---
title: "Your AI Agents Have God Mode (And Nobody Vetted Them)"
episode: 111
podcast: "The LeanScale Podcast"
publisher: "LeanScale"
guest: "Mark van Oppen"
guest_title: "Chief Revenue Officer"
date_published: 2026-09-04
date_modified: 2026-09-14
duration: 00:49:59
word_count: 7648
topics: ["ai-in-gtm", "outbound-sales", "enterprise-sales", "sales-leadership", "demand-generation"]
canonical_url: https://www.leanscale.team/knowledge/podcast/mark-van-oppen-secureauth-ai-agents-god-mode/
source: "LeanScale Knowledge Hub — https://www.leanscale.team/knowledge"
license: "Free to quote and cite with attribution to The LeanScale Podcast."
---

# Your AI Agents Have God Mode (And Nobody Vetted Them) — Full Transcript

> Episode 111 of The LeanScale Podcast, with Mark van Oppen.
> Published September 4, 2026 · 00:49:59 · 7648 words.
> Machine-transcribed and **not diarized** — speaker attribution is inferred, so verify
> attribution against the audio before quoting a specific person.
> Structured breakdown: https://www.leanscale.team/knowledge/podcast/mark-van-oppen-secureauth-ai-agents-god-mode/

## 00:00 — Cold open + intro

**[0:00]** If you can focus and deeply root your actions in solving that customer pain, then you're

**[0:08]** going to do great.

**[0:09]** And that's what the best sellers do.

**[0:12]** My guest today is Mark Van Oppen, Chief Revenue Officer at SecureOff, a go-to-market leader

**[0:18]** who has spent his career selling the least optional technology on earth.

**[0:23]** It's really fun to speak to somebody who's like-minded around the way we approach the

**[0:27]** industry.

**[0:29]** If an agent is using my credentials to execute a task, how is it even technically possible

**[0:34]** to understand if that action is being taken place by an agent versus Anthony?

**[0:40]** Fundamentally, it's not, right?

**[0:42]** If an agent is acting with your unique credentials, I would attribute that action to the credentials

**[0:47]** that are being used, right, to the user identity that's taking that action.

**[0:53]** What are the best ways to build pipeline in 2026 and, you know, is the email dead?

**[1:00]** Do we have to do other things?

**[1:03]** What is filling up your pipeline or the pipeline of your peers in similar roles?

**[1:08]** Yeah, we're taking a strategy of trust.

**[1:11]** So how do you get trust?

**[1:14]** You have to have a customer anecdote.

**[1:17]** You have to have a warm intro.

**[1:19]** You have to have somebody to say, "I think highly of this technology, and I'm a trusted

**[1:26]** voice that will help you earn a first meeting with a prospect."

**[1:32]** I mean, you really, really have to do that, and that's the hard way to do it.

**[1:38]** I really don't feel like there are too many hacks to growth anymore.

**[1:50]** Mark, you've said identity used to be a red light, green light decision, Anthony is Anthony,

**[1:56]** all done.

**[1:57]** What exactly broke that model the day we started handing real tasks over to AI agents?

## 02:03 — Identity used to be red light, green light

**[2:04]** Well, it's a great framing to start this conversation.

**[2:08]** So the first thing that changed was the implicit trust and human-level friction that existed

**[2:15]** naturally.

**[2:16]** I could verify Anthony is Anthony, and I can trust Anthony's judgment as the employee that

**[2:22]** I hired or the customer that is a paying trusted identity that is getting access to my system.

**[2:30]** There was a lot more sort of understanding of who's acting and when and why.

**[2:35]** Now, the emergence of AI as something with a delegated free will, for lack of a better

**[2:41]** term, has created every identity, the potential to run a team of unvetted, unbounded, unsecured

**[2:50]** actors that make decisions based on a loosely defined objective, and that creates a level

**[2:57]** of risk that is exponential in your organizations.

**[3:01]** So not only is an exponentially higher number of unique actors in all of these non-human

**[3:06]** identities that are running around in your organization, but there's credential sharing,

**[3:10]** there is an intrinsic change in what you can trust and who you are giving access to.

**[3:17]** So instead of just giving top-level access to Anthony, I have to pivot and look at assuring

**[3:25]** the right to act at every action layer in an ongoing way.

**[3:28]** Does that make sense?

**[3:30]** It does make sense.

**[3:31]** I'm wondering if there are certain things that people are doing that they don't even

**[3:36]** realize is opening up the level of risk.

**[3:39]** Are there some examples that you're seeing people do right now that's just totally leaving

**[3:43]** them open?

## 03:44 — What your employees are already doing without telling you

**[3:44]** Yep.

**[3:45]** So I think about it in a work context, where whether you are selling genes on the internet

**[3:53]** or you are managing a software as a service, your employees are starting to tinker with

**[4:01]** AI, meaning they've downloaded a desktop client.

**[4:06]** They've started to use AI to formulate emails or to write a little more eloquently or on

**[4:13]** target.

**[4:14]** And no matter how they've set up and started interacting with this new tool that's available

**[4:20]** to them, they're giving it context to get better output.

**[4:24]** And that context could be uploaded files.

**[4:26]** It could be a direct connection to an MCP server or model context protocol server that

**[4:32]** is fronting some proprietary source of data and people don't realize when they're just

**[4:37]** bantering back and forth with Claude, for example, Claude is creating agents to pursue

**[4:43]** and get answers on your behalf or to create the document that you've asked for.

**[4:49]** It is creating and taking the access that it knows about you to go execute some action.

**[4:56]** And the more things you connect it to, sanctioned or unsanctioned, the wider and the more ungoverned

**[5:01]** and unaware the enterprise security controls are to that behavior pattern.

**[5:07]** So if you think about it like the concentric circles of visibility, the most center trusted

**[5:14]** actor is a direct action that is Mark or Anthony and the keys I've given Mark or Anthony to

**[5:19]** take actions that he or she is doing every day.

**[5:24]** But then you start to watch an agent get delegated access pursuing some objective and that agent

**[5:29]** might spawn subagents.

