With over 200 AI security vendors in the market, how does an enterprise CISO decide whether to build a custom solution, buy an off-the-shelf product, or just wait out the hype?In this episode of the AI Security Podcast, Ashish and Caleb are joined by Kane Narraway, Head of Enterprise Security at Canva, to debate the realities of AI security in modern enterprises. Kane breaks down why simply sandboxing AI agents doesn't work for workforce productivity, explaining that an overly restrictive sandbox renders an agent useless because it inherently needs access to external files and databases to do its job.We dive deep into the "Confused Deputy" problem, the struggle of granting granular least privilege to AI tools (like letting a bot summarize only Caleb's emails), and whether the old-school concept of network proxies is about to make a massive comeback as the ultimate control layer for AI routing and authorization. Finally, Kane shares why he believes the scariest near-future threat isn't malware, but contractors utilizing "Bring Your Own Agent" (BYOA) in enterprise environments.
Questions asked:
00:00 Introduction to AI Agents in the Enterprise
01:50 Kane Narraway’s Background (Digital Forensics, Atlassian, Shopify, Canva)
02:50 The Build vs. Buy Debate in the Era of 200+ AI Security Vendors
09:00 Using Wrappers and Harnesses to Control Vendor APIs (Island Browser Example)
11:00 Why GitOps and PRs are Better for AI Configuration than MCP Deployments
13:00 The "Confused Deputy" Problem: Single-Player vs. Multi-Player AI Bots
16:50 How to Handle Agent Identity: "On Behalf Of" (OBO) vs. SPIFFE / NHI
22:50 Why Sandboxing AI Agents Fails for the General Workforce
28:20 Intent-Based Security and the Lack of Granular Access Controls
29:40 Are Proxies the Next Gen Firewall for AI Agents?
34:00 The Terrifying Future of "Bring Your Own Agent" (BYOA)
38:50 The "Gravel Road" Strategy for Managing Shadow IT and Vibe Coding
42:00 Dealing with Vendors Trying to Exploit Shadow IT Land Grabs
49:30 What Security Leaders are Over-Indexing On (Discovery vs. True Access)
50:40 The "You Laugh, You Lose" Cybersecurity Joke Challenge
Kane Narraway: [00:00:00] If you expose that API token, good luck. You are now completely owned and it has access to everything.
Caleb Sima: We haven't solved least privilege anywhere. I was just at a conference and someone was talking about the top problem is figuring out how to do well-behaved agents,
Kane Narraway: and I was like, "That is not the top problem."
Kane Narraway: We trust you, we just don't trust your agent, sorry. Often I'll get emails from people being like, "Hey, do you know you have 300 people in your org using our tool?" And I'm like, "Great, I will go turn that off now."
Ashish Rajan: We look back and there is just complete darkness. No one else is using it apart from us talking about it.
Kane Narraway: That's terrifying. I don't want to live in this world. But you can see it coming. Attackers are smart, and with AI they're even smarter, right? Yeah. And they're gonna adapt even quicker. Even when we plug these holes, it's gonna be like the next thing.
Ashish Rajan: AI agents with enterprise security is a huge challenge, and I had Kane Narraway, who is the head of enterprise security at Canva, to talk about some of the movements in enterprise security ecosystem, thanks to the coding agents, MCPs, AI agents.
Ashish Rajan: We spoke about how you can tackle AI security in [00:01:00] quadrants depending on whether you should build it, buy it. Where is the future going, especially if sandboxing is not a common practice that you can have? And we also spoke about where is the next frontier for AI security. Of course, managing identity is a true thing, managing agent security is a true thing, but all paths lead to something unique at the moment, which we may or may not have answers to.
Ashish Rajan: All that and a lot more in this episode of AI Security Podcast. If you are here for a second or third time and have been enjoying the episodes, please do share this with someone who is trying to tackle the agent security problem, enterprise security problem with the AI agents, whether it's shadow AI.
Ashish Rajan: And if you have a minute, hit the follow/subscribe button to support what we do. You can find us on all the podcast platforms, whether it's on Apple, Spotify, YouTube, or LinkedIn. I hope you enjoy this episode, and I'll talk to you soon. Hello, and welcome to another episode of the podcast. We have Kane with us.
Ashish Rajan: Thanks for coming on the show, man.
Kane Narraway: Perfect. Thanks for having me.
Ashish Rajan: Maybe to set things off, you can just share a bit about yourself.
Kane Narraway: Yeah, absolutely. So, you know, I'll give you the one-minute spiel. I won't go all the way back. But, like, I started my career in digital forensics. Uh, and so [00:02:00] where I started was going into enterprises, getting all their data for, you know, policing and forensic purposes.
Kane Narraway: And then I kind of flipped into enterprise security, which is like, how do I secure these environments from attackers, right? Yeah. And so I've done that now at Atlassian and Shopify, and today I'm at Canva where I'm doing that more again. But a lot of it has been not just securing it, not just using tools, but also thinking about how can we, how can we build our own stuff?
Kane Narraway: How can we keep on the cutting edge of things and not wait for vendors and others to, to kind of catch up and do it for us, you know?
Ashish Rajan: Yeah.
Caleb Sima: Kane, could I challenge you a little bit on- Oh, absolutely. ... on this? Because I think it's always a hot topic.
Kane Narraway: Yeah.
Caleb Sima: Uh, buy versus build, right?
Kane Narraway: Yeah.
Caleb Sima: Like, why? Why build?
Kane Narraway: Yeah. I actually gave a talk at, at BSides on Monday about this- Yeah ... on the Unprompted track. And so I don't think it's like a... It's not a binary choice. It's not a build versus buy. In my talk, I kind of went through the frameworks that I use to decide how we're gonna do it and what we're gonna do.
Kane Narraway: But I think of it as you can build things, yes. Yes. And when you build things, you maintain [00:03:00] them, you keep them good. You don't spread yourself too thin.
Caleb Sima: Yeah.
Kane Narraway: You can buy things, of course. And if you're gonna buy things, maintain those relationships, you know. Uh, work with the product managers, work with the teams, make that a collaborative relationship between you and them.
Kane Narraway: But I think there's two other areas that people don't talk about, which is you can build something with the express intention that you are going to delete it in three years, and so that's what we're doing with a lot of AI stuff now and that, like, there's, there's 200 AI security vendors out there at BlackHat right now, right?
Caleb Sima: And- It's almost like, well, who- Yeah ... isn't building what you want already? Yeah. Right? Yeah. Like, there should be. Why not use them? They're building it. I'm sure every solution under the sun- Yeah ... in AI security, there is- Yeah ... a vendor for,
Kane Narraway: right? Yeah. But here's the thing, right? Like- How many of those are gonna be around in five years?
Caleb Sima: Well, if you, if everyone keeps making the decision- ... just to try to build their
Ashish Rajan: own- No, you, you see the VC coming out of him- Yeah. ... like, "I have a niche with this company. You're buy- you're buying them." I
Kane Narraway: won- I won't go too much into this. You're pulling my thread, but I think it's a case of, like, look, um- We've got some time.
Caleb Sima: Yeah. [00:04:00] We wanna- Okay. We wanna do interesting
Kane Narraway: conversations.
Caleb Sima: Okay. Yeah. Th- the, the- Look,
Kane Narraway: this
Ashish Rajan: is the rules.
Kane Narraway: Yeah, yeah. Okay. So let's do it. Let's do it. Yeah. Let's do
Caleb Sima: it.
Kane Narraway: As a VC, you want an exit, right? And security companies, they're not generally IPO-ing these days. They're getting acquired.
Caleb Sima: No, no, and let's also make something here.
Caleb Sima: You know, like- Yeah ... I'm not wearing, um, a VC hat, but let's say- Yeah ... I'm wearing half a VC hat. Yeah, yeah. Right? Let's say I'm wearing half a VC hat. Mm. But also similar to it's not just about the exit of a company- Mm ... but where do you spend your time? Yeah. So if I put my operator hat on- Mm ... like out of all of the things-
Kane Narraway: Yep
Caleb Sima: the attack surface you've got to worry about- Mm ... running as a
Kane Narraway: CISO- Mm ...
Caleb Sima: why spend the time building the things- Mm ... that maybe there's already existing dedicated teams- Yeah ... going back on the VC with funding-
Kane Narraway: Yeah ...
Caleb Sima: that are entirely focused on building- Mm ... the solution that you need. Like, why then go t- take your time to go engineer that product?
Ashish Rajan: I have thoughts as well, but I'll let Keyne say it first. Yeah, yeah.
Kane Narraway: I will go back to the, the quadrants answer, and I think this will explain it a bit more. So I was talking, like, one is that you build something with the express [00:05:00] intention that you're gonna delete it, so the industry gets better, the vendors maybe consolidate, maybe they get better, and eventually you get to a point where you can be like, "Okay, you know, there's five vendors.
