Episode 365 ·

Shiven Ramji - Keeping Engineers Close to Customers, & The Passwordless Future

Today we’re talking to Shiven Ramji, the Chief Product Officer at Auth0. And we discuss tips for taking your career to a new industry. How Auth0 keeps their engineers close to the customers, and the obstacles we will need to overcome to reach a passwordless future. 

All of this, right here, right now, on the Modern CTO Podcast!

To learn more about Auth0, you can check them out at https://auth0.com

About Shiven Ramji:

You’re not much without a product, which is why Shiv brings 15 years of experience in B2B and B2C product management, engineering, operations, and business development to the Auth0 team. Driving everything from product innovation to strategy, Shiv helps guide where Auth0 is going next.

Shiv previously worked with Amazon, NBCUniversal DigitalOcean, and The Nielsen Company. When not talking product, Shiv likes to spend as much time hiking as possible, far far away from the inside of a computer.

About Auth0:

Auth0’s modern approach to identity enables organizations to provide secure access to any application, for any user. The Auth0 platform is a highly customizable identity operating system that is as simple as development teams want and as flexible as they need. Safeguarding billions of login transactions each month, Auth0 delivers convenience, privacy, and security so customers can focus on innovation. For more information, visit auth0.com, or follow Auth0 on Twitter and LinkedIn.

Transcript

(Joel Beasley at 00:00:03) Hello, my friends. Today we're talking to Shiv, the Chief Product Officer at Auth0. And we discuss tips for taking your career to a new industry, how Auth0 keeps their engineers close to the customers, and obstacles we will need to overcome to reach a passwordless future. All of this right here, right now, on the Modern CTO Podcast.

(Shiv at 00:00:29) Here we go.

(Joel Beasley at 00:00:30) This is the Modern CTO podcast.

(Shiv at 00:00:41) Yeah. So, well, I actually started as a — you know, so going way back — started playing with computers and programming at a very early age. By the way, I'm born and raised in Tanzania, so not the same technology exposure as most people in North America or the Western countries would. But, you know, start off very early age, was just fascinated by programming and technology. And then I ended up pursuing computer science and mathematics in college. And then after that, my first job was actually a developer. So I started out as a software engineer. And since you are in the media world, some of this may — you have a good understanding of the media world — you may know about this company. But actually, first company I'd started was Nielsen Media Research. So, you know, the TV ratings company.

(Joel Beasley at 00:01:44) Yeah.

(Shiv at 00:01:44) They do a lot more, obviously. But, and so started as a software engineer building lots of different software products there, and then, you know, had an amazing seven to eight year run there doing software, wearing different hats and growing different businesses. So that was like a phase in media and market research. And then I switched to — I went to Amazon for a couple of years where I was focused more on building their core advertising technology platform, which I think now is on a pretty large run rate. I don't remember the latest numbers, but, you know, it's somewhere around $15 to $17 billion business. It's built a really big business and scaled rapidly there, which was a lot of fun and learned a ton. And so and then I switched away from that, went into more marketing technology, where I worked at an email startup that was delivering customized, tailored advertising in your inbox for a while and then sort of have been in startup land since then. And then I completely changed industries again, went into cloud computing with DigitalOcean, which is building products for developers and competing with the giants of Azure and AWS and thriving by focusing on developers and simplicity. And then after that, you know, the founders at Observe sort of reached out and said, "Hey, we really like what you've done at DigitalOcean. We have a very interesting product for developers solving a really big pain point. Would you be interested in sort of replicating that growth here?" And so that's what led me to Observe. And actually, the backstory was, like, you know, my first project as a software engineer was building a single sign-on portal for Nielsen's field team. And so, you know, when Matthias and Eugenio asked me, "Hey, how would you like to build a product that solves identity?" I was like, I knew the problem really well myself because I've worked on it many, many years ago. So it was a no-brainer. I got the value proposition right away. And then, you know, getting to build again for developers and growing the business at the pace at which we've been growing has been fascinating. And so, so yeah. So that's my little bit backstory.

(Joel Beasley at 00:04:09) That's awesome. That's really cool how it came full circle for you like that.

(Shiv at 00:04:13) It did. You never expect it, and then somehow, you know, you always are able to connect the dots looking backwards. Right? And so this is certainly one of those stories.

