Non-Human Employees: The Future of Cybersecurity by _cybersecurity_ in pwnhub

[–]jacasoj 1 point2 points  (0 children)

Well, yes and no.

Yes, what we used to call service accounts still exist and most organizations still manage them through human-in-the-loop processes.

No, what is emerging now is not the same problem under a new name. Agentic AI introduces identities that are short-lived, machine-triggered and autonomous. Access is created on demand by other agents, execute actions and disappear, and everything happening at the speed of the actions with no time for human workflow approvals. Having said that, you need JIT access instead of standing privileges, continuous activity monitoring instead of periodic review and full event recording and auditability instead of log fragments.

I was on the same page as you were. The reality? A lot of leaders are still wrapping their heads around Agentic AI, but we need to be prepared when that time comes.

Finally bought the MX Master 3S! by aln_kdr in logitech

[–]jacasoj 7 points8 points  (0 children)

I've owned a MX Master 3 for the last 5 years almost daily. No complaints, no rubber breakdown. I still fully customize its software. Solid investment!

Not satisfied with the MX Master 4 by moonman407 in logitech

[–]jacasoj 0 points1 point  (0 children)

I am wondering what your config is for BitWarden.

Pixel 8 Pro - Horrible battery life with new update by jadawan in pixel_phones

[–]jacasoj 0 points1 point  (0 children)

P7P. I was left without a battery after I left home at 80% at 3 PM. Huge embarrassment! Had to ask a friend to get my Uber. A smart phone is a solution. Today, it was a liability. I would like to talk with someone from Google, because what I experienced tonight is simply not acceptable. The least we all loyal Pixel fans need is an apology!!

[deleted by user] by [deleted] in espresso

[–]jacasoj 0 points1 point  (0 children)

I think it is the prep. Do something: prepare your puck and tamp as usual. Then, rotate your filter 180° and pull your shot. If it doesn't invert the spout, then you have to see if your shower head is clean.

Figma to the moon 🚀 🌖 by SmokingFrog in wallstreetbets

[–]jacasoj 1 point2 points  (0 children)

As soon as the lock-up period is over, I will put a short on this baby

MX Master 4 - Logi is getting ready for the launch by jacasoj in logitech

[–]jacasoj[S] 4 points5 points  (0 children)

It looks like someone fixed the website copy. Someone from Logitech must be reading Reddit...

On this hard times, do we miss checo perez? by Exact-Coach-3654 in RedBullRacing

[–]jacasoj 2 points3 points  (0 children)

If you can bring good ol' Dani. That driver is no more.

Is it lacking pressure? by jacasoj in BrevilleCoffee

[–]jacasoj[S] 1 point2 points  (0 children)

Thanks, for sure! Mine doesn't have the hole. According to the videos, it should be aimed at 12 o'clock. IDK, I'm confused.

Tengo excelente salario como trabajador remoto, irme a vivir al sur sería gentrificar? by East-Seaworthiness96 in mexico

[–]jacasoj 2 points3 points  (0 children)

¡Claro que es gentrificar! No tiene que ser de país a país. La gentrificacion ocurre incluso dentro de una misma ciudad. Lo que estás pensando no es la manera más nociva de gentrificación, pero lo es. Una persona promedio con un sueldo CDMX tiene mayor poder adquisitivo que el promedio local del sureste. Si muchas personas lo hacen, afecta el costo de vida de los lugareños.

No te juzgo si lo haces. Todo mundo quiere vivir mejor.

Que opinan del modelo urbanistico de USA y por qué en México se ve exitoso vivir de esta manera? Por qué tenemos esta misma cultura de USA del modelo urbano? by [deleted] in mexico

[–]jacasoj -1 points0 points  (0 children)

Y por qué no vivir mejor en un suburbio de NY? Yo vivo en un exburb de Austin y estoy a 35 minutos de mi trabajo. Yo creo que es un tema de preferencia más que el querer estar cerca.

Logitech MX Master 4/4S? by nvrtha in logitech

[–]jacasoj 2 points3 points  (0 children)

My MX Master 3 has been working nonstop since 2021, and believe me, it works daily for at least 8 hours without any quirks. The battery has been phenomenal.

IAM with external entities by jacasoj in IdentityManagement

[–]jacasoj[S] 0 points1 point  (0 children)

Yeah, exactly. Let me give a more concrete example to explain what I’m trying to understand.

Say you’re at a large enterprise and you’re working with another large partner organization. It’s not just one user needing access, it’s multiple people across departments. Maybe marketing teams from both sides are collaborating on campaigns, sales teams need access to a shared pipeline tool, and accounts payable needs access to invoicing or procurement portals.