Kane Narraway: They're gonna be around for a bit of time. Let's pick one and build it." Wh- why do they get
Caleb Sima: better? Because you're open sourcing it or-
Kane Narraway: No. Open sourcing- I'm thinking, like, the vendors get better 'cause time has gone on. They've got more investment, more customers, the, you know- More data
Ashish Rajan: points to work with,
Kane Narraway: more improvement.
Kane Narraway: E- ex- exactly. Exactly. Yeah, yeah. Whereas when you come out and there's 200 vendors, how are you gonna pick a winner?
Caleb Sima: Sure.
Kane Narraway: And so... And then the other option is building stuff with abstractions. Uh, and so what... or buying stuff with abstractions, I should say. So what I mean by that is- Let's say there's a vendor I wanna use, but I build some glue tool in between it, and then maybe I can pull that vendor out if I need to in the future.
Kane Narraway: Yeah. And so the reason I say these things is that what happens if your little startup, uh, that you have consolidated on, you've built all your tooling into it, then gets acquired by a mega corp that maybe is gonna jack up prices-
Caleb Sima: Sure ... give you
Kane Narraway: less support.
Caleb Sima: Which
Kane Narraway: happens all the time. Exactly.
Caleb Sima: In fact, all security vendors-
Caleb Sima: that's what they're trying to do right now- [00:06:00] Exactly ... is just get bought by a mega vendor. Yeah. Yeah, yeah. Position themselves as they're being- Correct.
Kane Narraway: And, and, like, as a buyer, I have to insulate myself from that to some degree. Sure ... and, and, like, this is why we kind of go round in circles in industry in terms of, like, you know, I'll buy tool A, and then in three years, tool A will be bad, so I buy tool B, and then in three years, tool B gets bad.
Kane Narraway: So- And all we're doing is just rolling out vendors.
Caleb Sima: But yeah, I'm assum- I'm assuming, like, in your talk- Mm-hmm ... you, you probably have some sort of decision-making formula-
Kane Narraway: Exactly ...
Caleb Sima: on how you make your decision between- Yeah ... buy versus build. Yeah. What is that? What's
Kane Narraway: that
Caleb Sima: insight? Yeah.
Kane Narraway: I think it's gonna be unique to individuals, right?
Kane Narraway: And so, like, I do kind of, like, lay out the framework in terms of, like, look, everyone's saying, "Everyone's a builder now. You can just build things." Right. And it's not the reality, you know. I don't know if you've seen that meme picture which is, like, a company I know vibe coded their own Linear, and then it's, like, six months later, and it's like they've bought Linear again.
Kane Narraway: Like, it, it's one of those cases, right? And so- Which we
Caleb Sima: have seen. I have seen this- Yeah ... in real life, yes.
Kane Narraway: And so I think it's a case of, like, look, all I'm saying is it's not that simple, right? You need to think about if you are gonna, if you are gonna buy a vendor and you're gonna unify all your things into it, [00:07:00] that's then the relationship you need to maintain, and you're accepting that if they do get acquired by mega corp, you're gonna have to just deal with it, right?
Caleb Sima: Right.
Kane Narraway: Um, and so-
Caleb Sima: Or, or is that a point- Yeah, I, I think it's a little bit unique ... you know, if it's, you know, almost to your point is- Mm-hmm ... let's say out of those 200 vendors doing this AI security thing. Mm-hmm. So you just randomly, and I'm gonna make this super-
Kane Narraway: Yeah ...
Caleb Sima: you randomly throw a fishing pole, pull one of them back.
Caleb Sima: Decent people, same as everyone else. But say, "Okay, I'm gonna invest in you."
"
Caleb Sima: You build my thing for me."
Kane Narraway: Yep.
Caleb Sima: Yep. And then they get acquired by mega corp.
Caleb Sima: But then at, going back to your point, they've served their purpose. Mm-hmm. You are a design partner for them. Mm-hmm. You've built out their features.
Caleb Sima: Mm-hmm. They've worked. Now they're acquired, but now the rest of the vendors have also had time-
...
Caleb Sima: Similar to what you have said, over the next couple years- Yeah ... that build up their solutions. Mm-hmm. Then you just switch.
Kane Narraway: Yeah.
Caleb Sima: Is that n- Is that a-
Kane Narraway: I think it's a, it's an idealistic way of looking at it, I think, which is, like- Tools don't, uh, operate in a bubble generally, right?
Kane Narraway: Yeah. And so, like, let's think of vulnerability scanning, [00:08:00] right? As just a, just as an example, right? You need to give those findings to people, and it used to be that we cr- would create tickets, and now we create PRs and stuff, but you need to integrate that into your GitHub. You need to integrate into that, into your, all of your tooling.
Kane Narraway: And so let's say you are gonna switch a vendor, it's potentially like a 6 to 12 month engagement, at which point, going back to what you said earlier, it's like, there's much better things I could be doing than rolling out a vendor that I already have and just changing it.
Caleb Sima: Or just... So, you know, the integration and flexibility and just building your own on the primary needs, you could just do, especially with AI- Yeah
Caleb Sima: super fast today. Yeah.
Kane Narraway: Okay.
Caleb Sima: Yeah.
Ashish Rajan: But, but maybe just to add another lens, 'cause, you know, we've kind of spoken a lot about this on the AI Security Podcast as well, where there is a use case for organizations to build their own harnesses- Yeah ... around these solutions too. And I think it's the third quadrant that you were referring to where- Yeah
Ashish Rajan: you know that you want to have it- Yeah ... and you have to maintain it 'cause you would not pass on your own context to a third party.
Caleb Sima: Yeah.
Ashish Rajan: But
Caleb Sima: you're putting the wrapper around it.
Ashish Rajan: That's right. Exactly, yeah. But I think you're, you're choosing the path of we need some kind of connectivity. Like, I'm not gonna build the [00:09:00] next threat intelligence software or the vulnerability management software, but I want to be able to plug into it.
Ashish Rajan: And maybe it gets sold to a big corporate tomorrow, but I don't really care 'cause I just go to the next one who's- Yeah ... uh, still available.
Caleb Sima: Yeah.
Ashish Rajan: I, I feel there's still a solid use case for that to be built. Versus bought?
Caleb Sima: A- actually, you know, I'll give you a great example. Just recently, we bought Island, you know- Oh, yeah.
Caleb Sima: Yeah ... the enterprise browser, right? Yeah. And, you know, no offense to Island, but also the UI is not the greatest- Mm-hmm ... and it's not very responsive. But actually, what we ended up doing, it took us two days to do this, is we pulled all their API docs, all their stuff- ... built our own MCP off of it, and then integrated that into our existing workflow, and then we control all of the configs and the ability- Mm
Caleb Sima: to pull the data directly without ever using their UI, right? Yeah. So we get the main benefit of the hard-to-do stuff- Yeah ... which is the enterprise browser stuff.
Kane Narraway: Yeah, yeah.
Caleb Sima: But all the control, configuration, data, it then pulls through our workflows because- Mm ... we built these harnesses around it.
Kane Narraway: Yeah.
Caleb Sima: And that has been very useful in terms of, like, okay, we can automate [00:10:00] a lot.
Caleb Sima: Yeah. And, you know, the integration pieces and the data extraction pieces we can do using our own code and-
Ashish Rajan: Which, which was not possible earlier. You were stuck with a dashboard that someone has provided. Now you have the option to go I don't really care about all these 25 different things. I just care about that- Yeah
Ashish Rajan: two things." Yeah, yeah.
Caleb Sima: Yeah.
Ashish Rajan: I don't want anything else outside of it.
Kane Narraway: You're digging into a topic that I'm, I'm quite liking lately, which is, like, historically, security vendors wanted to be the single pane of glass, right? Oh, yeah. Yeah, yeah. All this single glass of pane, I think the joke goes. And-
Caleb Sima: They couldn't raise money without saying that.
Caleb Sima: Yeah. I mean, no, I mean, I,
Ashish Rajan: I, to, to be fair, I wanna throw some blame to CISOs as well, and, and leaders. They all wanted a single pane of glass as well. They did ask for it. Yeah, it's true.
Caleb Sima: That is true.
Ashish Rajan: Yeah. No
Caleb Sima: one's been able to build it
Ashish Rajan: to any specification. It's like the one ring to rule them all. Yeah. Was that the thing that people were saying with?
Ashish Rajan: Yeah, yeah. Yeah.
Kane Narraway: But, you know, it's a case now everything's just a wrapper for- ... your AI tool of choice, right? We've got past it already. Yeah. So, like, you kind of wanna, like, Terraform everything today. Yeah. And, like, you want everything in GitOps because GitOps is great for AI. You make a PR- It's true
Kane Narraway: [00:11:00] I can review it as a human- Yeah ... if I want to, I can build flows around it. Have you ever tried to deploy anything with MCP? Mm. Mm-hmm. It's, like, awful because, like- Yeah ... it- it's great for, like, me. I wanna change something. I wanna read an API. It's not good for, like, hey, I wanna deploy my MDM or something like that.
