Every AI agent a health system deploys is a new identity with standing access to clinical and financial systems, and most security programs were not built for a non-human workforce. As agents multiply, identity becomes the control plane, and leaders have to govern machine access with the same rigor they apply to people, before an auditor or attacker does it for them. But no identity program stops everything, and the systems that recover fastest treat resiliency as the other half of the same discipline: immutable backups that survive the attack, tested recovery playbooks, segmentation that contains the blast, and third-party risk that does not become an outage. This session covers both, how machine access gets provisioned, revoked, and governed, and how care comes back online in days rather than weeks when prevention fails anyway.
Ben Smith, CISSP, Strategic Agentic Technology Specialist, Sailpoint
Megan Antonelli, Chief Executive Officer, HealthIMPACT Live
00:00:00 Intro: Welcome to Digital Health talks. Each week we meet with healthcare leaders making an immeasurable difference in equity, access and quality. Hear about what tech is worth investing in and what isn't as we focus on the innovations that deliver. Join Megan Antonelli, Jenny Sharpe and Shahid Shah for a weekly no BS deep dive on what's really making an impact in healthcare.
00:00:30 Megan Antonelli: Your health system is hiring faster than HR knows. Every AI agent you turn on is a new employee with a badge standing, access to the EHR and the revenue cycle, and no manager. Most security programs were built for people. The workforce is now partly machines, and the auditors and the attackers have both noticed. Two weeks ago, Sailpoint and CrowdStrike expanded their partnership to bring identity context on humans, machines and AI agents into the Security Operations Center, which tells you where this is headed. Ben Smith has more than thirty years securing health and life science organizations, first at Microsoft and now at Sailpoint. He spends his days with CISOs and CIOs figuring out this out in real time. I am Megan Antonelli, CEO of Health Impact Live, and this is digital health Talks. Hey Ben, it's great to see you. So glad to have you back on the show. And here at Health Impact Digital Health Talks. How are you.
00:01:28 Ben Smith: Doing? Well it's great to be here. Megan it's great to see you again.
00:01:30 Megan Antonelli: Yeah absolutely. You know, we have added a new first question about rooms because we've been convening a lot of rooms with our operators, table dinners and of course our conference, the Health Impact Forum. And so I've been asking folks, what's the favorite your favorite room you've been in? It could be a job. It could be a meeting. It could be a wine cellar in Tuscany. What's what's your favorite room?
00:01:55 Ben Smith: You know, so I thought about this in the context of what we're going to talk about today. And, um, you know, one of the coolest rooms I was in was an actual, it's a, it's a chamber that Microsoft built where it's completely silent. So you go in and you shut, there's no light, there's no sound. You can literally hear your heartbeat in your ears. It's very interesting. For some people, it's very disorienting because they have to have some context of space and sound. I thought about that, but then I kind of I also thought about it in context of like the topic today. And I started thinking about, you know, one of the best rooms I was I've ever been in is a hospital incident command center, and it was from ten p m to two a m in the morning. Um, it was during what we called a code white drill. It's when basically the EMR system was down, we had to move to paper. And in that room, all the normal organizational silos, whether it was clinical leadership, it bio meds, nursing administration, all those silos completely broke down and everyone was looking at the exact same playbook at the exact same whiteboard, focused entirely on a single metric, and it was patient safety and care continuity. So these are roles of people that was basically kind of like work in their lane. They come in contact with each other, but they're focused on their job. And this is really a change in the environment. They're all having to work together to support this common goal. And they were willing to lean in and work and see what each other did and to accomplish that goal. But when you see a chief medical officer in like a security architect solving problems together, you kind of realize that technology is actually what is actually here to do. It's not about deploying like cool software. It's really about protecting the trust between a clinician and their patient. You know, and every time I speak with healthcare leaders, especially like at the Health Impact Forum about identity architecture and resiliency, that's the room that for me comes to mind that I try to recreate in those conversations.
00:03:47 Megan Antonelli: Yeah, yeah. Well, we've been hearing a lot about that. And I think, you know, we saw it play out kind of live. I mean, to, to sort of introduce the world to what that looks like on on the pit. They just won the last night. But it is it's, I think, very top of mind for everyone. And I think what's what's interesting now is that it's also framed. It's not just about the cybersecurity attack. There are many reasons why a health system might need to go to that. And that resiliency piece is, is huge. But tell our audience, those who haven't seen you on the stage at Health Impact about, you know, what you do at Sailpoint and what your role is now.
