Resources
- -
- Solutions
- RadiantOne
- Why Radiant Logic
- Company
- Support
- Resources
© 2026 Radiant Logic, Inc. All Rights Reserved. | Privacy Policy
Speaker: John Pritchard, PhD, CEO at Radiant Logic
Identity security has entered its chaotic era. This era is defined by the Three Identity Problem, in which human, non-human, and agentic identities don’t just coexist; they form an uncontrolled inheritance chain. A key element of this chaos is business users creating AI agents on low-code platforms, which are outside traditional identity controls and are invisible to security programs. In this keynote, Radiant Logic CEO Dr. John Pritchard examines what security leaders need to see, correlate, and act across the full identity chain before the chaos of the Three Identity Problem takes over.
Welcome to day two of Identiverse. I’m thrilled to be returning to the stage today.
Now that opening innovation was my inspiration for what I’m calling surviving our chaotic era.
At first you saw a single object, and then a second one entered and their gravity starts to interact. But they settle down into an equilibrium.
And then a third body enters.
Now history teaches us about this.
In eighteen ninety, a French mathematician by the name of Henri Poincaré determined that when you have three bodies in motion, there is no general solution.
There’s no predictable pattern. There’s no stable orbit.
And in that discovery, he created an entirely new field of mathematics.
We know that today as chaos theory.
That turbulence may feel very familiar to many of you in the room because for about twenty years we were a single body organization, humans.
We compiled them into directories, we secured them with SSO and MFA, governed them with IGA workflows.
And then non human identities arrived.
And for sure there’s been turbulence.
But we were approaching what I would say was a point of equilibrium when a third body has entered our system, Agentic AI.
Last year from the stage I predicted that humans and AI were gonna form multiplayer teams.
So firstly, that prediction was right. All you’re gonna hear about this week is agents and AI.
So that human AI pairing is happening right now.
And I’m quite sure for all of you, you’ve seen nothing short of a sea change in your organization around experimentation.
Which has unfortunately created a new class of a very old problem, sprawl.
Let me show you why.
Today we have a three identity problem.
Humans, non humans, and agentic identities make up your environment.
Your human actors you have under control, mostly.
And we spent our most recent years on the non human identity problem.
And yet we find ourselves today where our human actors are creating agentic workflows which are in turn spawning non human identities behind the scenes.
That isn’t a visibility problem.
It’s a causality problem.
And there’s a name for what’s missing.
Some seventy years after Poincare, another mathematician named Rudolf Kalman gave it to us. And he called that observability.
He defined that as an ability to determine the system’s internal state from its outputs.
So not just what exists but how it got there, what it’s connected to, and most importantly, what breaks when it changes.
Now if you come from the infrastructure ranks this is not a new term for you. We’ve been running observability for years.
And you know that there’s a difference between monitoring and observability.
Monitoring gives you signal.
Observability gives you state.
Visibility without state creates blind spots.
Let me give you an example.
A human creates an agent. That agent spins up service principles, each with their own standing permissions.
If the human changes roles or leaves, chances are that agent keeps running.
You could rotate every secret in your vault and you wouldn’t touch that access.
This is what I described as the uncontrolled inheritance chain.
Human to agent to non human identity.
And it is the three identity problem.
It’s a problem because when the source breaks, the chain does not.
Now, we’ve spent years at this in industry, as an identity ecosystem. And I think we have to ask ourselves, how did we get to this point?
Well it turns out that we may have an origin story for identity security and it’s been made by Hollywood.
Any fans of the Netflix series Three Body Problem?
Okay. For those of you who have not seen the series, I’ll give you the thirty second version.
A scientist has lost faith in humanity’s ability to solve our own problems.
She receives contact from a higher intelligence.
And she has to decide whether or not to respond.
Now in the television series, to respond she has to push a button.
And she does. And of course when she’s pushed a button there’s no going back.
Last year every CEO and CTO across industry had their own version of that button.
The AI shock had hit.
