Video: Zuma Launch Event | Duration: 5125s | Summary: Zuma Launch Event | Chapters: Welcome and Introduction (0.48s), CEO Welcome (61.4s), 300M ARR Milestone (109.295s), AI Agents and Identity (176.17s), Zuma Platform Announcement (428.3s), Runtime Authorization Gateway (653.8s), Manage and Govern (1251.385s), Team Acknowledgments (1775.045s), Introducing Zuma Platform (1820.085s), Zuma Insights Overview (1949.2s), Access Gateway Protection (2343.29s), Agent Governance Framework (2887.4001s), Shift Left Security (3418.275s), Customer Perspectives (3655.65s), Closing Remarks (4600.065s)
Transcript for "Zuma Launch Event":
Please welcome to the stage Chief Marketing Officer of Saviynt, Kevin Spurway. Good afternoon, everybody. Welcome to the NASDAQ Market Site. To everybody here in the room with us today in Times Square, I want to thank you for being here in person. And to everybody who's joining us out there online across the globe digitally, we're glad you're with us as well. I want to start by thanking our host today, NASDAQ. It's amazing to be standing here in one of the most iconic venues in the financial world. We're honored that you've opened it up for us today. Really appreciate it. So thank you, Nasdaq. I'm Kevin Spirway. I'm the CMO here at Sabiant. And I have the privilege of kicking us off today. I'm going to keep my part short. I don't think anybody here in the audience is actually here to see me, but we've got some amazing stuff to show you today and we're not just going to show it. We've built it so that you can experience it directly. I'm not going to spoil the details, but I'll say this, if you are here expecting to learn about incremental updates, you're in the wrong room. And there's no better person to unveil the new stuff we have than the person who's driven this company's vision from day one. He's our Founder, our CEO. Join me in welcoming to the stage, Sachin Nayar. Thank you. Thank you, Kevin, and welcome all. Sachin Nayar, CEO and Founder with Saviynt. What a great moment. Today's a very important day. So much to announce. It's an important day for enterprises. It's an important day for identity. It's obviously an important day for us. I wanna welcome all our customers, our partners, analysts, and the Sabian team members here and everybody logging in, over live streams. Thank you. So lots to announce, lots to announce. So so we'll we'll go fast. It'll be, it'll be amazing. Alright. Let's start. First and foremost, we just crossed 300,000,000 in ARR. Thank you. Thank you. This is six quarters after we had done the press release for 200,000,000 in ARR. What this demonstrates for us is is that the market and our customers believe in what Saviynt is building and what Saviynt continues to build and how we are servicing our customers and and the value they're getting from our product. Right? This that's what this stands for. The other thing that this stands for for me is this gives us the resources to continue to invest in solving this very critical problem. I have been doing identity now for, what, twenty five years, and I've never been more excited. Right, because now we started Identity with a compliance conversation, then we moved to security, and now we are talking about business enablement. We are talking about AI enablement. No AI workload should be in your production without tackling the identity elements. That's not a next step. That's not phase two. That's today. That's p zero. That's phase one. Right? So with that, let's let's talk about what this 300,000,000 or this this means for us. So in the last year, we've had over 80% year over year growth in terms of the new customer logos that or the new customers choosing us to support them. And we are very honored with this number, Right? Also, that really the reason why Sabian continues to do what we do, and from day one, our focus has been continuous innovation, relentless innovation, and just customer obsession. And anybody who is at Sabian or our customers hopefully continue to see that. Right? That that we never take any of our customers or the work we do for granted, and we are at it every day. And also the problem is evolving and again becoming mission critical. So so just super excited. Today, we'll talk about the first pillar here, which is the innovation. So the biggest thing when we talk about innovation, obviously, is AI and what everybody's doing with AI. The great thing now, everybody is a builder. Right? Everybody in an organization is building. Your obviously, your developers are building, but your business teams are building. Your infrastructure teams are building, and we are incentivizing every business leader to build. Right? That's what you're that's what we are doing as a culture, as a corporate culture. We are incentivizing more token usage. Right? We are we are cheering for teams that are building more AI agents and more AI applications. Right? So you have different, different persona of builders now than what you ever had before. And, obviously, there are there are the agent build platforms that we know, but now every major application is is giving you the ability to build your own agent. Data platforms are giving you the ability to build your own agents. But as we go through this world, what is the role of identity and access in this role? In this in in this, as you move your workloads to production, we've all been testing them for functionality. But like I said, the mission critical element here is as we move these workloads to production, how do you manage the access? And some of our customers, leaders in the industry, already spoken. Right? Identity is the most critical element when you start moving, when you start thinking about AI. This is a quote from Jameel Farsi, who's one of our customers' great friends, CTO of Equifax. Right? So it's unanimous. Right? Agents are new identities. Also, group of agents are new applications, and we have to manage the access that the agent has and the access of these applications, these agentic apps that these agents are building. It's it's multilevel. Same I think we have a Jita here in the audience with us. This is her quote. She's not looking at me, but it's important. That's okay. Again, from UKG, agents are identity is the control plane for agents. And let's let's dive further into it. Right? From a design perspective, we started our journey with Copilot, right, where we are where we are issuing a prompt and the agent is reading data, for us or or executing a workflow. Now we started moving, as we all know, to autonomous agents, then agents to agents. But agents to agents within a single, kind of universe or platform like Microsoft agents, talking to all the Microsoft services or Salesforce agents talking to all the Salesforce services. And now we are talking about agents to agents going across apps, across infrastructure. And agents sitting, being built in AWS Agent Core, accessing Salesforce, accessing Snowflake and Databricks, accessing your game site or your CS. What is the access that that agent will have in all those systems? The moment any of your agents have administrator rights in any of your applications like we used to do with service accounts, game over. That's dead on arrival. Right? Hopefully, we take that away from today. So all of these different and this is this is high level. But all of these different, permutations of agents and and and the progress we are making with agents requires different access, identity and access models to to deal with this. So with all of that today, it's my absolute honor and pleasure to announce what we have been working on, our teams, our partners, our design customers together for over a year and a half. Please, a big round of applause. We are announcing Zuma today. So really excited. Zuma is Saviynt's platform for AI and NHI. For AI agents, co pilots, autonomous agents, agents to agents, all the all the models that I talked about, end to end AI and non human identity security. Why did we choose the name Zuma? Just really quick. Zuma is iconic beach in Los Angeles. As most of you know, we are an LA company, and, and Zuma provides you the ability standing at this beach to to master the the waves and surf the waves of AI, which are not easy. Okay. So let's let's get excited. Now now we also bring the vibe. So, alright, now we are cool. So so just reiterating, now let's go through the different, capabilities that Zoomer provides. First and foremost, discover and remediate, not just discover. We all know agents are everywhere. We are as you work with our design partners, we are going in and discovering thousands of agents and, and non human identities. But but it doesn't end with discovery. It gets into understanding what access these agents have and immediately starting to remediate that. Then we get into protect and enforce. Right? How are we going to be in line and protect the access or the intent of these of these agents. And the third is managing the life cycle and governing this access. And we'll talk about each one of these, in more detail. So let's keep going. So now from an access perspective, before I move forward in describing the capabilities, I want to reiterate that Zuma has been built ground up by the Sabian team. It is purpose built to treat AI and NHI as first class citizens. What it means is the scale of AI, which we are talking about 100 to one compared to humans, the nondeterministic nature of that, all of those, it's the same principles or version of those principles as the foundation, but how are you going to build a system that scales and the speed of AI? Right? Because we have no time to detect things. We have no time to cure. Right? It all has to be moved left. It all has to be preventative. Right? So so all of those concepts have been taken into account, and