Ep 103 ·
IAM in 2026: From Anti-Patterns to Autonomous AI Agents with Advait Patel
Advait Patel (Broadcom): automate just-in-time access, build IAM up from least privilege, and keep AI agents on low-risk tasks until you can trust them.
Topic
Identity is the new perimeter. Least privilege, IAM anti-patterns, machine and AI-agent identities, and access that is granted just in time.
30 episodes · 6 questions answered
How do you stop treating compliance as a checklist?
Advait says treating compliance as a document checklist no longer works. Patching, visibility, logs and tracking who accessed or changed what need to be in place from day one, not added after something is found. With controls, guardrails and visibility from the start, you are not scrambling when auditors arrive, and engineers feel confident in the product and in passing any security or compliance review.
Advait Patel · Broadcom
How should just-in-time access change IAM in 2026?
Manual access requests — file a ticket, wait for IT security and manager approval — can take a day or several, frustrate developers and slow development. Advait says that has to go: developers should request just-in-time access that is checked against predefined controls and granted in seconds or minutes. Security is not locking everything; it is locking what needs to be locked and granting what needs to be granted.
Advait Patel · Broadcom
What KPIs should security leaders track once AI is part of security operations?
Advait says traditional KPIs — mean time to react, detect and resolve — are not wrong but are no longer enough. He adds signal quality (is AI improving existing workflows), engineer efficiency (is a problem fixed faster than before), decision quality (does AI recommend well enough that you are not deciding every low-risk task) and automation safety (how often AI-driven automations are correct).
Advait Patel · Broadcom
What IAM anti-patterns should organizations avoid?
What works for 100 engineers will not work for 10,000, so IAM has to fit your company. The anti-pattern Advait calls out is starting from the top — granting admin or power-user access and removing what goes unused after 30 days. Instead, start from zero trust and minimal permissions, assign roles by team (a database team needs services like DynamoDB or Cloud SQL, not VMs), and add permissions as needed.
Advait Patel · Broadcom
How can SREs use AI agents for root cause analysis?
Agents can track changes, collect logs, find patterns in production alerts, trace the root cause, check whether an incident has happened before, and write incident runbooks. But agents cost you visibility, so you need to know what they are doing and what they are capable of. Advait starts with low-risk tasks rather than handing an agent a production API key with no human intervention.
Advait Patel · Broadcom
Will AI agents become fully autonomous in production?
Advait sees the industry heading toward autonomous agents, but says you should never fully trust anything, especially AI, with a production system that touches customers and your company's reputation. Use autonomous AI for low-risk tasks where you are fine without visibility and confident in the results; if you are even 0.01% in doubt, he doubts people will use it in production.
Advait Patel · Broadcom
Ep 103 ·
Advait Patel (Broadcom): automate just-in-time access, build IAM up from least privilege, and keep AI agents on low-risk tasks until you can trust them.
Sneha Malshetti, Senior Security Engineer at Ethos, on IAM differences between AWS and GCP and balancing least privilege with velocity.
Uttej Badwane, Senior Security Engineer at Carta, on zero-trust implementation challenges and the future role of AI in security.
Stephen Kuenzli on IAM, AI-driven cloud security, and using agents and MCPs to improve security decision-making at scale.
Rowan Udell on AWS IAM best practices for production environments, least-privilege strategies, and role-based access patterns.
Scott Weston, senior consultant at NetSPI, on cloud penetration testing, the GCPwn tool he created, and how to get started with cloud security testing.
Dr. Natalia Semenova on zero-trust architecture, the challenges of asset and identity discovery, and identity as the core of zero trust.
Richard Stiennon on the ultimate guide to cloud security, the evolving threat landscape, and building defence in depth.
John Giglio on demystifying IAM, the security-vs-compliance debate, and data-perimeter controls for read, write, and download.
Cassie Clark on the intersection of security and human behaviour, choice architecture, and continuous awareness programmes.
Kushagra Sharma, Senior Platform Security Engineer at Booking.com, on security baselines, boundaries, and layered defences.
Tom Adamski on network segmentation, risk assessment before design, and layering AWS security tools for defence in depth.
Adam Shostack on threat modelling fundamentals, secure-by-design principles, and making threat analysis accessible to all teams.
Rich Mogull on cloud security maturity models, the mindset shift from on-prem, and setting realistic expectations with leadership.
Joseph South on the cloud IAM landscape, why IAM is the new perimeter, and getting leadership buy-in for security practices.
Andre Rall on the secrets to successful cloud security, building strong foundations, and aligning security with cloud strategy.
Chad Lorenc, Security Practice Manager at AWS, on cloud IAM beyond access control, showing value to leadership, and production-account security.
Divyanshu Shukla on practical strategies for defending Kubernetes clusters, detection techniques, and open-source defence tools.
Divyanshu Shukla on red-teaming Kubernetes clusters, understanding attacker mindset, and exploiting common cluster weaknesses.
Divyanshu Shukla on attacking and defending Kubernetes clusters in a hands-on workshop-style session.
Brett Johnson on the dark web, credential-stuffing attacks, MFA bypass techniques, and why humans are the weakest link.
Rodrigo Montoro on AWS security monitoring, threat modelling for new services, and restricting high-impact IAM permissions.
Nader Zaveri on organisational security culture, planning and budgeting for security, and incident-response preparedness.
Adam Smith on data privacy governance, building personal-data inventories, and fostering a privacy-first culture.
Jimmy Mesta on Kubernetes misconfigurations, continuous security checks, and when to choose managed K8s over self-hosting.
Syed Shareef, Senior Security Engineer at AWS, on data perimeters, combining SCP and IAM policies, and use-case-driven security.
Vincent Romney, Head of Global Security Architecture at Nu Skin, on zero-trust architecture and overcoming organisational resistance.
Vincent Romney, Head of Global Security Architecture at Nu Skin, on zero-trust architecture, programme design, and security planning.
Chris Neggel, Regional CSO at Okta, on the roadblocks teams face in cloud security and strategies to overcome them.
Gary Dylina of Narvar on preparing for large-scale events, SOC2, IAM setup, and when to make a first security hire.
New episodes twice a month
Follow Scale To Zero wherever you listen, or send us the question your team is stuck on and we will put it to an expert.