to move to automatic quotation using our platform, automatic quotation to certain endpoints. You can rotate on certain vaults. You can rotate on certain endpoints, databases, Linux devices, obviously, on on cloud IAMs as well, service accounts, and so on and so forth, and and service principles. So you can automatically perform the rotation dually on like, in parallel to different endpoints at the same time if you wish. So there are all kind of, greater sophistication there. After that, or sometimes in parallel, depending on our on our customers and the size of the account, we're helping our customers to move to the third generation, which is identify where is it, where are the places, where are the cases and the use cases that they can basically jump to the zero standing privileges approach, meaning that if, with using dynamic identities, and that is in in versus the automatic quotation for fixed accounts. And I'll give an example. If a certain container spins up, requires access to a certain database, Instead of having, a fixed account on that database that basically is their, fixed account that, unfortunately waiting to be hacked. Right? Then dynamic identities mean that Aculus is the one to create temporary access to that database with temporary identities that's being created, obviously correlated behind the scene to make sure that there is a full tracking, monitoring, and governance. But the whole access is facilitating on the identity level for temporary amount of time according to the requester's requirements and need. It can be for ten seconds. It can be for two days or thirty days or as much as as you'd like. The minimum is the best. So whenever the container spins up, gets the access, gets the temporary identity, and then Akeyless is in charge on deleting that particular identity. In a way, this is the application level solution for tokenizing, okay, for tokens. Right? For example, for OIDC tokens, dynamic identities are definitely within that, aka just in time, zero standing privileges within that thing within that realm. The fourth generation, and that's the whole that's the holy grail. That's the that's the golden, ideal that we should all get into, which is reducing the amount of secrets, credentials, certificates, keys to the minimum, and to help our customers to use to leverage the more advanced authentication, schemes and methods such as OAuth, OIDC, SPIFI, and SPIFIER. Sometimes, in some ways, also certificate, certificate short lived certificate authentication. But leveraging those advanced authentication, having Akeyless to be the identity provider for those, and by that to reduce down to the minimum the number of secrets within the organization. And those are the fourth generation that we help our customers. Some of them are able to go jump straight to the fourth generation, but the majority are splitting, you know, the solutions between all the fourth. And, yeah, and we're here to help. So that's the background behind, the secret list AI infineration in HI. Thank you, Oded. Before we jump in, there is this is Gartner's data that some of you may have already seen today. Less than one percent of enterprise applications are, AI agents. By twenty twenty eight, which is just over three years from now, almost thirty five percent of all enterprise apps will be AI agents. It is going to be one of the fastest growing enterprise product adoption scenarios. We are seeing massive acquisitions in the industry to address the challenges associated with security in the AI space. So let's jump right in. Oded, what is Akeyless' solution to help enterprises with the adoption of AI agents? And as we communicated earlier, this is how it works webinar. So if you could show us how the product works and walk us through the architecture, that'd be fantastic. Okay. Sounds good. Just wanna make sure that, you can, see my screen here. I think that you're seeing the wrong one. So let me just, yeah, let me just redo it quickly. Keep up the good pace that we have. And yep. Alright. Good. So straight to the point. I just spoke about the fourth generation of of of shifting from the traditional model of having fixed credentials up to secret list via rotation and dynamics dynamic identities. So secretless AI is the concept of leveraging, obviously, our technology and to embed that within MCP, MCP servers particularly. Also, you can do that within the AI agents themselves or depending on you look how you look at it in different components. But the whole notion is to help you guys, developers, architects, to make sure that the AI agent itself doesn't have secrets whatsoever. Okay? And that means that no fixed credentials, even not the rotated ones, rather than temporary credentials that are being created on the fly whenever are being needed, whenever a query needs to happen, especially from MCP server to the data store itself. And let's go one by one, for the, for the entire process, and by that, we'll be able to demonstrate that. So assuming an AI agent is getting a certain, query, right, and requires some kind of access to a certain data store that is being represented by an MCP server or encapsulated by an MCP server. So the MCP server traditionally would need to use some level of access to that certain data store, whether that MCP server encapsulates a