Ep 103 ·
IAM in 2026: From Anti-Patterns to Autonomous AI Agents with Advait Patel
Advait Patel (Broadcom): automate just-in-time access, build IAM up from least privilege, and keep AI agents on low-risk tasks until you can trust them.
Advait Patel is a senior SRE at Broadcom, where he balances performance, security and scalability in cloud environments. He is a founding member of AIVSS at the OWASP GenAI Security Project and has authored books including Implementing Security with AI and Implementing Identity Management on GCP.
Ep 103 ·
Advait Patel (Broadcom): automate just-in-time access, build IAM up from least privilege, and keep AI agents on low-risk tasks until you can trust them.
Advait says treating compliance as a document checklist no longer works. Patching, visibility, logs and tracking who accessed or changed what need to be in place from day one, not added after something is found. With controls, guardrails and visibility from the start, you are not scrambling when auditors arrive, and engineers feel confident in the product and in passing any security or compliance review.
Manual access requests — file a ticket, wait for IT security and manager approval — can take a day or several, frustrate developers and slow development. Advait says that has to go: developers should request just-in-time access that is checked against predefined controls and granted in seconds or minutes. Security is not locking everything; it is locking what needs to be locked and granting what needs to be granted.
Advait says traditional KPIs — mean time to react, detect and resolve — are not wrong but are no longer enough. He adds signal quality (is AI improving existing workflows), engineer efficiency (is a problem fixed faster than before), decision quality (does AI recommend well enough that you are not deciding every low-risk task) and automation safety (how often AI-driven automations are correct).
What works for 100 engineers will not work for 10,000, so IAM has to fit your company. The anti-pattern Advait calls out is starting from the top — granting admin or power-user access and removing what goes unused after 30 days. Instead, start from zero trust and minimal permissions, assign roles by team (a database team needs services like DynamoDB or Cloud SQL, not VMs), and add permissions as needed.
Agents can track changes, collect logs, find patterns in production alerts, trace the root cause, check whether an incident has happened before, and write incident runbooks. But agents cost you visibility, so you need to know what they are doing and what they are capable of. Advait starts with low-risk tasks rather than handing an agent a production API key with no human intervention.
Advait sees the industry heading toward autonomous agents, but says you should never fully trust anything, especially AI, with a production system that touches customers and your company's reputation. Use autonomous AI for low-risk tasks where you are fine without visibility and confident in the results; if you are even 0.01% in doubt, he doubts people will use it in production.
New episodes twice a month
Follow Scale To Zero wherever you listen, or send us the question your team is stuck on and we will put it to an expert.