
The Cybersecurity Defenders Podcast #255 - Defender Fridays: Identity Automation in the Age of Agentic AI with Matthew Chiodi from Cerby
Oct 10, 2025
Matthew Chiodi, Chief Strategy Officer at Cerby and a seasoned cybersecurity expert, dives into the implications of autonomous AI on identity security. He distinguishes between generative and agentic AI, sharing insights into the challenges of managing disconnected applications and manual workflows. Matthew explains how Cerby's innovative tools automate password management and enhance security for non-federated apps, while also emphasizing the necessity for human oversight in agentic systems. He also sheds light on the hurdles organizations face regarding SCIM adoption and managing enterprise social accounts.
AI Snips
Chapters
Transcript
Episode notes
Agentic AI Is Task-Focused Identity Automation
- Agentic AI differs from generic generative models by being task-specific, proactive, and trained on narrow domains.
- Cerby applies agentic AI to automate manual identity tasks for disconnected applications at scale.
Disconnected Apps Still Make Up Big Identity Gaps
- Up to ~40% of enterprise apps can be 'disconnected' because they lack SAML/SCIM support or charge for federation.
- This gap forces manual joiner/mover/leaver workflows that agentic automation can address.
Bridge Non-Federated Apps With Credential Injection
- Use a browser extension and credential injection to provide SSO-like access for non-federated apps.
- Automate password rotation and enable two-factor authentication where the app supports it to close security gaps.