And the real fear wasn’t the technology.
It was the fear of missing it.
So they made the call, go experiment, move fast, do not miss this window.
We pushed the button because we believed it was the right thing to do.
In the Netflix series, the aliens, the higher intelligence, demonstrate they could sometimes be a little dangerous.
And they fool humanity into thinking that they control the stars.
And there’s this moment in the show where they do that by making the night sky wink.
And that teaches humanity that visibility by itself can be deceiving.
Now I don’t see a genetic AI as the alien invasion of our time.
Although I think every graduating college senior of this year would argue with me.
But we’ve all seen the headlines. These frontier models are quite powerful.
And power and lack of governance is a dangerous combination.
And unfortunately this isn’t slowing down.
The reason is today’s agentic platforms are optimized for what?
They’re optimized for adoption.
They want to make it as easy as possible to have a frictionless experience.
And what makes them so powerful is not so much what your developers can do, but it’s what everyone else in your organization can do.
Now contrast that with our identity security platforms.
Those are optimized for control and for governance.
I don’t necessarily see these two in conflict but there definitely is a goal mismatch.
And that mismatch creates a gap.
And every time one of your business engineers creates another agent, that gap widens.
The reason is because it probably isn’t just one of your platforms, it could be many of them.
So let me describe a concept here. Let’s take three categories.
First category would be your hyperscalers. So your AWS, your Microsoft, your Google.
Your second category I’ll call your domain platforms. So Salesforce, ServiceNow, Workday.
Third category, the model makers.
Every one of them shipped some version of agent identity this spring.
And they all did it a little differently.
Microsoft built theirs into their directory. Google made theirs cryptographic.
AWS passes the human identity along with the call.
Salesforce gives the agent an identity itself. And Workday inherits the humans.
Absolutely none of these are wrong.
But they are racing for adoption.
And each is governing in their own way.
Now everything on this slide was accurate as of last week. I only bring that up because I’ve updated this talk three times, and that’s how fast the industry has been changing.
I think that’s why we feel like it’s a chaotic era.
So three categories, eight platforms, a very similar pattern. Everyone shipped adoption, governance followed, and the gap remains.
Which is probably why most of you are here this week. Because you are well aware of that gap.
I’m sure what started as a pilot in your organization became something close to viral adoption.
And now what are you trying to do with these agent management platforms? You’re getting integration requests from your teams. You’re trying to wire up SSO.
Kind of feels like the pre IGA days.
But I think that gap you’re going to quickly realize isn’t your inventory because that’s visibility.
It’s the causal chain.
It’s what Coleman’s observability principle tells us.
It’s not just what exists, it’s how it got there, what it’s connected to, and most importantly, what breaks when it changes.
Now multiply that gap at scale.
We have a name for this, it’s called agent sprawl. Gartner’s published several research papers on this.
By their projection, the typical Fortune five hundred enterprise will have somewhere in the range of one hundred and fifty thousand agents by twenty twenty eight.
All of you will have five times as many as you have today.
And by their analysis, only thirteen percent of you feel like you’ve got AI agent governance under control.
Thirteen.
But that metric creates another statistic for everyone in this room, one hundred percent job security.
Identity is absolutely necessary.
And the strongest confirmation of this you will see this week.
The market is racing. There’s an entire ecosystem that is trying to fill this gap.
Gartner formally named a category recently AI agent management platforms. One year ago that didn’t exist.
We see lots of other categories that we’ve been working with for years. Non human identity management, secrets management, workload identity.
All established, all absolutely necessary but not necessarily developed for the chain that I’m talking about.
So our foundational work is to first assess how well we’re covered.
Now for most all of you in this room today, identity and access management you absolutely have covered.
Secrets and certificates also covered.
But that’s probably the limit of your non human identity program.
It’s the layer underneath where we’re often exposed.
And this may surprise you a little bit. It’s not service accounts.
It’s not even the agents that your developers are creating.
You’ve been really good at security education for your teams.