Kane Narraway: Like, I'm not doing that via MCP. Yeah, you cannot
Caleb Sima: do
Kane Narraway: that.
Caleb Sima: No. No. But you could change config or get data. Yeah.
Ashish Rajan: Yeah, yeah, yeah.
Caleb Sima: Absolutely. Yeah. Yeah. That's
Ashish Rajan: right. So, so we... I guess the conclusion we're coming to, at least with the AI security ecosystem, is that to where you start with the build versus buy, and to what you were saying at, from your Unprompted talk, there are definitely quadrants where- organizations would have to make a call for whether we buy this for a short time period-
Kane Narraway: Yeah
Ashish Rajan: and/or we are comfortable with the idea that we're gonna buy a product and potentially they'll just get acquired or may not exist after a while.
Kane Narraway: Yeah.
Ashish Rajan: Or are we just build certain things that we think we need because we know we can't have the perfect dashboard? Yeah,
Kane Narraway: yeah.
Ashish Rajan: And to now tie that back to the enterprise security- Mm
Ashish Rajan: use cases as well, obviously there's not just one use case- Mm ... for AI today, there's multiple. Maybe you can expand on then how you look [00:12:00] at that space as well.
Kane Narraway: Yeah, I think everyone's gonna come at it from a different angle depending on what they care about, right? Like, the patching and vulnerability people are gonna come at it from a how do I use AI to patch things faster?
Kane Narraway: I think, like, I'm like a enterprise security guy, right? So I think SaaS, identity, devices, this kind of stuff. I think, like, how do I make my company more secure? How do I make the user experience really nice? And AI has kind of fallen apart in that area at the moment. Like, the, one of the limitations we have is we're very limited on the specs.
Kane Narraway: So like OAuth has their specs, you know, SAML has its specs, API k- keys and tokens and stuff have their specs, and it's a very distributed ecosystem in that, like, when you go back and you think when we did single sign-on for the first time, how long did it take for, like, all your vendors to get single sign-on?
Kane Narraway: How much TPRM shit did we have to do- Yeah, yeah, yeah ... to get us to the point where, you know, y- I kind of force everyone to do it. We kind of have to do that again with AI because, like, the access control portion of things is just not there today. [00:13:00] A lot of the times it's just, "Hey, yeah, use an API token," and if you expose that API token, good luck.
Kane Narraway: You're now completely owned and it has access to everything. Yeah. And so, like, there are vendors and ways and tools that you can secure this flow, and you can get it much better, right? Like, you can discover your agents, you can vault your credentials, you can use short-lived credentials, but it's very SaaS dependent.
Kane Narraway: And so it's great in your ecosystem when you are building something. Uh, it's terrible when you wanna go out and you wanna go talk to Google and Slack, and you wanna use Claude Tag, and you wanna do all this stuff. And, like, the biggest issue we see with this is the confused deputy problem, um, which I'm sure you guys are both aware of.
Kane Narraway: But where y- I think of this as there are AI c- use cases which are single player. Mm. It's like Kane wants to go, read Slack or something, great. Uh, and that uses Kane's permissions. It's really bad when you want, like, a bot that, like, I don't know, reads Slack all the time and summarizes things in a thread, because then, like, how do you query that?
Kane Narraway: Who has permissions to go do that? Can it read private threads? [00:14:00] And you get into this sort of like granularity access problem where it's like, who should have access to those things, and what tokens do we use to access those things? And it gets you... Like I say, you, you can do all of this manually. It's just a ton of work to think about setting it up.
Caleb Sima: It's interesting 'cause when I think about it almost visually in my head, I think about the, primarily the predominant use in our world has always been human access. Yeah. Yes. Which of course we still haven't- Yeah ... resolved.
Kane Narraway: Yeah.
Caleb Sima: And then there's this period where we're getting into system access. Mm.
Caleb Sima: Right? System identity, system access, and all of these areas. And then AI, I feel like, you know, the long... You know, here's human, and then we were just getting- Yeah ... into system, and then AI kind of came in- ... right smack, and then just phew. Yeah. Completely destroyed even our ability to start getting a handle on, oh, how do systems- Get access to things that aren't also human-like permissions, and that just, and, uh, going to your point, now it gets into even [00:15:00] granularized a- access- Yeah
Caleb Sima: for AI, and what does that look like? Oh, this Slack should only be able to summarize threads in this channel only during these timeframes. Is that even possible today?
Ashish Rajan: And I think to add to what you were saying as well, traditionally, the way people separated authentication, authorization was more, "I have single sign-on to Slack."
Ashish Rajan: I don't care what you do in Slack 'cause it's the Slack admin who looks after authorization.
Caleb Sima: Yeah.
Ashish Rajan: Whether Ashish can access, what he or she can do is Slack admin play, not an identity play at that point in time.
Caleb Sima: Yes, yeah.
Ashish Rajan: My job ends, the line is drawn the moment- Yeah ... you're authenticated.
Caleb Sima: Yeah. It's almost, you know, in security if you...
Caleb Sima: The sales team-
Ashish Rajan: Yeah ...
Caleb Sima: I make sure that they all are the right, you know, identity, authentication. But, like, actually it's to the sales leaders to decide in their team- Yeah ... who should have access to what.
Ashish Rajan: That's right. Yeah.
Caleb Sima: Right. But of course they don't. Yeah.
Ashish Rajan: The, the reason I bring that up is I wonder, you know, the, the single pane of dashboards, the single pane of glass we were talking about earlier, I wonder, we are almost entering that [00:16:00] ecosystem where we might as well just go, yes, we have all demanded that humans should have the right, uh, level of, or granularity to all these Slacks and Teams and everything else.
Ashish Rajan: Maybe we just shift our focus completely to agent if that's where the future is going, where AI agent's gonna be part of your Slack, part of your- Yeah ... uh, Salesforce, part of all the e- Are we just better off talking about auter- authorization from a system level? To your point, we can't solve the human one right now, and what we are seeing at the moment is, like, a split between, we haven't even solved least privilege.
Ashish Rajan: Yeah. I don't even know what that means even. We
Kane Narraway: haven't solved least privilege anywhere.
Ashish Rajan: Yeah. But,
Kane Narraway: uh- It, it's like an aspirational thing that we talk about. Yeah. But, like, no one's done least privilege, right? That's what... Yeah. We've not completed
Ashish Rajan: it. Which is, uh, and it goes back to your te- to what you were saying as well, the, the complexity.
Ashish Rajan: Do you feel is that an unknown unknown today? Or is that, are you finding that, oh, is that- Yeah ... goes back to your build versus buy? Is this what I'm buying for three years until the systems get so better that suddenly it's only agents talking and there's no Kane? Kane just goes, [00:17:00] "Make some." Yeah. "Tell me the information, and I'll work out."
Ashish Rajan: Yeah.
Kane Narraway: I think it really depends on your company's risk tolerance, all of that stuff. One of the nice things about Canva is we move really fast, and we always wanna be using the latest and greatest, and so do our engineers, right? And so the way I've been thinking about it as agent identities, I think there's three ways of doing it today.
Kane Narraway: That is, one the, the OBO, as we call it, the on behalf of. So we just- Mm-hmm ... basically say that the, the agent is Kane, it's taking his permissions it's using his account.
Caleb Sima: Kane has accountability for this agent. E-
Kane Narraway: exactly. And I think that's great, and we should push people to that as much as possible, but it falls apart because it's great until I move teams or until I leave the company.
Kane Narraway: And so, the... This is good because you said we haven't solved human identity, or we haven't, but we've, we've done pretty good. You know what I mean? We've, we've been doing this for, like, 20, 30 years at this point. Yeah. And so we're in a reasonably good state, whereas I think a lot of the agent stuff is very, very new and we're just not there yet.
Kane Narraway: So I think my advice to most people is- Use OBO, push, push people to that model, [00:18:00] really narrow down the use cases where you do need these, like, multiplayer agents where they do need to be team owned, and then I think you've got two choices for those team agents, which is, one, you can use API keys, NHIs, we call them, or you can use workload identities, SPIFFE, that kind of thing.
Kane Narraway: And I think both of them are good. There, there, like, there's pros and cons of each. I think in the long term, SPIFFE and stuff is, is probably where a lot of people will go. But, like, you can't go to a finance department or a sales org and be like, "Yeah, just run your agents with SPIFFE." Yeah. It's not, it's not gonna work, right?
Caleb Sima: So let me, let me, like, one thing to probably be very clear is there's these, there's workforce problem-
Kane Narraway: Yeah ...
Caleb Sima: and then there's production engineering
Kane Narraway: problem. Yes. Yeah.
Caleb Sima: And we are primarily talking about a workforce problem.