(Joel Beasley at 00:04:26) Yeah. So having changed industry so many times throughout your career, do you have any tips for wrapping your head around a whole new industry when you make a big change like that?

(Shiv at 00:04:38) Yeah. I think what's worked for me, and I don't know if these are universal things, but certainly these are things that have helped me is that when you change industries, you kind of bring fresh eyes to the problem. So oftentimes, you know, you're under the pressure, like, you need to be the expert. And so every time I take on a new thing, I don't put that pressure on myself because I actually bring the added benefit of not being an expert. So I can ask lots of questions and understand the industry from the ground up. The other thing is also when you change industries, it's good to be a sort of anthropologist, if you will. Because, and especially if you're a leader or if you're an executive, the tendency is normally to, like, come into a new org or company and start making big decisions. And I don't think that's necessary, obviously. You want to learn a lot about the company, the teams, the industry, the customers first. And so I always start by, you know, learning everything about the product, people, customers, and customers especially. I would really emphasize that when you speak to customers, you will learn a ton about the space. And so those are some things that have really worked well for me. And then, obviously, being open to learning and reading. So I, you know, end up doing that a lot. Like, just a practical example, when I, before I joined DigitalOcean, I was a big consumer of cloud products, but I'd never built cloud products directly. And so, you know, right before joining, I spent a lot of time just learning up about core networking technologies and storage solutions. And, you know, the world had changed, so I had to come up to speed. And similarly with Auth0, one of our principal architects had created a series, you know, introduction to authentication. So went and consumed all of that. So there are other ways you can come up to speed, but you have to be open to — you have to be curious and be open to learning fairly quickly.

(Joel Beasley at 00:06:48) Right. So when you're in that phase of learning about all the people at the company and learning about the customers, how would you — if you had to chalk up, like, a pie chart of how you're dividing your time with all that learning, what are you actually doing with your time, like, talking to customers or talking to people within the company to get context there? What does that look like?

(Shiv at 00:07:12) Yeah. In the first — so I'll share in the context of the journey of where you are in a company or the industry. So, for example, in the early days, if you're totally new to an industry and a company, I end up, you know, the first ninety to one hundred and twenty days, a bulk of my time is spending with customers and with internal subject matter experts who can bring you up to speed fairly quickly. So, you know, again, that's like a fifty-fifty or sixty-forty split, obviously over-indexing on customers first. As you get more familiar and as you start growing and maturing and maybe at a later stage, obviously that percentage changes quite a bit. And, I mean, for me, still I still spend at least 20 to 30% of my time in some way interacting with customer feedback. Now that could be, you know, being involved in a sales process or presenting to prospects. It could be that you are talking to industry analysts where you get aggregate knowledge of a certain space, if you will. And there are other things. You know, these days you get feedback from all channels. On social, people will post on Twitter. If you go to — if you have software product on G2 Crowd, there's always feedback posted there. If you're building a developer product, Hacker News is a great place to go constantly get feedback. And so I always keep tabs on those channels as a way to sort of always be current on what's working with our product. And then another really good asset also typically that's sort of underappreciated in companies tends to be your support teams and your support ticket queue. There are so many golden gems you'll find in your support tickets that will tell you where your product is not working or it's failing to meet the customer's needs. And so, you know, in aggregate, I still spend about 30% of my time with customers and customer feedback. And then the rest of it is really distributed internally across, you know, whether it's making sure that we're executing our current plans with our engineering teams or focusing on some big initiatives or big bets that we have that we may have decided to work on. So it evolves based on your maturity in the company.

(Joel Beasley at 00:09:42) Yeah. Absolutely. That makes sense how you can find a lot of gems in the support tickets, but I'm sure it's gotta be challenging to have the discipline to actually go through those because I'm sure that's not always the most fun thing to do. But can definitely provide a lot of value for improving.