**[5:31]** You might have a recurring or scheduled actor starting to happen, but it's happening whether

**[5:36]** you've sanctioned it or not.

**[5:38]** And I don't know of a business that can completely say there is no AI in our organization because

**[5:46]** people are people and they're going to start using the shiny new toys that are available

**[5:49]** to them.

**[5:50]** And whether it's sanctioned or not, they think they're doing something harmless.

**[5:53]** But all of a sudden it is opening up a vector of risk that the vast majority of businesses

**[5:59]** just aren't aware of yet.

**[6:01]** And I think we're going to see a wave of alerts and news articles around how this is going

**[6:08]** to bite people over time.

**[6:10]** Yeah.

**[6:11]** And I think we have started to see some of this already.

**[6:15]** We saw the open AI agents that were used to hack into the hugging phase and we're seeing

**[6:21]** a couple other kind of large scale.

**[6:24]** I feel like we've needed those big events to start ringing some of the alarm bells because

**[6:30]** a lot of people are just using this as if there's no risk at all and it's like this

**[6:34]** magic wand that you can use with no consequence.

**[6:37]** But now that some of those have started to happen, I anticipate there's going to be way

**[6:40]** more, especially as the models have gotten more powerful.

**[6:43]** I think securing this stuff down is going to become the number one problem for a large

**[6:49]** enterprise.

**[6:50]** Yeah, I firmly agree.

**[6:53]** And there's really three inherent vectors that vulnerability can surface.

**[7:01]** It's credential theft, so a lack of awareness of who aware long lived access tokens are

## 07:05 — Three vectors: credential theft, prompt injection, rogue behavior

**[7:08]** being stored or API keys or whatever the case may be.

**[7:12]** Those are getting handed off or stored inappropriately and they're just being passed around.

**[7:17]** So credential theft is the first one.

**[7:20]** Then there's prompt injection, right, you're seeing the instructions to this agent getting

**[7:26]** taken over by some malicious actor or even just clueless actor where the intended purpose

**[7:34]** goes rogue in some way or goes off the rails in an unintended pattern.

**[7:38]** And then just straight up rogue behavior where an agent is pursuing an objective and it cuts

**[7:45]** corners or accesses information or starts querying or taking action in a way that you

**[7:50]** can't predict.

**[7:52]** So you kind of have those three ways that this will manifest and it's changed the goalposts

**[7:58]** that we're all aiming for, that it's not verifying you are who you say you are, it's verifying

**[8:04]** in an ongoing and continuous way.

**[8:06]** Do you have the right, do you have the permission and is that action appropriately scoped for

**[8:12]** the business purpose behind it?

**[8:14]** And that's an ongoing sort of omnipresent posture that you're going to have to maintain

**[8:18]** in perpetuity with this new world of power tools.

**[8:22]** Yeah, and obviously there's so much pressure to leverage AI to increase productivity, effectiveness,

**[8:30]** efficiency.

**[8:31]** There's board level mandates to have these AI initiatives really kicked off and invested

## 08:36 — The CISO squeeze: becoming the department of no

**[8:39]** heavily into.

**[8:40]** So I think you have those two opposing forces and one role this tends to put in a really

**[8:46]** tough spot is the CISO in an organization.

**[8:49]** And in a world where there's a heightened level of anxiety to get productivity out of

**[8:54]** these super tools, you don't want to be the person that has to say no to everything.

**[9:01]** How should that person be thinking about this and how do you get them in a position where

**[9:07]** you can give people the tools they need, but also have the security that protects the company

**[9:13]** at all, at a whole?

**[9:15]** Yeah, so I think you're touching on a broader theme that we've seen in many, many of our

**[9:21]** customers already.

**[9:22]** The reason they're not all systems go adopting AI without any concerns is that this risk

**[9:30]** is understood by a CISO or by somebody who's thinking about compliance and data leakage

**[9:37]** and they're worried about the idea of what happens if we just say green light across

**[9:43]** all of AI adoption, what happens to our proprietary information, the information that you're now

**[9:51]** making accessible to these different models.

**[9:54]** And that's put the CISO in a position of being the department of no, just a big old stop

**[10:01]** sign around driving AI adoption.

**[10:04]** And what we endeavor to do is allow that CISO to be the department of yes.

**[10:10]** We want to help them green light the adoption of a variety of tools.

**[10:15]** And like I said before, it's happening whether it's sanctioned or not.

**[10:19]** So we want to help you get guardrails, be able to deal with the workforce identity,

**[10:24]** be able to deal with the customer identity and be able to deal with all these non-human

**[10:29]** delegated identities from the different humans out there, right?

**[10:32]** The humans aren't going anywhere, but the agents are also there.

**[10:36]** And so can you manage a behavior pattern?

**[10:39]** Can you attribute every action to an audit log?

**[10:42]** Can you maintain a zero trust posture throughout all the different identity types?

**[10:48]** And can you do so in a way that keeps you compliant?

**[10:51]** Can you do data redaction at the agent level?

**[10:56]** And the answer is yes with Securoth, but it's not a one-trick pony.

**[11:01]** It's not one product to solve this problem.

**[11:04]** It's making sure that you have a holistic approach across human and non-human.

**[11:09]** And you have the credibility and proven scale to do this for business critical customers

**[11:15]** at the largest scale.

**[11:18]** If an agent is using my credentials to execute a task, how is it even technically possible

**[11:24]** to understand if that action is being taken place by an agent versus Anthony?

**[11:30]** Fundamentally it's not, right?

**[11:32]** If an agent is acting with your unique credentials, I would attribute that action to the credentials

**[11:37]** that are being used, right?

