
Identity at the Center #390 - Identity Management for Agentic AI with Tobin South
Dec 8, 2025
Tobin South, co-chair of the OpenID Foundation's AI Identity Management Community Group, dives into the future of identity management for agentic AI. He discusses the evolution of AI perceptions, particularly after ChatGPT, and explains the vital distinctions between users and AI agents. Tobin provides insights on the Model Context Protocol (MCP), emphasizing its role in safe automation and identity governance. He also tackles the challenges of impersonation versus delegation risks, while sharing practical advice for developers navigating the AI landscape.
AI Snips
Chapters
Transcript
Episode notes
Identity Becomes Central As Agents Gain Autonomy
- Identity and access controls will become central as AI agents gain autonomy and act on behalf of users.
- Tobin South shifted his research to agent identity because agents expand the scope and risk of access management.
Provision Agents Through Your Identity Provider
- Use existing enterprise identity tooling to declare, provision, and govern AI agents rather than handing over user credentials.
- Implement provisioning and deprovisioning for agents in your identity provider now to manage risk.
AI Replaces The Human Assistant Scenario
- Tobin likened modern AI assistants to human executive assistants who previously handled emails and access.
- He warned against giving agents full credentials and urged selective, auditable access instead.