(Shiv at 00:10:06) Yeah. Yeah. We — yeah. And, yeah, it's hard. I mean, it's not easy to scale, but I'll share two examples, maybe, or at least I'll share where I got the inspiration for doing something like this. So when I joined Amazon, Amazon did two really interesting things. I think it was at a certain level, every year or every once every two years, you did two things. You actually went to a customer call center or a contact center, and you spent an entire day listening to customer calls and observing how, you know, the customer contact center representative handled incoming calls and the types of questions that were coming in and how they responded. I thought that was very good because you get a firsthand understanding of the customer perspective. The other thing they also did, and this was mandatory, is that, well, I think it was once a year, you actually spent two or three days at a fulfillment center on the floor helping, you know, picking and packing items so that you understood how the supply chain elements of the product and company work. Right? So I thought that was very interesting because, no matter where you worked in the company, you had these two opportunities that brought you really, really close to what the customer pain points could be. So, for example, when I was at DigitalOcean, we did something similar where we did rotation programs for the product manager team. And what they did was once every few months, they would go spend a few days sitting with the support team because we had some support team members in the office in New York. And, and so it was like a rotation. So they ended up spending, you know — they would pick when they wanted to do that so that it wasn't conflicting with big initiatives or anything like that. And they would go spend time with both support and customer success teams to understand firsthand what types of questions our teams were getting and what type of improvements you could drive out of that. So I think if you can introduce things like that in your teams, especially as you scale, I think those can be points of, like, inspiration to make sure that you're always keeping the customer front and center. And that it also, I think, forces a little bit of a continuous improvement mindset so that you're constantly taking defects or issues out of the system.

(Joel Beasley at 00:12:41) That's really cool. That's something that I wish I heard about more from CTOs and companies in general of doing that, putting engineers directly in front of customers or directly with sales or whatever, because it sounds so useful, so impactful for the engineers to do that. A while ago, we had a company on called Divvy. They're like a payment processing, and they were talking about how they call it empathy hour. And for one hour per week, their engineers have to sit in on sales calls or demos of the product. And he was talking about, again, like what you're saying, how that helped them scale so much and provided a lot of empathy between the engineers and the other parts of the org to prevent siloing. Do you do that kind of stuff at Auth0 today?

(Shiv at 00:13:36) Yes. Uh, couple of examples. So we do that on the product and engineering team, but let's start with product managers first. We do have actively product managers actively joining our sales teams in pitches and doing QBRs with customers. So that's a very good practice that we have. And then we also have our engineering leaders, and the engineering leadership will join. And I'll share two examples. You know, whenever we've had, like, an outage where we had service downtime that, you know, we didn't intend to — you know, because we're sort of like a tier zero critical service — we've had to get on calls with customers so that we can explain, you know, what happened, what are we doing to remediate this in the future, and the types of learnings and actions we have. And it creates a really good, healthy relationship with customers, and so our leaders do that fairly.

(Joel Beasley at 00:14:34) So you kind of have a postmortem with the customers?

(Shiv at 00:14:36) Yes.

(Joel Beasley at 00:14:36) Oh, that's really cool.

(Shiv at 00:14:38) Yeah. We will post our RCAs and postmortems online on our status page, but we will also do calls with our customers, with their customer success team, and walk them through the details and answer any questions that they may have. The other example is when, you know, we have large customers or customers are asking more complex things. You know, I'll just give a recent example. We just built our service to be deployed — so we're deploying on AWS, and now the service is also available on Azure. So there is a pretty large bank that was really interested in our Azure deployment and how we handle security. And so our chief architect in our engineering organization, you know, did several meetings with their CTO and architecture team to make sure that, you know, we were able to explain exactly how we build our products, how do we secure our products. And so, you know, and I remember our chief architect, like, getting firsthand information of, like, "Oh, this is what it is to, like, you know, sell to a really, really large institution," in this case, a bank, and the things they care about and the why behind that. And so I think bringing engineers and even product managers closer to those customer problems, to your point, to your early example, is really, really powerful because they can carry that context into the things they're working on on a day-to-day basis. And so I think this is a general problem. You know, as you're scaling fast and growing teams, I always think of this concept of, and we actually do look at this internally, like, what's the distance between the customer and the team that's building a feature? And I encourage, actually, one of the things I learned is it's a healthy thing to step back every two to three years, depending on how fast you're growing or may have to do it every year too, to look at that distance and say, you know, "Are we far away from the customer?" Because the further you are, the harder it becomes, and there, you know, there are more steps to get to value back to the customer. And so it's something you kind of want to refactor every few years to make sure that you're keeping, you know, that distance is minimized so that the team that's building a feature or a product can really get the — the feedback cycles are shorter, and they can act on that information.

