Skip to content

Talks, panels & podcasts

Talks

Conference talks, panels, podcasts and webinars, mostly about authorization, AI agents and open standards. Where there's a recording, there's a link to watch or listen.

Where I’ve spoken

18 cities in 8 countries. 72 of the 99 sessions below have a recording you can watch or listen to.

Everything, newest first

99 of 99

Coming up3

  1. TalkWeAreDevelopers World Congress North AmericaSan Jose, USA

    It passed auth, then production caught fire

    Why authorization failures are turning into reliability incidents, and how one policy decision point plus OpenID AuthZEN stops each layer of the stack making up its own answer.

    Upcoming
  2. PodcastApplication Security WeeklyOnline

    Authentication, authorization and securing AI agents

    With Mike Shema

    Upcoming
  3. TalkISC2 Security Congress 2026Aurora, Colorado, USA

    Identity as the control plane for software supply chain security

    With Vatsal Gupta (Apple)

    Upcoming

202617

  1. TalkTailscaleUp 2026San Francisco, USA

    Every tool call is a trust boundary: authorization for AI agents

    A reference architecture for agent access: sandbox the agent, route every tool call through a gateway, decide at a policy layer, log the lot. Live demo of Cerbos and Tailscale Aperture deciding on each tool call.

  2. InterviewThe Cyber HutOnline

    Vendor introduction: Cerbos

    With Simon Moffatt

    Authorization is the last improvised layer of identity. Why AI agents (which need access at runtime and can't be pre-provisioned) and AI-written code are forcing authorization out of the app, and why AuthZEN makes externalizing it an architecture decision instead of a vendor bet.

    Watch
  3. TalkWeAreDevelopers World Congress 2026Berlin, Germany

    The day the chatbot asked for sudo

    What happens when an AI agent needs more privileges than the person who launched it, and how to decide, per tool call, whether it gets them.

    Watch
  4. TalkIdentiverse 2026Las Vegas, USA

    Access reviews are dead. Long live decision governance

    With Vatsal Gupta (Apple)

    Access reviews assume access is something people have. In modern systems it's something that gets calculated, so governance has to move from reviewing entitlements to governing policy intent, enforcement and the decisions that actually happened.

    Watch
  5. WorkshopIdentiverse 2026Las Vegas, USA

    AuthZEN deep dive: mastering the OpenID authorization standard

    With Atul Tulshibagwale (CrowdStrike), Mark Berg (Axiomatics)

    A 2-hour masterclass on the AuthZEN Authorization API: the spec's internals, what implementers need to know, certification, and authorizing AI agents with COAZ.

    Watch
  6. TalkIdentiverse 2026Las Vegas, USA

    Beyond authentication: updates from the authorization frontier

    With Atul Tulshibagwale (CrowdStrike), Mark Berg (Axiomatics)

    Authentication is largely solved and authorization isn't. An update from the AuthZEN co-chairs on how Shared Signals, AuthZEN and Transaction Tokens fit together.

    Watch
  7. TalkDeveloperWeek New York 2026New York, USA

    Authorization: what's next? The unauthorized session

    Where the authorization standards actually stand (AuthZEN, OAuth RAR, CAEP and RISC), and which bits you can use today versus which are still theory.

  8. PanelEuropean Identity and Cloud Conference 2026Berlin, Germany

    Around the foundation: standards and infrastructure for the next-gen identity stack

    Watch
  9. PanelEuropean Identity and Cloud Conference 2026Berlin, Germany

    Signals, policies, and identity agency

    With Reiner Mertens (KuppingerCole, moderator)

    Agents are workloads that spin up, get permissions, do something and die. You can't wait 24 hours for an IGA process, so the building blocks (OAuth, AuthZEN, Shared Signals) have to make access reactive and signal-driven.

    Watch
  10. WorkshopEuropean Identity and Cloud Conference 2026, OpenID meetupBerlin, Germany

    AuthZEN overview

    The Authorization API 1.0 a few months after it went final, and what the working group is tackling next.

    Watch
  11. TalkDevWorld Conference 2026Amsterdam, Netherlands

    It passed auth, then production caught fire

    Authorization used to live in one codebase. Now every layer makes its own decision, and the failures show up as outages, retry storms and "can't reproduce" tickets. The fix: one policy decision point, coordinated with OpenID AuthZEN.

