Listen and watch now on YouTube, Apple, and Spotify.
In this episode of Engineering Enablement, I sit down with Robert Lucero, Chief Architect at Okta, to discuss how agentic AI is changing identity and access management. We explore how organizations should define agent identities, why authentication and authorization remain foundational, and how sandboxing, fine-grained permissions, and just-in-time access let agents operate autonomously without creating unacceptable risk.
Robert shares what Okta has learned from driving AI adoption among security-minded engineers, what makes a repository ready for AI agents, and why strong testing, CI, and review processes matter even more as AI generates more code. We also discuss AI’s role in software validation, the need for human judgment, and whether AI will ultimately give the advantage to security teams or attackers.
Some takeaways:
Identity becomes critical when AI agents move beyond content generation
AI agents need access to documents, source code, CI systems, ticketing tools, and other resources to perform useful work. Identity systems determine which resources they can access and what actions they can take.
Non-determinism makes tightly scoped access especially important. Organizations need dynamic policies, fine-grained permissions, and visibility when agents attempt to operate beyond their boundaries.
The definition of an agent identity is still evolving
Organizations have not yet settled on whether every agent or ephemeral workload needs its own identity. An agent might instead operate under an orchestrator, a service account, or the identity of a human owner.
The fundamentals of identity remain the same. Agents still need to be authenticated before organizations can apply authorization policies, governance, and access controls.
Treat AI agents like new hires
Start agents in a sandbox with tightly scoped access and clearly defined tasks. Like new employees, agents may seek out tools or information when their environment is missing something they need.
Rely on technical controls rather than assuming an agent has earned trust. Sandboxing, guardrails, and just-in-time access can limit the blast radius of unpredictable behavior.
Identity systems are a control plane, not an orchestration layer
The identity layer governs what agents can access, trigger, and call. The workflows connecting coding, review, testing, and deployment agents will likely be orchestrated elsewhere.
Identity systems can provide essential visibility into agent relationships. A relational record of agent-to-agent and agent-to-resource access makes it possible to investigate why an agent was able to take a particular action.
Successful AI adoption depends on useful outcomes
Okta’s security-minded engineers were initially skeptical because early tools did not reliably help them do their jobs. Adoption increased as coding models improved and became more effective in real engineering workflows.
The value of AI extends far beyond writing code. Engineers can use it to summarize documentation, review product specs, investigate production issues, and respond to customer requests more efficiently.
AI readiness starts with engineering fundamentals
Repositories need clear instructions, discoverable dependencies, compatible harnesses, and defined development practices before agents can work effectively.
Strong testing, CI, linting, and code review provide the safety nets AI-generated changes require. Improving a repository for AI agents often makes it easier for human developers to work in as well.
Passing tests does not prove that AI-generated code is correct
An agent can write tests and produce code that passes them without understanding the intended business outcome. Reliable validation depends on giving agents access to the right requirements and context.
Human judgment remains essential for determining whether software actually solves the problem. Developers, designers, test engineers, and product owners must still evaluate whether the result meets user and business needs.
In this episode, we cover:
(00:00) Intro
(02:16) Meet Robert Lucero
(02:56) Why identity becomes critical as AI agents access more systems
(06:07) Governing automated access for non-deterministic agents
(08:01) Defining and managing agent identities
(10:32) Authentication and authorization for AI agents
(13:33) Determining how much autonomy to give AI agents
(19:44) Identity systems as the control plane for AI agents
(22:40) Driving AI adoption among security-minded engineers
(25:48) Why AI’s impact on engineering extends beyond coding
(28:44) The three components of AI readiness for repositories
(30:55) AI’s role in software testing and validation
(34:26) Whether AI gives defenders or attackers the advantage
(36:01) Where to find the best food in the country
Where to find Robert Lucero:
• LinkedIn: https://www.linkedin.com/in/rlucero
Where to find Brian Houck:
• LinkedIn: https://www.linkedin.com/in/brianhouck
Referenced:
• State of AI Impact in Engineering Q2 Report 2026
• Okta
• The Hugging Face incident and the road ahead | OpenAI
• GitHub Copilot · Your AI pair programmer
• Claude Code by Anthropic | AI Coding Agent, Terminal, IDE