**[11:39]** To the user identity that's taking that action.

**[11:43]** So what Securoth does with these non-human identities, right, these agentic workloads

**[11:49]** is actually publishes an identity broker.

**[11:53]** So every agent that is acting on Anthony's behalf doesn't just inherit Anthony's credentials.

**[11:59]** It gets its own unique identity, a downscoped access token based on the objective it's trying

**[12:03]** to solve, much more time bound access, and every action is attributed to an audit log.

**[12:11]** And then there's alerting around what is being done.

**[12:15]** So you have an attributable history across every action being taken.

**[12:20]** You can look at like how many tokens were consumed by agent, by user, by team, by department,

**[12:26]** and you can look at and set policy around the ROI of certain adoption of these tools.

**[12:33]** But you have a level of visibility and control that's rooted in assigning a unique identity

**[12:38]** to the agent itself, and that unique identity, that agent, is attributed to Anthony.

**[12:45]** So Anthony's dozens of agents that are pursuing lovely tasks that are all well-intended are

**[12:51]** owned by a human or by a team, right, and you have an ability to tie that logic together

**[12:57]** so that you can attribute maybe a leftover service that's just sitting there and churning

**[13:02]** through tokens.

**[13:04]** Are there any industries you think this is going to be particularly important for, or

**[13:09]** do you think this should be a ubiquitous standard that any enterprise takes on?

**[13:14]** Yeah, I think the term we've started using is continuous authority, meaning you have

**[13:19]** a continuous authority verification attributed to every action, right?

**[13:25]** Does this person have the rights to do it?

**[13:27]** Does this identity, whether it's human or non-human, have permission?

## 13:28 — Continuous authority — and who feels it first

**[13:32]** And should they have permission to do it?

**[13:33]** So everything's downscoped, and I think that's the posture that everybody will need to maintain.

**[13:38]** I think that's just the evolution of where identity security is going.

**[13:44]** But it's starting to happen, and it's starting to come to the fore in really sort of midsize

**[13:53]** companies first, right?

**[13:54]** Think of it, maybe $100 million to $1 billion in revenue.

**[13:59]** They have hundreds of employees, but maybe not thousands.

**[14:03]** And they are modern enough that they're starting to really adopt these tools.

**[14:10]** Lots of the software development departments are AI-assisted, and they're leaning into

**[14:17]** cloud code.

**[14:18]** They're leaning into these tools, and they don't yet have attribution.

**[14:22]** That's a pretty sophisticated audience, so they haven't yet started running into sharp

**[14:26]** corners in the dark, getting bit by these problems yet, but they will.

**[14:31]** And right now, there's a really big miss in that audit log, and being able to verify,

**[14:38]** is it Anthony taking action, or is it some delegated actor on Anthony's behalf that is

**[14:43]** taking that action?

**[14:45]** And eventually, I think that's going to show up in compliance standards, in ISO standards,

**[14:50]** in SOC standards, in all kinds of sort of data access and sovereignty controls.

**[14:57]** People are going to worry about the delegated permissions that are existing in this sort

**[15:03]** of ungoverned pool of free will and judgment that didn't used to exist.

**[15:07]** It's effectively a sub-employee that you have a background check to that is starting to

**[15:15]** take action with your data, so it'll have to be treated in a really first-class security

**[15:20]** way.

**[15:21]** Yeah, I think the moment I started to get a little nervous was when I was experimenting

**[15:27]** with Open Gla, and making sure, hey, oh wow, this is so powerful, I need to have a dedicated

**[15:33]** machine, or at least a virtual machine that needs to be off my computer, because it can

**[15:36]** go into anything.

**[15:39]** And I named him Ben, and Ben did a lot of fantastic work for me.

**[15:44]** But I think that was the first time.

**[15:46]** And sitting in a founder's CEO seat, I do have God mode access to everything at Lean

**[15:51]** Scale.

**[15:52]** I can see the credentials, I can see the HR system, I can see all of our customers' data,

**[15:58]** I can see anything.

**[16:00]** So my credentials passed down to AI agents.

**[16:07]** Pretty alarming.

**[16:08]** And could potentially create artifacts that end up being public, or it's connected to

**[16:15]** my email, it's connected to my Slack, it could accidentally pull some data over here and

**[16:19]** Slack it to someone over there, so we have had to be very intentional about our security

**[16:23]** on AI.

**[16:26]** Not only having the right tools to monitor things, but also just structurally how we

**[16:31]** build and connect the different tools that we're using.

**[16:34]** So I think it's a massive, massive problem.

**[16:38]** And also, if you do it right, can unlock the productivity in a real way.

**[16:45]** But if done wrong, the risks are pretty severe.

**[16:48]** Yeah, I totally agree, and I think it's a good example to talk about OpenClaw and talk

**[16:54]** about the varying sophistication of a user.

**[16:57]** Because you are aware enough to be worried that you're delegating this kind of access.

## 17:03 — The vibe-coding C-suite and the pregnancy forecast

**[17:05]** But we had an enterprise customer at a significant scale joke that their biggest security concern

**[17:14]** is vibe-coding C-suite members.

**[17:17]** People that are very senior level that have really significant asks who are starting to

**[17:22]** vibe-code and create forecast models, but they're just clicking through consensus and

**[17:26]** giving access to really significant reaching identities.

**[17:33]** And we had one start building a forecast model that started predicting whether or not the

**[17:39]** women in the company were pregnant based on capacity, and it's like, "Okay, you can't

**[17:42]** do that."

**[17:44]** There's limitations around the data you can and can't use.

**[17:48]** And of course, an agent doesn't have that judgment, doesn't have that human context,

**[17:53]** doesn't have the sense of PII or not, unless it's been trained in a very anomalistic way.