this has been built by our teams ground up. Right? So that's a very important point to understand. We're not trying to fit a a different solution. This is this is all purpose built for this for for this moment. And it's all, a single unified platform. That means all the capabilities of detect, protect oh, sorry, discover and protect and manage all within one platform, but also tied to your human identity management. So you have full context of humans because AI and humans are connected. Right? So, so how do you get that context, which is critical to solve this problem? Alright. Moving on. Let's let's get into discovery. So very excited to announce, again, part of Zuma end to end posture management for AI and NHI. As part of that, when we talk about what we have been doing is building a very comprehensive ecosystem of partners across all the layers. You have the major, cloud providers, AWS, Google, Microsoft. You have the data providers, Databricks, Snowflake. You have the major security vendors here, Zscaler, CrowdStrike, Wiz, Sayara, that we have built deep integrations and partnerships over the last year, year or year and a half. Right? So so all of these, products or vendors are providing them providing us the signals, plus we have direct connectors that, you know, that has been Sabian's history and we have reimagined those connectors to work it and and introduce a new integration framework to again work at AI scale and the resiliency of AI and non human identities. And you can see all the different systems where where you are building your agents, where you're, from coding platforms, again, to infra platforms that are all all integrated. So excited. So now on top of this very extensive, integration ecosystem, I'm also excited to announce a few things. Now we also start going into shadow AI detection. Again, so with the shadow AI, I'm really excited to announce that Savant is now launching our own native web agent. It's optional, but this is where we start detecting what your what a lot of the agents that, that you cannot pull from the app layer. Right? Then we have deep integration with Zscaler to look at what shows up on the network and start pulling that in. Third is deep integration with CrowdStrike and WIS to start pulling up words on the endpoint layer that we can we can we can pull that into the system. So huge in terms of to make sure that we have the full inventory of your agents is very, very critical. And then when we have the inventory of agents, we're excited to announce our access graph, which is, infinitely expandable or scalable. And and in here, what we are doing and you'll see this in action after when when Vibhuti speaks today. We are talking about connecting humans. For me, that's critical to agents, then to nonhuman identities, the high level access, the coarse screen access, but then going to the permission level detail because that's the level this is this is a very important point. The permission level detail is something we have all, we have not we haven't been paying attention to it from because it hasn't been required from a human identity management perspective. Right? Because we control the access at the menu level or the code screen level, but agents operate directly through MCP servers or APIs, so their access is controlled directly at that permission level. So pulling in that permission into Saviynt, that permission level data into Saviynt and showing that on the access graph, tie it with usage and then tie it with alerts that we find and we'll show you our alerting language and how we are talking about alerts, the remediations and the risk associated with it, all within a single graph and all available, which is all actionable. Very excited. Very, very excited to announce this today. Okay. Moving on from, from discovery. Now let's talk about protect and enforce. So in here, today, major announcement from Saviynt, we are launching our runtime authorization access gateway. Right? This this is well, let's talk more about it. Okay? A very exciting very exciting, very exciting piece of innovation, core infrastructure for customers. This is a run time access authorization gateway, which is intent aware. So what that means is at design time, so this is an agent gateway that is sitting between the agent and the end applications, and it is intent aware. So at design time, when you put in why you created the agent, and and it is making sure that your purpose of the agent is is not being deviated with the actions of the agent. And then run time, when the prompts go in, what is again, same, same intent that the agent is following its intent because agents are biased for action. Right? They are biased for action. We we did a review internally where we asked, an agent to give us certain meetings, you know, what what are my meeting schedule for the next week, and we actually removed its access to the calendar. And the agent called another agent and and scanned our emails to find our meetings. Right? Agents are biased for action. They are not biased to stay within their lane for security purposes. So this intent and then how they are achieving that intent is very important. The second piece that this gateway is aware of is behavior. We are tracking the behavior of each and every agent and every non human identity. And again, the context back to humans, both from a volume perspective and a drift from your normal activities. And then you can obviously, create policies which again, have access to the entire Saviynt identity warehouse, ownership, again, the human context. So the policies are much richer versus just having the data in this session. And now let's go deeper into the intelligence. I'm really excited to announce some, you know, a lot of work our teams have been doing. We have Saviynt has now trained our own AI models for this purpose of the gateway. That's huge. Thank you. That deserves an applause. That's that's real depth in, in AI data science. These models, as we have tested them, are 100 x faster, 10 x cheaper, and are available for any sovereign cloud, which is critical to so many customers. Right? So so lots of work gone in here and and similar models are being built for all parts of identity as we move forward. Talk about, the deployment architecture for this. Like I mentioned, this gateway So first, it can this gateway can be stand alone or you can hook up our service. It's also available as a service that can be connected to any of your other gateways. Right? So, so don't get, caught up in the word gateway. That's just our way to explain that it is real time and, and interjecting the requests. Right? So now it is connecting to your MCP, servers or your API, which is then connecting to your target systems. Let's let's go into the details of how amazing what a paradigm shift it is as we move forward. First and foremost, as developers are building these, agents and applications, we do not want tokens, secrets, as well as entitlements to be embedded in the code. Right? As an identity leader, as a CISO CIO, this has to be the paradigm that we want identity controls to shift left, but we do not want them embedded by every developer. We have an opportunity with AI to do it right. Actually, we don't have an we don't have an option. We have to do it right because the the back end is not possible. Right? So so remove the credentials from these agents and these applications and manage them centrally in a standardized manner. Also so this will save time. Obviously, it's secure. But now think about and and manage them centrally, which can also be federated by department. So what that means is if somebody in treasury has 500 new agents or applications being launched, how does the treasury leader understand what those agents are and what is the access that their team has or the rest of the business has to those to that data. And by the way, this is financial data. Right? So now we can give the treasury leader one interface to manage all access or policies across all their agents and applications. Right? And same across the board, marketing, finance, etcetera. So so manage it centrally, but in a federated business model or or with one of your, subsidiaries. Right? And then all access is just in time. No standing privileges for agents. Right? Very, very critical. Right? Do not think, oh, this is just a nonhuman identity. Like, we have always been doing service accounts. It's a whole different ballgame. Right? Service accounts are predictable. We ask them to do something, they would only do that. Right? They didn't make decisions, dynamic decisions. We know the difference. But we cannot do the same paradigm that we did earlier. Right? It has to be just in time and in many cases, that access has to be appropriate to the request, at least to the design time intent of the agent, hopefully, the run time intent of the agent. For some of the applications, we can actually go to the run time intent of the agent where we know the schema or the structure of the application. Right? So very, very critical. And what is so, interesting about or a big differentiator with Sabian's gateway is we are reviewing every call, every hop of this agent. So when when one agent calls the other or whatever its its path is, we are in the middle of every hop. What it makes sure is there is no intent deviation or behavior anomaly at any one of the steps. Right? So it's it's end to end. So to achieve something like this, obviously, scale, design, availability becomes critical, right? So this has been this for Saviynt has been created by a team that has built similar solutions of this quality and criticality for one of the major cloud providers. We were excited to bring that team to Saviynt and and this team has now we have tested this already, ourselves and with our design partners, 