00:04:21 Ben Smith: Sure. So just a little bit of background on myself. So I, I actually started my career, as you know, like in healthcare as a, at a provider and not small to medium sized, not for profit provider in the Midwest region. Um, I worked my way from the clinical side all the way to the enterprise architect. By the time I left and went to Microsoft, I was at Microsoft for twenty years, focused on the entire healthcare ecosystem. So not just payers and providers, but also med tech and pharma, because it's interesting because until you understand that whole ecosystem, you don't have a complete picture of healthcare. And so I got to do that for, for twenty years and a lot of different roles The last couple of years. I spoke focused specifically on Agentic AI and helping customers develop their centers of excellence, what roles needed to be involved, how they need to interpret and prioritize their use cases, what solutions they need to look at. And through that process, I really came to what are the core three interests I have from a career perspective, it'll always be healthcare, whatever I do. If it were financial services, retail or manufacturing would not have the same level of interest. I really like the idea of using technology to improve people's lives, and there's no other way to do that than through healthcare. Um, also security. I've been involved with I s c squared and my local ish chapter for over twenty five years. So that had to be a core component of what I did. And then I just really got this. I embraced this idea of agentic AI and what it was going to do, how fast it was growing, how fast it was evolving. I really think it is that next turn or milestone in technology evolution, kind of like the internet, that's really going to change the way we think and in work. And by coming to Sailpoint, I actually had the opportunity to do all three of those, spend all of my focus, my time, specifically working with healthcare organizations in the areas of security and focusing on Agentic AI.
00:06:10 Megan Antonelli: Amazing. Yeah. No, I think the point you make about if you don't sit in a seat or really understand both the life sciences side and the payer side and the provider side, it is very hard to understand just the healthcare ecosystem as a whole, right? I mean, one, because of the number of transactions and things that go, but also because the priorities, the incentives, everything, you know, it tips on that. When you don't sit in one or the other, it's hard to know. And so having that background really does, I think, allow you to understand what the key drivers are in each of those organizations. So it really is so important. Now, you talked about Agentic AI, and we've been talking about it a lot. And, you know, when we go to health impact, everybody in the room pretty much understands that. But our podcast is a broader audience. So let's talk a little bit about, you know, what does that mean and what does it mean today? Because, you know, you were you've been working in it in a long time for a long time, but now we're hearing about it. You know, I'm seeing it on Instagram. I mean, my kids think they know what it is. What what does it really mean?
00:07:15 Ben Smith: Yeah. So it's changed tremendously and it is changing even faster. Um, what the environment looks like today is completely different than just six months ago. I mean, I remember when I was at the Health Impact Forum last fall and the conversations we were having, like there's been so many things that have happened since then. Um, I'd say when a health system deploys an AI agent, you know, that they haven't just deployed a software utility. I think a lot of times, um, leaders, if they're not familiar with agentic AI, to your point, um, they may just think that this is just another technology, just another software component they're adding to their environment. But what they've actually done is they've actually hired a digital employee that works twenty four over seven at machine speed, something that we haven't really seen before. traditional software executes deterministic hard coded rules. I'll give you an example. Let's say if you had like a a patient support portal and you had a bot and the patient can ask questions and get responses, well, the bot always behaves in the same manner and it works against the same set of data. And what you would want that system to do is whether I ask that question today or tomorrow, three weeks from now, a year from now, the answer is going to be consistently the same, right? Agents are completely what we refer to as non-deterministic. If the agent is really doing its job, it's learning. It's accessing additional data. It's accessing new data. It's taking different paths to its answer. It's its own model is growing and evolving, meaning that if I answer again, ask that question today, tomorrow, a week two, I'm going to get different answers, more complete answers, hopefully more complex answers, um, as it continues to evolve as well. So that's one of the big differences. You know, I would say like from a security standpoint, you know, you haven't just added an application, you've minted a brand new identity. So we're going to talk about identity and it's a good time to bring that up. If that identity is granted with static kind of broader API keys or permanent administrative privileges without like an owner being assigned to monitor it, what it does, you've essentially handed an unvetted contractor in all access hospital badge and a master key to your pharmacy, right? You basically set up these autonomous agents that are working. Some of them are ephemeral, meaning that they don't exist normally. They're just created when they're needed and then they can go away or decommissioned. So how do you track those things and see those things? Because again, the more important the activity of the agent, the more privileged access those agents are going to have. And so you need to have some level of risk scoring, right? How, you know, how critical are these? What do we need to be monitoring? And I know we'll talk about this here in a little bit, but it's really a lot of the same governance policies we had around humans, but even more complete and complex when we do the non-human identities, like agents.
00:09:57 Megan Antonelli: Yeah, it's I mean, it's really hard to get your head around in terms of thinking about that. And then also, to some degree, the staff that's then required to manage that, right? I mean, it the to some degree is exponential, right? I mean, is there a limit to how much you can, you know, how many agents you can add because of the management that's required for governance? Or is that kind of where you guys sit in terms of what you what you can help with?
