100,000 OAuth Grants Later, Security Teams Still Can’t See the Risk
Security Unfiltered PodcastSeptember 14, 2026

100,000 OAuth Grants Later, Security Teams Still Can’t See the Risk

Joe and Danielle discuss how AI has accelerated an already messy SaaS security problem, especially as employees connect more tools, more agents, and more data without centralized oversight. The conversation focuses on why traditional block or allow controls are breaking down, and how security teams can use agentic automation to reduce risk without slowing the business


00:00 - Why AI adoption is moving faster than cloud and SaaS ever did
01:20 - The professional pressure to skill up on AI now
03:19 - How cloud security and SaaS security lagged behind adoption
06:13 - Why organizations can’t simply say no to AI tools
08:30 - The difference between cloud-era experimentation and today’s browser-based AI
10:37 - Why AI security and SaaS security are becoming the same problem
12:31 - Why traditional onboarding and vendor review processes don’t scale
14:43 - The Salesforce example that exposed hidden risk in a large enterprise
17:00 - Why most third-party risk programs only cover part of the estate
19:07 - How decentralized tech adoption bypasses security workflows
20:31 - Why OAuth grants and third-party integrations are a major attack path
22:25 - Why attackers usually go after credentials and tokens, not zero days
23:19 - How AI lowers the barrier to entry for attackers
26:55 - Why defenders need agentic capabilities too
28:16 - The scale of unmanaged OAuth grants inside enterprises
30:26 - Why no one can hire enough people to review every grant manually
31:53 - How agents can analyze risk and recommend revocation at scale
33:33 - The reality check from customer conversations about AI visibility
35:24 - How security people think when told they can’t do something
38:16 - Reactance theory and why employees work around controls
40:25 - Incentives matter more than policy slogans
41:48 - Why binary block or allow controls create shadow IT
43:30 - How Nudge Security approaches SaaS and AI as one workforce problem
46:14 - Why a workforce edge model matters more than network or identity alone
48:26 - What just-in-time policy decisions could look like in the browser
50:10 - Why policy experience is as important as policy enforcement
52:08 - Danielle on Nudge Security’s free trial and LinkedIn presence

Affiliates
➡️ OffGrid Faraday Bags: https://offgrid.co/?ref=gabzvajh
➡️ OffGrid Coupon Code: JOE

➡️ Unplugged Phone: https://unplugged.com/
Unplugged's UP Phone - The performance you expect, with the privacy you deserve. Meet the alternative. Use Code UNFILTERED at checkout

*See terms and conditions at affiliated webpages. Offers are subject to change. These are affiliated/paid promotions.

Tesla Referral Code: https://ts.la/joseph675128

Follow the Podcast on Social Media!

Instagram: https://www.instagram.com/secunfpodcast/
Twitter: https://twitter.com/SecUnfPodcast
Danielle Russell, Nudge Security, security unfiltered, joe south, SaaS security,