50,000,000 plus identities at a single customer. This is per tenant. We're talking about 5,000 requests per second and this number is growing every day. We are talking about consistent performance under any workload and we are talking about four nines availability and we are working towards five nines as we speak, because we understand the criticality of this, right. We this is a whole new stack and a whole new product from Sabian. Thank you. Very, very exciting. And this part, this piece of infrastructure, this intelligent and resilient, scalable piece of infrastructure will become the backbone of all AI access security because this is now feeding directly at run time from your identity warehouse, from your governance, and then feeding back all the usage to your posture management. Right? Everything is connected. Okay. Moving on. Next, we talk about Saviynt Manage and Govern. Right? So in this, this is the third this is the third leg of this tool and we are offering end to end, again, life cycle management and governance. Let's talk about that. So the pieces of life cycle management governance. Number one, registry. Obviously, we all understand that's a must have. We need to know where our agents are. We talked about that with discovery. What is the access? The next very critical one is owners. Ownership, if you have agents in your organization that do not have an owner, a human owner assigned to them, we have a problem. Right? Because this is the bridge where we bridge the agents to the humans. Right? That's that's where it all starts. And now we can have a human accountable for the agent. Now we're not saying to review every action, we'll talk about this. The third is agent action certification, and Saviynt has launched a whole new paradigm on access certification that we'll talk about shortly. And fourth is bringing the cost and the tokens to the business. This is a very, very critical point. Right? Now remember, everybody in the organization logs into Saviynt for access, request, logs into Saviynt for access certifications. Right now, we all are struggling. We are all struggling with the token and the cost of AI, but we are making it an, IT problem. We have made a problem of the infrastructure teams like we did with cloud costs. We need to bubble this up to the business unit owners and tie it to their apps and to their business and and help them make decisions. You know, once you show this this data to the business unit leaders to say, oh, you have so many different agents. This is the function of each agent. But because so far, we've been incentivizing companies or or each other to build more agents. Now we are gonna get into the world where we want to bring efficiency to this process, method to the madness. Right? We've all learned. We've all played with these things. Now we have to operationalize this. And part of operationalizing these is to provide visibility of these agents and the associated costs, the models underneath, just high level. Why is something costing me so much because it's running on the highest level of model, which is not required. And IT doesn't need to make these decisions. We move these decisions to the business. Let the business make the decisions. It's a very critical part of governance. Obviously, our design customers, back to Equifax are clear. No owner There cannot be any agent without an owner. Moving forward, the certification paradigm shift. So what Savant will show you today, we're excited to launch this new a whole new many of our customers we've spoken to are saying, what is the what what about why are you talking about access certification and agents? Obviously, we have to talk about access certification and agents, but but and not the way we have been doing it all along. It's a whole different paradigm. So we have created a certification agent. Again, one of our own trained models that is trained for this purpose only that is reviewing every agent action. Right? So it's actually more secure. It's it's us shifting the controls to the left again. Right? It's not batch. It's not once a quarter or once a year. It's it's all the time. It's continuous. And then we still want the humans, the business leaders to be accountable for their agents so they review the inventory, the business purpose, the cost, and the point 001% deviations that the agent would have that was not blocked. Right? That they would that they would review, and that's that's the model. And all of this is, is now we are bringing true true security to the certification cycle, and all of this will be audit and compliance ready. So very, very excited about this. Also as we talk about governance for all of our existing customers, right, who are who've been working with Sabian for many years, We've also done a lot of work with AI. Over 90 of our customers today are on Saviynt's AI enabled platform. We are talking about onboarding applications in hours. Many of our customers are already seeing the results from these. Right? We're not talking about days and weeks. We're talking about hours onboarding all your apps within Saviynt in hours. We're talking about autonomous roles and not talking about building, the hard hard core, static roles that we've all been working on. That that world is over, with AI. Now we're talking about intelligent workflows and segregation of duty rules where we are suggesting to you what segregation of duty rules go in into, a new application that's onboarded, and we talked about the continuous cert. And to make all of that available to the customers, we have also launched an LLM based migration, an intelligent migration capability for customers wherever you are in your with your identity solutions or your privileged access management solutions or your application GRC solutions or now with your authorization solutions, all of that can be migrated into Sabian at one fourth the time, one fourth or one third the cost using intelligent capabilities that we built and all of this is being run, including the migration utilities by our engineering team. So we are learning from every customer. Very important. Okay. Now we talked a lot. What does it mean for our existing customers and what does it mean to new customers? We've kept it very simple, because this is a problem we all need to solve today. So for our existing customers, you'll be very excited to know that you already have access to all Zuma capabilities. All you have to do is work with us, and if you need more identities, Zuma identities, you just need to buy Zuma identities. And for some of your AI transactions, there is a credit system so you only pay for your consumption because most of us don't know how many AI agents we are gonna have or how many nonhuman identities we are gonna have or which ones of those we want to govern. So just pay for what you're using. You if you are a Savant, customer already, you you bought into this into Savant's idea of having a platform to support all identity types. And and we are true to that. So start using this today. All you need to do is add Zuma identities and, and some credits for our, for your, kind of AI AI utilization as per your AI utilization. And for any new customer looking at us today or our partners, we can start with Zuma only. Use Sabian. If there is a AI, NHI problem to be solved, Zuma is stand alone. It integrates with our a bigger platform, but it can be utilized stand alone. So so wherever you are in your identity journey, whatever identity products you're using, Xooma can integrate with that. So you do not need to replace your entire identity stack with Sabian to start using Xooma. That's that's our thought process. And if you are in that category where you start so obviously, we are already working with our customers, existing customers who are beginning who are already seeing value with the agentic identity platform, as well as the new AI, NHI. So again, big thanks to all the all the customers and design partners. And and Zuma has been designed to meet again, it's enterprise grade, but the value is day one because this is the new paradigm of identity. Right? Start today. Discover your agents and NHI today. Plug it into your existing security framework with with your network security, your endpoint security, and direct connectors from Sabiant. If you're already a Sabiant platform user, we will pull data from there, see value today, see, immediate, start remediating and managing immediately and then as you go down your journey, you should know that you're working with the company that supports all identity types. So if you want to expand it further, no problem. Okay. So with that oh, start surfing today. Alright. So before I end my session and my cool glasses, these are Savantella glasses, by the way, I want to thank our amazing engineering teams, product teams who have been working around the clock to make this happen. One big round of applause for that, for our team, please. Thank you. I also want to thank our amazing marketing team that put this event together. Thank you. And again, all of our customers and partners. So big, big thank you to everybody. Alright. Next up, it's my absolute honor to bring the person who's who's the thought process behind all of this on stage, my honor to introduce our chief product officer, Vibhuti Sinha. Good afternoon, everybody. Thank you, Sachin. Sachin just introduced the word Zuma, the product, the platform with many many teams at Sabiant have been living, breathing for the last several quarters. And for the next forty five minutes, I'm gonna show you what's behind this name. During my tenure at Sabiant, I have shipped many products and I don't say this lightly. This is the proudest moment for me for two reasons. Number one, the problem what Zuma is solving, every enterprise on this planet is