00:10:21 Ben Smith: Yeah, I think the, the interesting thing from a sales perspective and the reason why I joined Sailpoint and I believe that they have the right approach to it and sintering Agentic governance around identity is because you're really trying to answer a core question. And I, I always bring this up whenever I talk to leaders is what you're ultimately trying to do is we're trying to make sure that a user doesn't get access to data or tools via an agent or set of agents that they wouldn't have natively had access to. And let me unpack that for just a second, is that unless I understand what the native entitlement of that human user is compared to what they can get through an agent? I don't know if they've been over permissioned and since Sailpoint already through, you know, it's a huge market presence within healthcare. It's the only industry specific vertical sailpoint as we've invested specifically in healthcare, is that because we have that human identity context and what you're natively entitled to, we can then tell when you're over permissioned via an agent, we can throw an alert, we can apply all those governance policies to stop what we call inbound access, outbound access. We can terminate the session, we can invalidate that the token or the key, and basically stop that activity. Um, the challenge I see a lot of organizations do now is they're trying to put in a lot of different point solutions, maybe at the network layer or at the endpoint or the data protection layer. And then they're trying to rationalize all these signals and be able to take a uniform action. And I think that the challenge is, is that all those are very important. I think that those just become kind of spokes to the hub that is identity. And we can get those signals. So if we see a network activity or something happening, like, you know, we talked earlier about CrowdStrike and being able to get signals from CrowdStrike is a huge partner for us is then we can take action through those governance policies, even though the alert was actually happening on an external system. So I think that's really, really important in the way you approach it. So it's not an either or. It's a more of an and solution.
00:12:23 Megan Antonelli: Right. And you may I mean, you answered this a little bit, but I just want to understand in terms of kind of what has changed about the identity and sort of machine identities, because there have been machine agents and now they're evolving. I mean, does it come down to a little bit of the sort of non-deterministic, deterministic, what they're allowed to do? Or is it more, um, concrete than that?
00:12:49 Ben Smith: So let me let me back up a little bit. And you've heard me use the term non nonhuman identity. And I think when sailpoint and I'll just kind of talk from from our perspective, and I think other organizations might have their point of view, but when we originally we would use the term like nonhuman identity. And when we were thinking of non-human identities, we really started with those machine service accounts that you're referencing, right? There's no human owner to them, but they're running with privileged access. They're running servers and services and things that we need to, we need to monitor. And that was kind of like two years ago. We started with with machine identity security, but it was really to go in and find those service accounts that no human was, was, had, was an owner of and that, you know, are they still running and do they need to be running right with this privileged access, with static access? So that's where we kind of started. And then we moved into the agentic world because now agents are a little bit different, agents are a little bit different. So if you think about service accounts, they have that outbound entitlement. So just like a human, that service account is entitled to be able to do certain things. So they'll have access to data, they'll have access to tools, they have certain capabilities, entitlements, but they're basically operating very much kind of like a human, but they're just a non-human in that sense. Agents are a little bit different. Agents are a little more complex because it's not just the outbound entitlement of what the agents have access to do or access, it's who has access to the agent itself. So we call that inbound access. So again, back to that whole scenario of like looking at native entitlement for humans, I need to be able to control who has access to my agent or what has access to my agent. Because now we're in the world of multi-agent systems where agents are talking to other agents, and we need to be able to control that conversational boundary between agents as well as the humans accessing agents. And so I'll give you kind of a the perspective under like a certification review or an access review. Normally, if you think about access reviews, you're reviewing a human and what they have access to and do they still need access to that? You'd still have that access review for outbound entitlement. It would be usually with the agent builders saying, do the agents have the access they need to do what they that agent needs to execute? But at the same time, you might have an inbound access review that goes to the manager of a specific department within a healthcare organization to say, Does Megan need access to this agent? Should I recertify that she has access to it? Or what I do now is realize not only am I getting humans, I'm getting other agents that want access to my agent. Do I want those agents to have access? And unlike humans, where they do access reviews kind of on a thirty, sixty, ninety day period, it's kind of a time frame or time window where they review agents need to be reviewed kind of more along their life cycle, meaning that when they're created, you need to have that inbound and outbound review. Anytime they're altered or changed in any way, you need to have that review. And if they're decommissioned, you need to make sure that that underlying service account, that entitled, that agent is also decommissioned. So the milestones or triggers that cause those certification reviews again, are different than what you would do with humans.
00:15:56 Megan Antonelli: Got it. Yeah. I mean, I always go back to, you know, password protection and all, you know, forgetting the password and, you know, I mean, the workflow of it. All right. And with, with a clinician with this, I mean, what does that really look like in terms of the, the day to day of a hospital operations now that this layer is being added, you know, what does it mean for the security teams to kind of make this all happen and that agents are being managed, you know, in the same way as, you know, clinician identity management.
