Identity and access management for AI agents, and the synthetic identities nobody is governing: Greg Keller of JumpCloud
Michael opens with the question: could AI be the ultimate insider threat, not through hacking but by misinterpreting policies and hallucinating its way into administrative access?
Greg Keller's answer is that this is not an if. It is a practical reality already, and it is the newest problem in identity and access management.
Keller is co-founder and CTO of JumpCloud, which grew into a multi-billion dollar identity platform by offering a modern alternative to the traditional directory model.
What a CTO does
Keller's definition, after a joke about chasing butterflies and inventing impossible tasks for global engineering teams: the core mission is setting the tone and tempo for where the company's technology is headed.
He notes there are variants. Some CTOs are deeply embedded in engineering practice and rigor. Others are more customer-facing and product-inclined, which is where he sits, establishing the what and the why behind product initiatives and pulling the organization toward that.
Asked how he sees around corners on the technology stack, his answer is about avoiding a particular failure mode.
The job is ensuring an uninterrupted value chain that keeps demonstrating progress, because stagnating and plateauing is where good companies begin their decline.
And in practice that means meeting needs before the customers he sells to have articulated them. His phrase for the alternative is chase mode, which he calls a bad place to be, both for an inventor and for the sales organization, because it turns them into people running comparison tests against competitors. What he wants instead is to be able to say this is something you have not tried before, and here is why.
What identity and access management actually is
Keller's explanation is the clearest in the archive, and worth having for anyone whose eyes glaze at the acronym.
In any business, from remote-first software company to a brick-and-mortar office, a worker needs access to something in order to do their job. A retail employee using a badge to reach a point of sale terminal. An engineer signing into cloud infrastructure. A finance person logging into a transactional system.
So the acronym decomposes cleanly.
Identity. You and me. Human knowledge workers, cogs in the business machine.
Access. What we need to reach in order to do the job.
Management. How you continuously maintain appropriate access and security to those things.
And there is a spectrum of maturity, from startups that are typically very immature to multinationals that have bought every tool available to do it safely.
Why the old model stopped fitting
The historical version is Microsoft's, which Keller traces to the late 1990s and early 2000s.
The picture is familiar to anyone of a certain vintage. You walked into an office, sat at a cubicle, had a monitor on the desk and a tower underneath it that you knocked your knee against every time you moved your chair. Every machine was wired into an actual closet holding a rack of servers, and those servers determined who could sign in and what they could reach.
It worked well, harmoniously, for one ecosystem: that vendor's own products.
Then things changed. Keller's account of the last three companies he built is the argument. A Mac laptop. Anything he could put a credit card into to run the business: cloud productivity tools, cloud infrastructure, a cloud CRM. None of it in that vendor's ecosystem, and all of it carrying the same problem.
With a complication he flags precisely: there will still be some of that vendor's products in the mix. His finance people could not use Macs because they needed the proper version of the spreadsheet software for the work they do. So you have to manage those machines too.
His conclusion: real companies operate in a heterogeneous stack across many vendors, different operating systems, different working patterns, some remote and some in offices, some on-premises equipment and some cloud services. Providing identity and secure access across all of it, regardless of what or where, is the problem JumpCloud set out to solve.
Where single sign-on stops
Keller is generous about Okta, which he credits, alongside earlier companies including Ping Identity, with disrupting one specific aspect of the problem: single sign-on, securing access to anything a user reaches through a browser.
What that does not cover is everything else a person touches in a day, and his walkthrough of Michael's morning makes the gap concrete.
You walked into your home office. You logged into your laptop, possibly with a fingerprint. You entered credentials for your productivity suite. You needed another credential for the browser-based recording software.
Browser-based single sign-on handles part of that. What handles the hardware, the things on the laptop itself, or the file server beside the desk?
Why this matters before you adopt AI
Michael's framing for the operators listening is the practical bridge, and it is the most immediately actionable thing in the episode.
A lot of COOs are working out how to integrate AI into their stack, and the answer depends on what the pipes carrying the data look like. Identity and access management determines who can reach what, and which identities can interact with which others.
So his instruction is specific: go and ask your IT team how labor-intensive and manual it is to provision a new employee on their first day, and to then provision them onto new software as it arrives. That answer will tell you a great deal about whether AI can be enabled safely in parts of your company.
The public service announcement
Before answering the AI question, Keller delivers what he calls a public service announcement for COOs, and it has three parts.
Adoption is not an if but a when. Progressive COOs, security chiefs and IT leaders need to be aligned on aggressively adopting AI, or businesses fall behind.
The COO should be challenging the employee base on what they are doing now to improve their effectiveness and speed using it.
And the same COO should turn to the security chief and say that a declaration has been made that the company will get better, faster, more efficient and more accurate using AI, and ask what they are doing to support making that secure.