Kane Narraway: But they overlap more than you think, I think.
Caleb Sima: This, and this is the thing that I think is the gap.
Kane Narraway: Yeah.
Caleb Sima: The production engineering has, that the workforce does not have, is a CICD cycle and an operations management plane.
Kane Narraway: Mm-hmm.
Caleb Sima: Right? When a d- when engineering builds [00:19:00] an app, they deploy that app through their CICD cycle- Mm ... and then they have a management team that ensures that it operates in production environment- Yeah
Caleb Sima: and runs well. Yeah. In workforce, there's nothing. Yeah. It's,
Kane Narraway: it's like you said, you are the
Caleb Sima: sales force admin. Right? Yeah, yeah. You run it. So, like, and then in the example, like- Wait, wait,
Ashish Rajan: isn't that Kane? Uh, sent by security. But
Caleb Sima: like, you know, workforce, you know, like for example, on behalf of- Yeah ... uh, to your point, I think is very good on these transient things.
Caleb Sima: Yes. Agreed. Right? If I'm running an agent and I'm, you know, I'm chat or whatever, and it's just kicking things off and they're transient. But now, to your point, if I'm, now I wanna share my application or my- Yeah ... agent across so it's a shared service- Mm ... that then means it should go into a production, right?
Caleb Sima: And there needs to be an avenue where workforce can push to a CICD- Yeah ... where then another team, you know, whatever that happens to be, either the equivalent of sort of like, you know, ops and, and- Mm ... engineering, that then take that, [00:20:00] set it in a right place, manage it so that- Mm ... it's no longer OBO.
Kane Narraway: Yeah.
Caleb Sima: It has its own SPIFFE, it has its own service identity at which- Yeah
Caleb Sima: then it operates, right?
Kane Narraway: Yeah. Absolutely.
Caleb Sima: So it feels like that's the thing that we're missing that's it. That's all we've got to have is- Yeah ... can we get the CICD prod equivalent to workforce?
Kane Narraway: Uber wrote a great blog post recently on, on how they built out their SPIFFE and Spire setup for doing this, but again, they were focused on engineering use cases, so they were focused on, you know, like- We already have workflows, we already have Spiffy.
Kane Narraway: All we really need to do is have like, like an agent asset inventory. Yeah. You know, like an IAM- And this, this is, this is front line-
Caleb Sima: From engineering-
Kane Narraway: Yeah ...
Caleb Sima: in building an engineering service.
Kane Narraway: Yeah. Yeah. Uh, but, but you're right. I think we do need a way where we can democratize this, if you will, and make it better because, like, I've actually tried to have finance people write OPA policies in the past, and that, that went about as well as you can potentially expect.
Kane Narraway: Uh, no offense to them. They did great given
Ashish Rajan: the circumstances. Did they think OPA was like an accounting framework? 'Cause I'm like, I'm like, when I hear [00:21:00] OPA, I mean, I'm like, "Oh, that sound- sounds like an accounting framework." But not,
Caleb Sima: not to like, uh, you know, you're, you are right in the sense that failed, let's say, yesterday.
Caleb Sima: But today, do you think that could operate differently given sort of the way AI works today? Not in the sense- Yeah ... that obviously finance needs to know about OPA and its capabilities, but, you know, to the point of, you know, in the human world of saying to the finance people, "Hey, you know what your people need access to."
Caleb Sima: Yeah. "You figure that out." Mm. You know, now there's a, a better human way through AI- Mm ... to potentially for that person to say that, right?
Kane Narraway: Yeah. And I think a lot of the IGA vendors, um, and I'm not usually one to, like, pump them up, but, like, they've been doing a good job here, I think, in terms of, like, a lot of them have been ab- abstracting away all these, like, policies and stuff, and now it's just like a, a system prompt, right?
Kane Narraway: It's just an LLM. You just say like, "Hey, I want access to Snowflake." Yeah. And that's it, right? Yeah, yeah. And it's kind of the same thing, uh, but on the opposite way, right? It's like, "Hey, I just want the sales team, uh, or the sales team Okta group or something- Yeah ... to be able to access this, this [00:22:00] thing." And it's like, cool, yeah, have a Claude skill that goes off and writes a, an OPA policy.
Kane Narraway: And I think that's, that's possible. It's definitely... It's, it's probably the world we're gonna end in in the next sort of year or two. Yeah. And I think more people will start doing this. I still think it's a case of like, look, authorization is something I don't like, I don't want the sales team thinking about authorization, right?
Kane Narraway: Of course, that's not their job. I, I, I wanna, like, abstract that from them. Yeah. It's a case of like, how do I make this as easy as I can for them? And so yeah, I think it's a potentially like a two-phase approach of exactly what you say, but also for teams like mine, maybe building guardrails, so it's maybe like, yeah, maybe don't let anyone in the company be able to access our finance data.
Kane Narraway: Maybe that's like some sort of data tagging or something- Oh, yeah,
Caleb Sima: yeah ...
Kane Narraway: we can build in there.
Caleb Sima: It's like you need to build the sandbox they can play in.
Kane Narraway: Yeah.
Caleb Sima: Right? But not allowed out of that sandbox. Yeah.
Kane Narraway: Yeah.
Caleb Sima: You can assign the permissions- Yeah ... that you need anywhere here. As,
Kane Narraway: as long as they don't escape said sandbox.
Kane Narraway: Yeah,
Caleb Sima: right, right,
Ashish Rajan: right. Wait, sandboxing.
Caleb Sima: Which actually goes back to- Yeah. ... well, we haven't hit on that- Yeah ... which is the actual sandboxing
Ashish Rajan: part. May- maybe do... I, I think probably it's important to set the context as well, because [00:23:00] the whole hugging face is still pretty fresh for a lot of people.
Caleb Sima: Yeah.
Ashish Rajan: And I know all of us have thoughts on it, on sandboxing as a concept, how things escape out of it.
Ashish Rajan: But we were gonna talk about, uh, maybe Achie to set your context, and I'm sure we can all put some inputs into this. If you can just lay the groundwork for what's the point of sandboxing, and whether people are over-indexing on it-
...
Ashish Rajan: Or should be doing more of it.
Kane Narraway: Yeah. I can tell you about sandboxing we did at Canva before AI, and I think that will kind of frame into like some of the problems that, that you'll experience when you start doing it for AI.
Kane Narraway: So, um, like Canva, like many platforms, we have third-party libraries that we use to convert files, images, videos, that kind of thing. And so of course, when we're doing this, we're taking like an arbitrary upload- Mm ... that we don't know, we don't trust from our customers or attackers potentially. Yeah.
Kane Narraway: And then we're doing something with it, with a, a library that might have vulnerabilities in it, and a lot of these are open source, so you know they often do. And so we use sandboxing there, and we can truly sandbox it. We can put it in a nice [00:24:00] tight bubble. Uh, we can really limit it down, and we can say that, you know, if a malicious payload is uploaded, so what?
Kane Narraway: Mm. Like it's, it's not gonna affect the rest of our infrastructure. It's just gonna affect that customer's container. Mm. So a lot of people are using things like gVisor and, and Firecracker VM and stuff to do this. I think the problem with AI though is- Like, AI needs to do stuff. Like I can't put it in a nice neat bubble.
Kane Narraway: And you'll find this with a lot of them, is they're like, they're over-constrictive to the point where they're not useful, and I don't want people as individuals like-
Caleb Sima: 1,000% ...
Kane Narraway: poking holes in them.
Caleb Sima: Yes.
Kane Narraway: Because, like, that's just extra friction for no reason.
Caleb Sima: Yeah. That I, I am so on board with you on this, is I read constantly about the next new sandbox, and the thing that oh, it, you can only...
Caleb Sima: You give it access to the file system, but I need it to have access to a lot of the file system. Yeah. So then if it deletes it, it's gonna delete it. Yeah. Oh, well, then you go, "Oh, but I need it access to execute things." Well, execute... Yeah, but I need it access to execute things in my machine-
Kane Narraway: Yeah ...
Caleb Sima: not in the sandbox.
Caleb Sima: Yeah. How [00:25:00] do you protect against it doing bad there? And then that's the, to your point, AI's usefulness-
Kane Narraway: Mm ...
Caleb Sima: is its flexibility- Mm ... and its ability to do such amazing things, and we are trying to do this restrictive thing that all it goes down to is, managing a policy. Yeah. And no one wants to manage a policy, and I don't...
Caleb Sima: Even if I could manage the policy, I wouldn't know what to put in it-
...
Caleb Sima: Right- Yeah ... to make it behave the way that it's supposed to behave.
Kane Narraway: I think it's a case of, like, if you have a very deterministic scenario, so, um, like I think a good one that I've used quite a few times now is, like, let's say we have an AI bot that goes and, like, bumps versions in dependencies or goes and patches stuff.