struggling with what Zuma brings to the table. And the second one is the team, the design partners and the customers who have helped us in this journey to build and conceptualize the vision and also realize this vision of Zuma. Let's dive in. Every organization on this planet have now created new identities, which means these are the new agents, these are the new NHIs being created. The challenge with every enterprise is struggling with is where are these agents, how many of them do I have, who are the owners behind these agents, and who should I call if they get role. In fact, if I have to sum it up, these are the six challenges every enterprises are struggling with. Number one, what's my sprawl looking like? What's the exposure do I have? How do I contain the blast radius? What's the shadowy problem I have to deal with? Secondly, the owners behind these agents and what are they doing with that access? Another set of problems they are dealing with is when we look at these agents in totality, can I control them and what they are doing at runtime? Sachin did explain to you about Zuma Protect. We'll talk in detail about that. How do I ensure that all these agents are not violating my Zero Trust principles? So when we looked at all these six questions, this is exactly what Zuma brings to the table. Starting from discovering to protecting to managing these agents on a day to day basis, what every agent which is getting created right from the way and the day they are born to the time when they are getting terminated in your ecosystem. Let's start with the first pillar, which is discover pillar. Security programs, there's an old adage in the security world that you can't govern what you can't see. And this is exactly what Zuma Insights bring to the table. If you look at a lot of the enterprises, they are struggling with what and where my sprawl of AI systems looks like. Zuma solves this by few of the other aspects. But before I go to the aspects of Zuma Insights, also let's take a look at some of the stats and facts. You all keep hearing the numbers. One day it was 83 is to one, then it became 100 is to one. Today it's 144 is to one. I'm pretty sure these numbers will keep on growing. These are the numbers you have today. These are not future looking numbers. 95% of organizations are still reporting gaps with respect to the agent governance. How is Zuma Insights helping you with all this? Number one, it starts with giving you a comprehensive visibility. Every agent, MCP server, tool, secrets, keys, the moment they appear in your environment, Zuma gives you a visibility on that because we want you to know what's exploitable in your ecosystem. And the way if you understand what's exploitable is how you can predict what your blast radius is going to look like and how can you contain that damage. And of course, once you know about your blast radius to contain it, we give you enough levers, which allows you to terminate or kill these agents. Can you scratch that word kill? I was told by Madeline Marketing team not to use that word, but termination of the agencies is something which you can do it instantly. But we also realize that the challenge of shared shadow AI is absolutely real. And that's why we are solving it natively and we are also leveraging or empowering organizations to leverage their existing investments with Wizz, CrowdStrike and Zscaler to collect those signals as well. Let's take a look at how this all looks like in the actual reality. It all starts with a compendious view of your identities, be it human, non human or agents. And the first thing what we do is we build a complete catalog of all your agents, MCP servers and tools coming into the ecosystem. From here on, you also start building a catalog of all your non human identities, be it your access keys, secrets, credentials, OAuth tokens coming in from your cloud platforms, coming in from your on premise systems. And from thereon, we start giving you a very easy and nice view of telling where your risks or findings are. For example, how many of your agents have static credentials? How many of your agents do not have guardrails exposed or being enforced at runtime? Similarly, when you look at non human identities, how many of them have long lived credentials sitting in your active directory? But most importantly, we also let you define the policies what are driving these findings. If you have agents, which can pose data exfiltration risk, that's a big driver for your chief data officer to understand and start remediating on. Similarly, any agents which have been created using maker credentials, that's a big delegation issue. Same thing goes with non human identities. And last but not the least, we also understand that you can create your own policies to start looking and creating your own data patterns to find or start finding anomalies in your ecosystem. Now think of this as a starting point for your analyst. Now where we go from here is letting you define much more advanced insights by looking at, as Sachin rightly mentioned, an infinitely expandable access graph. The way to understand this graph is any agents always have an inbound access and an outbound access pattern. Inbound access represents all the humans' applications which can invoke this agent versus outbound access is showing you what agents, sub agents, tools and CP servers this agent can go to. And if you notice here, the mode of Saviynt here is that it can really go fine grained into the level of details what you can. The question which gets often asked to me is that you have given me an infinitely expandable graph, like, do I keep clicking on one note to another and it's just it's just a lot of overhead for me. Well, the answer is an MCP layer on top of this graph. What you are now seeing is a way and I would I am again very proud to say that this is industry's first MCP layered graph, which you can talk paint in real time asking what. Thank you. So what I just did is I let the graph get painted for the exact security findings what you want in your ecosystem and your analyst, your people who are investigating these breaches can really pinpoint what and where the issues are. More importantly, what we have also done is, this is not just a visual layer through which you are looking at issues. This also serves as your orchestration fleet. So as you can see, from here on itself, an analyst can take remedial or remediation actions. You can register your tools, you can configure guardrails. In fact, you can also route an ITSM ticket if it has to be created. Further, what also this allows an organization to do is create policies or suggest policy recommendations. Many of you who are in the identity industry know or understand the overhead of managing policies. It's not an easy thing to do. And Zuma, by looking at all the access patterns, all the insights what we are gathering, it can suggest that these are the policies what you can create. This is the future of how you should be interacting with an identity graph and MCP layer and talking and infinitely expanding is the way to go, which our team have created. Thank you. Alright. Now you found what the risks you have in your environment. The reality is that your developers or builders are not going to stop. They will continue to build new agents. The question then becomes, how do you ensure that the newly created agents, you do not introduce more risk in those? And how do you also ensure that all the existing agents, you're understanding if they are creating any more exposure or any more risk in your ecosystem? And that's where we go into the protect layer, with Zoom access. Let's start by some stats and facts again. 70% of the organizations say that their service accounts, their AI agents have more access as compared to the human counterpart. I think this is quite obvious we are seeing this across the board. In fact, 67% of the organizations are still running on static standing credentials, which is one of the reasons why it is so front and center on our Zuma Insights dashboard as well. The good part is that the industry have solved some of these problems. If you look at the attack surface, the content and routing problems of AI has already been solved. You will hear a lot about I do have a solution to protect my prompts. I do have a solution on how am I preventing my agents to get jailbroken. How am I solving for routing connectivity. These problems have been solved for. What is not answered for yet is the agent deviating from its goal. This is a very, very important problem what we are trying to solve. Authorization is not the same as appropriateness. That's what the intent deviation checks are for. Can you prove that this is a thing what this agent really did? Because these are not AI problems, these are identity problems. In fact, if you take a look at what has been solved so far and we call it as the three attack surface problem. You have vendors who build or who have been shipping content security gateways and this is the set of gateways which solves the prompt injection, the data leaks problem. Similarly, you have the NCP and LLM routing gateways solving the routing problems. Where Saviynt now comes in is to solve the identity problem and that is what the access gateway functionality is all about. Let's take a look at what else are we doing. As Sachin explained that there are three things in the access gateway, let me tell you a little more details on what is happening. Intent deviation, this is the hardest problem. This is an evolving problem in AI security. It all tells you that if an agent is doing something, was it really meant to do that? And we are doing these checks at two times. One, when the agent is getting registered versus when the agent is actually performing that transaction. The