(Joel Beasley at 00:17:11) That makes sense to really be intentional about reevaluating the distance to customer because I think that's definitely something that would be easy to let go if you're not being really intentional about that. But let's take a step back because I don't think we talked about it yet. Can you give me and the listeners an overview of what Auth0 actually does?

(Shiv at 00:17:35) Yeah, sure. So what we really provide is an authentication authorization service to our customers so that they can provide a secure login experience to their customers. And so really, if you say the problem is that every application needs authentication and authorization because you want to know you want to verify that this person is the person who they say they are, and does this person have access to that resource? It's really as simple as that.

(Shiv at 00:18:09) But implementing identity renewal is fairly complex, and mistakes can be catastrophic, as you know, because mistakes in a bad implementation can maybe cost you revenue because your conversion rates or sign ups can go down. And it can add risk to your company because if there is a security breach, a data breach, or noncompliance with privacy regulations, you know, you're at a risk to your business with fines and tarnishing your brand. So we take on all of that burden away, and we've built this identity as a service product. And we make it very simple and easy so that developers can easily configure them, add them to their applications, and can go live fairly quickly. So that's the core of what we provide to our customers.

(Shiv at 00:19:04) And then obviously we do that in we have a free product. Meaning, if you're a developer, you can go to the website today, sign up for an account, and you can have authentication embedded in your application within minutes. That's really cool. And then, obviously, we also scale. As developers or companies scale, we continue to provide additional capabilities and features as they start to mature.

(Joel Beasley at 00:19:28) Yeah. I think that's a really smart business model of giving it away for free at the lowest level, especially for something that's so foundational, like authentication, because I feel like for the most part, once people pick their provider or partner for that, they're probably not going to change it as they scale unless they have some needs that come up that their current partner can't satisfy. But, yeah, that's really cool. So what do you guys do better than the rest of the competitors?

(Shiv at 00:19:59) Yeah. So I always go back to sort of, you know, why do customers choose us? When we speak to them, what are the reasons? So I think there are a few. There are four or five things to touch on here.

(Shiv at 00:20:10) So the first one is really what we call speed and simplicity. So from a developer standpoint, they can very quickly integrate our SDKs or any other APIs, and they can go live fairly quickly. And so I think the number is anywhere about 80 to 90% of our customers go live in less than 30. And the reason is because the product is very easy to use, very easy to integrate, very easy to test as a proof of concept, and so you can go live very quickly.

(Shiv at 00:20:45) So that's a big benefit to our customers. The second one is around control and extensibility. And what I mean by that is when customers use us in this customer identity and access management context, they really want to control the experience, the branding, the type of friction and security that you want to implement. And so we give them the control that they want. But we also allow and we give them out of the box capabilities, but we also give them what we call extensibility, which is you can write your own custom code in the authentication pipeline. So you can do whatever you want to do because there's a good chance that we cover 80% of your needs and use cases.

(Shiv at 00:21:26) For that last 20%, you're developers and you want to write custom code. And so we make that very easy. So our customers love that capability. I think third one is, you know, we've been doing this for many, many years across 9,000 plus global paying customers. So we have lots of identity expertise.

(Shiv at 00:21:49) We are constantly contributing to standards bodies. We are producing content to educate the community about the standards and everything about authentication. And so we bring a lot of expertise so that our customers don't have to, and they really do appreciate that. And then the last two are just scale and security. So we make a lot of investments in securing our product and platform, but we build security features for our customers also.

(Shiv at 00:22:19) And then our service can scale. So we've been, you know, we're available in about 22 different regions globally. So if you have a global customer base or if you have a spiky workload, let's say, for example, the upcoming holiday season, you know, you don't have to worry about scaling your service. We do that automatically. We can auto scale the service up and down based on your traffic needs.

(Shiv at 00:22:46) And so I would say these are the five key reasons why customers come to us versus anyone else, any other vendor that's providing a similar capability.

(Joel Beasley at 00:22:59) Man, you killed that. You went right through it. Bam, bam, bam, bam, bam. Practice, man. Nice.

(Joel Beasley at 00:23:06) So do you find that you guys compete with your customers in build versus buy scenarios?

