Goodman's claim is that identity has quietly become the whole of security, because everything that used to mark a perimeter has gone. Okta's heritage was connecting employees to Salesforce and Workday; after the Auth0 acquisition it also signs you up to consumer services like OpenAI, and it now supports roughly 7,500 tools out of the box — a number he treats as a productivity argument rather than a boast, since a CIO who cannot say yes quickly to the tools a 10x engineer wants will lose the engineer. The sharper argument is about who else is already inside. The big breaches of the last five years, he says — Sony, Optus in Australia, several in India — ran through compromised third-party credentials: a cleaning company with access to payroll, a law firm, a marketing agency, all provisioned with usernames that never sat in the HR system, were never revoked, and eventually got shared. His conclusion is uncomfortable for most enterprises: every identity, employee or not, needs joiner-mover-leaver governance and privileged-access controls. The same logic now extends to AI agents — let one run 99% of an insurance upgrade if you like, but the transaction itself must step up to a human with a push to the phone or a Face ID check, and an AI service that skips that step is one you should not be using. Underneath it all sits the gap he wants closed: identity still has no pervasive industry standard, which is why nobody can say when they are secure enough.
Worth your time if you are
CIOs whose vendor list is longer than their headcount
Security leads who can name every employee but not every contractor
Ten-person startups already working with a hundred freelancers
Product teams weighing passwordless against one more OTP