00:16:31 Ben Smith: That is that is an awesome question, one that I deal with all the time. And I will say that a lot of different organizations are approaching it differently. Um, Sailpoint, uh, I would say core relationships are with the identity, identity and access management teams because that's where the human identity core was. But when we start talking about a genetic AI and even service accounts, sometimes service accounts are handled by the server team. They're not handled handled by the identity and access management team. Um, the agent builders may have the ability to create their own accounts to run those agents. And so one of the big things that have changed, and it's working again to try to figure out where is this responsibility going to land within the organization? Is the identity and access management team going to pick this up? Because if they are, you might need to reevaluate their budgets because they have a much broader scope of what they have accountability for. Um, if it's what I would say is going back to my whole point about the AI Centers of Excellence or AI steering committees, when you talk about AI, it really involves a lot of different groups. Like I mentioned before, data protection endpoint network, the agent builders themselves, you know, the developers, the identity and access management teams. And you really need to kind of come together and figure out who owns what, what those swim lanes are, who's going to be responsible and what, what solutions are selected to help. Um, I think the other thing, like you brought up the the piece that is a lot of times I don't say overlooked, but thought about kind of later is the SoC the security operations center, because when we talk about when an agent's working, you know, agent's going to try to figure out when they can access. And that may be contextual as well, meaning that they may only have access during a certain period of time, and it may be during off hours. And so the SoC needs to be able to see that in real time when that access occurs. And this is why I believe credential security is really important. Behavioral monitoring and understanding drift. So if you can build behavioral models around those security credentials, and then all of a sudden you have a way to tell that that credential is being used by a different identity in a different way, at a different time, accessing a different data set, the SoC can be alerted and then be able to establish a or to trigger a known kill chain to be able to stop that access. And I just want to kind of this is one thing that it's, it's kind of hard sometimes for CISOs maybe to kind of get their head around or maybe just accept, is that we've kind of reached the point where humans alone are not going to be able to combat this, right? These risks, whether they're coming internally or they're external risks, you're going to need to be able to leverage AI for defense because we know that AI is being leveraged for offense.
00:19:06 Megan Antonelli: Yeah, we heard I've heard similar things from the stage recently around. You know, they're just they're moving faster than we could possibly move in terms of scaling that. So you have to combat, you know, sort of the bots with the bots to a certain degree around how to really kind of manage this. And I mean, and to that end, when something goes wrong, I think you post it on LinkedIn recently around, you know, kind of a shutdown and a surgical containment. But when something goes wrong with an agent or a compromised account, you know what then happens? How do we avoid kind of, you know, interrupting the clinical workflow with, with the current systems that are in place.
00:19:46 Ben Smith: Yeah. And this is I kind of come back to the whole idea of like people process and technology. And again, um, technology in and of itself isn't going to solve anything with, without people being trained in the right processes in place. I think one of the things that we need to do is make sure that we're not using the same credential in multiple areas and early with early agentic development, what what the development would look like was very monolithic. They would get the agent as much access as it possibly could ever need to as many different data sets as it possibly ever need. And so then what happens is, well, if they have that access, maybe they use that same credential for another agent and then another agent, and you understand where this is going, right? As soon as that credential becomes, you know, exfiltrated or exposed in some way. Now I have access to what all that all those different agents can do or within my environment. I think isolating access and making sure that every single identity, whether that be non-human or human, has unique access and credentials that they use, because that's also going to allow you to then do that behavioral monitoring. Because if I had multiple agents using the same credential, the behavioral monitoring would be off the chart. Like I, I wouldn't really know what it's doing. And what's happened in that agentic world just come from more of a design software design perspective, is that we really moved away from that monolithic model to what I refer to as a microservices model. It's an old term we used to use in software, which means we basically take a very large program and we break it up into logical chunks so it can operate more efficiently. And any time you need to modify or work on something, you're working on a subset of the entire program. It's the same thing with identity. If a single nurse became, let's say, her credential became exposed in some way, you wouldn't want to like shut down the entire EMR, right? You want a way to isolate that one credential so that care could continue to be delivered regardless, right? You want to isolate, you want to be able to go forensics. What did that credential expose or have access to. So you want to also have that audit ability to go back and understand internally as well as externally, because things like that, if you have to report, like, say, a HIPAA report, you have to be able to go back and explain exactly when was that credential exposed, what did it access, what records were accessed? And unless you have that within your governance system around identity, it's very, very hard to do.