local file server, cloud provider access, whatever communication, communication, infrastructure, or a certain search engine within a certain API access. Regardless of what it is, right, either a database, an API access for Salesforce, or whatever, the MCP server would eventually require either an OAuth token, with either, database credentials, whatever it is. Right? So our goal is to make sure that the MCP server itself would not use any secret whatsoever. God forbid for the AI agent to somehow provide those secrets. By the way, it has been proven that it's it is possible. The AI agent themselves have obviously access to the code that they write. And and, you know, in some particular cases, they are able, unfortunately, to even expose the secrets that they leverage. Okay? So it's very important that the code itself would not have those credentials inside and know any way to authenticate the identity rather than to be gathered from the outside. So the MCP server to call the Akeyless. Right? Otherwise, right, the the MCP server requires those credentials. But the idea is basically for the MCP server to call the Akeyless API represented within a local gateway. It's a local local docker a stateless a status docker that you can leverage. Very easy to consume. You can also call the the global SaaS directly, but, obviously, we would recommend using the local gateway as as a docker. MCP server to authenticate to Akeyless using the using the advanced authentication provided by either the cloud providers. Most of you, I would guess, that would leverage the cloud providers I am. So Akeyless is able to authenticate the MCP server as an, as an ARN code with AWS or Google Identity or Azure Identity for that sense, so no secret is required. There is no secret zero that is being kept on the MCP server. Akeyless is able to authenticate. We have other methodologies also to do that in the on prem without any secret. I'll put that aside. But the MCP server, authenticates to Akeyless. Akeyless understands exactly who's calling. And according to the very detailed that is being preconfigured within Akeyless, we can do that, by the way, with identifying entire farm, entire cluster, a specific function. It depends on the level of granularity that you're that you're interested with. So Akeyless would identify that and would understand what kind of access is needed to those data stores, would approach those data stores, create either a token depending on the authentication scheme of those data stores. Right? So Akeyless is able to create either an OIDC token as an identity provider, would be able to create an a any temporary identity depending on the type of the platform. So local, temporary Oracle or MySQL account with particular entitlements that are being required. By the way, some of them can be created dynamically. So dynamic entitlements would be something in the future that we will, also represent how to create dynamic entitlements according to the AI agent behavior it needs. And that is being provided back once Akeyless is creating it, provided back to the MCP server. The MCP server is able to create the secure connection to that particular data store to perform what is needed, the query, and then to close to close the entire connection upon a certain time. And then Akeyless is able to completely delete that particular account or the token to be expired. That's in a nutshell how the solution works. We will also obviously be be happy to provide even more clarity. It is being can can be leveraged by, one of our dozens or hundred of, of plugins as well as SDKs that can be connected within the MCP server with various languages and so on and so forth. Suresh? Sorry. I was on mute. Folks, if you have further questions on this, please use the q and a panel to ask questions. And, of course, if you'd like us to demonstrate the product to you, we we can always request a demo through our website, and we'll be happy to customize the demo for your needs and provide those as well. But feel free to use the q and a panel to ask further questions. The next solution, Oded, is in the CHI Federation or nonhuman identity federation. Could you walk us through the nonhuman identity federation? What is it? What is the term SSO for machines? And, help us understand as well. Sure. So, again, within the the same realm and, Suresh, just to make sure that you can hear me well and everything is fine with the connection. Okay. Good. So in the same realm of presenting identity, whether it is temporary identity, a temporary token, or rotated secret for that sense, at the end of the day, what Akeyless facilitates here is a is ability to federate, right, between workloads that are operated on different environments. So whether you have an environment and this is, by the way, very much relevant to the era of AI agents, and I'll explain why. But first, the basic the basic use case here. Let's say that you have an environment that sits on both on prem and one of the cloud providers. Whenever that on prem machine requires access to the to the cloud provider, it requires an access, right, an identity an identity in order to actually approach the RDS database or the the MS, the Microsoft SQL, whatever it is. Right? So we are able to always authenticate the machine, authenticate the workload and the