Every argument clarity score on this site is built from rows on this page. Each
question and answer was assessed with names hidden, the host's own answers included, on
four things from 1 to 5:
directness (does it answer the question asked), coherence (do the ideas follow),
precision (concrete details and clear references), compression (says a lot per word). The weighted
mix (30/30/25/15) is the exchange score. A person's published score averages their exchange
scores on raw tape only, at least 8 of them, shrunk toward the cohort mean.
Full method →
Answered raw tape
D 5 · C 5 · P 5 · Cm 5 5.00
Q So concretely, um, with and without, uh, cross app access, uh, what does the state of the build out look like without it versus with it? Like, what can you do with this cross app access that you couldn't do otherwise?
A Yeah. So, uh, without it, it's, it's point to point and everything is different. If you're building an agent on Salesforce agent force or Google agent space, if you're building an agent on writer, any, any platform where you're developing your agents, you're, you will develop them with point to point permissions. So if I, as a user deploy an agent that was built on one platform, it will ask me if it needs access. So let's say it's a Google agent space agent and it wants access to my Gmail. It'll, it'll prompt me, can I have access to your Gmail? And I'll say yes, because I want you to do work for me with my email. It'll ask me if it can have access to my calendar, and I will say yes. And in that world, my company won't know that I've given it that permission, because it's, it's a permission that I as a user have granted to the agent I deployed as a user, but I have now given it access to my production corporate data. And so that is an exposure where companies have agents that they don't control. It's software written by a third party that's now accessing corporate data assets. And that is fundamentally a problem. What cross app access will do is it will allow agents to, um, to be registered into, into your IDP to, as I mentioned, to have their credentials managed, to have them appropriately rotated. To have governance deployed where they can be just in time provision and deprov…
AI assessment note: “without it, it's, it's point to point and everything is different”
Answered raw tape
D 5 · C 5 · P 4 · Cm 4 4.60
Q know what these agents are gonna do. Like, uh, you spoke about that fast food chain, um, that, you know, this, again, idea of going to take action, um, is, I guess it's both thrilling, but also somewhat scary, um, Especially if you don't have the right governance in place. So can you just talk about like the state of governance around these, around these agents and why that's important?
A Well, I, I think All of us are working to catch up with the capabilities of the technology, and we believe that we have a responsibility to help elevate the industry's readiness to deploy agents in a way that they can be safe, secure, and productive. And, and the industry's race to innovate has focused more on production than safe and secure, and so we, we believe we have a very important role At helping companies get the balance right. So I spend many of my days every week talking to customers, and I mentioned CISOs, Chief Information Security Officers, and CIOs, um, about these challenges and what they see in their businesses. And one of the most common questions that I hear them addressing within their companies is the issue of data governance. And specifically, what data is an agent able to get access to? And this, this is similar to the problem of authorization I mentioned previously. When you authorize an agent, what is it going to have access to read? But here the concern is really twofold. One is, what data should it be able to see? The second is, what data should it be able to use? And one of the latent concerns people have as they're deploying, deploying third-party agents, is they want to know if that data is going to be used anywhere else. So is it going to be used just for my query to help me do my work, which is usually fine? Or is that data potentially going to b…
AI assessment note: “one of the most common questions that I hear them addressing... is the issue of data governance”
Answered raw tape
D 4 · C 5 · P 4 · Cm 4 4.30
Q Now, a lot of people have talked about, well, we have agents, but we need a human in the loop. So, uh, it's, that sort of contradicts like the definition that you're giving. So where's the human's place in this equation then?
A Yeah, I, I think agents can take action autonomously. Often we think about agents as taking action on behalf of a specific human, but they don't necessarily have to be bound to a specific human. So as, as a consumer, I might have an agent that's my travel concierge that I, I tell it I want to take a family trip to, for a safari in Africa, and I can ask it to go off and do work, and it can scan tour companies, and it can look at airfares and airlines, and it can look at what, what are the best seasonal dates to travel, It can look at lodging. It can look at guides. It can go off and actually reserve all those things for me, and it can come back with a printed itinerary and charge, charge my credit cards for all that work. That agent in that example can act on my behalf, but we can also have agents within our corporations that act on behalf of a process or act on behalf of a server. Um, that the key for us is that they're doing autonomous work. They're doing work that is not specifically supervised and managed and maintained with a human being taking action.
