Dominic Jainy stands at the forefront of modern infrastructure security, bringing years of seasoned expertise in artificial intelligence, machine learning, and the decentralized complexities of blockchain. As cloud environments become the backbone of global enterprise, Jainy has focused his career on the increasingly precarious intersection of identity and access management. His insights are particularly vital now, as traditional security perimeters dissolve and attackers pivot toward exploiting the administrative keys to the kingdom. In this discussion, we explore the shift from persistent, “standing” privileges to a more ephemeral and secure model of just-in-time access, examining how integrated architectures are becoming the only viable way to defend high-velocity cloud ecosystems.
Organizations frequently struggle with standing privileges that remain active long after a task is finished. Why have these “dormant” permissions become such a critical vulnerability in the current threat landscape?
When administrative accounts hold onto their rights indefinitely, they effectively become “sitting ducks” for any motivated threat actor. In a traditional setup, once a user is granted high-level access, that permission often stays live in the background, creating a static and predictable target. Our findings show that a staggering 64% of organizations do not have a fully consolidated system for privileged access governance, which means they are often blind to exactly how many “master keys” are floating around their environment. If an attacker manages to compromise even one of these accounts, they don’t just get in; they get a permanent, high-privileged foothold that allows them to move laterally across the network. It turns what should be a temporary entry into a persistent, high-stakes security breach that can go undetected for months.
The concept of “Just-in-Time” access promises to revoke permissions automatically once a session ends. Could you describe the actual workflow of a user requesting this access and how it changes the security feel of a platform like AWS or Azure?
The shift to Just-in-Time access completely transforms the user experience from one of constant “always-on” risk to a precisely controlled, temporary event. When a developer or admin needs to enter a platform like AWS IAM, Azure Entra ID, or Google Cloud Platform, they don’t use a permanent login; instead, they request an elevated role through a centralized vault. Once that request is approved, the system dynamically assigns them to a specific group or role for a pre-set window of time. The user then operates through remote browser isolation, which feels seamless but ensures that every click and command is recorded and analyzed by KeeperAI in real-time. The most significant moment occurs when the timer expires; the system automatically strips away those permissions, removing the need for an admin to manually go back and “clean up” the access rights, ensuring no lingering credentials are left for an attacker to find.
According to recent data, 43% of organizations still allow direct application logins that bypass their identity providers. Why is there such a massive gap between the tools companies have and the way they actually use them?
This gap is a classic example of “convenience over compliance” that plagues many IT departments. Even though 55% of organizations in the Asia-Pacific region utilize identity providers for their daily employee logins, only 36% have actually gone the extra mile to deploy full-scale privileged access management. This discrepancy exists because many teams find secondary security layers to be an obstacle to their speed, leading them to use direct, “shadow” logins that the central security team can’t track. It creates a dangerous blind spot where the most sensitive administrative tasks are happening outside the sight of the very systems meant to protect them. Bridging this gap requires moving away from fragmented tools and toward a unified platform that makes the secure route just as fast and easy as the shortcut.
There is a strong argument that security tools must be “built-in” rather than “layered on” to be effective at scale. From an architectural standpoint, why is a zero-knowledge, integrated approach superior to using multiple third-party connectors?
The problem with many legacy systems is that they are built like a patchwork quilt, with Just-in-Time tools added as an afterthought on top of systems that were never designed for automatic revocation. As Craig Lurey has noted, trying to coordinate these separate systems—which often have their own disparate logs and policies—becomes a maintenance nightmare as an organization grows. By using a zero-knowledge architecture where password management, secrets, and session recording live in the same framework, you eliminate the friction and the bugs that come with third-party connectors. This “built-in” approach ensures that governance and audit records are kept in a single, unshakeable system of record. It provides a level of architectural integrity where you aren’t just adding another layer of complexity to manage, but rather simplifying the entire security stack into one cohesive, automated unit.
As we move toward a future of automated workflows, how does this new framework handle the unique risks posed by machine identities and AI agents?
Machine identities and AI agents are often the “unsung heroes” of modern infrastructure, but they also represent some of the most extensive and difficult-to-track permissions in the cloud. These automated accounts frequently carry massive privileges to move data or change configurations, and once they are created, they are rarely audited with the same rigor as human users. By applying the same zero-standing-access model to these non-human identities, we can ensure that a script or an AI agent only has the power it needs for the exact duration of its task. Because every session is monitored and recorded, we can use intelligent analysis to spot anomalies in machine behavior immediately. This creates a complete, end-to-end audit trail for every task, whether it was performed by a person in a remote office or an automated process running in the heart of a data center.
What is your forecast for the future of cloud identity security?
I believe we are entering an era where “standing privileges” will eventually be viewed as a relic of a less secure past, much like we view unencrypted passwords today. In the next few years, the industry will pivot toward a “zero-standing-privilege” default, where no one—man or machine—has administrative rights unless they are actively in the middle of a verified, time-bounded task. As attackers become more sophisticated at using stolen credentials to navigate cloud environments, the only way to stay ahead is to ensure those credentials have the shortest possible lifespan. We will see a massive consolidation of security tools, moving away from fragmented management and toward unified, AI-driven platforms that handle identity, secrets, and sessions under one roof. Ultimately, the goal is to make security so deeply embedded in the infrastructure that it becomes invisible to the user but remains an impenetrable barrier to any unauthorized intruder.