00:22:09 Megan Antonelli: Right, right. I mean, I remember hearing even from, you know, the human perspective of that, you know, kind of nurses using same. Same log logins, right? So the importance of.
00:22:19 Ben Smith: Generic generic log ons, right? Remember the generic log ons?
00:22:23 Megan Antonelli: Yeah, yeah. Um, it might have been one of our first, uh, sailpoint sessions at health Impact. I think that, you know, and, and, and now you realize how important that is because we're dealing with, you know, just the scale of it all. Um, and, and what, what's required. So, you know, I think, uh, you know, lessons learned and sort of applied.
00:22:45 Break: You're listening to digital health talks. When we return, we'll continue our discussion on how technology is revolutionizing healthcare delivery. Stay with us to hear more insights on creating sustainable, patient centered digital health solutions.
00:23:03 Megan Antonelli: You talked about the room and kind of the the resiliency of the health system and what happens when when things go down and, and things stop and we go to paper systems and what have you, what's the for you like when you look at systems that are well prepared and well, you know, sort of well trained for this. What separates the health systems that do come back online in days versus, you know, weeks, months?
00:23:31 Ben Smith: Yeah. And I know, you know, I've talked about this in the past, but it's really having, you know, kind of updated policies and procedures around that, that outage, understanding how that they're going to recover from it. The last thing you want to do is dust off a playbook, you know, recovery playbook that you haven't run in three years and then bring people together that haven't been necessarily trained on it. And I mentioned earlier one thing that we would drill and we would intentionally drill, we wouldn't announce the drill because if you knew when it was going to happen, you knew what was going to happen. You knew how to react. You know, we would actually do those drills within the hospital system at maybe one thirty in the morning, but you were on call in case something were to happen. You had to get to the hospital, kind of get to the ready room and kind of figure out where you went from there. I think the reason I think that needs to be evolved, if you find systems that are and we can look at the ransomware attacks, you bring up a great point like the ransomware attacks, like how long was it did it take for them to recover? And we know in some cases it was months. And the reason why is because when when those those credentials or, you know, whatever that may be that got into the environment, those disaster recovery, the business continuance, those data sets, whether it be credentials or core clinical data were connected at the time. So now that has then filtered into all those different systems. So even if you were to go, let's, I'll use an old term like tape backup, let's say you're going to go and restore those systems. You're restoring those same vulnerabilities back over the system. So you have to be intelligent in the sense that you need to have offline backups that are done on a regular basis, so that when you do that forensic analysis and you find out when the vulnerability occurred, you know, at what timestamp to go back and do your restoration. The other thing around identity governance, and you kind of brought this up earlier is, is that if you have a programmatic way to entitle a user, if you had to start from scratch, let's say, and you had you brought your HR system kind of back online and connected it, and everybody had an established role and you had an identity governance solution like identity security cloud from Sailpoint, you could just automatically reprovision everybody from scratch into their current role with their current entitlements. If you have to do that on a manual level. Could you imagine a department of one hundred people working on identity and access management having to go into each single system and provision you as a user with your role based access. It'd be impossible. That's why it takes months as opposed to days.
00:25:50 Megan Antonelli: I mean, it's. With all of the agents that are available and all of the kind of, you know. But health is coming up is, you know, every five thousand vendors there. They've got agents to offer you and you're going to have multiple agents. And as. We're looking at all of these kind of come through the door through whatever department. They're they're in. I mean, how is a health system, you know, able to even kind of manage the agreements and the contracts and the and the piece of that that is ensuring the right infrastructure and the environment.
