Identity Team - Q2 Roadmap
46 turns · 10 min captured of 48 min stated?Only the captured portion exists in the database. The remaining 38 min of this call was never transcribed, so nothing said in it appears anywhere in this application.
Showing 46 of 46 turns · 27 turns were used as evidence for at least one fact.
- Alex ReyesAegisCloud0:05turn 0ASR 89%
Alright, I think we've got everyone — Sofia, you just joined right?
- Sofia PetrovAegisCloud0:09turn 1ASR 97%
Yeah, sorry, I was just finishing up a Slack thread with the Detect team about the post-mortem follow-ups.
- Jordan WhitfieldAegisCloud0:17turn 2ASR 94%
Oh no worries at all, we were just doing the usual five minutes of 'can everyone hear me' so you didn't miss anything.
- Mike RomanoAegisCloud0:26turn 3ASR 96%
Ha, classic. Okay so, yeah, are we recording this? I want to make sure the folks who couldn't make it can catch up.
- Alex ReyesAegisCloud0:35turn 4ASR 89%
Yep, recording is on. Okay so — Q2 roadmap planning for Identity. I'm really excited about this one honestly, I think we have a genuinely strong quarter ahead of us.
- Ananya SharmaAegisCloud0:47turn 5ASR 96%
Same, and I feel like Q1 kind of lit the fire a little bit? Like, the Comply v2 launch last week showed what we can do when we're really coordinated, and I want that energy for Identity.
- Alex ReyesAegisCloud1:01turn 6ASR 88%
Totally agree with that. Comply v2 was a good moment for the org. And honestly, Identity has been in a bit of a holding pattern, so I think customers are ready to see some movement from us.
- Sofia PetrovAegisCloud1:15turn 7ASR 94%
Yeah, I've been looking at the support ticket volume and there's a pretty clear cluster around SSO configuration — specifically around just-in-time provisioning. Like, that's coming up again and again.
- Alex ReyesAegisCloud1:26turn 8ASR 91%
Right, and that's actually on my list as a Q2 priority. So let me just share my screen and walk through the draft roadmap so we're all looking at the same thing.
- Mike RomanoAegisCloud1:38turn 9ASR 92%
Perfect.
- Alex ReyesAegisCloud1:40turn 10ASR 96%
Okay so — three big themes for Q2. First is JIT provisioning and SCIM improvements, second is adaptive MFA policies, and third is what I'm calling the Identity audit trail, which ties into the Comply integration story.
- Jordan WhitfieldAegisCloud1:53turn 11ASR 96%
Oh, I love that the audit trail piece connects to Comply. That feels like a really natural cross-module story and honestly something we should be talking about in sales materials too.
- Alex ReyesAegisCloud2:06turn 12ASR 90%
A hundred percent, and that was actually a direct ask from — I think it was the Fortiguard Pro competitive deal we almost lost last quarter? The customer specifically said they wanted IAM events surfaced in their compliance reports.
- Ananya SharmaAegisCloud2:21turn 13ASR 97%
Yeah I remember that one. That was painful. But it's good that it's shaping actual roadmap items rather than just becoming a post-deal retrospective that nobody reads.
- Alex ReyesAegisCloud2:31turn 14ASR 95%
Exactly. Okay so let's go a level deeper on each one. Mike, you've been thinking about the SCIM work — do you want to take JIT provisioning?
- Mike RomanoAegisCloud2:42turn 15ASR 93%
Sure, yeah. So the current state is that JIT provisioning exists but it's kind of half-baked — you can provision users on first login but there's no good story around attribute mapping or role assignment from the IdP side. So what I'm proposing is we build out a proper attribute mapping UI, add support for group-based role assignment, and fix the SCIM endpoint inconsistencies that have been causing sync failures.
- Sofia PetrovAegisCloud3:07turn 16ASR 94%
The sync failures specifically — do we have a sense of scope there? Because I know Ananya you've been in the weeds on that.
- Ananya SharmaAegisCloud3:17turn 17ASR 95%
Yeah so there are basically three distinct failure modes. One is race conditions when you have concurrent provisioning requests, two is the SCIM patch operation not handling partial updates correctly, and three is just some gnarly edge cases around deprovisioning when a user is in multiple groups. None of them are insurmountable but they're all kind of annoying in their own way.
- Alex ReyesAegisCloud3:40turn 18ASR 91%
How long are we thinking for that piece — like, just a rough estimate at this point.
- Ananya SharmaAegisCloud3:46turn 19ASR 91%
If Mike and I take it together I'd say four to five weeks? We'd want to do it properly with good test coverage because the last thing we need is a reliability issue on top of everything the Detect outage already stirred up in terms of customer trust.
- Mike RomanoAegisCloud4:04turn 20ASR 93%
Yeah that's a fair point. The March outage definitely put everyone a bit more on edge about stability. I think that's actually — it's a good forcing function for us to be really disciplined about testing this quarter.
- Sofia PetrovAegisCloud4:19turn 21ASR 92%
Agreed. And I think the customers who were affected by Detect are going to be watching us closely, so any Identity work we ship needs to feel rock solid.
- Alex ReyesAegisCloud4:30turn 22ASR 97%
Okay so let's pencil in JIT and SCIM as weeks one through five roughly. Jordan, for the attribute mapping UI — have you had a chance to look at any of the existing flows? Because I know there's some legacy stuff in there.
