Who’s on this one
Alexis Moyse — CEO & Co-Founder, Clarity Security. Builds identity governance for teams who have run enough quarterly access review campaigns to know what the approvals are worth. Her argument: the category was designed to satisfy auditors, not to reduce risk, and those turned out to be two different jobs.
Stas Bojoukha — Founder & CEO, Compyl. 20+ years as a CISO across financial services, real estate, and energy.
Daniel Tangney — Host, GRC Radio.
Who should be in the room
- GRC and compliance managers — you run the quarterly campaign. This is about getting something out of it besides a signature.
- CISOs and security leaders — a clean way to tell an exec team that a passing review is not the same as controlled access.
- IAM and identity owners — including whoever just inherited the service accounts and AI agents nobody scoped.
Run of show
Forty-five minutes, no slides. A real conversation, then your questions.
- How we got here — SOX, documented proof, and a generation of tools built to produce audit trails rather than reduce risk.
- What a passing review actually proves, and what it leaves wide open.
- The four-step move from a periodic, documentation-first review to one that changes access.
- First 30 days — what Alexis tells teams to fix using the tools they already own.
- The identities nobody scoped — every AI agent you deploy has real access, provisioned fast and reviewed by no one.
- Live Q&A — open floor. Bring the review campaign you are dreading.