**[18:00]** And so you start to think about the skepticism and the sort of critical eye of the operator,

**[18:09]** and they have to respect the fact.

**[18:10]** They have this massively powerful risk generator that could also really make them this force-multiplying

**[18:17]** worker on your team.

**[18:19]** But there are some foot guns to be aware of.

**[18:23]** Hang on.

**[18:24]** I have to double click on that story.

**[18:25]** First of all, is that real?

**[18:27]** They built a forecasting model that was predicting what women in the company would get pregnant,

**[18:33]** and then two, what executive was that?

**[18:36]** Were they in sales?

**[18:37]** Were they in...

**[18:38]** I hope they weren't in HR.

**[18:39]** No.

**[18:40]** There was a senior executive in a fintech, and they were thinking about capacity models

**[18:46]** of their team.

**[18:47]** They were talking about productivity across departments, and it was a complicated forecasting

**[18:50]** model.

**[18:51]** But one of the things they had access to was an HR system, a couple of the demographics

**[18:58]** of their workforce was one of the pieces they had information about.

**[19:02]** And part of the reasonable actions that the agent was taking was forecasting availability

**[19:09]** of the workforce.

**[19:10]** And okay, they took date ranges, they took age ranges, they took gender, they took location,

**[19:15]** they took seasonality.

**[19:17]** And one of the things it started inferring was who was pregnant, who might become pregnant.

**[19:23]** And obviously, that's not information you can make a capacity planning decision around,

**[19:30]** and because it's a protected category, reasonably so.

**[19:34]** And they did the right thing.

**[19:35]** As soon as they realized that was happening, they omitted the data, they added a few more

**[19:39]** controls, but it's an example of giving an agent or giving a model, an objective, reasonable

**[19:46]** forecast planning, but the absence of human judgment around what can and can't be used

**[19:52]** in that discussion or in that exercise.

**[19:56]** Right.

**[19:58]** That's absolutely insane.

**[19:59]** And I think a really good example, especially for senior executives that do have very, very

**[20:05]** high access, and they may not be realizing what they're delegating down, I think.

**[20:10]** Yeah.

**[20:11]** Another one that was an interesting trait that popped up that was not quite the C-level

**[20:16]** problem.

**[20:17]** It was a read-only staffer in the finance department inadvertently correlated and exposed

**[20:22]** the exit package of an outgoing CEO, which of course is legally protected and all kinds

## 20:23 — The agent that exposed a CEO's exit package

**[20:29]** of non-disclosure protection there, but the timing, the line item in a budget, and the

**[20:38]** sort of association of the information that was accessed by this agent that, again, was

**[20:44]** looking at budgets and forecasts and capacity kind of stuff, it put two and two pieces together

**[20:49]** that a human wouldn't necessarily have been able to do or wouldn't have done it because

**[20:53]** it's that would have been reaching pretty far beyond, but wide-reaching information sets

**[20:59]** that they can then be sort of correlated, exposed something that was supposed to be

**[21:04]** private.

**[21:05]** Yeah.

**[21:06]** And especially in a lot of these cases, people are trying to get to the point where you can

**[21:10]** get to multiplayer mode with an agent.

**[21:12]** So the agent-based employee that many people can interact with, where it has a set of skills,

**[21:21]** it has its own connection to certain systems, and I was kind of using Ben that way.

**[21:26]** So Ben, I had him connected to the finance systems, I had him connected to our HR system,

**[21:32]** I had him connected to our PM system and our CRM, so he had access to everything.

**[21:38]** And people started using him for certain things like, "Oh, we want to do a forecast report

**[21:42]** over here.

**[21:43]** We can use XYZ over there."

**[21:45]** And then I quickly realized, somebody can just ask Ben what so-and-so salary is or

**[21:51]** somebody can just ask Ben why this person is on leave because he has access to my Slack.

**[21:57]** And as soon as we kind of opened it up in that way, then it was like, "Okay, we got

**[22:01]** to shut this down and reel it back."

**[22:04]** Exactly.

**[22:05]** And that's the sort of well-intentioned effort that starts to expose things that you didn't

**[22:11]** initially consider.

**[22:14]** And that skeptical sort of zero trust posture is the responsibility of a CSO to maintain.

**[22:22]** And so they're put in this uncomfortable position to be the Department of No and saying, "I

**[22:26]** need to limit the use of this because, oh my goodness, there are so many downstream

**[22:31]** effects of the widespread adoption of AI."

**[22:34]** But at the same time, the board, the investors, the employees are all clamoring to use these

**[22:39]** tools and lean into them and they're moving so fast that the power of these tools is so

**[22:45]** alluring.

**[22:46]** And so they're getting adopted and they're getting used and people don't quite realize

**[22:52]** it's a harmless use of this.

**[22:54]** Even though it's not sanctioned, I'm going to start using this account and I'm going

**[22:57]** to start using this tool.

**[22:58]** And I'm not really connecting it to systems, so it's not that egregious.

**[23:02]** But you start to see this waterfall effect of it's happening whether you like it or not.

**[23:08]** And I'd much rather arm a CSO with a really strong, auditable, defendable and visible

**[23:15]** map of what's happening in their organization and give them the tools to apply policy and

**[23:23]** apply not only budget policy, but data reduction and data security policy to the adoption of

**[23:29]** these tools.

**[23:30]** And it's been a lot of fun to start offering that to CSOs in these enterprises that are

**[23:37]** feeling it for the first time.

**[23:39]** Yeah, I think those guardrails are really important.

**[23:44]** Before starting the Lean scale, I ran RevOps for three companies and one of the CROs I

**[23:47]** worked with, he would always say, "You know what helps a race car go very, very fast?

**[23:55]** Breaks."