It’s everyone else. It’s your finance team, it’s HR, it’s marketing.
Everyone grabbed some low barrier, no code platform and developed an agent because it was easy.
Now in many ways these agents now behave like insiders.
They have all the access but not just the human intent.
Palo Alto’s chief security intelligence officer Wendy Whitmore I think coined the phrase that AI agents are becoming the new insider threat.
So one of the questions we have to answer is how well our security stacks can observe that.
The Ponemon Institute surveyed organizations since February.
Ninety two percent of you said that generative AI has fundamentally changed how your people access and share information.
Which would suggest we have to change how we govern it as well.
The Cloud Security Alliance now ranks over permissioned non human identities as one of the top risks.
And our SaaS telemetry bears this out. Agents carry about ten times the access that their work actually requires.
But our insider threat programs were built for human tells.
Things like disgruntlement, excessive file copying, odd hour logins.
And an agent has none of those. It doesn’t have a motive. It definitely doesn’t have an HR file.
But agents aren’t ghosts.
They just give off different signals.
They give off different observations.
Who created it? What it inherited? What is the human that sits behind it?
So that’s not behavior.
That’s identity context. That is us.
And the context is the chain.
Two families of tools were supposed to help us with this.
Access governance, which holds all the objects.
And behavior monitoring, which holds all the signals.
And each one has a job to do and it lights up its own corner of the map.
But what happens when the chain starts to appear?
It’s not isolated to one corner.
It runs across the entire board. That’s your entire environment.
And the fog in between. And that’s the gap.
It’s not that we don’t have visibility, we have plenty of visibility.
The problem is that no single family of systems was built to understand the entire chain.
And what’s missing isn’t another product or a category, I would say what’s missing is a function. It’s a common operating picture.
Last year I told you identity security was becoming a multiplayer game and that your people needed to share what they know.
And that was true, but I would tell you this year that’s incomplete.
This year the players aren’t enough, the systems have to actually share as well.
And let me explain why.
Everything in the agent era, every tool, every AI decision runs on context.
Context is the difference between a system that knows what it’s doing and one that is just guessing.
Let me give you my own example.
Somewhere in this audience is my CISO Cameron Matthews. Cameron where you at? Cameron reluctantly raising his hand.
Now look Cameron is a CISO for an identity security company for a CEO that used to be a former product leader who’s got a proclivity for AI experimentation. I would one hundred percent put that in the category of not fun.
But Cameron’s been great. We’ve leaned into these frontier models and really explored what their capabilities are relative to security posture. And he and I have had very similar experiences independently. We’ll be working in one of these advanced models, sometimes for hours at a time.
Debating often but reaching some decisions, and then suddenly the model seems to get dumber.
It’s as if it forgot some key decision that we already made.
Or we step away for a period of time and we come back and the model has forgotten everything we’ve done.
So these are two sides of the same coin and that coin is context.
When a model gets too much of it, it overflows. The term in industry is breaking the context window.
You step away too long and it forgets.
Now let me ask, why should identity security be any different?
Remember we built identity to control things. There’s a reason we call it the control plane. Not necessarily to share things.
And your teams are organized by function, your systems mirror those walls.
And in those data silos we have unintentionally created context silos.
Which means that our identity systems are perhaps running on the same starved context that makes AI get it wrong.
So before I would ever make an authorization decision on an agent, I would want to understand what is the context that decision is being made upon.
So they’ll give me four questions to get there.
First, I would ask what are all the relationships that agent has?
Who’s the human behind it? What machines can it reach?
What other agents can it trigger?
I would call that your roster. Think of that as all the humans and the non humans and the agents that are the team that you put on the field.
And I just don’t mean the agents that IT has provisioned.
If I were to do a quick poll of everyone in this room and ask you who has some type of AI task running that’s scheduled or delegated, Perplexity ChatGPT Claude, Your IT team didn’t provision that. You guys stood that up yourself. Just like Cameron and I did.
