À propos de cette session
Dans ce panel bilingue animé par Julien Turcot de GoSecure, Kacey Maher (SailPoint) et Nicolas Seigneur (Indigo Consulting) soutiennent que c'est désormais l'identité, et non le pare-feu, qui constitue le vrai périmètre, et que les agents IA forcent à redéfinir ce qu'on appelle une identité. Maher explique que les identités machines exigent une gouvernance distincte du modèle humain d'arrivée-mobilité-départ, puisqu'un agent est à la fois une application et un utilisateur, et déjoue les certifications d'accès statiques et ponctuelles construites pour des audits comme SOC ou PCI. Seigneur décrit l'IA comme un amplificateur des angles morts déjà connus (comptes génériques partagés, clés à privilèges élevés jamais désactivées), à une vitesse et un volume bien plus grands, comparant ce moment aux débuts chaotiques du cloud. Les deux s'entendent sur la nécessité d'une certification continue et fondée sur des politiques pour les comptes machines éphémères, puisque des comptes peuvent maintenant naître et disparaître en quelques secondes. La discussion se termine sur les PME québécoises : les programmes d'identité démarrent par les systèmes réglementés à haut risque et ne s'élargissent que lorsque la direction traite le risque de façon quantitative, le budget suivant une priorité décidée au conseil plutôt que des demandes venues d'en bas.
AI agents are rapidly scaling from pilot environments into full enterprise production, operating autonomously across core workflows. But as Canadian organizations race to adopt AI, a massive security and governance gap has emerged: the explosion of unmanaged non-human identities (NHIs). Unlike human employees, AI agents rely on a complex web of API keys, OAuth tokens, and certificates that are often scattered across cloud environments with zero oversight.
In this 45-minute panel discussion, our speakers will discuss the urgent necessity of governing AI agents alongside human identities. The panel will explore how organizations can break down the silos between traditional identity governance and machine-level secrets management to secure the modern, hybrid workforce.
What the Panel Will Discuss:
The Unified Identity Strategy: Why managing human identities and machine credentials in isolation is a recipe for a breach.
Establishing Human Accountability: Strategies for bridging the machine-to-human gap by ensuring every autonomous agent and secret is tied to an accountable, native human sponsor.
Active Lifecycle Governance for Machines: How to implement automated access certifications and Zero-Standing Privilege (ZSP) controls for AI agents, mirroring human HR lifecycle processes.
The Canadian Landscape: How local organizations are balancing the rapid deployment of AI with strict data privacy and compliance mandates.
À retenir
- Arrêter de vouloir faire entrer les identités machines et agents IA dans le modèle humain d'arrivée-mobilité-départ; bâtir une filière de gouvernance distincte pour les comptes de service et d'agents, rattachée à un propriétaire d'application, pas à une personne.
- Passer d'une certification d'accès ponctuelle (« ces 50 000 comptes avaient les bons accès aujourd'hui ») à une validation fondée sur des politiques, puisque les comptes d'agents éphémères peuvent naître et disparaître en quelques secondes.
- Auditer ses données d'identité pour pouvoir attester spécifiquement des agents : la plupart des organisations peuvent prouver qu'un humain n'a pas accès à une donnée sensible, mais pas qu'un agent que cet humain peut déclencher n'y a pas accès non plus.
- Traiter les identités non humaines comme un problème à prioriser, pas à résoudre d'un coup : commencer par les comptes de service et les lignes d'affaires les plus à risque plutôt que de vouloir tout gouverner en même temps.
- Faire de la gouvernance de l'identité et de l'IA une priorité budgétaire décidée par la direction; les demandes venues d'en bas aboutissent rarement sans que le leadership ait déjà quantifié le risque.
Conférenciers

Nicolas Seigneur is the Chief Technology Officer at Indigo Consulting Technologies, where he leads the company’s identity and security architecture. With over 15 years at Indigo, Nicolas has been instrumental in delivering large-scale IAM programs… Lire la suiteRéduire
Nicolas Seigneur is the Chief Technology Officer at Indigo Consulting Technologies, where he leads the company’s identity and security architecture. With over 15 years at Indigo, Nicolas has been instrumental in delivering large-scale IAM programs across CIAM, PAM, and Zero-Trust. He brings deep technical expertise, a practical mindset, and a passion for turning complex security challenges into scalable, business-driven solutions.

Julien Turcot has spent more than two decades on the front lines of cybersecurity, navigating boardrooms and breach rooms with equal precision. As Senior Vice President of Sales & Marketing at GoSecure, he has helped organizations across North… Lire la suiteRéduire
Julien Turcot has spent more than two decades on the front lines of cybersecurity, navigating boardrooms and breach rooms with equal precision. As Senior Vice President of Sales & Marketing at GoSecure, he has helped organizations across North America strengthen their defenses, respond to crises, and turn security from a cost into a competitive advantage. A seasoned strategist, relentless dealmaker, and natural storyteller, Julien blends technical insight with a human touch, proving that in a world of constant digital threats, relationships remain the most powerful firewall.

Kacey is a Jack-of-all-trades IT professional with 25 years of industry experience, 18+ of which have been spent exclusively working in the Identity Security space. Initially working as a Windows/Unix/DB administrator, he has worn many hats… Lire la suiteRéduire
Kacey is a Jack-of-all-trades IT professional with 25 years of industry experience, 18+ of which have been spent exclusively working in the Identity Security space. Initially working as a Windows/Unix/DB administrator, he has worn many hats throughout his extensive career: As an IAM analyst and architect he has designed, delivered, upgraded and supported complex large scale IAM solutions for industry leaders in the Healthcare, Finance, Insurance, Retail, Education and Government Spaces; as a trainer he has developed and delivered IAM training programs for everything from beginner-level admins to expert-level custom integrators; as a Senior Manager at multiple Big4 consulting firms he has lead teams in the successful delivery of IAM and security related work engagements; and now currently leverages his years of real-world implementation experience to help organizations identify the right answers to their burning Identity Security challenges. Kacey’s combined backgrounds give him a unique holistic view of the Identity Security space, the challenges and pitfalls encountered when implementing identity security programs, and how organizations can leverage industry leading offerings to overcome them.