    Watch
  12. DemoInternet Identity Workshop XLIIMountain View, USA

    AuthZEN profile for MCP (demo)

    With Atul Tulshibagwale (CrowdStrike)

    Per-tool-call authorization for AI agents, with the AuthZEN MCP profile as the wire format.

  13. TalkOpenID Foundation WorkshopSan Jose, USA

    AuthZEN working group update

    Where the AuthZEN specs had got to the week before IIW. The player jumps straight to my section.

    Watch
  14. PanelOpenID Foundation WorkshopSan Jose, USA

    OpenID for the enterprise

    With Atul Tulshibagwale, Mike Kiser (SailPoint), Dick Hardt (Hellō)

    AuthZEN, Shared Signals, SCIM events and IPSIE, and what they add up to for enterprise identity. My segment starts 3 hours 43 minutes into the recording (the player jumps straight there).

    Watch
  15. WebinarCISO Zero Trust webinarOnline

    Layered security: what aviation safety and cheese can teach us about zero trust

    James Reason's Swiss cheese model from aviation safety, mapped onto the six layers of zero trust, with authorization as the layer that holds the rest together.

    Watch
  16. TalkGartner Identity & Access Management SummitLondon, UK

    AuthZEN spec and working group update, plus an IdP interop demo

    Where the AuthZEN spec and working group had got to, then a live demo of identity providers calling out to policy engines through AuthZEN.

  17. Meetup(ISC)² London ChapterLondon, UK

    Layered security: what aviation safety and cheese can teach us about zero trust

    The Swiss cheese talk, reworked for a room of CISOs and security leads. The AV died halfway through, so the second half turned into 15 minutes of Q&A on AI agents and workload identity (which honestly went better).

202523

  1. TalkGartner IAM SummitGrapevine, Texas, USA

    Extend your identity providers with OpenID AuthZEN: fine-grained authorization and zero trust

    With Omri Gazitt (Aserto), David Brossard (Axiomatics)

  2. WebinarCerbos webinarOnline

    Fine-grained authorization for non-human identities

    Watch
  3. PodcastIdenterati Office Hours, episode 151.5Atlanta, USA

    AI agent KubeCon debrief

    With Mike Schwartz

    Recorded live at KubeCon North America.

    Watch
  4. PanelCyberArk Workload Identity Day at KubeCon NAAtlanta, USA

    Securing the future: workload identity in the age of AI agents

    With Pieter Kasselman, Christian Posta, Brett Caley, Andrew Block

  5. TalkISC2 Security Congress 2025Nashville, USA

    Beyond approvals: automating IAM for compliance, security, and business agility

  6. MeetupDevOps Exchange LondonLondon, UK

    Guest speaker

  7. WebinarCerbos webinarOnline

    Dynamic authorization

  8. WebinarCerbos webinarOnline

    Adding fine-grained authorization to MCP servers

    Watch
  9. PodcastThe Node (and more) Banter, PlatformaticOnline

    MCP: the new interface of the AI stack

    With Luca Maraschi, Matteo Collina

    The Model Context Protocol as the new interface between models, services and infrastructure, and what that means for who's allowed to call what.

    Watch
  10. WebinarCerbos webinarOnline

    Scaling authorization logic in a multi-tenant application

    Watch
  11. InterviewSoftwarePlazaOnline

    Zero trust authorization for non-human identities

    With Twain Taylor

    Watch
  12. TalkIdentiverse 2025Las Vegas, USA

    The rise of WASM-embeddable policy decision points

    Running the authorization decision wherever the request is: in the browser, at the edge or on a device, by compiling the policy engine to WebAssembly.

  13. PanelCyberSec Europe 2025Brussels, Belgium

    Authorization and identity panel

  14. TalkCyberWiseCon Europe 2025Vilnius, Lithuania

    Layered security: what aviation safety and cheese can teach us about zero trust

    The Swiss cheese talk: no single control is perfect, so stack them, with authorization as the layer that holds zero trust together.