Kane Narraway: Yeah. Like, it needs read and write access to GitHub. It needs access to some sort of threat feed.
Caleb Sima: Yes.
Kane Narraway: And it's gonna do very deterministic things, right? It's gonna go push updates- Yes ... push PRs, that kind of thing.
Caleb Sima: A great system service.
Kane Narraway: Yeah. Yeah, yeah. And like you, you could put that in a sandbox, right?
Kane Narraway: Yeah. You could really limit that down, only access these domains, only access these things. Which you should. Yeah. Yeah. And it, it's a lot of work to do that for each of your workloads, but when you start thinking about [00:26:00] it as like, "Here's a workload that's being used," then you can start putting protections around it.
Kane Narraway: But today, a lot of it is like, "Ah, I've just got my one API token- Mm ... that does 600 things, and it accesses- Mm-hmm ... everything." And like when you do that, th- then sandboxing is useless, right? Yeah.
Caleb Sima: And, and also going back to our workforce versus production- ... topic, I, I do think in the production world, it's a lot more of systematic, consistent types of functions- Yeah
Caleb Sima: and features- Yeah ... that, yeah, sandbox is an absolute, but when you go to workforce, it's very, very difficult, right?
Ashish Rajan: Yeah. Absolutely. But aren't people using sandboxing for coding gen- code generation as well? So a lot of, at least the use cases that I've come across where developers are being asked to be on a sandbox to produce code, 'cause whatever reason, you can't have the pre-hooks on Claude Code, and you're trying to, "Oh, we have to limit access to the sandbox."
Ashish Rajan: Mm. And kind of what, what you were saying and what you said as well, but it still requires access to file systems. It still requires it to be able to access a database. Mm. Then people go, "Oh, maybe I'll just use the AWS way. I'll just try to go on Bedrock," [00:27:00] or whatever the other option from Azure or GCP is.
Ashish Rajan: I mean, I guess when you guys are talking about sandboxing-
...
Ashish Rajan: Is it more the Firecrackers of the world, or is it the any kind of sandboxing where as a concept is not accurate for AI agents on the workforce side? Because ultimately, to use AI, you need access to file systems. Yeah. You need to access data source, where we're just creating another ma- mini laptop- Like-
Ashish Rajan: for lack of a better word.
Kane Narraway: Yeah, I think you're kinda nailing it, I think, which is, like you say, like you have these sort of known things that you're doing, great, but workforce isn't a known thing that you're constantly doing. And so, like, you know, it... Life is nice if you're using a frontier lab and you're just using a single vendor, right?
Kane Narraway: Like if you're just using Claude, they provide some level of sandboxing in their app if they do all these things. Yes, there's gonna be times it needs to touch the file system, but you know, that's why they ask for prompts and allow and auto mode and all of this stuff. But like if-
Caleb Sima: And by the way, you're still integrating the cust- employee's still integrating- Yeah
Caleb Sima: everything. Every
Kane Narraway: data source,
Caleb Sima: yeah, yeah. And they're still allowing all the tools. Yeah.
Kane Narraway: Yeah, yeah, yeah. So, it's very limited in terms of its security from that point of view, really.
Caleb Sima: So this goes back to our discussion last night or night before- Yeah ... [00:28:00] around, okay, everyone is focused on the sandbox, making the sandbox faster, tighter, quicker.
Caleb Sima: Mm. But to, I think, our discussion that we were like, that's great.
Caleb Sima: It's a good thing to do, but what is the challenge next that actually people should be focused on?
Kane Narraway: Yeah, great question. So like if we're moving beyond sandboxing, one of the issues that you kinda touched on at the end there is sort of tool use and, and third parties and stuff, right?
Kane Narraway: And so, we're always gonna have some level of tool use, and all of that tends to be powered by OAuth in a lot of cases, right? And so it's a lot of "Hey- I need to give my AI bot read access to my Gmail, and now it has entire read access to my entire inbox. But-
Caleb Sima: And I have no way of limiting it.
Kane Narraway: Exactly. And so a lot of people are talking about intent-based security, and it's like, you should only be able to read, like, emails from Caleb 'cause that's what the bot does. It- Correct ... I don't know, summarizes Caleb's emails or something. Correct. Yes. It's a very niche bot I have apparently. It's a Caleb bot.
Kane Narraway: Yeah, yeah. Um, but the [00:29:00] control's there today. You know what I mean? Like, Google has no way of enforcing this.
Caleb Sima: You have no granularized- Yeah ... level of permission. And by the way, I don't think it would even exist.
Kane Narraway: Yeah.
Ashish Rajan: Kind of works,
Caleb Sima: like- The level of granularity- Yeah ... c- ca- cannot be given- No ... by a system.
Kane Narraway: Yeah.
Kane Narraway: And so, like, a, a lot of people have said, "Why don't you just build in middleware that checks this?" And you, you can, but I think the reality is that, like, LLMs are non-deterministic, and they will do things to be helpful, and these sort of, like, middleware controls, I find they're kind of limiting. I have seen some people do some innovative stuff.
Kane Narraway: I think Tailscale are one example, where they're bringing it all down to the network player, so they're actually, like, reading the API calls, reading the network calls, and so they can do this to some degree in some tooling, which I thought was cool. But I don't want proxies in my solution. Like, the way I think about proxies is they're like a temporary solution for now, and this will be good for some people.
Kane Narraway: Like, there'll be banks and high security environments where people will do this, and it will make a ton of sense. But like taking it back 10 years ago, right? Like we used DMZs and [00:30:00] stuff like that. Do we do any of that now? No, not really. No. So like proxies were a temporary solution until the application layer stuff caught up, and I think that's where AI's going, right?
Kane Narraway: It's like people are bringing it down to the network level now 'cause that's what is controllable. It's the only option we really have. We don't have this authc at the app level, and then as that improves, it will probably get brought up. But I think it's a real hard problem 'cause it's a very distributed problem, like we were saying.
Kane Narraway: See, what's,
Caleb Sima: what's funny, 'cause I just posted on my LinkedIn a couple weeks ago that proxies are the answer. Give this guy a shout, he got a LinkedIn. Got some new followers. That proxies are the answer. So, you know, I, I wrote a thing that was specifically in debate of- Yeah ... with, for proxies versus identity platforms.
Caleb Sima: I don't think you're wrong either, but I think the context has made it. Wait, what's
Ashish Rajan: the, what's the, what's the...
Caleb Sima: Again? So I wrote a post around how, uh, you're seeing how now in the AI world proxies are becoming the answer again, right?
Ashish Rajan: Which is what we saw at Hugging Face as well, which they found zero-day and all that.
Caleb Sima: Yeah, yeah, but like proxies are becoming the place- Mm ... to be able to manage and do AI, and is it the right place to do AI? I wrote [00:31:00] this, you know, I j- I AI gen this funny comic s-strip, about how starving the agent, which is- Mm ... the proxy- Yeah ... becomes the control layer-
Kane Narraway: Yeah ...
Caleb Sima: for the agent, so you hold the creds.
Caleb Sima: Yeah. Right? In that control layer. And then what happens is if the agent wants to do a job, I wanna check, email and only summarize Caleb's emails only from Caleb. Well, then what happens is the agent has to create a manifesto, an agenda, hand it to the control layer.
Ashish Rajan: Yeah, proxy. Yeah,
Caleb Sima: the proxy.
Caleb Sima: Mm-hmm. The proxy will understand where it is, hand the credential, "Oh, you wanna do email? Fine. Here's the Gmail credential." That Gmail credential will, again, not be micro authorized. It's saying that you have access to all of Caleb's emails. All of them, yeah. But now the judging agent can then watch the traffic for that requesting agent and ensure that it is within the bounds of, oh, are you going through anyone that's not just Caleb's email?
Caleb Sima: Yeah. Are you going, are you starting to send email, or does it look like you are [00:32:00] drafting to send email? When in, when your agenda specifically states you are, are only summarizing emails, then it will go ahead and yank that cr- credential capability from the agent. And so this sort of capability of proxies, which by the way, you know, everyone in enterprise AI platforms are looking at proxies like OpenRouter, Bifrost.
Caleb Sima: Mm. A lot of these for both obviously cost usage, but also smart routing. Mm. Right? Which is, okay, I don't wanna- Yeah ... spend everything on Opus 5.0. I wanna use Sonnet 5.0 for- Yeah ... a lot of the other, you know, 'cause we got cost control, and so we need smart routing like OpenRouter.
Kane Narraway: Yeah.
Caleb Sima: And so these are now coming into enterprises as of g- as of course proxies.
Kane Narraway: Yeah.
Caleb Sima: Right? And then now people are putting more controls inside the proxy. It goes back You know, again, back to the '90s- Mm ... you know, where, hey, this proxy layer is starting to become the control layer again. It's, it's the firewall. Mm. It's the next gen firewall. It's the place where you're going.