second one is all about policy enforcement, dynamic governance policies. If you have and as an organization, you have a policy that any agent like you heard from Equifax CTO, that anytime an agent does not have an owner, they should always be blocked. There should no transaction been happening. That is what you can prevent from governance policies or using the agents' metadata. But we also empower organizations to do runtime policies, which are completely built using rego language and evaluated using open policy agents or OPA, which we truly believe that developers love. So you can do SOD checks, you can do just in time access as part of our policy enforcement engine. And the last one is the behavioral anomaly detection. If an agent decides to download 5,000 files because a terminated employee is trying to extract documents, we can detect and prevent that from happening. Some more information about intent aware and time authorization. I actually want you all to try this. I have said it to few people earlier the day. Go to your favorite agent, try writing some fuzzy prompts, go ahead and optimize my Google Drive files. Go ahead and and get the best possible compensation information about my employee and you would be surprised to see the data what you're going to get. An intent aware runtime authorization gateway exactly prevents you from doing such things. If the agent is trying to learn something and Sachin rightly mentioned that they are biased to give you some results, if they try to deviate from their intent and intent aware gateway prevents such catastrophic results to happen. Let me also explain a little more on why this is important. If you look at all the identities which were solved even today or till date, we used to have static access given to them, which means for human identity has been given access, the human identity will always work in that scope, in that boundary. With agents, we have to check that scope, that boundary every time when that call is happening because it can learn, it can adapt and it can deviate. That's what intent aware runtime authorization brings to the table. The question is, why do we think we are the best when we can do this? Saviynt's moat has always been about doing fine grained authorization. We have more than three decades of experience building, finding and authorization for your ERP, your CRM systems. That's what is powering the whole intent aware runtime authorization gateway. Very, very important point. No vendor on this planet can understand the level of security of SAP. Thanks to Vineeth, who is sitting there in the back, who has built this for the last ten years. Only we can do and handle the security of SAP at the level what we do. And that's the same model we are powering out with our gateway. The second one, Sachin did mention about the pre trained models, 100 times faster, 10 times cheaper. And the thing what we also do is we handle intent both at design and runtime. So let's take a look at some of the stats. I think we already explained. It is meant to handle the enterprise requirements and we are very, very cognizant about the resilience and also understand the readiness for volume, which we are going to get into. So these are some of the numbers, which again we are absolutely, absolutely proud of what the team has delivered here. Let's take a look at what this looks into reality. An analyst who is trying to understand tell me all the transactions which has been blocked for a platform like GitHub. So they can very easily again go to that same interface which I was showing you, And it can give them a very neat understanding of why the particular transactions has been blocked. But most importantly, when you're looking for intent deviations, what you're seeing on the screen is it is showing you that a particular agent went to a particular sub agent or tried to access a particular transaction on an enterprise application. It shows the deviation on why it has been deviated, where exactly the agent tried to do a tool call which it was not supposed to and then very easily the analyst can start taking corrective actions on it. For example, I can say that this particular deviation is something which should be there in the platform and I'm going to rewrite or redefine my policies. So you can orchestrate. You can ensure that these are not flagged as false positives or if you if it requires the the policy definitions to be changed, you can easily do that too. So now let's take a look at, if I really have to update the policy, what do I and how do I do that? It all goes down to looking at or understanding what a policy boundary is. What you are seeing here is the list of gateways sitting in your platform and it allows you to start defining and changing your policy modeling as well. A policy boundary allows you to figure out all the three aspects of gateway. One, checking your run time authorization, and you can put that into different modes. You can always have a run time intent deviation checks to be done in a monitor mode and you can just understand the patterns of your data access when it begins or when it starts in your organization. The second part here is how do you create these policies in a very easy and developer friendly language. What you see here is our policy builder allows developers to build policies in rego language and all of this gets evaluated through an open policy agent behind the scenes. This gives the power, this gives the fine grained visibility as well as creation of these policies. You can really, really go and create some policies which can really understand your business models and you can customize or extend it at any level of details. And then the last one, what you can also do is you can control what level of behavioral and threat anomaly detection what you want to do in case of volumetric checks or in case of behavioral checks. So this was all about the second tier, which was the protect layer. Now you have defined or understood what the risk you have in your ecosystem. You are also trying to protect what the risk you have and not introducing new risk in your ecosystem. The third layer is all about you have your agents on a day to day basis, how do you manage? How do you ensure that you are managing every aspects of that agent's life cycle? Let's take a look at it. Again, some stats and facts here. 40% of the accounts have outlook, the owners who actually created. This is a stark reality. 84% of the organizations, they are telling that they cannot effectively govern the agent's access. So where does it all starts for? What we our mantra when we start building the management layer is that you have to register, you have to own, and you have to track. Every agent regardless track every agent regardless of any and no exceptions in this case. It all starts with an agent registry process, which you can embed into different aspects of your overall platform, no matter whether they are being scanned or whether they are being created in real time. No matter whether they are being scanned or whether they are being created in real time. And from there on, you start the first process, which is assigning the ownership aspects. Now Zuma intelligently can detect if you have agents with no owners. It flags them as orphan agents and it can also start assigning or give you ownership recommendations. Ownership is a very, very important aspect because this is your starting point for governance. If you do not have owners, you are missing the complete point of governing that. In fact, if you look at majority of the agent building platforms do not have the concept of ownership. This is a huge problem in the AI security world and that's why we stress so much on this. The second aspect of tracking is an agent goes through many changes in its entire lifetime. So we are keeping a non reputable format and a reduced track of anything and everything which has happened to an agent right from the day they were created to all the way when they were terminated. And this becomes your record to meet your audit and compliance needs. Again, something which serves as a huge, huge value proposition to our customers. Let's take a look at this. You can always look at all the orphan agents, which Zuma tracks and from here on, you can start looking at which are the agents, which requires the ownership assignments to be done, which can be based on rules, which can be based on intelligent recommendations, which can be done based on the agents' metadata. And as you are seeing here, there are two concepts of owners what Saviynt is applying here. One is a business owner and the other one is a technology owner. A business owner are the people who are defining what's the goal, what's the objective of these agents are going to be. Technology owners are the ones who are actually implementing or building these. And you can, of course, have a lot of rankings to be done. The last part in this case is a timeline view. Again, as I said, business owners and technical owners are the two parts of it. And then from there on, we start looking at the timeline of your agents. Any and every aspect of your agent, identity changes, ownership changes, guardrails getting removed, everything getting stitched neatly for you to start looking at it, investigate if you have to fix anything or lastly, look at as your audit and compliance records as well. All right. So that was the first part of governance. The second part, as Sachin mentioned about the future of certifications, the new paradigm of governance control, let's talk about trust. See, what will happen is that as you will have many more agents coming up, what are you going to look for in an agent to start governing them effectively? And our answer to that is having a continuously verifiable trust score, which can