His metaphor for the alternative: you cannot hand sharpened scissors to every manager and individual contributor and send them running down the hallway.
His own company's example is instructive. Toward the end of the previous year they set a precedent of measuring and evaluating each employee's and each business unit's use of AI tooling. They laid the tools out, funded them, and had the security team evaluate all of them first. Then handed them out with no excuses, framed as something that would make people better rather than replace them.
His report on the outcome is that the results across engineering were as expected, and what it did for the go-to-market, finance and marketing teams was beyond what he anticipated.
Synthetic identities
The core of the episode, and the concept most operators have not yet internalized.
The third component, alongside efficiency and security, is that this is no longer only about human identities.
Synthetic identities are non-human. Every time you interact with an agent, it is performing a role or task you would otherwise ask a human to do.
And those agents have access requirements exactly as people do.
So the first thing a team needs to establish is which agents are coming into the business, which are going out from it, and what each has access to in either direction.
His inbound and outbound examples are both concrete. Is the agent responding to your customers through a chat interface confined to the dataset relating to that specific customer, so there is no co-mingling with anyone else's data? And how do you actually enforce that?
On the inbound side, he flags the protocol that lets agents talk to your infrastructure, which he describes simply as a front door: an interface layer through which agents reach your systems. And the same question applies. What does that thing have access to, and what are its lanes?
The Oprah problem
Keller's answer to the opening question about AI as insider threat is the sharpest passage in the episode.
The framing is that an agent is like any other worker. You grant entitlements to a person. A rank-and-file engineer has a very specific set of permissions, what the field calls scopes, defining what they can reach and do once inside a system.
The failure mode is what happens when nobody governs the equivalent for agents. His image: it becomes an Oprah giveaway. You get an access key, and you get an access key, and you get an access key.
And before anyone notices, there is no governance or manageability over any of it.
Which is, in one line, the argument for treating agent access the way you treat employee access: as something granted deliberately, scoped narrowly, and reviewed.
The 5 things I took away from this conversation
1. Audit your agents in both directions. Which agents are coming into the business, which are reaching out from it, and what each can access. Almost nobody has this list, and it is the prerequisite for every other conversation about AI safety inside a company.
2. Ask how long it takes to provision a new employee. Michael's question is the diagnostic I am taking away. If provisioning a person on day one is manual and slow, your identity infrastructure will not survive contact with a fleet of agents that need scoped access.
3. Agents get entitlements the way employees do, or they get everything. Greg's Oprah image is the memorable version. Access keys handed out with no governing structure produce an environment nobody can audit, and the point of no return arrives quietly.
4. Secure it before you hand it out, then hand it out with no excuses. JumpCloud's sequence was security review first, then funding, then distribution framed as a capability rather than a threat. That order matters, because doing it the other way produces shadow adoption you cannot see.
5. The COO should be putting the question to the security chief. Not asking permission. Declaring the direction and asking what support is needed to make it safe. That reframing is the difference between security as a blocker and security as a partner.
FAQ
What is identity and access management? The set of systems governing who can reach which resources in an organization and how that access is maintained over time. Keller breaks the acronym into identity, meaning the person or entity, access, meaning what they need to do their job, and management, meaning keeping that appropriate and secure continuously.
What is a synthetic identity? A non-human identity, such as an AI agent, that performs work a person would otherwise do and therefore requires access to systems and data. Keller's argument is that these need entitlements and governance exactly as human identities do, and that most organizations have not started.
How is AI an insider threat? Not through hacking, but through over-broad access. Keller describes agents accumulating access keys with no governing structure, at which point an organization loses the ability to audit or manage what any of them can reach, and misinterpretation or hallucination can act on more than intended.
What does single sign-on not cover? Anything that is not reached through a browser. Keller's walkthrough covers logging into a laptop, the device itself, and local infrastructure such as a file server, none of which browser-based single sign-on addresses, which is the gap JumpCloud was built to close.
How should a COO approach AI adoption securely? Keller's sequence is to declare the direction, have the security function evaluate the tools before distribution, fund and provide them explicitly rather than leaving people to find their own, and then measure usage across teams. The framing to employees is that the tooling makes them better rather than replacing them.
Also mentioned
- JumpCloud, and its approach to heterogeneous device and application access
- Okta and Ping Identity, and the single sign-on category they defined
- Model Context Protocol, the front door through which agents reach company infrastructure
- Scopes and entitlements, the mechanism for constraining what any identity can do
- The pre-cloud directory model, and the closet full of servers it depended on
Listen to the full episode
Greg Keller on Between Two COO's
Between Two COO's is hosted by Michael Koenig. Subscribe on Apple Podcasts, Spotify, or wherever you listen.
The COO's Execution Playbook
Frameworks, templates, and hard-won lessons from operators who've been in the chair. Every Tuesday.
No spam. Unsubscribe anytime.