00:26:23 Ben Smith: Yeah, no, that's a great question. I would I would say that, um, vars are not enough anymore. And, and what's happening in back up a little bit to what you said, is that like, again, in that I, that AI steering committee or center of excellence, whatever you want to call it, there's usually a subcommittee responsible for evaluating the implementation of AI within existing applications. Um, we use epic for for an example. So epic is releasing Agent Factory where they're going to actually have an agent platform very much like snowflake, Databricks, ServiceNow, um, Salesforce, you know, all these other applications that you may run at enterprise level now have a genetic platforms. And the interesting thing is when those started, the risk was low. And the reason the risk was low is those agents worked within the security context of the user within the application. So I know what that user has access to. And the only data that agent accessed was also in that application. So we refer to those kind of as packaged agents. But what's happened is they've evolved even further now to where those agents may be, let's say, for example, are built within epic. They'll have the ability to reach out to bed, control, clinical engineering, pharmacy, all these different types of areas. Well, now they're not operating within the scope of just the epic application. They're actually talking to other things. And so the way that we want to be able to track that is by looking at the core credential that agent is using and maybe, maybe working on behalf of the user, or it may have its own service credential, but either way, we're going to be able to track what it's doing and see if something is either normal or atypical and needs to stop. The thing that I would say is when I talk to going back to the AI steering committee, is there's usually a subcommittee really responsible for reviewing those releases where you're adding agentic. And so even if they're buying a net new product, there'll be a review to, well, like, what is that agent doing? What can it access? What security context is it working in? What is its purpose? What visibility and logging do we have? And so usually there'll be a writer, right? There'll be like an AI compliance writer that goes along with the bar to talk about things like no standing access or no standing privilege for, um, help desk or like, say, service people, because that's the way it used to be. Like I would purchased an application, I'd pay for a service contract. And then they had administrative privileges to contact in whenever they wanted to, to help support the application that just in time access needs to go away because the last thing we want is an agent external to our organization having administrative privileges to do whatever it wants, whenever it wants. So back to the security context of saying we only want them to have access when we manually grant it, there's a human in the loop so that we know what they're doing when they're doing it. And when they're done, that access goes away, right? So there's a lot of things that can sit in that writer. And I think healthcare is really important that they have that because they're the interesting thing. If you look at the application catalog for a hospital or healthcare system, it is so much larger than almost any other industry because there's so many different pieces, you know, everything from the outpatient registration experience all the way through durable medical equipment for people that have been discharged and need additional follow up. There's just so many different applications that you have to be able to track that level of, you know, support. And now you mentioned earlier is sometimes the support function will actually leverage agents to go in and read logs to kind of figure out what went wrong faster. But now, well, now you're giving log access to agents as well.
00:30:03 Megan Antonelli: Right? I mean, you know, and I, we talk about this often in terms of, you know, nobody wants any more point solutions. But healthcare is designed around point solutions because, you know, of the nature of the departments and the needs. I mean, I remember talking about the EHR twenty years ago and everyone saying, oh, it's not specific enough. It's not, you know, it doesn't tailor to my specialty, it doesn't tailor. So therefore, here come all the point solutions. Here comes all the things. And that's just within the clinic. You know, the clinical space of that, let alone supply chain and everything else and all of the applications. And it's remarkable what I'm hearing from folks who are saying we have a thousand pilots running around AI implementation, let alone, you know, on top of all the apps and applications that they have. So it is it is a vast and, and a little bit scary. And I have to say, when I talk to you, I feel less scared because it.
00:31:00 Megan Antonelli: There are smart people. Working on this and that there is governance in play here and there is there are ways to stop this. So I didn't prep you with this. So you know, up to you if you want to take it. But in terms of the conversations that are happening right now around where do we, where do we limit, where do we stop and what are the threats? You know, how does that sit with you as someone who literally works in this every day?
00:31:28 Ben Smith: Yeah, I think it's interesting. I think, um, if I look how things have evolved over time, I think a lot of organizations Kind of want to be very prescriptive about how they leverage agentic AI technology. So we say agentic AI, you can have systems that are agentic AI systems because agents are built into the programming. You can have actual agents, right, that you that are actually performing a function like a digital worker. I think a lot of them started with very prescriptive ideas of these are the platforms that we're going to use. We're going to stay in this one little world over here, and we're really going to limit, you know, users access. What what we've learned for a long time is when you limit users ability to do what they feel like they need to do, they're going to leverage their own personal knowledge to get it done. Historically, we used to refer to it as shadow it. Now what we have, we coined this term shadow AI. And so let's say there's a corporate approved function, whether that's, say it's Copilot or Gemini or whatever. It's it's something that's been corporate approved, but that's not what they're used to using, or it doesn't give them the response or doesn't have the right connectors to get to the right data. It may be the only internal facing and not external facing. And they need data from the internet. You know, what ends up happening is they will leverage another tool in the environment and it'll go. And so what we've tried to do is give the visibility. One is that you again, when I say you need to be able to discover you can't govern what you can't see, you need to be able to discover in your environment, not just the sanction, but even the unsanctioned use of AI. Because and it may not be that it's all nefarious, right? In a lot of cases, it's just users trying to get their job done. They either are uneducated on how to use the approved tool, or they're just more comfortable using another tool. And it may be that you've discovered a pattern of behavior that means you need to open up maybe another tool set to your users, right? So it's a two way street. I think what we've learned though, is that whole idea of, we're going to constrain the users to these, these specific platforms has kind of been undone because you've got different applications that have come in that run on different cloud platforms. For example, some started saying, we're just going to use Microsoft, and now they have applications that are leveraging AWS or Google Cloud Platform, right? Um, but to your point, earlier, now it's gotten even bigger because now you've got other applications that are embedding agentic platforms in their actual tools. And so it's not like you can force everybody to just use one when agents are coming in across their whole portfolio or catalog of applications. And so you're kind of going back, like, I think the, the big thing is, is think about it from a governance perspective. And I think this is why, again, identity is really critical. And this is a conversation I like, I swear I have like two or three times a day is that you can do one of two things. You can either develop governance policies for those agents in every single platform that you potentially run in your environment. Now you're either going to triple the size of your identity and access management team, or you're going to hand that off to the application support team, which they're not. That's something that they don't normally do, or you're going to need to find some solution that allows you to have a central control plane for all of your agents, regardless of where they run, and be able to have centralized governance policies for agents that run on disparate systems. Right? Because going back to what I talked about earlier, is that conversational boundary of, let's say you have an agent from one platform talking to another, to an agent on a different platform, and you've got governance policies that are siloed across those two platforms. Well, what's controlling the conversational boundary between the agents?