Ashish Rajan: I guess the OSI model hasn't really [00:33:00] changed all these years.
Caleb Sima: No, it's just- Maybe
Ashish Rajan: we're going back- ... new tech
Caleb Sima: stack-
Ashish Rajan: That's right ...
Caleb Sima: every single time.
Ashish Rajan: It's going back down the stack again, though. Yeah. We just, we went up the stack, now we're going back down again. Go back down.
Caleb Sima: And then we'll go back up. Yeah. Right? I think that's the reality. Yeah, yeah. Yeah. So. And we did this with cloud, too.
Caleb Sima: Yeah, yeah. Remember, there was all the cloud A- AWS
Ashish Rajan: proxies. The first version was- Yes ... proxy, yeah, yeah. Yeah,
Caleb Sima: yeah.
Ashish Rajan: And but then do you guys feel, obviously, it's very easy for us to kinda go down that path, but if you wanna bring it back to today's reality, right? Yes, these challenges exist. Not everyone may have an intelligent proxy, like an open router.
Ashish Rajan: 'Cause I don't look at them as a regular, uh, Apache proxy that I'm putting in. It's my, it's a more intelligent smart routing tool, as you were calling it earlier. Yeah A, a lot of people may not even have that ecosystem, and perhaps the engineering people starts that first. It's not the security people who start that first.
Ashish Rajan: So today, as we stand and have this conversation about sandboxing, identity, and workforce versus your engineering application solution thing-
Kane Narraway: Mm.
Ashish Rajan: Today as we stand is the ideal way, and I know there are a lot of unanswered questions. Are we [00:34:00] saying that, A, have an I- to, to what you were saying earlier, the handing over like BOO, sorry, what was it?
Ashish Rajan: OBIO. OBIO. Yeah. BOO was like BYO- On behalf of. Yeah. Yeah. Like BYO, bring your own
Kane Narraway: Bring your own agent. Yeah. That's
Ashish Rajan: what we all do today. Yeah, yeah. 'Cause I'm like, there is people- That'll be
Caleb Sima: the next phase.
Kane Narraway: Oh,
Ashish Rajan: wow. Can
Kane Narraway: you imagine?
Caleb Sima: Can you
Kane Narraway: imagine? That, that will come up, bring your own agent. I, I don't want to encourage anyone to do this.
Kane Narraway: No, 'cause I'm the one who's gonna have to deal
Ashish Rajan: with this. Yeah, no, but imagine every
Caleb Sima: contractor- You want to say this is a joke, but you kinda like, "Oh, this might be feasible." Yeah, no. Yeah. You could see a future where this happens.
Ashish Rajan: I can imagine all the contractors already working on bring my own agent. All the contractors are like, "Hey, I'm only going to be here for six months."
Ashish Rajan: "I don't want to use your agent. I have my own skills." Yeah. "You want me to come in, do a job?"
Kane Narraway: I... That's terrifying. I don't want to live in this world. But you can see it coming. I can. Yeah, yeah, yeah. Yeah, that's what makes it scary.
Ashish Rajan: Uh, but the, the point being, so what's the current path, for people who are looking at this today?
Ashish Rajan: How do you approach this today- Yeah ... when we are far from that smart box proxy thing?
Kane Narraway: Yeah, [00:35:00] look, I think it's gonna be unique to individuals, right? Yeah. And so, like maybe I will give you three answers depending on your use case. So like if you are a big enterprise, or you care deeply about security, and you don't care about a little bit of extra, extra friction being put in, proxy all the things.
Kane Narraway: Honestly, like we do MCP proxies, uh, at Canva. That's fine. We don't do the more like network or LLM proxies at the moment, but, it's on the cards for the future. So I think, if that's something you care about, if this is a risk that is big enough to you, and you, you've done everything else well, you've done the foundations, do that.
Kane Narraway: If you're an engineering heavy org, start building out Spiffe and workload identity and stuff like that, 'cause you can move to that now and solve the problem to some degree. But you're always gonna be left over with these NHIs, like you're never gonna solve that problem. So I think that's where the proxying and maybe a vendor- Mm
Kane Narraway: uh, does come in to, to kind of help you a little bit there. And then finally, I think- You can just wait. Like, if, if this... if you aren't in a deep AI-pilled company or whatever- Mm-hmm ... and, you know, you're at a legal firm, and maybe you just [00:36:00] use, like, Lagora and Harvey and that's it, uh, you can wait.
Kane Narraway: Like, I do think the standards are evolving. Big shout-out to the team at Okta and Aaron and stuff like that, because they're building the latest MCP spec, they're building the latest agent spec, and I see a world in which, like, five years' time, this is a solved problem and it's really good. But I think it's gonna take a long time for us to build those specs out, get that support across the board.
Kane Narraway: You know, I think the answer is basically, yes, buy something now if that's something that you care about. Build it if you have the engineering skill set, start doing it. And three, if you... If this isn't your world, ignore it. Maybe you're not listening to the podcast. You can ignore it for now.
Kane Narraway: Yeah. But you can just ignore it. Yeah. It's not the most urgent problem probably. Phishing is still out there, all of this stuff. It's just normal stuff getting faster. I- So if you're already doing that stuff, fine. I,
Caleb Sima: I love that. I love this third point, by the way. Mm. Which I don't think a lot of people...
Caleb Sima: You have to be a certain level of confidence and be in security to know that that third point is an important one to bring up now. Oh, my God.
Ashish Rajan: Yes.
Caleb Sima: Yeah. Yeah. 'Cause I was just at a conference, and someone was [00:37:00] talking about, well, h- like, the top problem is figuring out how to do well-behaved agents, and I was like, "That is not the top problem."
Caleb Sima: Yeah. Mm. That's probably, like, number 20 somewhere.
Kane Narraway: It's like-
Caleb Sima: Maybe even in, like, not
Kane Narraway: even
Caleb Sima: in the- It's
Kane Narraway: stopping
Ashish Rajan: Bob from accounting from clicking a link.
Kane Narraway: Yes. Yes. Pe- like, pe- people out there still getting hit by malicious dependencies, right? That's a huge problem right now. Huge problem. Yeah, yeah. Supply chain.
Kane Narraway: AI is, like, not the worst. It's, it's the smallest-
Caleb Sima: Yeah ... biggest... you know, smallest problem right
Ashish Rajan: now. Well- You know, last time, I think it was, funny enough, last It's BlackHat, I wanna say. We were talking about this, and one of someone- uh, Jason Hades, I think, made a point where people who are taking the AI pill, uh, like all of us over here, and many who will probably watch or listen to this, it's like we're probably like the edge of a halo.
Ashish Rajan: We're like the 1% of the 1%. Yeah, yeah. We just feel everything in AI. Sure,
Caleb Sima: sure.
Ashish Rajan: And you, and you look back, and there is just complete darkness. Yeah. No one else is using it apart from us talking about it, and there's a small ecosystem of people in a dark room.
Kane Narraway: Or even worse, they're using Copilot.
Ashish Rajan: Oh, [00:38:00] that,
Kane Narraway: that is- With a back
Ashish Rajan: jab.
Ashish Rajan: That is definitely... Microsoft is hating me. You
Kane Narraway: need to add that to your roast. Oh. See, like,
Caleb Sima: that's a
Ashish Rajan: good- Yeah, yeah. ... roast. I will do that. The point being, I guess we're-- there's definitely a lot of unanswered things as well. Yeah. But also to what you guys said, maybe this is not the number one problem.
Caleb Sima: Yeah.
Ashish Rajan: Maybe the number one problem is to stop people-- And I, I guess we haven't even touched on vibe coding at all yet. The whole idea of a lot of people are with that capability. Like, we spoke about the enterprise use case. We spoke about the proxies. We didn't really talk about the fact when you don't even own the infrastructure.
Ashish Rajan: It's like you've gone to, and no hate on Vercel or Lovable or any of the ad ones, basically. Yeah. But you basically have enabled teams to use services- ... that create infrastructure under your domain or subdomain, in this case. And what is that? I'm sure that's, like, top of mind for you as well, I imagine.
Kane Narraway: Yeah. Like, that was also a part of my talk on Monday- Can't, can't, can't trust one of them ... believe it or not. Yeah, yeah, yeah. Yeah, exactly. Like we- Right? Yeah. I wanna say there's one of them. Yeah. You, you, you can generate arbitrary [00:39:00] code now, which is why we sandbox our things. But, uh- Like a
Ashish Rajan: sales pitch, right?
Kane Narraway: That's okay. He's allowed. He's
Ashish Rajan: allowed.
Kane Narraway: Um, yeah, it's, it is a really interesting sort of use case, and, like, there's all this talk of, like, secure paved roads, right? Yeah. In security, it's like build the secure thing that is just built into the platform, and that's fine. And kind of what I've been talking about lately is what I call gravel roads, which are things you know are really bad, but it's better than the alternative.