**[23:57]** Because if you don't have breaks, then you can't just let the engine run and open it

**[24:02]** up as much as you want.

**[24:03]** You have to be able to stop yourself from getting in a crash.

**[24:07]** So I think in a lot of ways, it's this too, it's like, "Hey, yes, we can be hyper productive,

**[24:11]** but we got to put those guardrails in place first."

**[24:13]** I'm curious.

**[24:14]** Yeah, I really like that phrase.

**[24:15]** I'm totally going to steal that because that's a great example of something that's nonintuitive

**[24:22]** and a counter control that allows you to move fast with confidence.

**[24:26]** Well, his name is Tom Miller.

**[24:29]** He wrote the book, Call Your Shots.

**[24:31]** That's an excellent go-to-market book and he has plenty of colorful metaphors and analogies

**[24:38]** that I steal all the time.

**[24:40]** So I think you have to pay him a royalty, but it should be fine.

**[24:43]** All right, I'll be sure to look it up.

**[24:46]** So I know you're sitting in a CRO role today.

**[24:51]** AI has impacted go-to-market quite a bit in pretty much every aspect.

**[24:57]** It's completely changed the dynamic of how you get in front of customers, how you show

## 25:00 — Every employee now has a spam cannon

**[25:04]** up in the market, and a lot of things are changing.

**[25:08]** It's changing so quickly.

**[25:09]** I started LeanScale in 2021.

**[25:11]** We did RevOps.

**[25:12]** Mostly it meant some Salesforce and HubSpot work.

**[25:16]** Now we're building full agent fleets for companies.

**[25:20]** We're building agentic workflows for companies.

**[25:24]** How are you leveraging AI in a go-to-market context?

**[25:30]** We're leveraging AI in a lot of ways, but I think one of the things that's worth just

**[25:39]** noting is that power tools have emerged for BDRs, for sales reps, for RevOps teams, for

**[25:49]** people like me that want to do pipeline inspection, want to do deep analysis of the health of

**[25:54]** deals.

**[25:57]** My favorite term to describe what is now in the hands of every employee is a spam cannon.

**[26:04]** That spam cannon phenomenon is super dangerous unless you have a sense of skepticism around

**[26:12]** it.

**[26:13]** I get cold emails from people soliciting me all the time to sell some various product

**[26:21]** that are way too customized for the level of stranger that I am to them.

**[26:27]** This is not a warm intro.

**[26:29]** This is somebody that's crawled social platforms like LinkedIn.

**[26:34]** They've looked at my history.

**[26:36]** They'll maybe make a reference to where I went to college or something, but it's a level

**[26:41]** of personalization that would be inappropriate for a BDR to do about me, and it sticks out

**[26:50]** like a sore thumb.

**[26:51]** There's this beautiful, very accurate, cleanly researched monologue that's very specific

**[26:57]** to me about why I should take a first meeting with them, but immediately I delete it because

**[27:02]** it smells like AI.

**[27:03]** It smells like something that is a clod skill to crawl all the public data points they can

**[27:10]** find about me.

**[27:12]** I use that as an example to warn my team about what not to do when prospecting.

**[27:19]** We're trying to earn the next engagement, earn the next trust, and that behavior has

**[27:26]** shown up across all kinds of BDRs where you're sort of too specific when you're reaching

**[27:33]** out to somebody and it's clearly inappropriate for the level of relationship you have.

**[27:39]** Maybe try to add value and be specific but concise.

**[27:44]** You're asking them for an investment to read the next two lines, and then you're asking

**[27:48]** for an investment to maybe open this white paper that's specific to them and matters

**[27:53]** to their persona, but you're trying to earn just little by little each further investment

**[28:01]** in your communication, especially when it's cold.

**[28:05]** Does that answer the question or should I talk about some of the tooling or how we're

**[28:09]** using AI among our staff itself?

**[28:11]** No, I think we can get into that too, but one question I have, what are the best ways

**[28:18]** to build pipeline in 2026?

**[28:24]** Is email dead?

**[28:25]** Do we have to do other things?

## 28:26 — Is cold email dead? Building pipeline on trust

**[28:27]** What is filling up your pipeline or the pipeline of your peers in similar roles?

**[28:32]** Yeah, we're taking a strategy of trust, so how do you get trust?

**[28:38]** You have to have a customer anecdote.

**[28:41]** You have to have a warm intro.

**[28:43]** You have to have somebody to say, "I think highly of this technology and I'm a trusted

**[28:50]** voice that will help you earn a first meeting with a prospect."

**[28:56]** So we're using things like a prospecting tool that looks at all of LinkedIn connections

**[29:03]** and 10Q posts from public companies and seeing what they're saying, maybe analyst panels

**[29:13]** and speaker panels.

**[29:14]** We're looking at all this public information and trying to correlate who we might know

**[29:19]** so we can get a warm door opening and handshake there.

**[29:24]** Maybe there's common history in their employment, maybe there's a warm intro among our investors

**[29:31]** or their investors or some mix there, but it's establishing trust early.

**[29:38]** What I don't want to do is truly cold approach them without some level of trust that can

**[29:45]** be corroborated from a perspective they care about.

**[29:48]** Whether it's me, whether it's a common connection point, whether it's a common former employer

**[29:54]** or something like that, there's got to be some trust earned and established.

**[29:59]** So that's really the nucleus of how we're trying to approach new logos.

**[30:04]** Anchor to trust somehow.

**[30:06]** Yeah, I think that's always the number one way to get in front of a prospect to get referred

**[30:12]** in by a peer or have them see a company leveraging your product as well.

**[30:26]** The only thing I think about in that context is can it go fast enough?

**[30:30]** These companies that are, you just raise your Series A, you raise your Series B, there's

**[30:34]** quite a bit of pressure to grow quickly and keep up with momentum and you likely made

**[30:39]** a lot of promises or in the fundraising process too.

