About this session
In a bilingual panel moderated by GoSecure's Julien Turcot, Kacey Maher (SailPoint) and Nicolas Seigneur (Indigo Consulting) argue that identity, not the firewall, is now the real perimeter, and that AI agents are forcing a redefinition of what counts as an identity. Maher frames machine identities as needing governance distinct from the human joiner-mover-leaver model, since an agent is both an application and a user, can hold service-account privileges alongside a human's credentials, and defeats today's static, point-in-time access certifications built for audits like SOC or PCI. Seigneur describes AI as exacerbating pre-existing gaps (generic accounts, orphaned high-privilege keys, shared credentials for iPads or line-of-business tools) at far greater speed and volume, comparing the shift to the early, chaotic days of cloud adoption. Both call for policy-based, continuous certification of ephemeral machine accounts rather than certifying every individual instance, since accounts can now be created and destroyed within seconds. The discussion closes on smaller Quebec organizations: identity programs historically start with regulated, high-risk systems and expand only once leadership treats risk quantitatively, with budget following board-level priority rather than bottom-up requests.
AI agents are rapidly scaling from pilot environments into full enterprise production, operating autonomously across core workflows. But as Canadian organizations race to adopt AI, a massive security and governance gap has emerged: the explosion of unmanaged non-human identities (NHIs). Unlike human employees, AI agents rely on a complex web of API keys, OAuth tokens, and certificates that are often scattered across cloud environments with zero oversight.
In this 45-minute panel discussion, our speakers will discuss the urgent necessity of governing AI agents alongside human identities. The panel will explore how organizations can break down the silos between traditional identity governance and machine-level secrets management to secure the modern, hybrid workforce.
What the Panel Will Discuss:
The Unified Identity Strategy: Why managing human identities and machine credentials in isolation is a recipe for a breach.
Establishing Human Accountability: Strategies for bridging the machine-to-human gap by ensuring every autonomous agent and secret is tied to an accountable, native human sponsor.
Active Lifecycle Governance for Machines: How to implement automated access certifications and Zero-Standing Privilege (ZSP) controls for AI agents, mirroring human HR lifecycle processes.
The Canadian Landscape: How local organizations are balancing the rapid deployment of AI with strict data privacy and compliance mandates.
Key takeaways
- Stop trying to fit machine and AI-agent identities into the human joiner-mover-leaver model; build a separate governance track for service and agent accounts tied to an application owner, not a person.
- Move access certification from point-in-time attestation ('these 50,000 accounts had correct access today') to policy-based validation, since ephemeral agent accounts can be created and destroyed within seconds.
- Audit for identity data that supports attestations about agents specifically: today most organizations can prove a human lacks access to sensitive data but cannot prove which agents that human can trigger have access to it.
- Treat non-human identity as a scoped, prioritized problem, not an all-or-nothing one: focus first on the highest-risk service accounts and business lines rather than trying to govern every account at once.
- Push identity and AI governance as a board-level, top-down budget priority; bottom-up requests for tooling rarely succeed without leadership already quantifying the risk.
Speakers

Nicolas Seigneur is the Chief Technology Officer at Indigo Consulting Technologies, where he leads the company’s identity and security architecture. With over 15 years at Indigo, Nicolas has been instrumental in delivering large-scale IAM programs… Read moreRead less
Nicolas Seigneur is the Chief Technology Officer at Indigo Consulting Technologies, where he leads the company’s identity and security architecture. With over 15 years at Indigo, Nicolas has been instrumental in delivering large-scale IAM programs across CIAM, PAM, and Zero-Trust. He brings deep technical expertise, a practical mindset, and a passion for turning complex security challenges into scalable, business-driven solutions.

Julien Turcot has spent more than two decades on the front lines of cybersecurity, navigating boardrooms and breach rooms with equal precision. As Senior Vice President of Sales & Marketing at GoSecure, he has helped organizations across North… Read moreRead less
Julien Turcot has spent more than two decades on the front lines of cybersecurity, navigating boardrooms and breach rooms with equal precision. As Senior Vice President of Sales & Marketing at GoSecure, he has helped organizations across North America strengthen their defenses, respond to crises, and turn security from a cost into a competitive advantage. A seasoned strategist, relentless dealmaker, and natural storyteller, Julien blends technical insight with a human touch, proving that in a world of constant digital threats, relationships remain the most powerful firewall.

Kacey is a Jack-of-all-trades IT professional with 25 years of industry experience, 18+ of which have been spent exclusively working in the Identity Security space. Initially working as a Windows/Unix/DB administrator, he has worn many hats… Read moreRead less
Kacey is a Jack-of-all-trades IT professional with 25 years of industry experience, 18+ of which have been spent exclusively working in the Identity Security space. Initially working as a Windows/Unix/DB administrator, he has worn many hats throughout his extensive career: As an IAM analyst and architect he has designed, delivered, upgraded and supported complex large scale IAM solutions for industry leaders in the Healthcare, Finance, Insurance, Retail, Education and Government Spaces; as a trainer he has developed and delivered IAM training programs for everything from beginner-level admins to expert-level custom integrators; as a Senior Manager at multiple Big4 consulting firms he has lead teams in the successful delivery of IAM and security related work engagements; and now currently leverages his years of real-world implementation experience to help organizations identify the right answers to their burning Identity Security challenges. Kacey’s combined backgrounds give him a unique holistic view of the Identity Security space, the challenges and pitfalls encountered when implementing identity security programs, and how organizations can leverage industry leading offerings to overcome them.



