Om sesjonen
Identity governance is often a graveyard of accumulated permissions — years of role changes, project access, and forgotten entitlements quietly compounding into a sprawling attack surface. At Norges Bank Investment Management (NBIM), we decided to tackle this head-on using AI.
Over the past year, we leveraged large language models, intelligent automation, and custom-built AI tooling to conduct a comprehensive identity and access cleanup across our organization. The result: over 10,000 stale or excessive access entitlements identified and remediated — accumulated over nearly a decade — dramatically reducing our identity attack surface.
But cleanup was just the beginning. We built an ecosystem of AI-powered tools to make identity governance sustainable and accessible to the entire organization: interactive dashboards for access intelligence, MCP (Model Context Protocol) integrations for real-time identity data querying, AI-powered chatbots for self-service access insights, and reusable AI skills that enable non-security staff to make informed access decisions.
This talk walks through our end-to-end journey — the technical architecture, the organizational change, the wins, and the hard lessons — so you can take practical ideas back to your own environment.