**[30:42]** So can you, although it's effective, can you scale it and can you accelerate it and can

**[30:50]** you inorganically move it forward fast enough to keep up with the growth that you have to

**[30:54]** achieve?

**[30:55]** Yes, and I think that comes from credibility.

**[31:01]** So you're familiar with SEO and have you heard and started talking about AEO?

**[31:05]** Oh yes.

**[31:06]** Yeah.

**[31:07]** We've had a couple of platforms that...

## 31:10 — AEO, indexed content, and scaling the warm intro

**[31:10]** We've had a couple of platforms that help companies optimize for AEO and yeah, a couple

**[31:16]** of AEO engineers, so absolutely.

**[31:20]** Yeah.

**[31:21]** So I think the way to scale that is thought leadership pieces, the case studies, robust

**[31:30]** documentation around specific problem statements that are written in a pattern that's crawlable

**[31:36]** and searchable and indexable and that will help you show up.

**[31:40]** When somebody starts asking an LLM how to solve this problem, they're using phrases,

**[31:47]** they're using terms, they're framing this and you have to have written content that

**[31:52]** can be picked up and that can be indexed by those.

**[31:55]** Otherwise, you're not on the list of potential vendors for this problem and then you magnify

**[32:01]** that with the best sort of warm intro indexing possible.

**[32:07]** And that takes a lot of effort, but there are some really cool tools out there that

**[32:10]** help you magnify and take advantage of your executive team's extended network, your investor's

**[32:16]** extended network and everybody else in the company's extended network where you may be

**[32:20]** able to earn a warm intro that then gets bolstered by the credibility of the sort of indexed thought

**[32:27]** leadership pieces that are out there.

**[32:29]** But it makes it just a little less cold when you're reaching out to a target account.

**[32:35]** Absolutely.

**[32:36]** No, and I think you have to have some proprietary content, you have to have some opinionated

**[32:44]** takes on something and then you have to show up on other people's sites as well and be

**[32:48]** mentioned in other areas and it takes a lot of investment.

**[32:52]** So I know we talk a lot about, you know, LeanScale invests quite a bit in content.

**[32:57]** We do podcasts, we do educational content, we do newsletters, we do white papers, case

**[33:01]** studies, the whole thing.

**[33:03]** And it takes a long time, but once you have been doing it consistently, it really starts

**[33:08]** to compound and it's a tough thing to replicate and keep up and you can't do it through just

**[33:16]** AI ghost writing a million articles about something like you actually have to get credible

**[33:22]** companies and sources to also co-author content with you.

**[33:28]** So it's a huge moat if you invest in it.

**[33:31]** Are there any tools that you're using that are helping with this, especially you mentioned

**[33:38]** LinkedIn mining connections, because I think that's an interesting one where, yes, I have

**[33:43]** 8,000 connections on LinkedIn, but I probably really only know and could make an intro to

**[33:50]** about 1 to 200 of them.

**[33:54]** How are you navigating that?

**[33:55]** Yeah, we use a tool called Vue.

**[33:58]** So V-I-E-U and it's been helpful for us to just take the monetization of our extended

**[34:11]** leadership team and investor team's network out of their hands and put it in the hands

**[34:16]** of a seller.

**[34:17]** So a seller can say, "Hey, I want to go after Acme Company.

**[34:20]** Who do I know but Acme Company?"

**[34:22]** He or she can put this information into Vue and Vue can say, "Okay, well, you have several

**[34:29]** paths to a secondary connection and there was a common thread or somebody who knows

**[34:35]** this board member spoke on a panel together and had this thread or this connection point,"

**[34:42]** or "They had a breach last year.

**[34:44]** This was the attributed fault.

**[34:46]** This is somebody who gave commentary on the article that wrote about it and they're connected

**[34:53]** to your company in this way."

**[34:55]** So it'll really map all the publicly available sources and allows you to seek that warmer

**[35:02]** intro where it's not definitively saying, "I, Anthony, have a first party connection

**[35:07]** that I would remember."

**[35:08]** It's not really for those 200 connections that you feel good about introducing.

**[35:12]** It's to actually do something useful with a whole bunch of data points that are more

**[35:18]** complex and nuanced and complicated than you would know first person about yourself and

**[35:23]** putting the action to mine that context and that data in the hands of my sellers instead

**[35:28]** of counting on you to just remember the correlation or a connection across everybody you may have

**[35:35]** connected to over the last 15 or 20 years.

**[35:38]** Yeah, and I think there's just so much data to be going through, and I think if you're

**[35:43]** manually trying to go through your LinkedIn or manually trying to go through your connections,

**[35:46]** it's really, really difficult.

**[35:48]** But knowing that that's the key, like any edge you can get into the warm intro space,

**[35:55]** of course also backed by content and searchability, I mean, you really, really have to do that.

**[36:02]** And that's the hard way to do it.

**[36:05]** I really don't feel like there are too many hacks to growth anymore.

**[36:11]** It's like you have to do this the good old fashioned hard way and compete really, really

**[36:17]** heavily because everybody is weaponized with all of these AI capabilities too.

**[36:21]** Yeah, very, very much so.

**[36:23]** And one of the things that's important is that it's not just looking at LinkedIn data.

**[36:29]** It's looking at interests, right?

**[36:31]** Maybe there was a comment made publicly on Rossignol, a brand that makes skis.

**[36:38]** And so you know this person that happens to be a CTO at Acme company or even a CISO at

**[36:44]** Acme company, it likes or follows a social account of a ski manufacturer and has interacted

**[36:52]** with their content about excited to use this new product that launched last fall.

**[36:57]** You start to associate that person has an interest in skiing.

**[37:02]** I can use that as a way to set a first meeting because you know that that's a kind of an

**[37:09]** uncommon level of depth and correlation.