    Watch
  15. PanelCyberWiseCon Europe 2025Vilnius, Lithuania

    Building the future: trends in modern application architecture

    With Kenneth Rohde Christiansen, Paul Dragoonis, Romano Roth, Victor Lyuboslavsky

    Watch
  16. TalkEuropean Identity and Cloud Conference 2025Berlin, Germany

    AuthZEN: the OpenID Connect for authorization

    An update from the AuthZEN Working Group on the Authorization API and the growing list of interoperable implementations.

    Watch
  17. PodcastIdenterati Office HoursOnline

    The rise of the embeddable PDPs

    With Mike Schwartz

    Watch
  18. PodcastSoftware Engineering Radio, episode 664Online

    Stateless decoupled authorization frameworks

    With Emre Baran, Priyanka Raghavan (host)

    Watch
  19. InterviewAmazic at KubeCon EuropeLondon, UK

    Revolutionizing authorization: what's next for Cerbos

    With Luke Trigg, Milo Oudenaller

    Watch
  20. DemoGartner Identity & Access Management SummitLondon, UK

    OpenID AuthZEN interop demo

    Multiple vendors' policy engines answering the same AuthZEN requests. I wrote the Envoy integration, with Cerbos doing the deciding behind it.

  21. WebinarFusionAuth and Cerbos webinarOnline

    Choosing the right authentication and authorization deployment

    Self-hosted versus SaaS for authentication and authorization, and how to decide which fits.

    Watch
  22. WebinarCerbosOnline

    11 authorization and IAM trends for 2025

    Watch
  23. PodcastDevOps Paradox, episode 297Online

    Streamline access control using Cerbos

    With Darin Pope, Viktor Farcic

    Moving from hardcoded permission checks to externalized authorization.

    Watch

202429

  1. PodcastIdenterati Office Hours, episode 73Online

    The future of AuthZ, from A to Z

    With Mike Schwartz

    Watch
  2. PanelGartner IAM SummitGrapevine, Texas, USA

    Authorization panel

  3. MeetupLondon AI Engineering MeetupLondon, UK

    Authorization for AI agents

    15 minutes on why AI agents need a policy decision point of their own, for a room that was mostly fintech engineers.

  4. PodcastPurePerformance, episode 221Online

    The security and resiliency challenges of cloud native authorization

    With Andreas Grabner, Brian Wilson

    Watch
  5. LivestreamCerbos community livestreamOnline

    Ask me anything

    Watch
  6. PodcastShipTalkOnline

    Don't reinvent the wheel

    Why authorization should no longer be an afterthought.

    Watch
  7. LivestreamCNCF Cloud Native LiveOnline

    Beyond the black box: robust authorization in RAG-based AI systems

    RAG pipelines will happily hand an LLM documents the user was never allowed to see. How to filter what goes into the context window with query plans from the policy engine.

    Watch
  8. PanelAuthenticate 2024 (FIDO Alliance)Carlsbad, California, USA

    Read-out from the AuthZEN interop event

    Watch
  9. MeetupDisruptive Tech LondonLondon, UK

    Layered security: what aviation safety and cheese can teach us about zero trust

    The first outing of the Swiss cheese talk, framed around the CrowdStrike outage: no single control is perfect, so you stack them.

  10. PodcastAmazic podcastOnline

    Cerbos Hub launches to separate and manage authorization policies at scale

    With Twain Taylor

    Why running the policy engine as WebAssembly, in the browser and at the edge, matters once you have a fleet of decision points to manage.

    Watch
  11. TalkWeAreDevelopers World Congress 2024Berlin, Germany

    Decoupling authorization with Cerbos and WebAssembly

    Authorization that runs anywhere it's needed: in a React app, at the edge, on a device or in the cloud, by compiling the policy engine to WebAssembly.

  12. WebinarCerbos webinarOnline

    The business case for externalized authorization

    With Dan Maher

    Watch
  13. TalkEuropean Identity and Cloud Conference 2024Berlin, Germany

    Un-complicate authorization maintenance

    Watch
  14. WebinarFlagsmith and Cerbos webinarOnline

    Feature flags and authorization: key tools for modern development

    With Ben Rometsch (Flagsmith)

    Watch
  15. PanelIdentiverse 2024Las Vegas, USA

    Authorization panel

  16. TalkDevDays Europe, DevOps Pro and CyberWise 2024 (online)Online

    Beyond code: shaping security in a developer-driven world

    Every developer is a security engineer now, whether they signed up for it or not. Where developer experience and security meet, and why security tooling has to help rather than block.