AI assessment note: “Often we think about agents as taking action on behalf of a specific human”
Answered raw tape
D 4 · C 5 · P 4 · Cm 4 4.30
Q that you brought up. The 10% of the companies that have agents out there feel good about the security. Uh, of their agents. How is that possible? I just don't understand how you could have such a large number of companies deploying this technology, knowing, going back to your definition, that it takes action, and then also like raising their hands and being like, well, it's probably not secured well.
A Yeah, it's, it's the reality of the race to innovate. It's now, and that has been fine while these agents were in prototype, but it is now the case that they're now shifting into production, and they're doing it faster than customers had anticipated, and so it creates added urgency to make sure that we, we are, um, we are considering how those agents can be managed. One of the challenges is, historically, and history here is not going back that long, There hasn't been a standard for how agentic identity can be managed. Um, so one of the ways that Okta is helping the industry address that problem is we've advocated for a new open standard, um, called cross app access. I think Alex, you might be familiar with that. What the standard does is it defines a standard protocol for how an agent's identity can be registered and managed with any identity provider, um, including Okta's, but with any identity provider. And the goal is to allow developers who are building agents to build them from the start in a way that the credentials for those agents can be appropriately vaulted and secured. They can be managed by policy and rotated, um, and that they can be governed, um, so that they're provisioned and deprovisioned as they're needed, as opposed to being static credentials that are just always available. Um, these basic capabilities need to, need to have a standard in order to allow comp…
AI assessment note: “it's the reality of the race to innovate”
Redirected raw tape
D 2 · C 4 · P 4 · Cm 3 3.25
Q bottom up pushing this stuff, uh, to make folks, um, you know, aware of the capabilities. Uh, but at its current stage, we're seeing some like really trillions of dollars or trillion plus, uh, committed to the build out of AI infrastructure. And something that we worry all the time on this show or wonder about really is Is that being overdone? So where do you stand on that question?
A I can't really speak to the macroeconomic investment of what's going into AI. What I can tell you is from, from Okta's perspective, we really worry about the security exposure with this race. Um, so you, you can look at the energy investments that are required for this technology. You can look at the amount of VC funding that's going into, uh, companies in this space. You can, you can assess different opinions on, on where the ROI is going to be and which investments are overdone versus underdone. But regardless of how you feel about all of those trade-offs, the, the challenge of having an industry where people are racing so fast to innovate that they're deploying technologies before they've secured them, that's a real exposure that companies are faced with today. And so from Okta's perspective, our whole goal is to bring in identity security fabric that allows companies to control for that risk and to secure themselves and their users and their customers so that they won't be exploited By having threat actors exploit agentic AI in their environments. That that's really what we're all about.
AI assessment note: “I can't really speak to the macroeconomic investment of what's going into AI.”
Redirected raw tape
D 1 · C 4 · P 4 · Cm 3 2.95
Q Can you talk about that risk? Like where is the risk in the process?
A Well, one of the, I'll give you a couple of examples of that. So, um, so let me give a little bit about Okta and our perspective on this. It might help for some of these conversations. So Okta is 16 years old and we were born in a prior wave of, of technology modernization. And that was the shift, um, back in, in 2009, 2010 from on-premise computing into cloud-based computing. So from on-prem software into software as a service. And our company was founded as Salesforce had taken the CRM market from an on-prem market into, into SaaS. Um, Workday had taken the HRMS market from on-prem into SaaS. And Okta was founded out of that wave as, as our founders recognized, and Todd McKinnon and Freda Karest had, had spent time in Salesforce and had witnessed that transformation and saw what SaaS was going to do to the tech industry. And they created Okta as a platform to enable companies to make the leap into the cloud. So our first use case was managing human identity, and it was helping companies that were moving from on-prem and starting to add cloud-based applications, helping companies have employee identities that could access both on-prem and cloud applications, and that evolved into managing that human identity. What does that human identity have access to? How is it authenticated into all these technologies? And over time, How is it appropriately authorized so that when we, once…
AI assessment note: “let me give a little bit about Okta and our perspective on this.”