- Jordan WhitfieldAegisCloud4:46turn 23ASR 94%
I have, yeah, and honestly it's — it's not terrible but it's also not great. The configuration screens feel like they were designed for an engineer rather than an IT admin, which is probably accurate. I've started sketching out a redesigned attribute mapping flow that uses a more visual drag-and-drop approach and gives you inline validation so you can see if your mappings are going to work before you save.
- Ananya SharmaAegisCloud5:12turn 24ASR 92%
Oh that inline validation piece is really smart, because right now you basically have to save, trigger a test login, see that it broke, go back and try to figure out what happened. It's a terrible loop.
- Jordan WhitfieldAegisCloud5:26turn 25ASR 90%
Right, exactly! And it generates a disproportionate number of support tickets because people just — they don't know what they did wrong. So if we can surface that feedback in the moment it should meaningfully reduce support load too.
- Alex ReyesAegisCloud5:41turn 26ASR 94%
Love it. Okay, adaptive MFA policies — Sofia, this is yours I think.
- Sofia PetrovAegisCloud5:46turn 27ASR 94%
Yeah so the vision here is moving away from static MFA rules — like, everyone in this role gets MFA — toward something that's context-aware. So you'd factor in things like login location, device posture, time of day, whether it's an unusual access pattern. And based on that you can either prompt for MFA, step up authentication, or in low-risk scenarios maybe let it through without friction.
- Mike RomanoAegisCloud6:11turn 28ASR 96%
That's a big feature though, right? Like, are we scoping the full adaptive engine or is this a first iteration?
- Sofia PetrovAegisCloud6:19turn 29ASR 91%
Definitely first iteration. I'm thinking we start with location and device posture as the two signal inputs, build the policy engine to be extensible so we can add more signals later, and ship that as a beta in Q2. Full GA with more signals would be Q3.
- Jordan WhitfieldAegisCloud6:36turn 30ASR 96%
That's a really sensible scope. And I think shipping it as beta is smart — we can get real customer feedback on the policy configuration experience before we commit to the full design.
- Alex ReyesAegisCloud6:49turn 31ASR 95%
Yeah and honestly from a competitive standpoint this is overdue. SentinelShield has had something like this for a while and we keep getting asked about it in enterprise deals.
- Ananya SharmaAegisCloud7:01turn 32ASR 95%
Ugh, yeah. Every time SentinelShield comes up in a deal it's like — okay, what's their talking point this time. But I do think our implementation can be more tightly integrated with the rest of the platform, which is a real differentiator.
- Alex ReyesAegisCloud7:17turn 33ASR 93%
That's exactly the angle. Like, the fact that adaptive MFA signals can feed into the Identity audit trail and then surface in Comply reports — that's something SentinelShield can't do because they don't have the compliance layer.
- Mike RomanoAegisCloud7:32turn 34ASR 90%
Okay so then the audit trail — this is the one I'm most excited about personally. Can we talk through what the data model looks like? Because I want to make sure we're designing this in a way that Comply can actually consume it cleanly.
- Ananya SharmaAegisCloud7:49turn 35ASR 95%
Yeah absolutely. So the idea is that every significant Identity event — login, logout, MFA challenge, provisioning change, role assignment, policy update — gets written to a structured event log with a consistent schema. And then we expose that via an internal API that Comply can query when it's generating reports.
- Sofia PetrovAegisCloud8:08turn 36ASR 92%
And the Comply team is on board with this? Like, have you guys talked to them?
- Alex ReyesAegisCloud8:15turn 37ASR 91%
I had a quick chat with Priya on the Comply team last week, yeah. She was really enthusiastic about it. Apparently identity access events are one of the biggest gaps in what they can currently include in SOC 2 reports, so this would actually unlock a lot for their customers too.
- Jordan WhitfieldAegisCloud8:34turn 38ASR 95%
That's great to hear. I think cross-team stuff like this is where the platform story really shines and it's something we should be doing more of in general.
- Alex ReyesAegisCloud8:45turn 39ASR 92%
Agreed. Okay so — I think we have a pretty solid shape for Q2. JIT and SCIM improvements, adaptive MFA beta, Identity audit trail. Mike, do you want to take a first pass at breaking these down into epics in Jira before our next planning session?
- Mike RomanoAegisCloud9:02turn 40ASR 94%
Yeah I can do that by end of week. I'll also flag any dependencies I see on shared infrastructure so we can get those on the radar early.
- Alex ReyesAegisCloud9:13turn 41ASR 96%
Perfect. And Jordan — are you good to share the attribute mapping designs in Figma this week so the team can give feedback async?
- Jordan WhitfieldAegisCloud9:22turn 42ASR 95%
Absolutely, I'll post the link in the Identity channel tomorrow morning. I'm really happy with where it's heading and I want everyone's eyes on it before I get too attached to any particular direction.
- Alex ReyesAegisCloud9:34turn 43ASR 89%
Ha, the designer's curse. Okay, I think that covers everything — honestly this was one of the more energizing planning sessions we've had in a while. I feel good about where we're headed.
- Ananya SharmaAegisCloud9:47turn 44ASR 90%
Yeah, same. Q2 is going to be a good one.
- Sofia PetrovAegisCloud9:51turn 45ASR 93%
Alright, thanks everyone. Talk soon.