(Shiv at 00:23:14) Yeah. That's a good question. So that tends to be one of the biggest reasons. A lot of teams, there are really two scenarios. Either they had cobbled some internal solution, and so the decision they're trying to make is, do I want to continue to invest in that, or can I use a service like ours? Or sometimes maybe their use case is so complex that they are like, well, given our needs, we think we should go build it on our own. In either scenario, and this is something we talk to our customers a lot about, there is a very on a tactical basis, there's a cost calculation here, which is, is this something you should be building your expertise on?

(Shiv at 00:24:01) Let me just give you an example. Let's say if you're an online retailer selling flowers. Your expertise is in really building this amazing customer experience, seamless checkout, beautiful imagery so that somebody can buy the flowers that they want and they can get delivered in the time that they want. That is a unique business differentiator. Figuring out how to log in, how to prevent bot attacks, how to verify, is not uniquely differentiating.

(Shiv at 00:24:30) And so the one part of the equation is a very simple thing, which is like, look, is this the best use your engineers' time? And more often than not, the answer is not. We take that burden on so that your developers don't have to. The other part, I think, is a business lens, which I think is probably more important, which is, you know, especially given in the last twelve to eighteen months, given that we all live through a global pandemic, we were seeing an acceleration in digital experiences. I always joke, we all thought QR codes were dead.

(Shiv at 00:25:08) And then here we are. Every time we go to a restaurant, you know, QR codes are saving us. And so, you know, the customer experiences are changing rapidly. Now our customers have to differentiate through those digital experiences. And so I think you have to look at what can this identity as a service or authentication as a service, how can it enable you in achieving those goals? Better frictionless sign up, reducing fraud, reducing credential stuffing attacks or bot attacks. Those are all things that actually impact your top line.

(Shiv at 00:25:46) And so I think the business case here, frankly, is on enabling downstream teams and business teams where they can find and, you know, time to market ultimately. You can go live very quickly. And so those are the reasons, or that's the case really against building it in house. But, you know, we still have lots of lots of customers and teams and applications that still choose to do that. So there's quite a bit of room and opportunity there.

(Joel Beasley at 00:26:16) So do you ever see a client decides to go build it in house instead, but then they have vastly underestimated the undertaking and come back to you?

(Shiv at 00:26:28) Yes. All the time. Nice. And I would have that multiple, multiple times. And, you know, actually, the interesting thing is, of course, this is very pronounced in large companies and you have legacy apps and, you know, you may have an existing in house solution.

(Shiv at 00:26:47) But I find that, you know, we also serve a lot of startups. We have a startup program also where we cater and help them with the startup plan so that they can scale. And you find even when entrepreneurs are building new companies, they make the same choice, which is like, this is not something I should be building. This is really something that I should just get out of the box so that I can scale.

(Joel Beasley at 00:27:13) Nice. Do you guys utilize any AI behind the scenes at Auth0?

(Shiv at 00:27:19) We do have, we do use machine learning models, especially in our anomaly detection engine. Hundreds of features across your login activity and build this anomaly detection engine, which essentially produces risk scores, which tells our customers whether a login is risky or not. And based on that risk score, you know, the customer can configure or decide, do they want to block that login? Should they step up authentication? Should they add another factor or another verification in the process?

(Shiv at 00:28:01) And so, yeah, we've been investing a lot in that in the last two years. And, you know, these products are completely invisible to the customer because the machine learning models are working behind the scenes. But they add a lot of value because we're able to stop a lot of bot attacks on our customers' deployments.

(Joel Beasley at 00:28:24) That's really cool. Yeah. I love hearing about the such wide variety of use cases for applying machine learning. Because recently, I was listening to this other podcast called HPE Tech Talk, which is a tech podcast by Hewlett Packard. And they did an episode with Walt Disney in their studio lab.

(Joel Beasley at 00:28:44) And they were talking about how they actually use AI for anomaly detection in the filmmaking process. Because they used to have these quality control experts that would go through literally every frame of a movie and look for anomalies at the pixel level. So a single pixel miscolored on a single frame of an hour and a half long movie. And they had people doing that.

(Joel Beasley at 00:29:11) And so but now they have AI that's able to do it and find these anomalies. And the quality control people are able to do more critical problem solving on, alright. Now we found this anomaly. Is it worth solving, and how do we go about solving it? And, yeah, I don't know. That's just something I kind of geek out about.