be assigned to each and every agent. How do you do that? What we are saying is that all the different aspects of services which can share the context, whether they are agent lifecycle or ownership information or it is coming in from our gateway regarding the runtime authorization, posture's data, NHI credentials being used, all of these will serve as signals going and allowing us to build a continuously agent trust score, which can be verified at any given point of time. And that trust score again, going back into your services like certifications, insights, access requests, consuming that and making intelligent decisions. This is the future of governance and we want to call it as a runtime governance paradigm shift. Let's take a look at how this will change, how separation of duties and certifications will be done in future. Today, if you look at separation of duties, you look at one identity, you define what kind of toxic combinations that identity has and that's about it. In future, what we are saying is that in agents, this is not going to work. In agents, for you to calculate the effective access, for you to understand the separation of duty checks, you have to look at all the different tools what the agent is accessing. Who is the user who is trying to access or invoke that agent, the access of that user, who is the owner of that agent, as well as the complete tool chain. All of that have to be factored in continuously at every agentic transaction to figure out if there are any SOD conflicts. That is the future of SOD. The second one is certification. I think everybody in the room here understands how certifications are done. Once a quarter, people just go and say select all, certified rubber stamping, it's rampant everywhere. That's not how agent certifications would be done. What we are saying is that an agent, you are not going to certify the access, you're going to certify their trust. And the trust is something which is evolving continuously, which means we look for intent deviation, we look for anomalous behavior, we look for tool paths and that's how it is calculated. Let's take a look at how this will look in real life. It all starts with, we understand that to do all these governance checks, it can't be done with a human in the loop. So what we have done is we have created agents who is going to do this on human's behalf. We are calling it as reviewer agents. It could be supervised, it could be delegated depending on the level of autonomy, which you are going to give to these agents. And these are completely trained on the data, on the models, what we have built in house. The important part here is to understand that these agents are going to look or think of them as governance agents or certified agents. These agents are going to look for all your agents sitting in your environment and continuously reviewing what is happening in this ecosystem. At the top, what you see here is an agent which just got flagged and it came into this list. It's called the Deploy BlockBot agent. It has a TrustScore of 74. Supervise agent is looking at what do I do about this? Is it violating any principles and based on the review it is doing, it flagged and said that this agent is good to go. But there will be certain agents where a supervisor agent or a certified agent cannot figure out what to do about it because it the trust score is moderate. It is not able to make a decision. Only for such agents, a human in the loop would be required. This is a very important distinction to understand because when you are dealing with the volumes with which we are going to handle this, having a human in the loop performing certification will not scale and that's what we are trying to explain here. What exactly I'm reviewing here is the drift which we observed. So our gateway figured out that this agent is trying to do something which it was not intended to. In this particular case, it's trying to, do a delete object on s three, which was never a permission given to this agent. So it is flagging that as a risk. And once it comes as a risk, you can look for all the different trust signals. You can look at what's the drift here, in terms of permissions. If there is any drift with respect to credentials. So all what we are saying is that once you combine all these signals, that's what formulates the trust score of an agent and depending on whether it could be reviewed by an agent automatically or it could be a human in the loop doing this. This is the future of agent certification where customers can really hand over the platforms like Zuma to go ahead, look at their agent, look at the agent deviations continuously, and it starts understanding and flagging where you have what kind of risk and also ensure that you meet governance not as an afterthought, but which is something embedded in your overall workflow. Alright. So this was the third, pillar. And from here, I would also like to say that I don't think in this era, any vendor can claim that I'm going to secure your entire agentic architecture, your applications and data on my own. And that's why we truly believe that all the partnerships, the investments we are doing to secure our partnerships with the hypervisors, with agent development platforms, data platforms becomes extremely imperative because only when you combine the identity and security or cybersecurity context, that's when you can have a true agentic architecture coming in play. The last segment of this, of my talk track here is also going to be Sachin did mention a point about shifting identity controls to Lyft. What does that really mean? What we are saying is that today, when you have developers or builders building agents, we are saying or our mantra is that we want them to secure agents the moment they start building the agents and not as an afterthought. What does that really mean? It means that when you are creating or writing a piece of code, we want to start flagging where exactly and what exactly the issues you are introducing when you are writing that piece of code, which means anytime when Saviynt is introduced or embedded into your building platforms, we ensure that the agents entry gets created. We ensure that you are using scope permissions and any kind of high privilege API calls are flagged even before you start introducing them into the system. So rather than these checks being determined once the agent is live in production, this is happening when the developer or builders are coding this into your actual ecosystem. Let's take a look at how this looks like. On the left hand side, you will find a developer writing a piece of code. But what we have done with our SDK embedded and this is Cursor, for example, that a developer can immediately start registering the agent onto Sabian's platform, as well as if the developer wants to gain access into Salesforce with this agent, what they are doing is they are calling all the relevant Salesforce permissions, not going into an identity tool, but right from cursor, which reduces friction for these developers, which is a huge, huge value add for developers because it increases the pace at which they can develop. And secondly, they're also ensured that they do not or should not be getting any more access onto Salesforce versus everything is tunneled through Saviynt's SDK, which is nothing but a runtime authorization layer in the backend. So this is something what we are really pumped and excited about because this will truly change how identity has or will be taught, especially when you look at the developer ecosystem. We are saying that identity controls are now going to be shifting left and developers don't have to think about identity and access management as an afterthought. This is the list of native integrations what we are building starting with Cursor, Lan Qing as the two big platforms what we are integrating with. And again, as this ecosystem evolves, we are also ensuring that Sabian's SDK, Sabian's shift lift controls keep getting embedded in every developer platform as we speak here. I hope this gives you all a good sneak peek of what we are building with Zuma. I want to end my presentation by saying that we truly believe that Zuma is the most advanced identity security platform to secure and govern your AI workloads, your AI agents, and we are just getting started. So with that, it's a wrap from my side. I hope this was useful all the time. Thank you. Now you all saw the product. You all heard the vision. Now it's time to understand the reality of how this is impacting customers in the real world. For this, I would like to invite, Sabian's Head of Customer and Product Marketing, Nupur Goel, to talk and share the details with our real customers in this. Thank you. We spent last one hour unveiling and pulling the curtain back on Sabian's latest innovation, Zuma, the enterprise AI identity security platform. And the energy in this room and online is electric. Sachin talked about our vision, why we build Zooma, what capabilities does it have. We would be talked about how it can help you. But we all know vision only matters if it can survive the reality of enterprise production environment. To bridge the gap between innovation and implementation, I'm thrilled to be joined by two leaders who are not just looking at the AI revolution, but are architecting it within their own organization. With that, please join me in welcoming Vineeth Gupta from HP and from UKG, Ajita Chaudhry. It just came off. That's okay. You're gonna grab this. In the pocket. That's totally fine. Do you wanna sit here? I think I was told to sit here. Perfect. Whatever works. So, Ajita and Vineeth, let me start by saying thank you so much for joining us today. Why don't we quickly start? Can you tell a little bit about yourself and your role? Sure. I