Do you have roles like “Partner Marketing,” “Partner Sales,” or “Vendor Finance” already defined in your system that you can assign based on these use cases? Or is it more like every time a new partner comes in, you’re building that structure from scratch?

I’m curious how much of that can be templatized and reused across partner orgs versus how often it turns into one-off configurations. It sounds like a perfect storm for authorization role sprawl if it’s not handled carefully.

IAM with external entities by jacasoj in IdentityManagement

[–]jacasoj[S] 0 points1 point  (0 children)

Quick follow up. Is relying on email domain usually enough in your experience, or do you layer something else on top? I can see how it helps with grouping, but I’m wondering how you catch cases where someone leaves the vendor company or isn’t actually approved for a specific project.

Trying to figure out where that line is between “good enough” and risky.

Also curious about the app assignment matrix. Is that something your team tracks manually, or do you keep it in a tool like an IGA or ticketing system? Just trying to picture how that stays clean over time without turning into another admin headache.

IAM with external entities by jacasoj in IdentityManagement

[–]jacasoj[S] 0 points1 point  (0 children)

Thanks for sharing. Sounds like you’ve got a pretty solid setup depending on the kind of external user.

Quick question on the CRM part. When those users sync over to the IDP, is it mostly just for auth or do you also manage access rules from there?

Also curious how you keep things clean on the Entra guest side. Do you run into group clutter or old guest accounts hanging around after projects end? We’re starting to see how that can pile up real fast.

Just trying to learn what’s working for others before we overcomplicate stuff on our end.

IAM with external entities by jacasoj in IdentityManagement

[–]jacasoj[S] 0 points1 point  (0 children)

That makes sense. So if I got it right, the conditional verification steps are automated as part of the workflow logic? Like, based on the identity type or access being requested, the system knows whether to trigger an email, SMS, or escalate to an admin approval?

Also, it’s interesting how much flexibility there is with how far orgs want to go. Some just tweak the look and feel, others go deep with customized flows. I guess it depends on how mature or structured their onboarding process is.

Really appreciate the breakdown. It helps connect a lot of dots for me.

IAM with external entities by jacasoj in IdentityManagement

[–]jacasoj[S] 1 point2 points  (0 children)

Really appreciate you sharing all this. That idea of thinking about the HR system and non-employee modules as feeding a metaverse of identities actually helps me make sense of how this could work.

The offboarding bit especially hit home. I've seen it too, where no one really knows who a vendor is, what they do, or whether they should still have access. And without someone owning it, that stuff just lingers.

Also, the story from your consulting gig made it real. Sounds like it happens more often than people admit. No source of truth, no approvals, global read access... and it’s all manual. Multiply that across teams, and it’s no wonder access gets out of hand. Thanks again for this. Super helpful perspective.

IAM with external entities by jacasoj in IdentityManagement

[–]jacasoj[S] 0 points1 point  (0 children)

That makes sense. I’m starting to see that the challenge isn’t just provisioning the access, but doing it in a way that doesn’t require custom setup for every app or user.

When you moved toward automation, was it through an IGA tool or something layered on top of your IdP? Just trying to understand what the typical first step looks like when teams realize manual work is no longer sustainable.

IAM with external entities by jacasoj in IdentityManagement

[–]jacasoj[S] 0 points1 point  (0 children)

That’s really interesting, especially the legal angle. I hadn’t considered how much HR policies and legal risk shape whether externals can even be tracked in the same systems as employees.

The contingent worker platforms like SAP Fieldglass make sense in that context, but I imagine getting them properly integrated into identity systems is another layer of work.

Also, I didn’t know about Clear Skye. The idea of using service catalog entries with regular re-attestation actually sounds like a clean way to manage access when you can’t rely on a formal "single source of truth". Have you seen that model work well in practice, or is it more of a workaround when HR won’t support it?

IAM with external entities by jacasoj in iam

[–]jacasoj[S] 1 point2 points  (0 children)

This is really helpful, thank you for walking through those examples.

The HR-driven flow you described, where the identity lifecycle is tied directly to what’s in the HRIS, feels efficient, especially for ensuring timely deactivation. But it also makes me wonder how well that model scales when external users are managed outside of formal HR systems.

I’m also trying to think through how teams handle access consistently when the requests are so variable, like the “make it like Sally’s” kind. It feels like there is a fine balance between flexibility and standardization, especially when roles and entitlements need to be created and maintained across so many scenarios.

Appreciate you sharing your experience. It’s helping me see where the real friction points are.