    Watch
  17. WebinarWeAreDevelopers Live, Security DayOnline

    Un-complicate authorization maintenance

    As soon as you have more than one user type, permission logic slowly turns into spaghetti. Taking an app from basic roles to fine-grained attribute checks with a decoupled policy engine, and the blockers you hit on the way.

    Watch
  18. WebinarCerbos webinarOnline

    Future-proofing fintech in the age of cloud and microservices

    With Edgar Rivera (4G Capital)

    Watch
  19. LivestreamCNCF Cloud Native LiveOnline

    GitOps for application authorization

    Watch
  20. PodcastThe Scripting Den, episode 15Online

    What comes after the MVP

    Watch
  21. PodcastThe Business of Open SourceOnline

    Getting your pricing model right(-ish)

    With Emily Omier

    Recorded at KubeCon Europe in Paris.

  22. InterviewChris ChinchillaOnline

    Save time implementing roles and permissions in application development

    With Emre Baran, Chris Chinchilla

    Watch
  23. WebinarCerbos and ByteGrad webinarOnline

    Implementing access control in Node.js, React and serverless apps

    With Wesley (ByteGrad)

    Watch
  24. InterviewDevOps in Agile Way at KubeCon EuropeParis, France

    KubeCon Paris and security

    Watch
  25. InterviewAmazic at KubeCon EuropeParis, France

    KubeCon Europe 2024 recap

    With Milo Oudenaller

    Watch
  26. LivestreamCNCF Cloud Native LiveOnline

    Heterogeneous microservice authorization

    With Taylor Thomas

    Watch
  27. PanelStripe fireside chatOnline

    How to build an effective pricing strategy for your startup

    With Morgane Zerath, Nick Telson-Sillett, Matthew Roberts (host)

    Watch
  28. PodcastJamstack Radio, episode 142Online

    Decoupled authorization

    With Emre Baran

    Watch
  29. PodcastAmazic podcastOnline

    Cerbos Hub has launched to give you authorization superpowers

    With Twain Taylor

    Watch

202317

  1. TalkConf42 DevSecOps 2023Online

    Modernizing authorization: from basic roles to decoupled ABAC

    Watch
  2. WebinarCNCF webinarOnline

    Cloud-native chronicles: lessons learned from building Cerbos in the open

    Watch
  3. InterviewCivo TV at KubeCon North AmericaChicago, USA

    Access control: key strategies for system security

    A 43-second clip on managing authorization and user permissions in SaaS systems.

    Watch
  4. TalkCivo Navigate Europe 2023London, UK

    How authorization evolves: from basic roles to ABAC

    Watch
  5. PodcastAmazic podcastOnline

    Cerbos separates authorization from application code and is lightning fast even at scale

    With Twain Taylor

    Watch
  6. TalkDeveloperWeek CloudX 2023San Mateo, California, USA

    Modernizing authorization: from basic roles to decoupled ABAC

    Where role-based access control runs out of road, and how to move to attribute-based policies without rewriting your app.

  7. PanelBoxyHQOnline

    The future of authorization

    Where authorization is heading, with speakers from GitLab and Microsoft.

  8. MeetupCloud Native LondonLondon, UK

    Cloud-native chronicles: lessons learned from building Cerbos in the open

    What it actually means to be cloud native, after 2 years building an open-source authorization layer: Prometheus, OpenTelemetry, Helm, early user feedback, and being open to pull requests.

  9. LivestreamCNCF Cloud Native LiveOnline

    Modernizing authorization

    Taking an app from role-based access control to attribute-based policies, live, without rewriting it.

    Watch
  10. PodcastAsk A CISO, season 3 episode 12Online

    Decoupling authorization from your applications

    With Raphaël Peyret

  11. PodcastThe Stack Overflow Podcast, episode 553Online

    Going stateless with authorization-as-a-service

    With Ben Popper, Cassidy Williams

  12. WebinarCNCF webinarOnline

    Cloud-native application authorization

    Fine-grained policies, observability with OpenTelemetry and Prometheus, and shipping policy changes with GitOps and Argo.