Kane Narraway: Oh. And so, like, you know, I think ngrok is a good example. Like, not to hate on the vendor, I think tu- let's call it tunnels- Yeah. Yeah ... to be generic. Yeah. Yeah. Like, you can create a tunnel from your workstation to the cloud- Yeah ... that someone can connect to, right? Yeah. And devs just want the easiest access possible, and so you'll get use cases, and this is something I've been dealing with for, like, 10 years now is, like, people just hosting their apps and- Ngrok
Kane Narraway: putting it on the public internet, right? Yeah. And so, like, it's the same with prototyping, right? Like, if you don't have a good way to prototype in your company, people are gonna use the Lovables and all of that, and maybe you don't have an enterprise agreement with them. So I think it's a case of, like, look, you can do all the [00:40:00] shadow IT in the world, but, like- and Grot tunnels still exist, right?
Kane Narraway: And so I think it's a case where you need to build this gravel path, and you kind of need to accept as a security person, this isn't perfect, but it's better than the alternative, which is pushing people to the unknown shadow IT things.
Caleb Sima: Yeah. I, you know, that is an awesome term, by the way.
Kane Narraway: Hmm. Gravel
Caleb Sima: road.
Caleb Sima: Yeah. I was
Ashish Rajan: gonna use that as well. Yeah,
Caleb Sima: yeah. Good one. I like it. I like it because it it's very true in the sense that I actually think people should vie more for that.
Kane Narraway: Yeah.
Caleb Sima: And a lot of people, especially in security, I think we... I, I don't wanna call it, you know, being a perfectionist, but are saying, "Okay, if it's not done in that right paved path-"
Kane Narraway: Yeah
Caleb Sima: for example, like, but just getting something that's better than the alternative is- Hmm ... a great thing to think about.
Kane Narraway: That is security, right? Like, I think of security as just perfect engineering. You know what I mean? Like, a perfect system is secure.
Caleb Sima: Sure.
Kane Narraway: And all of that. But we live in a world of MVPs and product market fit and speed and all of this thing, right?
Kane Narraway: And so, like, we as [00:41:00] security people can't ignore that. Like, we can't build perfection and spend 10 years doing it. We have to build something that works for, like, 90% of people today, and then we can improve those things from there.
Caleb Sima: So maybe I can ask a little bit, going back to the, sort of the question that he was doing.
Caleb Sima: Some of the struggles for, like, the Lovables and others is it creates that new problem of I am now, shoving things into Lovable, creating those things, hosting those things, and there should be some capability to both get visibility of that- ... and/or ability to do preventive controls from an enterprise perspective.
Caleb Sima: So now how are these vendors reacting to that? So similar, like, you know, I know you're on the operations side, but, you know, maybe on the product side-
Kane Narraway: Yeah ...
Caleb Sima: do you see enterprise customers... You know, if I go to you and say, "Oh, I want my employees to use Canva," but from a security perspective, I wanna know the kinds of content they're creating in your application- Yeah
Caleb Sima: and the ability of whether they're hosting [00:42:00] that. Do I have any enterprise hooks or controls to be able to do that? Are you seeing that starting to come across?
Kane Narraway: People are talking about shadow AI, but, like, I don't really see shadow AI as a unique thing. It's just shadow IT. Yeah. Yeah. Like, there's no difference, right?
Kane Narraway: Yeah. And so- That's
Ashish Rajan: fair ...
Kane Narraway: I think it's a case of, like, if you're already doing shadow IT, you're gonna see this stuff. But I, I do find that what you're talking about is something a lot of vendors have taken to as, uh, like, marketing in a way, and sales, which I, I don't feel personally great about, 'cause often I'll get emails from people, uh, like that being like, "Hey, do you know you have, uh, 300 people in your org using our tool?"
Kane Narraway: And I'm like, "Great, I will go turn that off now." Uh... I will go block that. Um, thanks for telling me. Hmm. And so, like, there definitely is, and that's the whole land and expand thing, right? Like, this is a selling pitch for a lot of these tools, which is, like, get the users hooked, get big enough to the point where- Locking it down isn't an option, and then the IT team is like, "Oh, we need to buy an enterprise agreement now, I guess, 'cause everyone wants to use [00:43:00] it, and they've built all their flows in it."
Kane Narraway: So I think, like, you can get ahead of this stuff with preventative controls, allowlisting, all of that stuff, and I think that's the world people should be in in AI. Like, I think we're rapidly moving from a world where detection is not enough. I think prevention has to be a part of the equation now, but- So how do you keep your
Caleb Sima: exec
Kane Narraway: staff from
Caleb Sima: creating their new board deck in Lovable?
Kane Narraway: Yeah.
Kane Narraway: I mean, like, there's a few ways, right? You've got, like, if, if there's local apps, you can use application allowlisting, you can do DNS blocking, you can do all of this stuff, but it's a high-friction control that isn't liked by most, right? Yeah. And I think that historically the companies that I've worked at have never done this kind of thing apart from, like, malicious content, right?
Kane Narraway: Like, we don't say what apps you can and can't use, but I think more and more that is becoming the, the trend because, like, often the conversation is now, like, "Ashish, we don't trust you." It's not that. It's, "Hey, Ashish, we don't trust your agents, and your agents are gonna go do wild stuff."
Ashish Rajan: Mm.
Kane Narraway: And so it, it's a, it's a bit of that "We trust you.
Kane Narraway: We just don't trust your agents. [00:44:00] Sorry."
Ashish Rajan: Yeah. But I do find that it's funny to what you said about the Lovables and Replites of the world, uh, on the land grabbing thing, which is kind of fascinating because the challenge they have from business perspective is that the Claude and OpenAIs of the world are trying to build, like, they have the Claude Design, which allows you to go to a step further in the engineering space, and I'm sure Claude, uh, Canva has a version as well.
Ashish Rajan: Mm. It's not just them anymore. They may have started that ecosystem, but then all these bigger players behind them have noticed, hey, there's a need for this. And I think I was talking to someone earlier about this as well, the people building this in security as well, where now you can have your own identity agent, identity app builder, and the whole idea is that to what we were saying earlier, you don't need a dashboard.
Ashish Rajan: You just probably need certain things that you care about as an identity person or a cloud person or enterprise person. You prompt it. It creates it with all the integration to- ... CloudStrike, Palo Alto, whichever you want. It already has that integration. And people have started seeing glimpses of that, and I think it's not just anymore that [00:45:00] my executive is using it or people-
Caleb Sima: Is, is this the replacement of BI with AI?
Caleb Sima: Is that-
Ashish Rajan: Yeah, yeah. Yeah. That's right, yeah. So a lot of people have started going down that path as well. So it's not just the Lovables and Duplets of the world, it's the Microsoft ecosystem is also going, "Hey, you know, just prompt it and it'll just make you the thing you want."
Caleb Sima: Yeah.
Ashish Rajan: Same with presentations.
Ashish Rajan: And I'm with you on the prevention thing, but I, I think we spoke to a few people about even there, there are layers to that prevention as well now. Yes. Yeah. That it's not just the, "Hey, I'm using Salesforce," but Salesforce has that agent forcing inside it- Yeah ... which traditionally was never a thing that we would talk about.
Kane Narraway: It's a real hard problem as well, because, like, when I ask you the question of, like, what is an agent or where does an agent live, it's really hard to actually answer that- Yeah ... in enterprise environments today, 'cause you've got... Yeah, you've got your, your Claudes, your OpenAIs, your local stuff on the workstation.
Kane Narraway: Maybe you've got stuff running in Bedrock in the cloud and other stuff. But, like, you know, Salesforce have their own stuff, so now you've got agents in SaaS. And so
Caleb Sima: what- And what is the definition of agent is also a- Yeah ... big discussion point. Agent is quite a big...
Kane Narraway: [00:46:00] Yeah. Yes. Yeah. A- a- and so, like, when you think about identity access and governance of these agents, a lot of them aren't looking at any of that stuff in SaaS land, and it's exactly the same we've had with OAuth, where, like, we did, EDR and we did, like, workstation stuff.
Kane Narraway: Yeah. And then it's like, well, all the phishers moved to OAuth, right? And so now all the f- all the stuff went to, like, OAuth fishing and we're getting ClickFix now, where it's like rather than, "Hey, download this malicious binary"- Copy paste it ... it's, yeah, copy-paste this terminal command. And so, like, attackers are smart, and with AI they're even smarter, right?
Kane Narraway: Yeah. And they're gonna adapt even quicker. And so, even when we plug these holes, there's gonna be, like, the next thing.
Ashish Rajan: Mm.
Kane Narraway: And there's always gonna be something, I think. That's the reality.
Ashish Rajan: Yeah. Uh, it's funny, I did a copy with... The ClickFix, the first time I heard of it was really interesting, 'cause I don't know if it was in the 2000s where, I don't know if you guys ever did this, but there used to be this thing where people would send you a URL which when you open looked like Facebook.