So I think what you’ll quickly realize is that the first context problem is that your roster is probably bigger than we believe.
Second question.
Let’s assume you actually had that roster.
Is it real time?
When your people leave though, do you offboard all the agents they created?
So here’s a hypothetical. Let’s take a rep on your sales team.
Last quarter that rep built an agent to help interact with prospects and leads.
I said it was hypothetical.
He hits his quota, blows it out, gets recruited, leaves the organization.
HR closes the file, you off board everything, your access review comes out clean.
For every system that you know about.
But if that agent still lives in a tool that’s outside of your governance, what is it doing?
It’s still trying to achieve whatever goal it was created to do. And we don’t know how that’s going to behave.
And this isn’t just my story. Microsoft has a name for a recent capability they came up with which is called ownerless agents.
They have literally built a dashboard to help you hunt them down.
So that’s the second context problem.
Now let’s assume you actually knew that agent was staying behind. Then one piece of context would be critically important for you, which is the name of the human that created it.
Because that’s going to give you insight into what types of access it has inherited.
We call that providence. And that’s the third context problem.
Before any agent does anything in our environments, somewhere in your stack there’s a policy engine making a decision. Is it allowed to do what it’s trying to do? Is it authorized?
And if you think about what we just talked about, the roster, real time providence, we may ask ourselves how should the policy engine act? What kind of decision should it make?
If it’s overly conservative, I run the risk of blocking the business.
If it’s overly permissive, I run the risk of inviting in a threat.
Two sides of the same coin. Neither one of them great. This is why this is such a challenging problem.
Now in your environments you have a set of systems that are deployed where all of that context lives. It’s just separated.
Endpoint systems tell you what’s running. Governance tells you what you have access to. The platform, the agent platform will tell you the humans that created it.
But this last one, the context for the decision, that one’s hard. That doesn’t really have a home.
Because answering doesn’t mean creating another system or another column. It’s like creating a row of that information.
And no one system actually holds that row.
Every system holds a piece.
And to a large degree that is the three identity problem. It’s not visibility, it’s causality.
Context is what gives you the causal chain, and observability is how we get that picture.
That way all of the decisions that our systems are making are using the same shared context.
Somewhere in the last eighteen months, the Agentic era arrived in your environment.
And for most everyone in this room, I think you share the exact same sentiment. You were not invited.
Like a bad dinner party guest, you were definitely not invited.
But it landed on your desk anyway. The business pushed the button, and now you have agents on your roster.
No single system is going to give you everything that you need, so it is up to us to build that picture.
In the Netflix series there’s a man named Wade who decides the best way to save humanity is to bring together a cross functional set of experts.
He gets a physicist, an engineer, a nanotechnologist, even a detective.
Not because he feels one of them has got the answer, but he feels that each one has a piece.
And I believe we sit at exactly the identical position in identity security today.
Each one of our systems holds a piece of the story.
Where an agent was built, who sponsored it, what it’s doing.
But no single system holds the whole picture.
And I think that’s our work as a community is bringing that together.
That’s why this was never a visibility problem.
Each of our systems already sees a part of their own truth.
What they all lack is the full context.
Seeing your own corner’s visibility but knowing the relationships between everything, that’s observability.
And what we need to do is assemble and share that context that each of those systems holds so there is a single version of that truth.
Three identity types. Human, machine, and now agent. Each one inheriting from the last.
No one carries access that can fully see the entire picture.
But what they do have is shared context.
Henri Poncare could not solve the three body problem but it required the planets to be able to share their positions.
Your three identity types have the same problem.
Each one lives in a different system and has a different life cycle.
In Ponkari’s world, the three body problem stopped being chaos the moment the bodies share their position.
The three identity problem stops being chaos the moment our systems do.
Last year I called this a multiplayer game. And this year I’m telling you that that game is winnable, but only when the systems play together.
Stable configurations do exist, but when the bodies hold the relationship and they share it with each other.
And that’s our work. That’s your work. Let’s go find our stable eras.
Thank you very much.