Let Ticket-Pushers Retire
Travis questions entire security governance career paths
Jun 16, 2026 · 36 min · 13 segments
In this episode: - Why AI agents can't be trusted users - The hardest security decisions are about what not to protect - Everything in security is a proxy, including agents - Secure-by-default…
Travis McPeakGuestDave TagareHostYou've helped build security in some very different worlds, like Netflix scale cloud, Databricks, like pretty massive product surface, and now AI-first coding workflows at Cursor.
What's one hard constraint that never goes away and you find that people tend to underestimate every time the tech stack changes?

There's a quote from a long time ago, but the NSA is like elite hacking group.

They would come in and they would just be quiet in an organization and just observe what's going on.

And by the time they would go do whatever it is they had to do, they understood the inner workings of the business and complex systems and all that better than anybody that works at that company did.

and the reason this is so hard in security is because for a business to function as a good business like things are moving forward things are changing all the time there's a lot of work being done um that you just have no visibility into you often find out things late and then on top of that security is already spread thin you know there's like large stuff changing they may introduce risk so like security has to be very very choosy with how and where they get involved I think that's the number one dynamic is like we're always going to have more that we have to be doing than we can actually do.
And so when obviously the volume is so much greater than what's possible to be done, you know, let's maybe talk through like how, for example, if you're securing an agent, right, and not the user, like how does that translate into your workload today?

It's really like interesting and unanswered question in industry identity, right? Like what identity is this agent? Is it the identity of the user that launched it? Is it the identity of where it's running from? Like the platform, you know, like an AWS instance or something? Does it have like some own identity? So I don't think anybody's like really figured that out.

And I assume like most things in industry, we're going to get completely different answers to that question.

And then you have to go and grant the identity access to things, which is I am an access control, which we've also historically been awful at as an industry, like setting up things, least privilege.

Like I did a talk on this one time, like we've been talking about least privileges, like we should do this thing since 1970.

Um, and Netflix, I did a project called repo kid, which I think is like the best cut of this, which is you just deliberately give a little bit more than you think anybody needs.

And then of course, when you do that, like you need to add permissions, you need a system for doing that.

And what's interesting in this model is that everything is moving so fast driven by just new technology, transformational technology that people really want to adopt into their business.

And we in security just don't have great answers for what we're going to do here.

And at the same time, because of the urgency of it, many businesses are not going to wait three years for the security team to figure out a clue of what to do.
You've helped build security in some very different worlds, like Netflix scale cloud, Databricks, like pretty massive product surface, and now AI-first coding workflows at Cursor.
What's one hard constraint that never goes away and you find that people tend to underestimate every time the tech stack changes?

There's a quote from a long time ago, but the NSA is like elite hacking group.

They would come in and they would just be quiet in an organization and just observe what's going on.

And by the time they would go do whatever it is they had to do, they understood the inner workings of the business and complex systems and all that better than anybody that works at that company did.

and the reason this is so hard in security is because for a business to function as a good business like things are moving forward things are changing all the time there's a lot of work being done um that you just have no visibility into you often find out things late and then on top of that security is already spread thin you know there's like large stuff changing they may introduce risk so like security has to be very very choosy with how and where they get involved I think that's the number one dynamic is like we're always going to have more that we have to be doing than we can actually do.
And so when obviously the volume is so much greater than what's possible to be done, you know, let's maybe talk through like how, for example, if you're securing an agent, right, and not the user, like how does that translate into your workload today?

It's really like interesting and unanswered question in industry identity, right? Like what identity is this agent? Is it the identity of the user that launched it? Is it the identity of where it's running from? Like the platform, you know, like an AWS instance or something? Does it have like some own identity? So I don't think anybody's like really figured that out.

And I assume like most things in industry, we're going to get completely different answers to that question.

And then you have to go and grant the identity access to things, which is I am an access control, which we've also historically been awful at as an industry, like setting up things, least privilege.

Like I did a talk on this one time, like we've been talking about least privileges, like we should do this thing since 1970.

Um, and Netflix, I did a project called repo kid, which I think is like the best cut of this, which is you just deliberately give a little bit more than you think anybody needs.

And then of course, when you do that, like you need to add permissions, you need a system for doing that.

And what's interesting in this model is that everything is moving so fast driven by just new technology, transformational technology that people really want to adopt into their business.

And we in security just don't have great answers for what we're going to do here.

And at the same time, because of the urgency of it, many businesses are not going to wait three years for the security team to figure out a clue of what to do.
Every episode on Radar is fully transcribed, speaker-labeled, and rich with metadata. Here is a taste of this one. Try Radar for free to see the rest.
3 of 5
Let Ticket-Pushers Retire
Travis questions entire security governance career paths
One Wrong Agent Action
When AI mistakes cost millions, Travis warns
Security Exists For Business
Why security must speed alongside business goals
+2 more clips · 3 min 13 sec of audio in all
7 of 22
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
All 5 clips — the highlight moments, each cut as its own audio, with a title and a speaker
All 13 segments — the transcript broken into labeled sections, every ad read marked
All 22 topics — jump to every other episode discussing the same subject
Every related episode — other shows Radar links to this one
No account is needed to search Radar.