Uploaded November 2025 | Updated September 2026, 2 days ago
Opal Security CEO Umaimah Khan argues authorization has been under‑invested compared to authentication—and that the rise of agents makes access control the first domino to fall. She discusses MCP, JIT, dynamic access beyond RBAC, and founder advice for balancing productivity and risk as enterprises adopt AI from much smaller teams.
CHAPTERS:
0:04 - Intro: Opal Security and intelligent access controls
0:23 - Who/what/how: tying identity and access together
1:03 - We solved authn; authz was ignored in fast‑moving teams
1:54 - Agents create a pivot point for authorization
2:24 - Prior tectonic shift (cloud); now identity/access will shift first
3:05 - First to fall: access control before governance
3:30 - Reactive controls: MCP auth, JIT; early and messy
3:50 - “Printer driver” analogy; standards likely from model providers
4:12 - Expect new attack vectors while building fast
6:00 - Who is “you” with thousands of agents? Identity persists
6:56 - RBAC as a building block; dynamic, context‑aware access
8:03 - Security as judgment; need dynamic systems making calls
10:26 - Advice: weigh productivity vs risk early; hard to rip systems later
Opal Security CEO Umaimah Khan argues authorization has been under‑invested compared to authentication—and that the rise of agents makes access control the first domino to fall. She discusses MCP, JIT, dynamic access beyond RBAC, and founder advice for balancing productivity and risk as enterprises adopt AI from much smaller teams.
CHAPTERS:
0:04 - Intro: Opal Security and intelligent access controls
0:23 - Who/what/how: tying identity and access together
1:03 - We solved authn; authz was ignored in fast‑moving teams
1:54 - Agents create a pivot point for authorization
2:24 - Prior tectonic shift (cloud); now identity/access will shift first
3:05 - First to fall: access control before governance
3:30 - Reactive controls: MCP auth, JIT; early and messy
3:50 - “Printer driver” analogy; standards likely from model providers
4:12 - Expect new attack vectors while building fast
6:00 - Who is “you” with thousands of agents? Identity persists
6:56 - RBAC as a building block; dynamic, context‑aware access
8:03 - Security as judgment; need dynamic systems making calls
10:26 - Advice: weigh productivity vs risk early; hard to rip systems later