(Shiv at 00:29:32) Yeah. It's a really cool application of the technology too. Because you're saving time and, frankly, you're improving the quality of the movie itself. I didn't even think that that was an application. That's really amazing.

(Joel Beasley at 00:29:43) Yeah. Right? So I saw that Auth0 had a partnership with ThinAI. Are you still engaged with them, and what's that like?

(Shiv at 00:29:53) We've recently launched an integrations marketplace. So we're constantly integrating with downstream providers. And, essentially, this extensible framework that we've built allows us to really connect with other business systems. So let me just give one example. Some of our customers may want to do ID proofing or ID verification.

(Shiv at 00:30:20) The classic example is, you know, let's say you use an app to buy wine from a merchant online, and it got delivered, but, you know, before they deliver, they verify your ID. Same thing with Airbnb and others. But, anyway, so there is some form of verification that says you are who you are. For whatever reason, most of the times, it's due to compliance and highly regulated industries.

(Shiv at 00:30:48) Now we don't provide ID proofing today out of the box. And so what we've done is we've partnered with others who do, and they can easily integrate into our marketplace. And so there are all of these categories of ID proofing and developer tooling, consent management. There's a whole, you know, CRM, web analytics providers, a whole host of categories that we essentially integrate with so that these partners can then provide the value that our customers are looking for. And so we, you know, we now have over 120, 130 new partners that we've added into our marketplace, and the plans are to continue to add more.

(Joel Beasley at 00:31:34) Very cool. So I want to talk a little bit about the passwordless future. It's the current buzzword, I feel like, in your industry that I'm super interested in. Because we recently, on the podcast, had on Zane Bond from a company called Keeper Security. They're a top rated password manager.

(Joel Beasley at 00:31:55) And Zane was talking about the potential for the passwordless future and how there's three different ways to authenticate, whether it's something you know, something you are. And I cannot remember the third one. You're going to have to check out that episode. But I'm just curious from your perspective, what are some of the challenges that you think we need to overcome to get to where we will no longer need passwords?

(Shiv at 00:32:25) Yeah. So there are a few here. So first off, you know, we also want to get to a place where passwords are completely eliminated because they are actually a big attack factor. If you look at most breaches and the like. So there are several things we're doing here. The first one is, you know, supporting existing standards. So, for example, WebAuthn is a standard that's an industry. So we just added support for that where we allow our customers to enroll these additional factors, you know, roaming authenticators or platform authenticators such as, you know, Windows Hello or Apple Face ID, Touch ID. And then we also allow and we allow our customers to enroll their customers progressively.

(Shiv at 00:33:18) So because one of the things in the customer identity and access management space is that unlike, you know, in the workforce or employee use case, you know, you can force your employees to always do two factor authentication or

(Joel Beasley at 00:33:31) Right.

(Shiv at 00:33:32) Or whatever. But for customers who are maybe checking out on your website or they're there to view content or whatever. You have to be you have to only introduce friction if you absolutely need to. And so what we've done is we've allowed progressive enrollment of these new factors, and then now we also allow our customers to set those platform authenticators to be the primary authenticator. So, you know, you don't have to do your second factor and the like.

(Shiv at 00:34:04) So we, you know, this capability was built very uniquely to allow our customers the flexibility to progressively enroll or cut over directly should they choose to. And I think so that's sort of part one. The second part is really around making sure that we can verify who that person or customer is. So, for example, you know, now that we're part of a larger company in Okta whose specialty has been in workforce authentication, we can really partner together to figure out because we probably know a lot about the different identities.

(Shiv at 00:34:47) And we can probably ensure our customers that this identity that is trying to log in is verified. And so, you know, you don't need to essentially ask for a password. And so we've done all of, you know, so going back to we've done everything from log in with Magic Links, doing one time passcodes, to supporting these standards such as WebAuthn. And I think the future is going to be, you know, us providing some very unified verified ID such that our customers don't have to ask the customers to use their password and, you know, they can use their primary identifier just to log in because we know so much about the user.

(Shiv at 00:35:34) So I think that's one. And the second thing is we want to do this in a way that's also compliant with privacy. I think customers really care about our privacy. And so this is where, you know, there are solutions today if you look at login providers, what I call social login providers such as Facebook, Google, and others. You know, I think the tricky thing is, well, if you're using those login providers, what is the level of privacy that you're getting with them?