Ashish Rajan: Mm. And people... But it had, like, a hookback to your email, so your friend would copy-paste the URL onto the browser or click on the link. It's literally a [00:47:00] local HTML that opens up in the Facebook- Yeah ... and sends the username and password of the friend or whoever you send it to. Mm. It was, like, a thing going on for some time.
Ashish Rajan: I don't know
Caleb Sima: if you ever- Oh
Ashish Rajan: Okay. Dub- it wasn't like, hey a, like, a hack of Facebook. It was literally-
Caleb Sima: Like CSRF type of thing?
Ashish Rajan: Yeah, yeah, like targeting people in the sense to what you, what power- what these ClickFix does, copy-pasting PowerShell. I'm like, "That's a pretty advanced move for someone to open PowerShell-" Yeah
Ashish Rajan: and copy-paste a thing." But we've been doing this before as well to, going back to what we were saying in the beginning, that agent probably is not the biggest problem when we are making people copy-paste stuff onto PowerShell. It's like- Yeah, yeah, yeah ... maybe this is just, I guess a b- a better-
Caleb Sima: It is the security industry.
Caleb Sima: We like to raise the alarms on anything to make it-
Ashish Rajan: Anything new as well specifically. Yeah, yeah. I mean, I mean, our, our entire podcast is built on emerging tech, I guess. Yeah. But, uh, maybe to bring it back. Yeah. I feel like there is, there are parts here, and maybe the theme we are going with is that if you're trying to address AI agents today or AI security based on the three examples you gave or three use cases, you can use the [00:48:00] risk posture that you have- Mm-hmm
Ashish Rajan: to make decisions, and maybe the quadrant that you said earlier for whether you're building it, buying it, or hopefully just having it for a short period, say speed dating for a while, for a while. And but then it comes down, there's still a lot of unanswered questions in this ecosystem, which we haven't answered, and probably networking becomes a big...
Ashish Rajan: We'll have a next-gen proxy as well someday. It's coming.
Kane Narraway: I
Ashish Rajan: mean,
Kane Narraway: we, we have next-gen EDRs now, so yeah.
Ashish Rajan: Oh, yeah, yeah. There is, there is that as well. Uh, so, uh, maybe the bottom line here is that don't forget the foundations Focus on the fundamentals, that if you have not solved phishing, you probably wanna focus on that first- Yeah
Ashish Rajan: before you jump on AI.
Caleb Sima: Yeah. Of course. But nobody listens to us. Is
Ashish Rajan: anyone listening to this podcast as well? I don't know, like, it's just three people in a dark room talking. Well, at
Caleb Sima: least we're having fun, though.
Ashish Rajan: Yeah. Yeah.
Caleb Sima: We're having fun
Ashish Rajan: together. This is, this is the halo. It's like the halo we're sitting in.
Ashish Rajan: No, but, was there any other thing that we wanted to wrap before we wrapped up?
Caleb Sima: No. I mean- Uh- ... I never... Yeah, actually, have you noticed this? I never really have a wrap-up. [00:49:00]
Ashish Rajan: Yeah.
Caleb Sima: I don't, I don't usually have last words.
I
Ashish Rajan: don't, I don't have any wrap-up either, but I, I- I let you
Caleb Sima: always do the
Ashish Rajan: wrap-ups. No, it's, it's one of those ones where I feel like I do wanna give an opportunity.
Ashish Rajan: Actually, maybe I gotta give you the opportunity.
Caleb Sima: You get to give us the opportunity.
Ashish Rajan: Yeah. So is there anything that you're seeing that we may have not spoken to you about, and maybe... Like, it's, it's a question that I've been asking more people, is that, is there something in AI security that we are over-indexing on versus under-indexing on things that we should be actually over-indexing on?
Kane Narraway: Yeah, I think from my point of view, discovery is like we were kind of saying about earlier, like, I think discovery is good, but what about the agents in Salesforce? What about the agents in all these SaaS tools, right? And so, like, I think discovery is good, don't get me wrong, but I think discovery is only ever gonna get you so far.
Kane Narraway: And so you gotta think about, where is your asset inventory and all this stuff. And as much stuff as you can put into that as possible, great, but you're never gonna get everything. There's just no way of doing it right now. So, I think it's something for people to think about in terms of how much risk they have, and- I did have a joke, actually, for
Ashish Rajan: you. Oh, yeah. Okay. So maybe let's, let's move that section then. Oh, yeah. All right. Yeah. So this is [00:50:00] the, uh, you laugh, you lose section. Yeah. And we're talking about, uh, jokes, so you have five seconds to react on the joke. Do you have a joke?
Caleb Sima: Well, yeah, I think he has a joke for you.
Caleb Sima: I have a joke. We, we always have a... But maybe you guys have a joke. So we, him and I both- What? We all have to have a joke? Yeah, yeah. I do
Caleb Sima: not have any jokes.
Ashish Rajan: Well, you can al-
Caleb Sima: Do I look like a joker?
Ashish Rajan: Oh. I know this is- But you can laugh at our jokes if you want.
Caleb Sima: I will do that.
Ashish Rajan: All right. Okay.
Caleb Sima: I liked his, his last one. He already injected a nice burn, so.
Ashish Rajan: Oh, yeah, the, the co-pilot one, yeah. Yeah. Fair. Okay. This is gonna be interesting. So Ashina, I'll give you a better one that I saw.
Ashish Rajan: Do you know shiny hunters?
Caleb Sima: Yes.
Ashish Rajan: Do you know why we can't catch shiny hunters?
Caleb Sima: Why is that?
Ashish Rajan: Because they ran somewhere. Oh.
Caleb Sima: Oh. That's a pretty good one, though. You know, I gotta give you some credit. For a cyber
Kane Narraway: joke, that's not too bad. I,
Ashish Rajan: I wish I could take the credit for this joke- ... but someone else told me and I was like, "I'm using that."
Ashish Rajan: For,
Kane Narraway: like, the, the British and Australians, you know, like, the Penguin bars. Oh, yeah. The really bad jokes or, like, the Christmas cracker jokes. That's what I feel like that is. Yeah, this is- Yeah ... one of
Ashish Rajan: those dji, dji, dji.
Kane Narraway: Yeah, that... W- which, [00:51:00] again, corny- Yeah, yeah ... and cheesy, but not bad for a cyber. Yeah,
Ashish Rajan: yeah.
Ashish Rajan: Yeah. What, what's yours then?
Kane Narraway: Mine's a bit of a roast more than a joke. Okay. But I, I think it's there, and so mine is, uh, do you think there are more security vendors than there have been AI security breaches? Oh, 1000%.
Kane Narraway: Like, you, you... Yeah, you, you gotta get some roasts from him. Yeah, yeah. Yeah.
Ashish Rajan: Yeah, yeah. I need some more from you.
Kane Narraway: Yeah. This is... You got... He's got them naturally, I think,
Ashish Rajan: just flowing. Yeah, I think, it... I think they sh- I need to have you on my earpiece. Yeah. As, uh, as, like, I'm standing on, 'cause you're on the cloud as well today.
Ashish Rajan: Yeah. I look forward to hearing that, but it was a great conversation. Where can people find, connect with you, your blog, if you've been putting your thoughts in?
Kane Narraway: Yeah, absolutely. I think, uh, probably easiest way, connect with me on LinkedIn, but my blog is just my name, so it's Kane Narraway. If you search for that, you'll find it.
Kane Narraway: Uh, a lot of what I've been doing is writing about identity and agent, uh, access control, basically. So yeah, if you wanna learn more, you can do
Ashish Rajan: that. And the next gen proxy.
Kane Narraway: And bring- Maybe that'll be the next
Caleb Sima: one ...
Ashish Rajan: bring your own agent.
Kane Narraway: Yeah. [00:52:00] Bring your own agent. Which I'm gonna go register the domain now.
Kane Narraway: Oh, no. So, yeah. I mean- Bringyourownagent.ai. Yeah. I'm, I'm gonna go register it. I, I, I will go create a startup to fix that right now.
Ashish Rajan: Someone's already building
Kane Narraway: it. As, as this
Caleb Sima: goes out, I'm,
Kane Narraway: I'm just... Someone is already gonna build it.
Ashish Rajan: No,
Caleb Sima: no.
Ashish Rajan: Thank you for watching or listening to that episode of AI Security Podcast.
Ashish Rajan: This was brought to you by TechRiot.io. If you wanna hear or watch more episodes of AI Security, check that out on aisecuritypodcast.com. And in case you are interested in learning more about cloud security, you should check out our sister podcast called Cloud Security Podcast, which is available on cloudsecuritypodcast.tv.
Ashish Rajan: Thank you for tuning in, and I'll see you in the next episode. Peace.

.png)
.png)

.jpeg)