work for HP, the the printer and the PC group, not the HPE. I just want to make it here. I'm based out of Palo Alto. I am part of cybersecurity organization, manage identities, data, and other stuff. Ajita? Ajita Chaudhry. I work at a company called UKG. Kronos, Priory, and Ultimate Software merged in 2020, and now it's UKG. And we service frontline workers primarily and do payrolls as a management company. And I manage identity and security engineering at UKG. Thank you, Ajita, for joining us. Thank you, Vineeth, for joining us. Let's talk about agentic AI, agentic identities. As teams rapidly deploy agents, how are you preventing agents' fraud? And what risk do you see emerging as these agents gain access to your data, applications, and business processes? So Why don't you start? Okay. I can go first. Traditionally, when you think about identity, it's either human identity or a non human identity, and they were finally defined. You know exactly what they were going to do at any given point of time. When you start thinking about AI identities or agentic identities, they're autonomous. They make decisions and execute them at a speed that we haven't seen before or accounted for before. And the risks on those accumulate a cumulative risks. And what we have been trying to do or how we are thinking about it is, of course, as Savant is thinking about it as well as visibility and ownership and bringing governance to run time. So same alignings seem very similarly to how Savant is doing governance around AI. That's how we we are approaching as well. What about you, Vineeth? Yeah. So add to what, Rita is saying. We are doing couple of other things as well. For us, one of the big things was rolling out a very comprehensive cybersecurity policy that's based on cis8.one. You guys can go read it out. Because we felt that unless we educate people, what does this word governance mean, what does it mean, about, agent security and so on, I think we had to educate people first. Because in in minds of people, I think people are a little humans are very trusting by nature. Right? So you have to tell them this can happen, and these are the policies and so on, and you have to add it to the so that's one of the things we have done. And then like Aditiya said, couple of other things we are doing very, very quickly. One is discovery because I think, you were talking about it. Right? If you don't know what is there in the ecosystem, you can't protect yourself against it. Right? So the discovery part of it has been key. The second part of it is, call it, visibility or observability. We want to see exactly what that agent is doing. Once we see our the thought process I have is once I see what it is doing, I can put more governance and controls on it. Because I think we are running against, an interesting thing. Cybersecurity as a function cannot be a blocker. It needs to be enabler. And and that's where the friction it's becoming a little bit more of a friction right now. I'm sure all of you have seen it, but we don't want to be that. So so that's what we are doing. That's a very good point because you cannot treat agents as workloads anymore. You got to start treating them as first class identities. And you got to see them first. Unless and until you know what exists, you cannot go on them. So we heard Pibhuti talked about gateway, three kind of gateway. How are you dealing with this? Have you employed or deployed any of your day plate any of the agent gateway so far? So we have looked at one of your gateways, definitely, access gateways. Very, very, I mean, great potential because what it can do is from a single pane of glass, I can actually put governance. And, and that was important because, again, I think all of you have the same we don't have hundreds of humans on our teams who have who are out there to do some coding and looking at it, the whole whole nine yards. Right? So so some tools like that, which can sort of do a broad based control on a single pane of glass, I think that helps. So we have looked at that too. We have actually been providing a lot of feedback to his team as well as in what we think can be done. But it's a it's a great start, I think. I I really enjoy how how much feedback you give us. You keep on challenging our road map. You make sure that our product is not just talking about theoretical risk. It's actually, you know, solving the real world problems. Anita, you have also been our design partners. I would love to hear your thoughts on this. So as always, we've been design partners with Saben for a while now. Some of the key elements that we are trying to work through also is bringing governance, especially the agent governance to real time. Mhmm. And to get that diffusion would be gateway. One of the solutions would be the gateway. But gateway also means different things to different people. It could be an MCP gateway. It could be an agent to agent gateway, and it could be model gateway as well. So in this case, when when Savant is designing an access gateway that is purely specific to agent and then agent behavior at one time, That's something that we would be very interested in deploying. We'll keep tires on it right now, but the devil is in the details because those agent run times to go on those at run time properly needs a metadata that that that needs to be calculated. And most of the companies don't have it. Yeah. Yeah. The ownership, we still are missing ownership. We still have to account for the permission sets that are there. Those are some of the things that we would have to work through before we are ready to say, yes. We can we can implement this. Yeah. But, I completely agree with you because design time policies cannot survive in this agentic world. You have to ensure that you are enforcing control while your agent is actually running a task. You cannot just, you know, okay, I designed these policies and get it over with. So we you you both talked a lot about visibility. So let me ask a very basic question. How does having visibility and governance over AI identities impact risk posture, speed of innovation, and confidence in deploying AI at scale? I think there are couple of factors at play there. Right? Visibility is important because you have to know what an agent is doing. I think we talked about it. Agents have a bias towards action or an end goal. So I tell it to do x and might decide to do a y. I'll say go add a identity. It might go and move that identity and so on. So if I cannot have visibility, then I think it's a it's a matter of time something disastrous is going to happen. I think all of you probably read the news. You must have heard about I find it a little interesting, though, that OpenAI agent escaped. I'm like, is it hot air or something? So but but, I mean, you guys see that. Right? So it has lots of unintended, you know, consequences out of it. So that is why I'm very high on observability. The other thing we'll have to figure out what to do with that observability. I'll I'll try to explain. There'll be hundreds and thousands of agents and they will generate, I think, terabytes of, raw data on a daily basis. Those days are gone when all of this data will be mined and then next day a SOC agent will come and look at it and so on. So we'll have to figure out how to make it actionable really quickly and and so on. So that is why I think, foundationally, the observability will have to do better. So far, it has not been a problem. People have all these same tools and so on, but this will have a this will need a fundamental rethink and, report around it. Right? Yeah. Agree. So to add to that, what does visibility and governance need to be? Or what would that mean in terms of an agent, right? From our perspective, it enables business. If we are able to solve those two problems, visibility and governance for agents, that means we can scale. We can scale at enterprise levels very quickly and be able to secure the business as well without just saying without slowing down the business. So if we can solve those two problems, visibility and governance, that basically means I can scale. That's how we would approach that. That's a very good point. You've got to fundamentally rethink your strategy. We have always protected the static identities. Yeah. But now you're talking about agents, and they can be hot air balloon. You never know. So, you know, you guys are way further in your journey when it comes to, agent security. As AI agents become more autonomous, what identity security capabilities, in your opinion, will become nonnegotiable in next twelve to twenty four months? So we talked about it a little bit earlier as well. Right? I think foundation first, manage your foundation properly. Zero trust, least privilege, compromise identities, compromise passwords. The paradigm has changed, like I said. Some of these things, we are talking about agents not having an owner. People have, these accounts which do not have an owner and and so on. It's a fact foundationally, start from there. If you have a solid foundation, a lot of things will be fine. Like I said, zero trust and, least privilege and so on. If there's least privilege fundamentally built into the into your ecosystem, the agent cannot go and do other rogue stuff and so on, hopefully. So that's how I look at it. Focus on the foundation first. Don't look at the fancy stuff. So Yeah. It's the mindset shift. It's like, you know, continuously Yeah. You know, the information, oh, we'll get to it when we get to it. I think some mindset will have to shift. Yeah. Right. So for us, data hygiene and then building with identity as your center will absolutely be one of those things that non negotiable going forward. Because if you're not able to govern your identity or what it has access to, it