**[37:13]** And so what Vue does and what we're trying to teach our team to do is use all available

**[37:19]** context you can to put together a really hard set of data points about your target customer

**[37:27]** so that you can be super specific.

**[37:30]** But you do it in a way where you're not going to immediately launch an essay at this target

**[37:36]** that feels creepy and too deep.

**[37:41]** You want to do it where you're offering them something of value.

**[37:45]** You're hooking them with a direct reference to something you know they're interested in

**[37:49]** based on the context you've put together and then earning a little further investment,

**[37:53]** every one of those interactions, so that you can get to a meeting, ultimately a meeting

**[37:58]** where then you earn a demo and you earn a pilot or an investment in your desired outcome.

**[38:07]** Are you seeing all these tools kind of raise the floor of your current reps or is it your

**[38:15]** really good reps that are taking this and just 10X'ing their productivity?

## 38:21 — Does AI raise the floor or 10x your best reps?

**[38:21]** It's a little bit of both.

**[38:22]** And I have to share that I was an AI and a meeting recording skeptic, right?

**[38:31]** The first sort of tools that showed up were things like meeting recorders and automated

**[38:37]** notes and summarized action items that took the transcript of these meetings.

**[38:43]** And my reaction was, oh man, that hides the lazy reps because all of a sudden they're

**[38:48]** not actually taking notes in real time and capturing the follow-on items.

**[38:53]** It's getting automated for them and I actually don't know.

**[38:56]** Are they good at doing this themselves?

**[39:00]** Do they have command of this or is it all sort of hidden by automation?

**[39:04]** Now is that a bad thing?

**[39:06]** Maybe not.

**[39:07]** It's in raising the floor of your more mediocre reps.

**[39:12]** But what I started to see was that it also turbocharged your most capable reps.

**[39:18]** And I became a believer after we actually installed and started using Gong at my previous

**[39:26]** employer and a lot of the reps started leaning in to not only the initial summarization and

**[39:33]** action items that it was surfacing in that tool, but they started using it to build customized

**[39:40]** material.

**[39:41]** They were starting to use it for custom follow-up, for prospecting, for all kinds of more detail.

**[39:49]** And if they brought a level of skepticism, it didn't come across as creepy.

**[39:54]** So my initial concern was that it would hide my low performers and make it harder to tell

**[40:00]** who really had command of their deals.

**[40:04]** But how it's borne out is people leaned in to the tools and started using it and all

**[40:10]** of a sudden they're able to accomplish their business and they know their business well

**[40:17]** enough to defend it in conversation, which gives me a lot of comfort that they are deeply

**[40:22]** involved.

**[40:23]** They're just using power tools that didn't exist when I was in that role.

**[40:28]** What did it do to your good reps?

**[40:29]** So it sounds like, okay, help some of the, we'll call them poor performers, catch up

**[40:34]** to maybe what the good ones were already doing.

**[40:37]** Are they even or are your good ones taking it to another level?

**[40:42]** The good ones are leaning into ways that they can automate manual tasks.

**[40:49]** So I have one guy who started building a prospecting list and he could have done this manually.

## 40:59 — The $30 prospecting list

**[41:00]** He could have built this target list of 50 accounts or whatever it was over the course

**[41:05]** of a day and done all this research himself, but he took the initiative to build a custom

**[41:10]** Claude skill, gave it, started training it and giving it context of here's an example

**[41:16]** of all the dialogue I had in a deal that we lost.

**[41:18]** Here's one that we won.

**[41:19]** Here are the traits that mattered.

**[41:20]** Can we find a list that were in, you know, these parameters that have might have similar

**[41:25]** pain points.

**[41:26]** And all of a sudden he had a targeted list in his territory with a likely buying committee

**[41:33]** identified and he was able using secure off to send me the cost of tokens that it burned

**[41:40]** to do this task.

**[41:42]** And it was like $30, right?

**[41:44]** Like it was, it took 30 minutes cost $30 and he could have put that together over the course

**[41:51]** of two full days work maybe.

**[41:54]** But I was thinking, oh my goodness, if you're willing to lean into these tools available

**[41:59]** to you, you can make a decision and be a force multiplier for your very best reps when it

**[42:04]** comes to sort of being a targeting system for your prospecting efforts.

**[42:09]** And he started doing that.

**[42:10]** It was really fun.

**[42:11]** So I think these AI tools were just scratching the surface of how they become a force multiplier

**[42:21]** for all kinds of roles and the sellers that are curious, that are willing to learn that

**[42:26]** are not stagnant in the way they work are going to be the most successful and we're

**[42:34]** seeing it in real time in our organization.

**[42:39]** Is there anything in your opinion that cannot be facilitated or done by AI that, hey, this

**[42:48]** is where the sales team really holds their ground and adds their value where AI is not

**[42:55]** replacing that?

**[42:57]** I think it comes down to empathy, right?

**[43:00]** Empathy is something that can't be replaced.

**[43:03]** I was speaking to a previous colleague recently and we used the sort of the casual term of

**[43:12]** you can't teach, give a shit.

## 43:13 — You can't teach give a shit

**[43:14]** You can't teach somebody showing up with deep empathy for how this problem is affecting

**[43:21]** that customer.

**[43:22]** And AI is clinical in how it diagnoses information and spits out a result, right?

**[43:31]** A really good seller can look at how a problem is manifesting in a specific customer and

**[43:38]** say, okay, I'm going to tailor my response to be an extension of their team and focus

**[43:44]** on the business outcome that matters to them.