(Shiv at 00:36:06) Right? And so I think on our side of the equation, that'll be something that we can bring uniquely because we have no—we're not using anyone's data for any other nefarious or different business model. Right? Our job is just we want to provide a secure and safe login, and that's really it. And so our use of these different signals and data points is really to provide this frictionless login experience and also verifying that the person is who they say they are.

(Shiv at 00:36:38) So I think we're in a unique position to be able to solve that given that we're already solving for so many of its use cases, and we would be an independent provider doing that. Right? We're not signing with Amazon. We're not signing with Apple. We're not signing with Google or Facebook or whoever. Right? It's really a truly independent service that is there to serve both our customers and their customers.

(Joel Beasley at 00:37:07) That makes a lot of sense about trying to make it as frictionless as possible because I feel like when you require two-factor authentication, that just makes people annoyed sometimes. Right?

(Shiv at 00:37:21) Yeah. And, I mean, look. I'm very familiar with two-factor authentication, and so to me, it's okay.

(Joel Beasley at 00:37:29) Yeah. Yeah.

(Shiv at 00:37:30) But you have to think about, you know, we're all tech savvy, and we use products and phones and log into products all day long. So we're used to that. But I think, you know, I always think of, like, if you're thinking about your family or your aunt or your uncle or your grandparents and, like, their experience with the bank that's now asking for SMS verification. Like, these are all friction points that, you know, in the case of—they have to think about that, that, yes, security is important, but they also don't want to add additional friction along the process. And so I think that's the tricky balance here.

(Joel Beasley at 00:38:09) Right. And if added security means added friction to the sign-in process, I feel like most people are just not going to be secure.

(Shiv at 00:38:18) Yeah.

(Joel Beasley at 00:38:19) Like, if they think of the choice.

(Shiv at 00:38:21) Correct.

(Joel Beasley at 00:38:21) Yeah. Yeah. So how many years do you think we are until passwords are a thing of the past?

(Shiv at 00:38:29) Oh, we've been—I think in the industry, we've been predicting the demise of passwords for quite a while. We are much closer, I think, today than we ever were, simply because, a, lots of people have devices. The world is getting extremely connected, and we have a lot more data signals to verify, perhaps, who you are. And so I think we're much closer to that world. It's really hard to say, is this two or three years away?

(Shiv at 00:39:03) Let me just share some examples. When we—you know, it's funny. When MFA as a—you know, multifactor authentication came out, you would have thought everybody has adopted MFA. Not the case. The adoption is pretty slow. I think about a—I've seen these numbers about a year, year and a half ago. Like, MFA adoption was in the five to 10% range. Okay. So just think about it. You know, as much as we—because technologists, we all love to believe that we built this, so I'm sure everybody will adopt it. But, you know, adoption sometimes takes much, much longer. I would imagine that MFA adoption is much higher today, but still low compared to where it could be. And so I think the same is true of true passwordless, which is I think there are enough solutions out there, and there is enough progress where I think we are starting to see adoption of some of those solutions.

(Shiv at 00:40:07) But I think it's going to take us a few years before we completely get there. And I think that it also varies. Like, I think in other—and you have to take a global view of this too, which is in other markets. Right? You know, email is not even a unique or primary identifier. Right? It tends to be your phone number. And so there, things get easier because you can do one-time codes and things like that. So I think we are making steady progress, but it's hard to say is this going to be a three to five year journey or ten year journey. I think it really depends on adoption of these capabilities.

(Joel Beasley at 00:40:48) Absolutely. And that's a lot harder to predict because, I mean, I feel like the technology is there today to do it. Yeah. It's just a matter of using it, adopting it, and eliminating that friction. But, okay. So I do want to hear about the Okta acquisition a little bit because I know that was still pretty recent. That happened in May. Right?

(Shiv at 00:41:10) Yes.

(Joel Beasley at 00:41:11) Very cool. So what has that been like, and where are you now in the process?

(Shiv at 00:41:18) Well, I think, you know, the acquisition news was very exciting simply because both of us, both companies sort of were solving for the same problem. But we arrived at it, obviously, from—we started at different places. Right? So they started focusing on providing this seamless and secure experience for employees, contractors. And we started with, you know, seamless and secure experience for your customer's customer. So customer identity access management. And the beauty of bringing both of these capabilities together is really together we can, well, we can accelerate these big ambitious goals such as passwordless faster than doing it on our own. And the second thing is we can truly help solve the breadth of use cases. You know, we talk about workforce authentication, customer, and access management. So these are two big use cases and categories, but there are a lot more that are emerging that we also want to solve for.