humans that comes from a certain environment and to be able to facilitate the temporary access by creating those temporary identities and the tokens and to provide that to the requester. So even if you have a function that requires access to Salesforce API, instead of having that secret or that identity stored within the code, it will be able to approach or it it is able to approach Akeyless to ask for an access to the Salesforce API. We will we will create the token for the Salesforce, OAuth mechanism, and then that particular function would be able to, approach and access, directly with the Salesforce. When you think of it, this is a world of multi connectivity between hybrid and multi cloud and SaaS, services, and specifically within the realm of AI agents where it is actually one step further where you have some of the compute to happen on a certain vendor, some of your data sources. Right? The the compute, the LLA models in in lot of cases will run, and runs from the vendors that are able to provide it to you, such as, obviously, you know, OpenAI and Anthropic and, obviously, these cloud providers and some of them. But so some of the commit ran by other party. Your data is being encapsulated by MCP servers, sometimes on on prem, sometimes on the cloud, and everyone needs to have access to between. So it's a cross cross platform authentication that requires an identity provider within those two. In a simple words, this is SSO for machines just like we've done it for years for humans. This is now SSO for machines, and this is how we federate among all of those components. Suresh, back to you. Yeah. We have a question from one of our, customers. Fanatics, they're building an AI agent, to help Fanatics users and want to ensure it interacts with Akeyless securely. Do you have any examples or best practices for implementing secretless authentication with Akeyless for an MCP server? Sure. There's obviously, even a specific specific blog post we have recently have created. We'll be happy to share it, with you as Rich. Just make sure that it's being published to that particular individual, or via our, our LinkedIn post together with the webinar materials. Please feel free once you read that to approach us, and we'll be happy to, guide you through and make sure that everything is, well documented for your needs. But, definitely, you'll see there step by step to integrate our one of our SDKs within your MCP server, obviously, the prerequisites for configuring dynamic secrets, allocation within the, Akeyless platform. Yes. I'll make sure I send this to you. And, I know we are at the bottom of the hour. I have one minute. I want to use this one for your closing comments. In the list of attendees that we have, I see, folks with IAM titles. I'm seeing two CSOs. I'm seeing, information security professionals. So there is differing and various audience in here. What would be your, recommendations? How do they get started? What is, what are your closing thoughts, to all of these individuals on how they can best implement it? Two major things. One is cooperate. I think that the fact that you just named a lot of positions is just for everyone to know within this conversation. There is no one organization in which there's a certain persona that is in charge of this. In every organization, machine identities is is something that requires cooperation because of its nature. So cooperate and make sure that you have the committee, and you're creating this virtual team in order to have this those agreements. You would not agree on everything, but we can obviously help you from our best practices and experience. Number two, there is some tendency to think of some optimum only after we will get to one hundred percent of understanding of how we're going to do it. We will be able to provide a solution. Right? Obviously, this is the right thing to do in a regular business. Right? But AI agents and machines are coming in strongly. This is no more a question of when. It's a question of how do you deal with it because it's happening. So our advice would be to just start with managing those credentials, managing those secrets, and those, those keys, and not to wait because in the majority of it, I just wanna make sure that my picture is well seen. And, yeah. Okay. In the majority of it, you would find that the secret stores are very much clear. They are within your cloud. They are within your code. They are within your, infrastructure. Not everything opening the code. Some of it can be dealt with just configuration. There are a lot of, secrets that are already within Kubernetes clusters. So it's not does not necessarily mean that you need to open open everything in order to actually provide a solution. Just start and see incremental steps and improvement with time. Thank you, Oded. That that was fantastic. And, folks who asked the question, I sent a link to a blog titled embracing a secretless approach with Akeyless that outlines best practices as well. I hope you find it useful, but then again, please feel free to reach out or contact us. We are happy to provide a customized demo for your needs as well. Oded, thank you again for your time. Folks, thank you for taking your Wednesday morning to be with us today, and I look forward to working with you all. Take care. Thank you.