    Watch
  13. TalkCivo Navigate 2023Tampa, Florida, USA

    Solving the never ending requirements of authorization

    What starts as a check on the user's email domain turns into a web of if/else statements. The stages every company goes through with permissions, and a GitOps approach to scaling policy.

    Watch
  14. InterviewThe New Stack at CloudNativeSecurityConSeattle, USA

    How Cerbos controls access decisions for your software

    Watch
  15. PodcastReact Round Up, episode 212Online

    User authorization with Cerbos

    With TJ VanToll

    Watch
  16. TalkCloudNativeSecurityCon North America 2023Seattle, USA

    Externalized authorization

  17. PodcastModern Web podcast (This Dot Labs)Online

    Authorization on the web with Cerbos

    With Rob Ocel, Adam L. Barrett

20227

  1. WebinarCodementorOnline

    Solving the never-ending requirements of authorization

    Watch
  2. LivestreamJS Drops (This Dot Media)Online

    NodeJS: authorization using Cerbos

    Watch
  3. TalkAPI World 2022San Jose, USA

    Solving the never ending requirements of authorization

    What starts as a check on the user's email domain turns into a web of if/else statements. The stages every company goes through with permissions, and a GitOps approach to scaling policy.

  4. LivestreamTeach Eddie livestreamOnline

    Authorization for your apps with Cerbos

    With Eddie Jaoude

    Adding decoupled, open-source access control to an Express app, live.

    Watch
  5. TalkCollision 2022Toronto, Canada

    The great decoupling

    A 3-minute startup pitch on the Collision stage: stop pulling engineers off the roadmap to rebuild authentication, authorization and identity, and pick open-source building blocks off the shelf instead.

    Watch
  6. TalkDevOps & Cloud Days 2022Online

    Solving the never ending requirements of authorization

    Watch
  7. TalkDeveloperWeek Europe 2022Online

    Solving the never ending requirements of authorization

    Watch

20181

  1. TalkAI Congress LondonLondon, UK

    Powering predictive commerce at scale

    With Matthew Tamsett (Qubit)

20171

  1. PodcastDrill to Detail, episode 16Online

    Qubit, Visitor Cloud and Google BigQuery

    With Mark Rittman

    Qubit's Visitor Cloud and running it on Google BigQuery.

20161

  1. TalkGoogle Cloud NEXT London 2016London, UK

    Fun with a petabyte

    Querying terabytes isn't cool any more. Interactive analytics against a 1 petabyte dataset in BigQuery, live on stage, and why it was cheaper and easier than it sounds. Still my favourite talk.

    Watch

Speaker kit

Short bio

Alex Olivier is co-founder and CPO of Cerbos and a co-chair of the OpenID Foundation’s AuthZEN Working Group. He builds, writes and speaks about authorization for applications, APIs and AI agents.

Longer bio

Alex Olivier is co-founder and Chief Product Officer of Cerbos, an open-source authorization platform, and a co-chair of the OpenID Foundation’s AuthZEN Working Group, which standardizes fine-grained authorization. He contributed to the AuthZEN Authorization API 1.0 and co-authored COAZ and its MCP binding, which bring AuthZEN to AI agent tool calls.

Before Cerbos he spent more than a decade building products and authorization systems at Microsoft, Qubit, Zencargo and several startups. He has written extensively about securing MCP servers and AI agents, and speaks regularly at Identiverse, EIC, Gartner IAM, WeAreDevelopers and ISC2 events (and, in a previous life, Google Cloud NEXT). He lives in London.

Headshot

Download my headshot (JPG, 400 × 400). Use it wherever you need to.

Things I like talking about

  • Authorization for AI agents and MCP. Every tool call is a trust boundary, and you can’t pre-provision an agent.
  • AuthZEN and the standards stack. How AuthZEN, Shared Signals and Transaction Tokens fit together, and what’s usable today.
  • Externalized authorization and policy as code. Pulling permission logic out of the app before it turns into spaghetti.
  • Layered security and zero trust. The Swiss cheese talk, borrowed from aviation safety.
  • Decision governance. Why access reviews stop working once access is computed at runtime.
  • Authorization as a reliability problem. When a permissions bug shows up as an outage.

Get in touch

Email alex@cerbos.dev or message me on LinkedIn. I’m happy to do keynotes, talks, panels, workshops and podcasts, in person or remote.