00:35:06 Ben Smith: Yeah. And so that's what I think we'll kind of start turning and they want to get to a whiteboard. They want to draw it out. They want to understand, I get it, but every environment is unique. And so I think the best way to start is, you know, we do a lot of consultative kind of upfront, um, really smart people that have come into sailpoint and will basically sit down and it's not really a sales exercise. It's really more like I say, consultative to say, what are you doing today? What is your vision? What kind of steering committee do you have in place? What are your policies? What do you hope to achieve? What are your major concerns? Um, and then basically kind of take all of those business factors and kind of roll that into more of a technical architecture and design of looking at what are you doing in the network? What are you doing in the endpoint? What are you doing for data protection? What are you doing in your vault around privileged access management credentials? How can we bring that into a centralized governance policy that applies to all your agents, regardless of the platforms they're running in?
00:36:03 Megan Antonelli: Right. Yeah, I know, and I think it's so critical and I've talked about it, you know, pretty much everyone I've talked to, you know, for a couple of months now, in terms of where this all comes down to is, is that governance? And I think what's so interesting about what you're talking about, which is that the, the power of being able to sort of see the context, right? And for it to respond to the context, it only works when you have the governance in place, the identities in place, that you can then track what's happening. And then if if you're able to do that and as you said, have the visibility to see this shouldn't be happening, this should be happening, this is sanctioned, this isn't sanctioned. Then it becomes such a powerful tool. And the the fears can be allayed a bit.
00:36:50 Ben Smith: I couldn't have said it better because without that context, you don't have you know, we talk about just in time access of granting, granting entitlements just when the user needs them or an agent needs them. The only way you're going to do that is to have that identity context. Who is that person? Where do they work? When do they work? What do they normally do without that context? And you're just like saying using a point solution, you're looking for kind of like infrequent behavioral signals, but you can't really make a really good decision about whether that person should or shouldn't have access without that expanded context. You hit, you hit the nail on that. I couldn't have said it better than what you just did.
00:37:26 Megan Antonelli: Oh, well, it's only from learning from you. Now when it comes to we have our our five good things and we're talking about some scary things, but, you know, just really powerful technology. But things are changing fast. And as you look at kind of the last six months since we were, you know, together in in February and June and, and what's to come, what do you see on the horizon within healthcare that is, is very exciting. And that, I mean, it can be from a tech standpoint, or it could be from how we're we're using the tech, but, you know, ties to our five good Things segment.
00:38:04 Ben Smith: You know, it's funny because I think a lot of people expect me to answer that kind of more from a technology perspective. Like, and, and honestly, I, I really think it's kind of, for me, the most exciting thing and I'm positive development that I've seen is that we've got this unprecedented, unprecedented alignment between like clinical executives and cybersecurity leaders. So a lot of these conversations were very compartmentalized out in the different silos. And it's, it's really, it's a much bigger problem to solve, and it kind of needs all hands on deck. And I think what's what's interesting is in a lot of cases, we're seeing those clinical leaders kind of lean in and want to understand the problem and the solution. They definitely understand the risk. I think they're more educated. I think a lot of health systems have done a lot of work, making sure that everyone in the organization understands that security is everyone's responsibility and understanding risks. But I just think that the level of people leaning in together and working together across the different boundaries has been, is been important, I think. The other thing is that I always think about IT security as the Department of No. A lot of times a lot of organizations are like, well, if we ask security, we know what answer we're going to get. It's going to be no. So let's just not ask security or whatever it may be. And it's been a friction point, honestly, of, of basically getting in the way of treating patients. Right. Because again, if you make the security so difficult to use. What you're doing is you're creating time delays and time that can be spent with patients and addressing patients needs. But now I over, I'd say over the last two years, specifically my time, my last time at Microsoft, my time now at Sailpoint, you know, you know, all the different industry events that have happened. You know, I see CISOs chief medical information officers, chief medical officers, chief nursing officers, they're kind of starting to speak the same language because remember, when we start talking about specific terms, you kind of need to stop. And we try not to use acronyms, right? Don't use acronyms. You need to say the whole word. But I think it was one of those things where, you know, you would say like agentic AI at one point in time and like maybe one person in the room knew what