is not can it get access to a system? Should it get access to the system? Should it be able to execute anything at at at a given time? Sometimes it's not even should it get access. It could have access, but shouldn't should it even execute? So given that identity centric building, like, great SDK, like, being able to leverage that and build with identity as your first principle. And then design based on that would be one of those nonnegotiable, items going forward for us to be able to scale business. A lot of organizations come to us and, you know, that that has not even started. They just ask us is, where should I start? What should be my first step? So what would be your advice to the organizations who has not yet started operationalizing air security? Like I said, focus on the fundamentals. Start from there. Don't be paralyzed. I think one of the things is people look at it and say, oh, this is so much to do. And I think there's a lot of, I call it, fraud in the ecosystem as well. So you have to cut that out. Focus on the fundamentals slowly and slowly build a foundation. I think you have to start from there, and you have to start now. Like I said, we will get to it. When we get to it, it does not work anymore. So that's that's how I look at it. That's what I tell my team as well. I said, make small incremental progress. Don't look at this big initiatives, multimillion, nine month long initiative. By that time, lot of damage could have happened. It's one of my thoughts. Yeah. And we do not have infinite budgets or resources to deal with that anymore. We've got to invest smart. Yeah. Pretty big deal. We need more. Right? It's don't don't create that debt. Yeah. Yeah. Solve fundamentals first. Don't create tech debt, especially when you're building new stuff. That's how I would I would say you should have approached and always identity centric. Right? Identity is the key now. So I think that's why we call it identity at the center of security. Identity is the fabric that connects everything. Yep. So you both know, in my panels, I love to ask lightning round questions. So how about one quickly now, one word, that's all you get. One word to describe the biggest AI identity to us today, Vineeth. Scary. Scary? That's fair. Accountability. Accountability. Unknown agent or overprivileged agent? This item. Unknown agent. For me, it's overprivileged agent. So you both divided the devils among yourself. Okay. The last one, AI identities, assets or attack surface? Both. Yeah. Both. You both are speaking like a true identity professionals. Mhmm. Thank you so much with that. Yeah. I would wrap this up, and I am sure our audience also found this extremely, learning session. I always learn a lot from my customers. Now it's my extreme privilege to invite Siemens' president, Paul Zulfagari, on stage to take us forward. Thank you. Well, let me also, let me also on the end of the program, but thank everybody for coming, for the online audience, for participating, for all of you to be here in person. It's a very exciting day for Savant and we're super happy that all of you could participate with us. Now that video serves a lot of purposes, but one of them is as an LA company that just named its new product after a surf break, there was no chance you're getting away without at least two videos showing people surfing. But I do think that that video also demonstrates something we want to get across here. If you really took a look at that, what you would see is at the very beginning, the cluster of surfers, there's a lot of confusion. How do people get in the right lineup? You saw the beauty of it. You also saw the power of it. But if you actually noticed, you also saw that some of the people found a way to harness that power, harness that wave and ride it really to success. And that's the image we want all of you to think about when you think about what Saviynt discussed today and released today. That with Zuma, there is an opportunity for companies, for organizations, for partners and for the market to really harness this incredible wave coming from AI and turn it into something useful and powerful for all of you in your organizations and in the market in general. One of the other things I wanted to point out too is that for the for us, what you saw with the panel, which I thought was very it's important to point out, is the panel was not just here discussing general market conditions or discussing they were here talking about how they actually helped us design and build the product. And so one of the things that's very important to understand is the pride that we have in the product that we release today, yes, it's a function of the incredible work of our employees and the hardworking insights and vision of all the people here, but it is also born of our experience working with some of the best companies in the world and getting their feedback about how to solve problems like this. So we feel very capable of standing here today and using superlative words, words like the only one, the best, the newest, the ones that's the most scalable, because we didn't just build it in a vacuum, we built it in close cooperation with our partners and our customers. And so that's why we're so confident that what we released today is valuable and will be valuable to the market at this moment in time. I think it's critical as we end the program to accept the fact that identity security is at the center of AI. It's at the center of AI and we believe has the ability to not just harness, but to accelerate the adoption of AI. This is a different thinking for companies and solutions that always are talking about cybersecurity or security or concerns. Most of them are talking about slowing something down, being careful, being concerned. What Saviynt believes is we have an opportunity with Zuma to participate in the acceptance and adoption of AI, which puts us on a very different side of the ledger. We're on the side of the ledger where companies are figuring out how do they extract huge value from these products and from these solutions. And so what we feel most excited about is we have a chance to work in that environment and allow companies to fulfill the real true value from AI. But to do that, we have to also accept that the responsibility is difficult and it's challenging. And that is why it was so important that today we made it very clear, we did not try to extend existing solutions, existing applications, existing platforms, existing methods to manage humans over onto this new challenge. What we did was something very different. We said start from the ground up and ask yourself what would you need to create to provide the most powerful solution to companies that want to harness and energize their AI. And so we started from scratch. And that means that what we delivered, what we delivered today and what's available to the market today was purpose built for this challenge. You have to understand this is a new product and a new solution for a new challenge. We made the very deliberate decision to not try to extend or expand pre existing solutions, applications or approaches, but we started by saying, what's the problem we're trying to solve and how do we solve it? Now you might say, well, couldn't anybody have done that? Maybe, but the company you want doing it is the company that understands enterprise identity security at scale, that understands what IT professionals and organizations are trying to accomplish. And so while we built a product from scratch, we built it with practitioners and with an understanding of what the market is looking for. And so that's why we're so proud today to release Zuma, to bring it to the market and really to help companies understand, if you put identity security at the center of AI, there is no limit on what you'll be able to do with AI. So with Zuma, let me just end by saying, we believe it is the market's only complete end to end identity security product purpose built and designed around securing the needs of AgenTic AI and AI agents. And that's a very profound thing to say, but we believe very strongly in our ability to say it. And it's why we wanted to come to New York, to NASDAQ, to this event, to hold it both in person and electronically and make sure the world understood the importance of what we have brought and why we believe our ability to both discover, protect and manage is unique and brings extraordinary valuable to the marketplace. It's also very simple and in many ways that's the elegance of what we've created. So one way to demonstrate the power and the simplicity of what we have developed is to give you all the opportunity to start. So we've designed a solution and a trial that's free and available, easy to download, easy to begin using, easy to start understanding the value of. The way we see this is, we can sit up here, we could talk for days, at the end of the day, what will really matter is your experience. So we're very excited to release today the free trial version of Zuma. That trial version will allow organizations to gain value from day one, see the value, build the internal business case, gain the confidence and eventually deploy Zuma widely and broadly across their organization. So we would recommend for anybody that's trying to look at solve this problem, go to the website, begin the trial and see for yourself. So with that, I'm going to bring to a close the online version and want to thank everybody for being here, particularly for our guests that have been very patient in the our webcast and online version. That part of the program is going to come to a close. So with that, I want to thank everybody for their participations and patience and hope that you can see the excitement that we have for our product and our company into the future.