(Shiv at 00:42:27) So I think bringing both of these capabilities together in a unified fashion helps us address our customers' needs faster. We have complementary capabilities so we can bring unique things to our customers that I don't think anyone else can, frankly, in this space. And, you know, we can achieve these ambitious goals of having a truly independent provider that does passwordless much, much different. And so far, the integration—I mean, the acquisition, obviously, has gone really well by all counts, by our measures internally, obviously. And it's incredibly exciting because we get to dream up a much bigger and more bolder future for the industry. And so I think teams on both sides are equally excited to collaborate, get to know each other, and start solving some of these bigger problems. So that's the journey we're on, and we expect to share a lot more as we continue to refine our vision and sort of specific plans on, well, what happens to the products and platforms and roadmaps.

(Joel Beasley at 00:43:38) That's really cool. I like how a couple times so far you've mentioned that being an independent provider is a real strength for you guys because that's not something I've really thought about in terms of authentication before. But it makes so much sense that you don't want your authentication provider having other lines of business that includes selling data because that's just so scary. Like—

(Shiv at 00:44:07) Yeah. Selling data or, you know, so it's everything from selling data or providing other services too. So I'll just give some examples, like, you know, you have identity services Microsoft provides. You have identity service from AWS. You have identity service from Facebook, from Google, from Amazon. But they all have all these other businesses too. Right? So, you know, they are not truly independent or are not motivated by truly securing our customers or our customers' customers. Right? Because they're, you know, they're operating in so many different businesses and probably have other incentives internally to sway things one way or the other. So we truly believe having this independent platform that is frankly agnostic of any cloud and agnostic of any other downstream business so that we can truly focus on the problem that our customers really care about. And I do think it's a big differentiator for our customers. This notion of being independent is important because we're a critical tier zero service, and you don't want any other objectives to come in the way of that. So I think there—it's a big differentiator, and I think it's important to our customers.

(Joel Beasley at 00:45:30) Absolutely. So, yeah, shout out to all the CTOs listening. Implement Auth0 so my stuff can be safe, please.

(Shiv at 00:45:39) Exactly. We're all consumers at the end of the day. Exactly.

(Joel Beasley at 00:45:43) All right. Well, we're coming up on time. Is there anything that we didn't get out there that we want to make sure we get out before we call the podcast?

(Shiv at 00:45:52) No. I think, you know, well, just a couple of things. We are always looking for feedback and given that you have a very technical audience listening, if there's anything that we can do from a product or service perspective, obviously, we'd love to hear about that. And then, second, you know, this is, like, you know, my fifth or sixth sort of run at building products. And at least the things that I have learned is that all of the things that are not unique to your core business, you should rent or outsource, in this case. It just gives you a lot more velocity in how you can build for your core needs of your customers. And so, you know, things like authentication is just one of those. Like, it's really important. Every app needs it. But, you know, strongly recommend CTOs and companies not to take that on because it's just not your unique differentiator.

(Shiv at 00:47:01) And so, you know, and then beyond that, it's, you know, I think we all talk about authentication. You know? Everybody thinks of login box and login as a service. Obviously, that's the first thing you do. The other thing is as you continue to grow your business or the customers that you're serving, you're going to go on your own identity maturity, if you will, and you'll find that you're going to need a whole lot more down the line in terms of security, compliance, in global scale that a lot of companies don't think about initially. And so, again, that's something that we can easily scale with our customers and provide. So it's another area to also watch out for.

(Joel Beasley at 00:47:45) Yeah. And I think that both of what you just said really tie into each other of planning for the scaling needs of your authentication and just focusing on what you're good at. Because if authentication isn't your differentiating thing, you're not going to have a wide enough perspective to think about those future things. As with really anything, a part of your business that you're not—that's not your core competency. And yeah. I don't know. I feel like that's something that should be so intuitive to just go all in on your core competency and outsource everything else, but not enough companies are doing it.

(Joel Beasley at 00:48:26) Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you would like to hear discussed on the podcast, either add me on LinkedIn, or send me an email [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.