you're talking about. You even said that earlier. And it's like, everybody kind of understands because it's permeated not only your work life, but your personal life. People are using generative AI all the time. But I think the other thing is that that now those leaders are also recognizing that cybersecurity is not just an IT cost center. It's like, how can we do the same for less? Now they see it's an indispensable component of clinical quality and patient safety. Areas where they're wanting to invest because they don't want to be that next headline. They don't want to be the organization that did not do their due diligence in putting the right standards or policies in places. And the other thing is, and I always, again, kind of back to that people process and technology is you can have the best technology in the world, but if you haven't trained your people and you haven't developed your processes and tested them, that technology will fail. And you also kind of brought up the other piece I just mentioned is, is that until you've kind of embraced this new world and kind of got everybody on board kind of working together, like my example about that incident command center is that you're going to have a failure. There's only, you know, us in like the industry that we're in, there's going to be an event. We know there's going to be event. It's just a matter of time. And when that event happens, then everybody's point of view changes. And what you don't want to do is be reacting to an event. You want to be able to be proactive in understanding and reducing that risk. And your point of if it does happen to me, how do I recover and not put my patients at risk? And the only way you do that is through practice and education and training. And again, having the right tools is great. But again, if you're not trained on them, you're going to be in that three to four month recovery period that we all don't want to be in.
00:41:51 Megan Antonelli: Yeah, no, it is. It's amazing. And I do, and having watched it and having always, you know, known and, and felt we always have to have security, you know, a few security sessions be discussing it, you know, uh, but now the understanding of the fact that if you don't have it, you don't really get to have the benefits of all of this technology. I mean, that it isn't, it isn't a, you know, add on. It is actually the fundamentals to what allows for the success in this. So amazing.
00:42:24 Ben Smith: Yeah. I just want to say one more thing. Like, I, I, I can't give you enough credit in the Health Impact forum because because you can't really be successful in a vacuum. And this isn't about a hospital system competing with another hospital system for patients. This is about doing the right thing for everyone. And the more leaders that talk and share what they've learned, good and bad, the better we're all going to be at it. And having like the Health Impact Forum where people can come together, ask questions, everybody's there in support of each other, sharing what they've learned. That's how we're all going to do better together.
00:42:55 Megan Antonelli: Yeah, one hundred percent, I agree. Fabulous. Well, besides coming to Health Impact and meeting the team, let our audience know how they can get in touch with you.
00:43:05 Ben Smith: Yeah. So obviously Ben Smith, you can reach me on LinkedIn. If you put in Ben Smith's point, I'll pop up right away. Um, I do speak at a lot of events. You'll see me, I'll be at AI med. Um, so usually if there's a forum in Sailpoint, uh, participating, you can find me at the booth or on stage at some point breakout. Um, love having one off conversations. I do have people reach out to me on LinkedIn and just want they've seen something and they want to ask a question. I'm happy to help wherever I can. And to your point, you know, I would say even more importantly, we're going to be diving much deeper into these topics at the Health Impact Fall Forum. So we will be there. I will be there. Uh, we'll be talking about it. And we'd love to meet everyone in person that gets that comes out.
00:43:44 Megan Antonelli: Awesome.Well, thank you so much, Ben. Always a pleasure. Look forward to seeing you very soon. And to our audience. Thanks for listening. Any questions? Again, don't hesitate to reach out. And certainly, uh, come join us at the Health Impact Forum in October. If this conversation got you thinking, that is the whole point, share it with someone who needs to hear it. Subscribe to Digital Health Talks. Follow us on YouTube at Health Impact Live and visit Health Impact live dot com. This is Megan Antonelli, CEO of Health Impact Live. And this is digital health Talks. Let's keep fixing health care one conversation at a time.
00:44:17 Outro: Thank you for joining us on Digital Health Talks, where we explore the intersection of health care and technology with leaders who are Were transforming patient care. This episode was brought to you by our valued program partners, Heidi, the AI care partner built for every moment of the clinical day. Natera. Advancing. Contactless. Vital signs. Monitoring. Sailpoint. Securing healthcare identity management and access. Governance. Your engagement helps drive the future of healthcare innovation. Subscribe to digital health talks on your preferred podcast platform. Share these insights with your network and follow us on LinkedIn for exclusive content and updates. Ready to connect with healthcare technology leaders in person? Join us at the next Health Impact event. Visit Health Impact live dot com for dates and registration. Until next time. This is Digital health talks where changemakers come together to fix healthcare.