**[43:47]** And if that works out, the byproduct of that is using our product, excellent, then they

**[43:52]** pull you across the line.

**[43:54]** But that sort of human judgment and empathy is not something that AI will be able to replace.

**[44:01]** I think it takes a level of earnest care from a seller to anchor to a business problem and

**[44:09]** how it's actually hurting a specific customer because they all are a little different, right?

**[44:14]** All these businesses are a little different.

**[44:16]** All these people's jobs are a little different.

**[44:18]** And if you can focus and deeply root your actions in solving that customer pain, then

**[44:26]** you're going to do great.

**[44:28]** And that's what the best sellers do.

**[44:30]** Yeah, and I think definitionally, if you have a friend who's listening to something tough

**[44:35]** you're going through, having a human hear it is the part that's adding value and empathize

**[44:44]** with you, as you mentioned, versus I could get some text back, but it doesn't count because

**[44:49]** it's not a human that is really taking some of that burden on.

**[44:54]** Because I think when you're still selling to people, people are people, and you have

**[45:01]** to build that empathy and they have to feel heard.

**[45:04]** They have to feel like, I'm stealing that one by the way, you can't teach give a shit.

**[45:08]** So that's my new, I'll trade you Tom Miller's quotes.

**[45:14]** But that in essence is what makes it so important and what builds that trust.

**[45:20]** And then also you're on the hook for it, you're accountable.

**[45:25]** Somebody on the other side, if something goes wrong there's potential justice to be served.

**[45:30]** So I think all those components are really, really hard to strip away.

**[45:34]** Yeah, it is after all about people.

**[45:40]** Years ago a politician got in trouble for basically saying corporations or people or

**[45:46]** whatever the quote was that ultimately didn't land well for obvious reasons.

**[45:52]** But companies aren't actually the topic that tends to matter.

**[45:59]** It's the people within those companies where that pain manifests and if you can help solve

**[46:04]** the problem for the people, then the companies will do business together because you are

**[46:10]** actively making their life easier.

**[46:13]** And that's what we strive to do and one of the things that just gets me the most excited

**[46:19]** about my role today at Securoth is that the problem statement has evolved in identity

**[46:26]** security.

**[46:27]** It used to be just human actors and then you had workforce, workforce identity was one

**[46:33]** problem statement.

**[46:34]** And then it was customer identity where you're talking about basically people you pay money

**[46:37]** to or people who pay money to you.

**[46:39]** And the level of friction that they will tolerate and the level of access and credentials and

**[46:43]** sort of customized user experience that you need to serve for them.

**[46:47]** And now you have this new vector of delegated from any human type, delegated access, delegated

**[46:56]** free will and an actor that has to be governed and attributable in some way.

**[47:01]** It's a new problem, it's a new challenge and it's going to show up in different ways across

**[47:05]** different verticals, across different organizations and it's really fun to be in a position that

**[47:12]** can with confidence give guardrails to the whole problem statement.

**[47:17]** And I think that's where legacy identity vendors are just missing the boat.

**[47:22]** It's not like a startup that's just focusing on non-human identities can solve the problem

**[47:28]** in full if they don't have credibility and confidence around all the human identities.

**[47:33]** You have to be able to solve the whole picture and do so in a way that removes the pain and

**[47:39]** allows the CISO to move from the department of no or this big red stop sign or whatever

**[47:46]** it is, roadblock, to enthusiastically green lighting.

**[47:51]** The adoption of these tools because there's confidence in the overall posture and the

**[47:55]** new problem that has shown up in the last really two years.

**[48:00]** Well, Mark, I really appreciate what you're doing in the space.

**[48:05]** I think this is a whole new world for so many people.

**[48:08]** And I think we haven't had, we're starting to, we haven't had too many big headline issues

**[48:14]** just yet, but I know they're on the way and everything you're doing at SecureAuth I think

**[48:19]** is going to give people the right guardrails to be productive, but keep their companies

**[48:23]** and people safe as well.

**[48:25]** And I really appreciate everything you shared on the go-to-market strategies.

**[48:28]** There really aren't any hacks anymore.

**[48:30]** I think you're not going to go crank out the email and LinkedIn spam cannons and get in

**[48:35]** front of people and nobody's going to be responding to it.

**[48:37]** It's the good old fashioned, put out content that adds value and builds trust.

**[48:43]** Look for those warm connections, get customer case studies, get customers talking about

**[48:47]** your product and show up in ways that have an organic connection.

**[48:52]** And as always, I'm a firm believer sales isn't going anywhere.

**[48:55]** I think there's a huge difference between buying from a bot and buying from a human,

**[49:01]** especially if you're selling something that is mission critical to that person's job and

**[49:06]** livelihood.

**[49:07]** It's very tough to build that trust without a human interaction.

**[49:11]** So Mark, thank you for being on the podcast.

**[49:14]** Thank you for doing what you're doing.

**[49:16]** Thank you for sharing what you shared and I can't wait to see what you and SecureAuth

**[49:20]** do next.

**[49:22]** Thank you very much.

**[49:23]** It's been an absolute pleasure and it's really fun to speak to somebody who's like-minded

**[49:28]** around the way we approach the industry and it'll be a lot of fun to go through this next

**[49:33]** macro change with everybody as we all try to adopt AI and get confident in mitigating

**[49:41]** the downsides of a new and exciting technology.

**[49:44]** Yeah.

**[49:45]** Well, things are changing so fast that we need to keep each other up to speed.

**[49:50]** So I appreciate you sharing and thank you.

**[49:53]** Great.

**[49:54]** Thank you.
